Compare commits

..
Author SHA1 Message Date
Archipelago e3bcd9fca9 Archipelago — open-source initial import 2026-08-12 10:55:49 +00:00
433 changed files with 9518 additions and 27824 deletions
-93
View File
@@ -1,93 +0,0 @@
Copyright 2011 The Montserrat Project Authors (https://github.com/JulietaUla/Montserrat)
This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
http://scripts.sil.org/OFL
-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------
PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.
The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.
DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.
"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).
"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).
"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.
"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.
PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:
1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.
2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.
3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.
5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.
TERMINATION
This license becomes null and void if any of the above conditions are
not met.
DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
+2 -2
View File
@@ -11,8 +11,8 @@ android {
applicationId = "com.archipelago.app"
minSdk = 26
targetSdk = 35
versionCode = 48
versionName = "0.5.28"
versionCode = 45
versionName = "0.5.25"
vectorDrawables {
useSupportLibrary = true
-9
View File
@@ -54,15 +54,6 @@
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="archipelago" android:host="pair" />
</intent-filter>
<!-- Remote-signer pairing deep link (NIP-46, companion 0.5.28):
nostrconnect://<client-pubkey>?relay=...&secret=... — the
node's login QR, hand-off from any QR scanner app. -->
<intent-filter>
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="nostrconnect" />
</intent-filter>
</activity>
<!-- Embedded FIPS mesh node: split-tunnel VpnService (fd00::/8 only),
@@ -1,40 +1,5 @@
package com.archipelago.app
import android.app.Application
import android.os.Looper
import android.webkit.WebView
import com.archipelago.app.data.ServerPreferences
import com.archipelago.app.fips.FipsNative
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.launch
class ArchipelagoApp : Application() {
private val warmupScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
override fun onCreate() {
super.onCreate()
// Warmups that otherwise land inside the first frame:
// - FipsNative.available dlopens the 7 MB Rust core; referenced from
// composition (NESMenu, mesh auto-start), it blocked the UI thread.
// - The first DataStore read gates the nav graph's start destination;
// parsing it here means the launch gate resolves in the first
// emission instead of waiting on cold disk IO.
warmupScope.launch {
FipsNative.available
runCatching { ServerPreferences(this@ArchipelagoApp).launchState.first() }
}
// First WebView construction pays Chromium provider load (~150-400 ms
// cold). Absorb it while the main thread is idle before the kiosk
// needs it, instead of serially after the connection probe.
Looper.getMainLooper().queue.addIdleHandler {
runCatching { WebView(this).destroy() }
false // one-shot
}
}
}
class ArchipelagoApp : Application()
@@ -9,7 +9,6 @@ import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.core.splashscreen.SplashScreen.Companion.installSplashScreen
import com.archipelago.app.ui.navigation.AppNavHost
import com.archipelago.app.ui.screens.releaseKioskWebView
import com.archipelago.app.ui.theme.ArchipelagoTheme
import kotlinx.coroutines.flow.MutableStateFlow
@@ -20,13 +19,7 @@ class MainActivity : ComponentActivity() {
private val pendingPairUri = MutableStateFlow<String?>(null)
override fun onCreate(savedInstanceState: Bundle?) {
// Hold the branded system splash until the nav graph has its launch
// state — without this the splash dropped at the first composed frame,
// which was EMPTY (the DataStore read hadn't landed): splash → black
// flash → UI on every launch.
var navReady = false
val splash = installSplashScreen()
splash.setKeepOnScreenCondition { !navReady }
installSplashScreen()
enableEdgeToEdge()
super.onCreate(savedInstanceState)
pendingPairUri.value = intent?.dataString
@@ -36,7 +29,6 @@ class MainActivity : ComponentActivity() {
AppNavHost(
pairUri = pairUri,
onPairUriConsumed = { pendingPairUri.value = null },
onReady = { navReady = true },
)
}
}
@@ -46,14 +38,4 @@ class MainActivity : ComponentActivity() {
super.onNewIntent(intent)
pendingPairUri.value = intent.dataString
}
override fun onDestroy() {
super.onDestroy()
// Swiped out of recents (or otherwise finished) — let go of the
// retained kiosk WebView so the next launch starts clean. Without
// this the FIPS service keeps the process (and the static WebView)
// alive, and "close the app" no longer restarted it. isFinishing
// keeps config changes (rotation) on the fast reattach path.
if (isFinishing) releaseKioskWebView()
}
}
@@ -1,69 +0,0 @@
package com.archipelago.app
import org.json.JSONObject
/**
* JNI binding to the companion's non-mesh native surface (same
* libarchy_fips_core.so as FipsNative — backup + nostr signer crypto, built
* from Android/rust/archy-fips-core).
*
* Same contract as FipsNative: JSON over strings, failures come back as
* {"error": "…"} rather than exceptions, and [available] is false on ABIs
* the .so isn't built for so every caller can degrade gracefully.
*/
object NativeCore {
val available: Boolean = try {
System.loadLibrary("archy_fips_core")
true
} catch (_: Throwable) {
false
}
// ── Backup (#128): the node's ADR-005 envelope ──────────────────────────
/** Encrypt a JSON payload into an ADR-005 envelope (ChaCha20-Poly1305). */
external fun backupEncrypt(payload: String, passphrase: String): String
/** Decrypt an ADR-005 envelope back to its payload JSON. */
external fun backupDecrypt(envelope: String, passphrase: String): String
// ── NIP-46 remote signer (#139) ─────────────────────────────────────────
/** Generate a fresh nostr key: {"secret","pubkey","npub","nsec"}. */
external fun nostrGenerateSecret(): String
/** Import a key from hex or nsec…: {"secret","pubkey","npub","nsec"}. */
external fun nostrSecretFromAny(secret: String): String
/** Parse nostrconnect://…: {"clientPubkey","relays":[…],"secret","perms","name","url","image"}. */
external fun nostrParseConnectUri(uri: String): String
/**
* Sign `{kind, content, tags, created_at}` with the signer key: returns
* the full signed event JSON. Approval happens BEFORE this call — the
* native side never signs unasked.
*/
external fun nostrSignEvent(secretHex: String, eventJson: String): String
/** NIP-44 v2 encrypt/decrypt; result JSON: {"result": payload} or {"error": …}. */
external fun nostrNip44Encrypt(secretHex: String, peerPub: String, plaintext: String): String
external fun nostrNip44Decrypt(secretHex: String, peerPub: String, payload: String): String
/** NIP-04 fallback (deprecated but still spoken by real clients). */
external fun nostrNip04Encrypt(secretHex: String, peerPub: String, plaintext: String): String
external fun nostrNip04Decrypt(secretHex: String, peerPub: String, payload: String): String
/** True when a native reply is an error envelope. */
fun isErr(json: String): Boolean = try {
JSONObject(json).has("error")
} catch (_: Exception) {
true
}
/** Error text from a native reply, or a generic message if malformed. */
fun errMsg(json: String): String = try {
JSONObject(json).optString("error", "native call failed")
} catch (_: Exception) {
"native call failed"
}
}
@@ -1,229 +0,0 @@
package com.archipelago.app.data
import android.content.Context
import com.archipelago.app.NativeCore
import com.archipelago.app.fips.FipsPreferences
import com.archipelago.app.nostr.NostrSignerPreferences
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.withContext
import org.json.JSONArray
import org.json.JSONObject
/**
* Companion backup & restore (#128) — the phone side of "losing your phone,
* or wiping it to cross a border".
*
* The payload (servers + FIPS identity/peers + signer key + flags) is
* serialized to JSON and sealed into the node's ADR-005 envelope (Argon2id +
* ChaCha20-Poly1305) by the native core — the SAME envelope the node uses,
* not a second format. The passphrase never leaves the encrypt call.
*
* Transport is deliberately boring: a plain .json file the user saves via
* the system file picker (SAF) — on GrapheneOS there is no cloud backup and
* there should be none here either; the file goes wherever the user puts it
* (USB drive, computer, a folder synced their way).
*/
class BackupManager(private val context: Context) {
private val servers = ServerPreferences(context)
private val fips = FipsPreferences(context)
private val signer = NostrSignerPreferences(context)
/** Everything the backup captures, for the restore preview UI. */
data class PayloadSummary(
val serverCount: Int,
val hasFipsIdentity: Boolean,
val hasSignerKey: Boolean,
val appVersion: String,
)
/** What a restore actually did, for the result UI. */
data class RestoreResult(
val serversRestored: Int,
val activeSet: Boolean,
val fipsIdentityRestored: Boolean,
val signerKeyRestored: Boolean,
)
private fun appVersion(): String = try {
context.packageManager.getPackageInfo(context.packageName, 0).versionName ?: ""
} catch (_: Exception) {
""
}
/**
* Assemble the encrypted backup envelope. Runs on IO: DataStore reads
* plus the Argon2id KDF (tens of ms) + AEAD.
*/
suspend fun createBackup(passphrase: String): String = withContext(Dispatchers.IO) {
require(passphrase.isNotEmpty()) { "passphrase required" }
val active = servers.activeServer.first()
val saved = servers.savedServers.first()
val fipsId = fips.identity()
val peers = fips.peersJson()
val partyPeers = fips.partyPeers()
val partyName = fips.partyName()
val partyListen = fips.partyListen()
val signerSecret = signer.secret()
val payload = JSONObject().apply {
put("app", "archipelago-companion")
put("payloadVersion", 1)
put("appVersion", appVersion())
put("createdAt", System.currentTimeMillis() / 1000)
put("servers", JSONArray(saved.map { it.serialize() }))
put("active", active?.serialize() ?: JSONObject.NULL)
if (fipsId != null) {
put("fips", JSONObject().apply {
put("secret", fipsId.secret)
put("npub", fipsId.npub)
put("address", fipsId.address)
put("peers", JSONArray(peers))
put("partyPeers", JSONArray().apply { partyPeers.forEach { put(JSONObject().apply {
put("npub", it.npub); put("ula", it.ula); put("name", it.name)
put("ip", it.ip); put("port", it.port)
}) } })
put("partyName", partyName)
put("partyListen", partyListen)
})
}
if (signerSecret != null) {
put("signer", JSONObject().apply { put("secret", signerSecret) })
}
put("flags", JSONObject().apply {
put("introSeen", servers.introSeen.first())
})
}
val envelope = NativeCore.backupEncrypt(payload.toString(), passphrase)
if (NativeCore.isErr(envelope)) throw BackupException(NativeCore.errMsg(envelope))
envelope
}
/**
* Peek at a decrypted backup (passphrase already checked) to preview what
* a restore would do. Does NOT touch any stored state.
*/
suspend fun readBackup(envelope: String, passphrase: String): Pair<PayloadSummary, JSONObject> =
withContext(Dispatchers.IO) {
val payload = NativeCore.backupDecrypt(envelope, passphrase)
if (NativeCore.isErr(payload)) throw BackupException(NativeCore.errMsg(payload))
val obj = JSONObject(payload)
if (obj.optString("app") != "archipelago-companion") {
throw BackupException("Not a companion backup (this may be a node backup — restore it on the node)")
}
val summary = PayloadSummary(
serverCount = obj.optJSONArray("servers")?.length() ?: 0,
hasFipsIdentity = obj.has("fips"),
hasSignerKey = obj.has("signer"),
appVersion = obj.optString("appVersion", ""),
)
summary to obj
}
/**
* Apply a decrypted backup to this install. Merge semantics — a restore
* never silently destroys what's already here:
*
* - Servers upsert (npub-first, [ServerPreferences.upsertServer]) — same
* identity merges, never duplicates.
* - The backup's active server is set active only when none is.
* - FIPS identity/peers restore only when this phone has none (a phone
* that already paired has a live identity the node peers with; swapping
* it from a backup would strand the current pairing). Peers merge by
* npub otherwise.
* - Signer key restores only when none exists locally.
*/
suspend fun restoreBackup(payload: JSONObject): RestoreResult = withContext(Dispatchers.IO) {
val serverArray = payload.optJSONArray("servers") ?: JSONArray()
var restored = 0
for (i in 0 until serverArray.length()) {
val raw = serverArray.optString(i)
val entry = ServerEntry.deserialize(raw) ?: continue
servers.upsertServer(entry)
restored++
}
var activeSet = false
val activeStr = if (payload.isNull("active")) null else payload.optString("active", "")
val activeEntry = activeStr?.takeIf { it.isNotBlank() }?.let { ServerEntry.deserialize(it) }
if (activeEntry != null && servers.activeServer.first() == null) {
servers.setActiveServer(activeEntry)
activeSet = true
}
// FIPS identity: only adopt when this phone has none.
var fipsRestored = false
val fipsObj = payload.optJSONObject("fips")
if (fipsObj != null && fips.identity() == null) {
val secret = fipsObj.optString("secret")
if (secret.isNotBlank()) {
fips.saveIdentity(
com.archipelago.app.fips.FipsNative.Identity(
secret = secret,
npub = fipsObj.optString("npub"),
address = fipsObj.optString("address"),
)
)
fipsRestored = true
}
// Peers: union by npub with whatever is already here (an empty
// store takes the backup's list wholesale).
val backupPeers = fipsObj.optJSONArray("peers")?.let { arr ->
(0 until arr.length()).joinToString(",", "[", "]") { arr.optString(it) }
} ?: "[]"
fips.mergePeersJson(backupPeers)
val partyArr = fipsObj.optJSONArray("partyPeers")
if (partyArr != null) {
for (i in 0 until partyArr.length()) {
val p = partyArr.optJSONObject(i) ?: continue
val npub = p.optString("npub")
val ula = p.optString("ula")
if (npub.isNotBlank() && ula.isNotBlank()) {
fips.upsertPartyPeer(
com.archipelago.app.fips.PartyPeer(
npub = npub, ula = ula,
name = p.optString("name").ifBlank { "Phone" },
ip = p.optString("ip"), port = p.optInt("port"),
)
)
}
}
}
if (fipsObj.optString("partyName").isNotBlank()) {
fips.setPartyName(fipsObj.optString("partyName"))
}
fips.setPartyListen(fipsObj.optBoolean("partyListen", false))
}
// Signer key: only adopt when none exists locally.
var signerRestored = false
val signerObj = payload.optJSONObject("signer")
if (signerObj != null && signer.secret() == null) {
val secret = signerObj.optString("secret")
if (secret.isNotBlank()) {
signer.saveSecret(secret)
signerRestored = true
}
}
// Flags: a user who completed the intro on the old phone shouldn't
// see it again on the new one.
val flags = payload.optJSONObject("flags")
if (flags?.optBoolean("introSeen", false) == true) {
servers.markIntroSeen()
}
RestoreResult(
serversRestored = restored,
activeSet = activeSet,
fipsIdentityRestored = fipsRestored,
signerKeyRestored = signerRestored,
)
}
class BackupException(message: String) : Exception(message)
}
@@ -9,7 +9,6 @@ import androidx.datastore.preferences.core.stringPreferencesKey
import androidx.datastore.preferences.core.stringSetPreferencesKey
import androidx.datastore.preferences.preferencesDataStore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.map
private val Context.dataStore: DataStore<Preferences> by preferencesDataStore(name = "server_prefs")
@@ -30,18 +29,6 @@ data class ServerEntry(
/** Label to show in lists — the user-given name, or the address if unnamed. */
fun displayName(): String = name.ifBlank { address }
/**
* Is this node reachable over the Archipelago FIPS mesh?
*
* A node that advertised either identity (npub) or a mesh address (ULA)
* came from a FIPS-capable pairing QR. Anything else — a hand-entered LAN
* box, someone else's server behind their own VPN — is a plain HTTP
* target, and the companion must NOT raise its own tunnel for it: Android
* allows exactly one VPN at a time, so doing so would silently take the
* tunnel away from whatever the user actually uses to reach that node.
*/
fun isFipsNode(): Boolean = npub.isNotBlank() || meshIp.isNotBlank()
/** Bracket bare IPv6 literals (the mesh ULA) so they form valid URLs. */
private fun urlHost(host: String): String =
if (host.contains(":") && !host.startsWith("[")) "[$host]" else host
@@ -102,9 +89,9 @@ class ServerPreferences(private val context: Context) {
private val introSeenKey = booleanPreferencesKey("intro_seen")
private val gestureHintSeenKey = booleanPreferencesKey("gesture_hint_seen")
private fun activeServerFrom(prefs: Preferences): ServerEntry? {
val address = prefs[activeAddressKey] ?: return null
return ServerEntry(
val activeServer: Flow<ServerEntry?> = context.dataStore.data.map { prefs ->
val address = prefs[activeAddressKey] ?: return@map null
ServerEntry(
address = address,
useHttps = prefs[activeHttpsKey] ?: false,
port = prefs[activePortKey] ?: "",
@@ -115,52 +102,19 @@ class ServerPreferences(private val context: Context) {
)
}
// distinctUntilChanged on every flow: DataStore emits on EVERY write to the
// file regardless of key, and each spurious emission recomposed whatever
// screen collected it (the kiosk recomposed on gesture-hint writes).
val activeServer: Flow<ServerEntry?> = context.dataStore.data
.map { prefs -> activeServerFrom(prefs) }
.distinctUntilChanged()
val savedServers: Flow<List<ServerEntry>> = context.dataStore.data.map { prefs ->
val raw = prefs[savedServersKey] ?: emptySet()
// Sorted so set-iteration order can't produce a structurally different
// list for the same servers (which defeats distinctUntilChanged).
raw.mapNotNull { ServerEntry.deserialize(it) }.sortedBy { it.displayName() }
}.distinctUntilChanged()
raw.mapNotNull { ServerEntry.deserialize(it) }
}
val introSeen: Flow<Boolean> = context.dataStore.data.map { prefs ->
prefs[introSeenKey] ?: false
}.distinctUntilChanged()
}
/** One-shot flag for the three-finger-hold teaching overlay. */
val gestureHintSeen: Flow<Boolean> = context.dataStore.data.map { prefs ->
prefs[gestureHintSeenKey] ?: false
}.distinctUntilChanged()
/** Everything the nav graph needs to pick a start destination, derived
* from ONE DataStore emission. Collecting introSeen and activeServer as
* two separate flows let them land in different frames — the intro flag
* could resolve first and flash the Connect screen at a paired user
* before the active server arrived. */
data class LaunchState(
val introSeen: Boolean,
val activeServer: ServerEntry?,
/** Every saved node — the launch gate needs the COUNT to decide
* whether to ask which one to connect to. */
val savedServers: List<ServerEntry>,
)
val launchState: Flow<LaunchState> = context.dataStore.data.map { prefs ->
LaunchState(
introSeen = prefs[introSeenKey] ?: false,
activeServer = activeServerFrom(prefs),
savedServers = (prefs[savedServersKey] ?: emptySet())
.mapNotNull { ServerEntry.deserialize(it) }
.sortedBy { it.displayName() },
)
}.distinctUntilChanged()
}
suspend fun setActiveServer(server: ServerEntry) {
context.dataStore.edit { prefs ->
@@ -37,7 +37,6 @@ class ArchyVpnService : VpnService() {
private val scope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
private var warmerJob: Job? = null
private var handoffKickJob: Job? = null
// Seamless transport handoff (Wi-Fi ⇄ 5G ⇄ future BLE). Without this the
// tunnel's underlying network stays pinned to the interface that was
@@ -205,20 +204,14 @@ class ArchyVpnService : VpnService() {
/**
* Track the phone's default network and hand the mesh over to it as the
* phone roams (Wi-Fi ⇄ 5G). Two actions per change:
* phone roams (Wi-Fi ⇄ 5G, and later BLE). Two actions per change:
* 1. setUnderlyingNetworks(new) — the tunnel's packets follow the live
* network instead of dying on the one it launched with.
* 2. re-home the mesh — kick the session warmer so discovery + sessions
* rebuild on the new path; the node's own fast-reconnect (1s) redials
* peers over the new route.
* rebuild on the new path immediately; the node's own fast-reconnect
* (1s) redials peers over the new route.
* onAvailable also fires for the FIRST network, which is how the initial
* underlying network gets set.
*
* requestNetwork, NOT registerDefaultNetworkCallback: this app is routed
* through its own TUN, so its "default network" IS the VPN — a default
* callback fires once with our own tunnel and never again on Wi-Fi ⇄ 5G.
* A NetworkRequest's default capabilities include NOT_VPN, so requestNetwork
* tracks the best real transport underneath instead.
*/
private fun registerNetworkHandoff() {
if (networkCallback != null) return
@@ -243,6 +236,10 @@ class ArchyVpnService : VpnService() {
}
}
networkCallback = cb
// requestNetwork tracks the BEST network of the request; when the
// phone moves Wi-Fi→5G the callback re-fires onAvailable with the new
// one. (registerDefaultNetworkCallback would also work; requestNetwork
// lets us extend to BLE-capable transports later.)
runCatching { cm.requestNetwork(request, cb) }
}
@@ -254,22 +251,13 @@ class ArchyVpnService : VpnService() {
runCatching { setUnderlyingNetworks(arrayOf(network)) }
if (changed && FipsNative.isRunning()) {
Log.i(TAG, "network handoff → re-homing mesh on new default network")
// Coalesced, not immediate: marginal Wi-Fi flaps the default
// Wi-Fi ⇄ cell in bursts, and an aggressive warmer pass per flip
// meant near-constant session churn — the "reconnects a lot"
// report. The re-pin above still happens on every change; only
// the rediscovery kick waits for the network to hold still.
handoffKickJob?.cancel()
handoffKickJob = scope.launch {
delay(2_000)
if (FipsNative.isRunning()) startSessionWarmer()
}
// Fresh warmer pass drives immediate rediscovery/session rebuild
// on the new path instead of waiting out dead-link timeouts.
startSessionWarmer()
}
}
private fun unregisterNetworkHandoff() {
handoffKickJob?.cancel()
handoffKickJob = null
val cm = connectivityManager
val cb = networkCallback
if (cm != null && cb != null) {
@@ -3,10 +3,8 @@ package com.archipelago.app.fips
import android.content.Context
import android.content.Intent
import android.net.VpnService
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.withContext
/**
* Glue between pairing and the mesh: persists the node peer from a scanned
@@ -38,27 +36,20 @@ object FipsManager {
* No-op on devices without the native lib (non-arm64).
*/
suspend fun registerNode(context: Context, info: FipsPairInfo?, alias: String) {
if (info == null) return
// Every caller reaches this from a Compose scope — i.e. the MAIN
// thread — the instant a pairing QR decodes. Everything below is
// main-hostile: touching FipsNative dlopens the 7 MB mesh core,
// ensureIdentity runs native ed25519 keygen, and VpnService.prepare
// is a binder round-trip. Left on the UI thread it froze the frame
// right after the camera got the code, which reads as "the scanner
// is slow" when the scan itself already succeeded.
val consent = withContext(Dispatchers.IO) {
if (!FipsNative.available) return@withContext null
val prefs = FipsPreferences(context)
ensureIdentity(prefs)
prefs.upsertNodePeer(info, alias)
peersDirty = true
// Restart the mesh with the new peer RIGHT NOW when consent already
// exists — relying on the consentNeeded collector left a running
// mesh on the OLD peer list whenever the collector wasn't active
// (fresh pairings looked dead until a full app restart).
VpnService.prepare(context) == null
} ?: return
if (consent) startService(context) else _consentNeeded.value = true
if (info == null || !FipsNative.available) return
val prefs = FipsPreferences(context)
ensureIdentity(prefs)
prefs.upsertNodePeer(info, alias)
peersDirty = true
// Restart the mesh with the new peer RIGHT NOW when consent already
// exists — relying on the consentNeeded collector left a running
// mesh on the OLD peer list whenever the collector wasn't active
// (fresh pairings looked dead until a full app restart).
if (VpnService.prepare(context) == null) {
startService(context)
} else {
_consentNeeded.value = true
}
}
/** Generate-once mesh identity. Returns null only if the RNG/native fails. */
@@ -76,17 +67,11 @@ object FipsManager {
* through AppNavHost instead.
*/
suspend fun autoStartIfReady(context: Context) {
// Self-dispatching for the same reason as registerNode: callers reach
// this from Compose scopes, and dlopen + binder must not ride the UI
// thread (the connect path calls it while the scanner is still up).
val ready = withContext(Dispatchers.IO) {
if (!FipsNative.available) return@withContext false
val prefs = FipsPreferences(context)
if (prefs.identity() == null || !prefs.hasPeers()) return@withContext false
// consent missing — don't prompt here
VpnService.prepare(context) == null
}
if (ready) startService(context)
if (!FipsNative.available) return
val prefs = FipsPreferences(context)
if (prefs.identity() == null || !prefs.hasPeers()) return
if (VpnService.prepare(context) != null) return // consent missing — don't prompt here
startService(context)
}
fun startService(context: Context) {
@@ -89,38 +89,6 @@ class FipsPreferences(private val context: Context) {
suspend fun hasPeers(): Boolean = JSONArray(peersJson()).length() > 0
/**
* Union the stored node peers with a backup's peer list, matched by
* npub — the backup's copy wins for the same npub (its addresses are what
* the restored identity pairs against). Used by companion restore (#128)
* after [saveIdentity] adopted the backup's mesh identity.
*/
suspend fun mergePeersJson(incomingJson: String) {
context.fipsDataStore.edit { prefs ->
val current = JSONArray(prefs[peersKey] ?: "[]")
val incoming = try {
JSONArray(incomingJson)
} catch (_: Exception) {
JSONArray()
}
val incomingNpubs = mutableSetOf<String>()
val merged = JSONArray()
for (i in 0 until incoming.length()) {
val peer = incoming.optJSONObject(i) ?: continue
val npub = peer.optString("npub")
if (npub.isNotBlank()) {
incomingNpubs.add(npub)
merged.put(peer)
}
}
for (i in 0 until current.length()) {
val peer = current.optJSONObject(i) ?: continue
if (peer.optString("npub") !in incomingNpubs) merged.put(peer)
}
prefs[peersKey] = merged.toString()
}
}
// ── Mesh Party (phone↔phone) ────────────────────────────────────────────
suspend fun partyListen(): Boolean =
@@ -1,445 +0,0 @@
package com.archipelago.app.nostr
import android.content.Context
import com.archipelago.app.NativeCore
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.withContext
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.Response
import okhttp3.WebSocket
import okhttp3.WebSocketListener
import org.json.JSONArray
import org.json.JSONObject
import java.security.SecureRandom
import java.util.concurrent.TimeUnit
import java.util.concurrent.atomic.AtomicReference
/**
* NIP-46 remote-signer session (#139) — the phone side, wire-faithful to
* rust-nostr's reference bunker (`signer/nostr-connect/src/signer.rs`),
* which the node's login flow will interoperate with:
*
* 1. Client (the node's login page) shows a `nostrconnect://` QR.
* 2. We scan it, connect to its relay, subscribe to kind-24133 events
* p-tagged to our signer key, and send a `connect` request carrying the
* secret (the client validates it and answers "ack").
* 3. Requests arrive as NIP-44-encrypted kind-24133 events; we respond over
* the same channel. `sign_event` is the one method that never runs
* without a human tapping Approve on this phone.
*
* The session lives while the app is around (the login handshake takes
* seconds); there is no background service in v1 and no remembered-session
* auto-reconnect (research doc flow C — deferred deliberately).
*/
object BunkerManager {
sealed class SignerState {
/** Native core unavailable (e.g. x86 emulator) — signing impossible. */
object Unavailable : SignerState()
/** Key exists, no session. */
object Idle : SignerState()
/** No signer key generated/imported yet. */
object NoKey : SignerState()
data class Connecting(val relay: String) : SignerState()
/** Connect request sent; waiting for the client to ack. */
data class AwaitingClient(val relay: String, val clientName: String) : SignerState()
/** Handshake complete — this is the state where requests are answered. */
data class Ready(val relay: String, val clientName: String) : SignerState()
data class Failed(val reason: String) : SignerState()
}
/** One signature request awaiting a human decision. */
data class PendingRequest(
val id: String,
val method: String,
val clientPubkey: String,
val clientName: String,
val kind: Long?,
val content: String?,
/** Formatted tag lines for the approval card. */
val tags: List<String>,
val createdAt: Long?,
/** The full unsigned event JSON handed to the native signer on approve. */
val unsignedEventJson: String,
)
private val _state = MutableStateFlow<SignerState>(SignerState.Idle)
val state: StateFlow<SignerState> = _state.asStateFlow()
private val _pending = MutableStateFlow<PendingRequest?>(null)
val pending: StateFlow<PendingRequest?> = _pending.asStateFlow()
private val client = OkHttpClient.Builder()
.connectTimeout(10, TimeUnit.SECONDS)
.pingInterval(25, TimeUnit.SECONDS) // relay keepalive
.build()
private data class Session(
val socket: WebSocket,
val relay: String,
/** The client's pubkey (hex) from the nostrconnect URI. */
val clientPubkey: String,
val clientName: String,
/** The pairing secret — echoed back during handshake, then kept for
* validating an incoming `connect` from the same client. */
val secret: String,
/** Our connect request id, to match the client's ack response. */
val connectRequestId: String,
/** Our signer secret (hex). */
val signerSecretHex: String,
/** Our signer pubkey (hex). */
val signerPubkeyHex: String,
/** Event ids already handled (relays may redeliver). */
val seen: MutableSet<String> = java.util.concurrent.ConcurrentHashMap.newKeySet(),
)
private val session = AtomicReference<Session?>(null)
/** Refresh Idle/NoKey state (suspend; call from a coroutine — DataStore reads hit disk). */
suspend fun refreshState(context: Context) {
if (!NativeCore.available) {
_state.value = SignerState.Unavailable
return
}
if (session.get() != null) return
val prefs = NostrSignerPreferences(context.applicationContext)
_state.value =
if (prefs.secret() == null) SignerState.NoKey else SignerState.Idle
}
/**
* Pair from a scanned or deep-linked `nostrconnect://…` URI. Returns a
* user-presentable error on failure, or null on success (state moves to
* Connecting → AwaitingClient).
*/
suspend fun pair(context: Context, uri: String): String? {
if (!NativeCore.available) return "Signing is unavailable on this device"
val appContext = context.applicationContext
return withContext(Dispatchers.IO) {
val parsed = JSONObject(NativeCore.nostrParseConnectUri(uri.trim()))
if (parsed.has("error")) return@withContext parsed.getString("error")
val prefs = NostrSignerPreferences(appContext)
val secret = prefs.secret()
?: return@withContext "No signer key yet — generate or import one first"
val info = JSONObject(NativeCore.nostrSecretFromAny(secret))
if (info.has("error")) return@withContext info.getString("error")
val clientPubkey = parsed.getString("clientPubkey")
val relays = mutableListOf<String>()
parsed.optJSONArray("relays")?.let { arr -> for (i in 0 until arr.length()) relays.add(arr.optString(i)) }
val clientName = parsed.optString("name").ifBlank { "client" }
val pairSecret = parsed.getString("secret")
if (relays.isEmpty()) return@withContext "The pairing code carries no relay to reach the client on"
teardown()
var lastError = "no relay could be reached"
for (relay in relays) {
_state.value = SignerState.Connecting(relay)
val opened = openSession(
relay, clientPubkey, clientName, pairSecret, secret, info,
)
if (opened != null) {
session.set(opened)
prefs.savePairing(
NostrSignerPreferences.Pairing(clientPubkey, relay, clientName)
)
_state.value = SignerState.AwaitingClient(relay, clientName)
return@withContext null
}
lastError = "relay $relay did not answer"
}
_state.value = SignerState.Failed(lastError)
lastError
}
}
/** Re-establish the last saved pairing without a fresh QR. */
suspend fun resume(context: Context): String? {
if (!NativeCore.available) return "Signing is unavailable on this device"
val appContext = context.applicationContext
return withContext(Dispatchers.IO) {
val prefs = NostrSignerPreferences(appContext)
val pairing = prefs.lastPairing()
?: return@withContext "Nothing to resume — no saved pairing"
val secret = prefs.secret()
?: return@withContext "No signer key"
val info = JSONObject(NativeCore.nostrSecretFromAny(secret))
if (info.has("error")) return@withContext info.getString("error")
teardown()
_state.value = SignerState.Connecting(pairing.relay)
val opened = openSession(
pairing.relay, pairing.clientPubkey, pairing.name,
secret = "", signerSecretHex = secret, info = info,
)
if (opened == null) {
_state.value = SignerState.Failed("relay ${pairing.relay} did not answer")
return@withContext "Could not reach ${pairing.relay}"
}
session.set(opened)
_state.value = SignerState.AwaitingClient(pairing.relay, pairing.name)
null
}
}
fun unpair() {
teardown()
_state.value = SignerState.Idle
}
private fun teardown() {
session.getAndSet(null)?.socket?.close(1000, "unpaired")
_pending.value = null
}
private fun randomId(): String {
val bytes = ByteArray(8)
SecureRandom().nextBytes(bytes)
return bytes.joinToString("") { "%02x".format(it) }
}
private fun openSession(
relay: String,
clientPubkey: String,
clientName: String,
secret: String,
signerSecretHex: String,
info: JSONObject,
): Session? {
val signerPubkeyHex = info.getString("pubkey")
val connectRequestId = randomId()
// The listener needs the Session, the Session needs the WebSocket:
// bind through a holder set right after newWebSocket returns (OkHttp
// invokes onOpen on its own dispatcher after the network round-trip,
// i.e. always after the bind below).
val holder = AtomicReference<Session?>()
val request = Request.Builder().url(relay).build()
val socket = client.newWebSocket(request, object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
val s = holder.get() ?: return
// Subscribe to requests addressed to us (p-tag filter), from
// now — no history replay of stale login attempts.
webSocket.send(
"""["REQ","${s.connectRequestId}sub",{"kinds":[24133],"#p":["${s.signerPubkeyHex}"],"since":${epochSecs() - 120}}]"""
)
// Handshake: the signer sends `connect` carrying the secret
// (rust-nostr's NostrConnectRemoteSigner.send_connect_ack —
// the exact frame the node's client waits for).
val content = JSONObject().apply {
put("id", s.connectRequestId)
put("method", "connect")
put("params", JSONArray().put(s.signerPubkeyHex).put(s.secret))
}.toString()
if (!sendEncrypted(s, content)) {
_state.value = SignerState.Failed("Could not encrypt the connect message")
}
}
override fun onMessage(webSocket: WebSocket, text: String) {
val s = session.get() ?: return
handleRelayMessage(s, text)
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
if (session.get()?.socket === webSocket) {
_state.value = SignerState.Failed(t.message ?: "relay connection failed")
session.getAndSet(null)
}
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (session.get()?.socket === webSocket) {
_state.value = SignerState.Idle
session.getAndSet(null)
}
}
})
val s = Session(
socket = socket,
relay = relay,
clientPubkey = clientPubkey,
clientName = clientName,
secret = secret,
connectRequestId = connectRequestId,
signerSecretHex = signerSecretHex,
signerPubkeyHex = signerPubkeyHex,
)
holder.set(s)
return s
}
private fun epochSecs(): Long = System.currentTimeMillis() / 1000
/** Encrypt a JSON-RPC frame to the peer and publish it as kind 24133. */
private fun sendEncrypted(s: Session, json: String): Boolean {
val enc = NativeCore.nostrNip44Encrypt(s.signerSecretHex, s.clientPubkey, json)
if (NativeCore.isErr(enc)) return false
val payload = JSONObject(enc).getString("result")
val event = JSONObject().apply {
put("kind", 24133)
put("content", payload)
put("tags", JSONArray().put(JSONArray().put("p").put(s.clientPubkey)))
put("created_at", epochSecs())
}.toString()
val signed = NativeCore.nostrSignEvent(s.signerSecretHex, event)
if (NativeCore.isErr(signed)) return false
return s.socket.send("""["EVENT",$signed]""")
}
private fun handleRelayMessage(s: Session, text: String) {
val arr = try {
JSONArray(text)
} catch (_: Exception) {
return
}
if (arr.length() == 0) return
when (arr.optString(0)) {
"EVENT" -> {
val event = arr.optJSONObject(2) ?: return
if (event.optLong("kind") != 24133L) return
val id = event.optString("id")
if (id.isNotEmpty() && !s.seen.add(id)) return
val author = event.optString("pubkey")
if (author != s.clientPubkey) return // not our client
handleClientEvent(s, author, event.optString("content"))
}
// OK / CLOSED / NOTICE: nothing actionable for the bunker in v1.
}
}
private fun handleClientEvent(s: Session, author: String, content: String) {
// NIP-44 is the mandated transport; NIP-04 stays as receive fallback
// for clients that still speak the deprecated scheme.
val plain = run {
val nip44 = NativeCore.nostrNip44Decrypt(s.signerSecretHex, author, content)
if (!NativeCore.isErr(nip44)) JSONObject(nip44).getString("result") else {
val nip04 = NativeCore.nostrNip04Decrypt(s.signerSecretHex, author, content)
if (!NativeCore.isErr(nip04)) JSONObject(nip04).getString("result") else return
}
}
val msg = try {
JSONObject(plain)
} catch (_: Exception) {
return
}
val id = msg.optString("id")
val method = msg.optString("method", "")
if (method.isNotEmpty()) {
when (method) {
"connect" -> {
val params = msg.optJSONArray("params") ?: return
// Param 0 must be OUR pubkey (client is connecting to us,
// not some other bunker through this session).
val target = params.optString(0)
val givenSecret = params.optString(1)
val authorized = target == s.signerPubkeyHex &&
(s.secret.isBlank() || givenSecret == s.secret || givenSecret.isBlank())
if (authorized) {
respond(s, id, result = "ack")
_state.value = SignerState.Ready(s.relay, s.clientName)
} else {
respond(s, id, error = "unauthorized")
}
}
"get_public_key" -> respond(s, id, result = s.signerPubkeyHex)
"describe" -> respond(s, id, result = "connect get_public_key sign_event ping")
"ping" -> respond(s, id, result = "pong")
"sign_event" -> {
val params = msg.optJSONArray("params") ?: return
val eventJson = params.optString(0)
val ev = try {
JSONObject(eventJson)
} catch (_: Exception) {
respond(s, id, error = "malformed event")
return
}
// Never overwrite a pending request silently — a second
// tap on the node would otherwise cancel the visible one.
if (_pending.value == null) {
_pending.value = PendingRequest(
id = id,
method = method,
clientPubkey = author,
clientName = s.clientName,
kind = if (ev.has("kind") && !ev.isNull("kind")) ev.optLong("kind") else null,
content = if (ev.has("content") && !ev.isNull("content")) ev.optString("content") else null,
tags = formatTags(ev.optJSONArray("tags")),
createdAt = if (ev.has("created_at") && !ev.isNull("created_at")) ev.optLong("created_at") else null,
unsignedEventJson = eventJson,
)
} else {
respond(s, id, error = "busy")
}
}
else -> respond(s, id, error = "not authorized")
}
} else if (msg.has("result") || msg.has("error")) {
// A response to OUR connect request (the client's ack).
if (id == s.connectRequestId) {
if (msg.has("error")) {
_state.value = SignerState.Failed("Client rejected the connection: ${msg.optString("error")}")
} else if (msg.optString("result") == "ack") {
_state.value = SignerState.Ready(s.relay, s.clientName)
}
}
}
}
/** Approve the pending request: sign and send the result. */
suspend fun approve(): Boolean {
val s = session.get() ?: return false
val req = _pending.value ?: return false
val ok = withContext(Dispatchers.IO) {
val signed = NativeCore.nostrSignEvent(s.signerSecretHex, req.unsignedEventJson)
if (NativeCore.isErr(signed)) {
respond(s, req.id, error = "signing failed")
false
} else {
// Result is the signed event, JSON-stringified per the spec.
respond(s, req.id, result = signed)
}
}
_pending.value = null
return ok
}
/** Deny the pending request with an explicit error. */
fun deny() {
val s = session.get() ?: return
val req = _pending.value ?: return
respond(s, req.id, error = "denied")
_pending.value = null
}
/** Send a JSON-RPC response frame to the client. True when the WS send worked. */
private fun respond(s: Session, id: String, result: String? = null, error: String? = null): Boolean {
val frame = JSONObject().apply {
put("id", id)
if (error != null) put("error", error)
if (result != null) put("result", result)
}.toString()
return sendEncrypted(s, frame)
}
private fun formatTags(tags: JSONArray?): List<String> {
tags ?: return emptyList()
val out = mutableListOf<String>()
for (i in 0 until tags.length()) {
val tag = tags.optJSONArray(i) ?: continue
val parts = mutableListOf<String>()
for (j in 0 until tag.length()) parts.add(tag.optString(j))
out.add(parts.joinToString(" "))
}
return out
}
}
@@ -1,95 +0,0 @@
package com.archipelago.app.nostr
import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import androidx.datastore.preferences.preferencesDataStore
import com.archipelago.app.NativeCore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.flow.map
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import org.json.JSONObject
private val Context.signerDataStore: DataStore<Preferences> by preferencesDataStore(name = "nostr_signer")
/**
* Storage for the phone-side NIP-46 remote signer (#139): the signer secret
* key (hex) and the last pairing, so a re-opened app can resume a session
* without re-scanning the node's QR.
*
* Same plaintext-DataStore model as the FIPS secret (app-private storage,
* no extra OS keystore ceremony — the node login password lives the same way
* in ServerPreferences); the nsec grants the ability to sign as this identity,
* never node login.
*/
class NostrSignerPreferences(private val context: Context) {
private val secretKey = stringPreferencesKey("signer_secret")
private val clientPubkeyKey = stringPreferencesKey("pair_client_pubkey")
private val clientRelayKey = stringPreferencesKey("pair_client_relay")
private val clientNameKey = stringPreferencesKey("pair_client_name")
/** The signer secret (hex) or null when no key exists yet. */
suspend fun secret(): String? = context.signerDataStore.data.first()[secretKey]
val secretFlow: Flow<String?> = context.signerDataStore.data
.map { it[secretKey] }
.distinctUntilChanged()
suspend fun saveSecret(hex: String) {
context.signerDataStore.edit { it[secretKey] = hex.trim() }
}
/** Generate a fresh signer key (fails if the native core is missing). */
suspend fun generateSecret(): JSONObject = withContext(Dispatchers.IO) {
val json = NativeCore.nostrGenerateSecret()
val obj = JSONObject(json)
if (obj.has("error")) throw IllegalStateException(obj.getString("error"))
saveSecret(obj.getString("secret"))
obj
}
/** Import a secret from hex or nsec…; returns the parsed key info. */
suspend fun importSecret(raw: String): JSONObject = withContext(Dispatchers.IO) {
val json = NativeCore.nostrSecretFromAny(raw.trim())
val obj = JSONObject(json)
if (obj.has("error")) throw IllegalArgumentException(obj.getString("error"))
saveSecret(obj.getString("secret"))
obj
}
data class Pairing(val clientPubkey: String, val relay: String, val name: String)
suspend fun lastPairing(): Pairing? {
val prefs = context.signerDataStore.data.first()
val pubkey = prefs[clientPubkeyKey] ?: return null
val relay = prefs[clientRelayKey] ?: return null
if (pubkey.isBlank() || relay.isBlank()) return null
return Pairing(pubkey, relay, prefs[clientNameKey] ?: "")
}
suspend fun savePairing(pairing: Pairing) {
context.signerDataStore.edit {
it[clientPubkeyKey] = pairing.clientPubkey
it[clientRelayKey] = pairing.relay
it[clientNameKey] = pairing.name
}
}
suspend fun clearPairing() {
context.signerDataStore.edit {
it.remove(clientPubkeyKey)
it.remove(clientRelayKey)
it.remove(clientNameKey)
}
}
suspend fun wipeKey() {
context.signerDataStore.edit { it.remove(secretKey) }
}
}
@@ -1,294 +0,0 @@
package com.archipelago.app.ui.components
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Restore
import androidx.compose.material.icons.filled.Save
import androidx.compose.material3.Icon
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import com.archipelago.app.data.BackupManager
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.SuccessGreen
import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.launch
import kotlinx.coroutines.withContext
import java.text.SimpleDateFormat
import java.util.Date
import java.util.Locale
/**
* Backup & Restore (#128) — the hub's BACKUP sub-page (same container as
* Nodes/FIPS), the phone side of losing your phone or wiping it to cross a
* border. See docs/companion-backup-restore.md for the envelope and merge
* semantics; this composable is the flow only.
*/
@Composable
internal fun BackupSection() {
val context = LocalContext.current
val scope = rememberCoroutineScope()
val manager = remember { BackupManager(context) }
var passphrase by remember { mutableStateOf("") }
var confirm by remember { mutableStateOf("") }
var status by remember { mutableStateOf<String?>(null) }
var statusError by remember { mutableStateOf(false) }
var busy by remember { mutableStateOf(false) }
// Decrypted backup awaiting the user's go-ahead (restore flow).
var restorePreview by remember { mutableStateOf<Pair<BackupManager.PayloadSummary, org.json.JSONObject>?>(null) }
fun say(msg: String, error: Boolean) {
status = msg
statusError = error
}
val exportLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.CreateDocument("application/json")
) { uri ->
if (uri == null) return@rememberLauncherForActivityResult
scope.launch {
busy = true
try {
val envelope = manager.createBackup(passphrase)
withContext(Dispatchers.IO) {
context.contentResolver.openOutputStream(uri)?.use { out ->
out.write(envelope.toByteArray())
} ?: throw BackupManager.BackupException("could not open the destination file")
}
say("Saved — keep the file and the passphrase somewhere safe.", false)
} catch (e: Exception) {
say(e.message ?: "backup failed", true)
} finally {
busy = false
}
}
}
val importLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument()
) { uri ->
if (uri == null) return@rememberLauncherForActivityResult
scope.launch {
busy = true
try {
val envelope = withContext(Dispatchers.IO) {
context.contentResolver.openInputStream(uri)?.use { it.readBytes().decodeToString() }
?: throw BackupManager.BackupException("could not read the selected file")
}
val (summary, payload) = manager.readBackup(envelope, passphrase)
restorePreview = summary to payload
} catch (e: Exception) {
say(e.message ?: "restore failed", true)
} finally {
busy = false
}
}
}
Column(verticalArrangement = Arrangement.spacedBy(10.dp)) {
SectionCopy(
"An encrypted copy of everything this phone holds — nodes and their passwords, " +
"your mesh identity, the remote-signer key. Same envelope your node uses (ADR-005), " +
"one passphrase, no cloud."
)
// ── Create a backup ──────────────────────────────────────────────
SectionHeader(Icons.Default.Save, "Create a backup")
GlassField(
value = passphrase,
onValueChange = { passphrase = it },
placeholder = "Passphrase",
visualTransformation = androidx.compose.ui.text.input.PasswordVisualTransformation(),
)
GlassField(
value = confirm,
onValueChange = { confirm = it },
placeholder = "Repeat passphrase",
visualTransformation = androidx.compose.ui.text.input.PasswordVisualTransformation(),
)
SectionHint("The passphrase cannot be recovered — a backup nobody can open is a paperweight.")
WideAction(
text = if (busy) "Working…" else "Save backup file",
onClick = {
if (busy) return@WideAction
if (passphrase.length < 8) {
say("Use at least 8 characters — this passphrase guards every secret in the app.", true)
return@WideAction
}
if (passphrase != confirm) {
say("The two passphrases don't match.", true)
return@WideAction
}
val stamp = SimpleDateFormat("yyyyMMdd-HHmm", Locale.US).format(Date())
exportLauncher.launch("archy-companion-backup-$stamp.json")
},
)
Spacer(Modifier.height(2.dp))
// ── Restore a backup ─────────────────────────────────────────────
SectionHeader(Icons.Default.Restore, "Restore a backup")
SectionHint(
"Nothing is overwritten: nodes merge by identity, and the mesh identity and " +
"signer key only restore when this phone has none."
)
WideAction(
text = if (busy) "Working…" else "Choose backup file",
onClick = {
if (busy) return@WideAction
if (passphrase.isEmpty()) {
say("Enter the backup's passphrase first.", true)
return@WideAction
}
importLauncher.launch(arrayOf("application/json"))
},
)
restorePreview?.let { (summary, payload) ->
Spacer(Modifier.height(2.dp))
Column(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(14.dp))
.background(Color.White.copy(alpha = 0.04f))
.border(1.dp, Color.White.copy(alpha = 0.08f), RoundedCornerShape(14.dp))
.padding(12.dp),
verticalArrangement = Arrangement.spacedBy(6.dp),
) {
Text(
"Backup verified${if (summary.appVersion.isNotBlank()) " (made by v${summary.appVersion})" else ""}",
color = SuccessGreen, fontSize = 13.sp, fontWeight = FontWeight.SemiBold,
)
SummaryRow("Nodes", summary.serverCount.toString())
if (summary.hasFipsIdentity) SummaryRow("Mesh identity", "included")
if (summary.hasSignerKey) SummaryRow("Remote-signer key", "included")
WideAction(
text = if (busy) "Restoring…" else "Restore onto this phone",
onClick = {
if (busy) return@WideAction
scope.launch {
busy = true
try {
val result = manager.restoreBackup(payload)
restorePreview = null
passphrase = ""
confirm = ""
say(
"Restored ${result.serversRestored} node(s)" +
(if (result.activeSet) ", set active" else "") +
(if (result.fipsIdentityRestored) ", mesh identity" else "") +
(if (result.signerKeyRestored) ", signer key" else "") +
". Restart the app to reconnect.",
false,
)
} catch (e: Exception) {
say(e.message ?: "restore failed", true)
} finally {
busy = false
}
}
},
)
}
}
status?.takeIf { it.isNotBlank() }?.let { msg ->
Text(
msg,
color = if (statusError) Color(0xFFFF6B6B) else SuccessGreen,
fontSize = 12.sp,
textAlign = TextAlign.Center,
modifier = Modifier.fillMaxWidth(),
)
}
}
}
@Composable
internal fun SectionHeader(icon: androidx.compose.ui.graphics.vector.ImageVector, title: String) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(10.dp),
) {
Icon(icon, contentDescription = null, tint = BitcoinOrange, modifier = Modifier.size(18.dp))
Text(title, color = TextPrimary, fontSize = 15.sp, fontWeight = FontWeight.SemiBold)
}
}
@Composable
internal fun SectionCopy(text: String) {
Text(text, color = TextMuted, fontSize = 12.sp, lineHeight = 16.sp)
}
@Composable
internal fun SectionHint(text: String) {
Text(text, color = TextMuted.copy(alpha = 0.8f), fontSize = 10.sp, lineHeight = 13.sp)
}
/** Wide orange-outline action button in the menu's visual language. */
@Composable
internal fun WideAction(
text: String,
onClick: () -> Unit,
icon: androidx.compose.ui.graphics.vector.ImageVector? = null,
) {
Row(
Modifier
.fillMaxWidth()
.height(44.dp)
.clip(RoundedCornerShape(12.dp))
.background(BitcoinOrange.copy(alpha = 0.15f))
.border(1.dp, BitcoinOrange.copy(alpha = 0.4f), RoundedCornerShape(12.dp))
.clickable { onClick() },
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.Center,
) {
if (icon != null) {
Icon(icon, contentDescription = null, tint = BitcoinOrange, modifier = Modifier.size(16.dp))
Spacer(Modifier.size(8.dp))
}
Text(text, color = BitcoinOrange, fontSize = 13.sp, fontWeight = FontWeight.Bold)
}
}
@Composable
internal fun SummaryRow(label: String, value: String) {
Row(
Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.SpaceBetween,
) {
Text(label, color = TextMuted, fontSize = 12.sp)
Text(value, color = TextPrimary, fontSize = 12.sp, fontWeight = FontWeight.Medium)
}
}
@@ -1,46 +1,37 @@
package com.archipelago.app.ui.components
import androidx.compose.foundation.Image
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.res.painterResource
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import com.archipelago.app.R
import com.archipelago.app.ui.screens.PixelArtLogo
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.SurfaceBlack
import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
/**
* Full-screen loader shown while the app is dialing a node.
*
* Two faces, because they are two different promises:
* - [mesh] `true` — a FIPS node: the branded "F*CK IPs" screen, because what
* is loading really is a connection to a cryptographic identity, not an IP.
* - [mesh] `false` — a plain node reached over the network like anything
* else. No mesh branding at all: claiming the mesh is carrying a connection
* it isn't is worse than an anonymous spinner.
* The branded "F*CK IPs" full-screen loader — shown whenever the app is
* dialing the node over the mesh (relaunch race, post-scan first connect),
* instead of an anonymous spinner. The point of the brand: what's loading
* is a connection to a cryptographic identity, not an IP.
*/
@Composable
fun MeshLoadingScreen(
mesh: Boolean = true,
nodeName: String = "",
done: Boolean = false,
) {
fun MeshLoadingScreen(message: String = "Dialing your node by its key — no IPs harmed") {
Box(
Modifier
.fillMaxSize()
@@ -48,39 +39,39 @@ fun MeshLoadingScreen(
contentAlignment = Alignment.Center,
) {
Column(horizontalAlignment = Alignment.CenterHorizontally) {
// The app's own badge — the same ringed mark as the launcher icon
// and the system splash, so launch → splash → this screen is one
// continuous identity.
Image(
painter = painterResource(id = R.drawable.ic_logo),
contentDescription = null,
modifier = Modifier.size(112.dp),
)
Spacer(Modifier.height(24.dp))
// The brand's circle-container logo (as on the connect screen /
// web login): pixel-art "a" centered in a black disc.
Box(
Modifier
.size(120.dp)
.clip(androidx.compose.foundation.shape.CircleShape)
.background(Color.Black)
.border(
1.dp,
Color.White.copy(alpha = 0.14f),
androidx.compose.foundation.shape.CircleShape,
),
contentAlignment = Alignment.Center,
) {
PixelArtLogo(Modifier.size(64.dp))
}
Spacer(Modifier.height(20.dp))
Text(
text = if (mesh) "F*CK IPS MESH" else "CONNECTING",
text = "F*CK IPs MESH",
color = BitcoinOrange,
fontSize = 16.sp,
fontSize = 18.sp,
fontWeight = FontWeight.Bold,
letterSpacing = 4.sp,
)
Spacer(Modifier.height(10.dp))
Spacer(Modifier.height(8.dp))
Text(
text = when {
mesh -> "Dialing your node by its key — no IPs harmed"
nodeName.isNotBlank() -> "Reaching $nodeName"
else -> "Reaching your node"
},
color = if (done) TextPrimary else TextMuted,
text = message,
color = TextMuted,
fontSize = 13.sp,
textAlign = TextAlign.Center,
modifier = Modifier.padding(horizontal = 32.dp),
)
Spacer(Modifier.height(28.dp))
SlidingLoader(
modifier = Modifier.width(220.dp),
done = done,
)
Spacer(Modifier.height(24.dp))
CircularProgressIndicator(color = BitcoinOrange)
}
}
}
@@ -30,9 +30,6 @@ import androidx.compose.material.icons.filled.Dashboard
import androidx.compose.material.icons.filled.Dns
import androidx.compose.material.icons.filled.Groups
import androidx.compose.material.icons.filled.Keyboard
import androidx.compose.material.icons.filled.RestartAlt
import androidx.compose.material.icons.filled.SettingsBackupRestore
import androidx.compose.material.icons.filled.Key
import androidx.compose.material.icons.filled.SportsEsports
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.shape.RoundedCornerShape
@@ -73,7 +70,6 @@ import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import com.archipelago.app.R
import com.archipelago.app.data.ServerEntry
import com.archipelago.app.ui.screens.restartCompanionApp
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.SurfaceDark
import com.archipelago.app.ui.theme.TextMuted
@@ -108,62 +104,22 @@ fun NESMenu(
onKeyboard: () -> Unit,
onBackToWebView: (() -> Unit)? = null,
onMeshParty: (() -> Unit)? = null,
// Remote-signer pairing request (nostrconnect://… deep link, or a scan):
// non-null opens the hub on the signer sub-page and pairs. Consumed once
// the signer section hands it back via [onSignerPairHandled].
signerPairRequest: String? = null,
onSignerPairHandled: () -> Unit = {},
) {
// Pairing state is latched here (not passed straight through) so the
// source can clear itself while the request stays alive until consumed.
var pendingSignerPair by remember { mutableStateOf<String?>(null) }
var signerScan by remember { mutableStateOf(false) }
LaunchedEffect(signerPairRequest) {
if (signerPairRequest != null) pendingSignerPair = signerPairRequest
}
AnimatedVisibility(visible = visible, enter = fadeIn(), exit = fadeOut()) {
// Contained hub overlay: a centred glass panel (not full-screen) that
// holds the card page and its sub-pages (Nodes, FIPS, Backup, Signer)
// and scrolls inside its own bounds when content is tall. Tapping the
// dimmed backdrop dismisses.
// holds the card page and its sub-pages (Nodes, FIPS) and scrolls
// inside its own bounds when content is tall. Tapping the dimmed
// backdrop dismisses.
Box(
Modifier.fillMaxSize().background(Color.Black.copy(alpha = 0.7f))
.clickable(indication = null, interactionSource = remember { MutableInteractionSource() }) { onDismiss() },
contentAlignment = Alignment.Center,
) {
AnimatedVisibility(visible = visible, enter = fadeIn() + scaleIn(initialScale = 0.95f), exit = fadeOut() + scaleOut(targetScale = 0.95f)) {
MenuPanel(
servers, activeServer, onDismiss, onSelectServer, onAddServer, onScanQr,
onEditServer, onRemoveServer, onRemote, onKeyboard, onBackToWebView, onMeshParty,
signerPairUri = pendingSignerPair,
onSignerScan = { signerScan = true },
onSignerPairHandled = {
pendingSignerPair = null
onSignerPairHandled()
},
)
MenuPanel(servers, activeServer, onDismiss, onSelectServer, onAddServer, onScanQr, onEditServer, onRemoveServer, onRemote, onKeyboard, onBackToWebView, onMeshParty)
}
}
}
// Pairing-QR scanner for the signer sub-page — a full-screen glass
// modal hosted OUTSIDE the hub panel so it isn't clipped to the panel's
// bounds (same layering the pairing scanner gets from WebViewScreen).
QrGlassModal(
visible = signerScan && visible,
title = "Scan pairing QR",
status = null,
idleHint = "Point at the nostrconnect QR the node or client shows",
permissionRationale = "Camera access is needed to scan the pairing code",
onDismiss = { signerScan = false },
onDecoded = { text ->
if (text.startsWith("nostrconnect://")) {
signerScan = false
pendingSignerPair = text
}
},
)
}
@Composable
@@ -180,9 +136,6 @@ private fun MenuPanel(
onKeyboard: () -> Unit,
onBackToWebView: (() -> Unit)?,
onMeshParty: (() -> Unit)?,
signerPairUri: String?,
onSignerScan: () -> Unit,
onSignerPairHandled: () -> Unit,
) {
var showAdd by remember { mutableStateOf(false) }
// The saved server being edited, or null when adding a new one.
@@ -221,10 +174,9 @@ private fun MenuPanel(
.widthIn(max = 420.dp)
.fillMaxWidth()
.padding(horizontal = 20.dp)
// Cap height at 70% of the screen — a ~15% breathing margin top
// and bottom — the panel wraps short content and scrolls inside
// its own bounds when a sub-page outgrows this.
.heightIn(max = (LocalConfiguration.current.screenHeightDp * 0.70f).dp)
// Cap height just short of the full screen; the panel wraps short
// content and only scrolls in the rare case it outgrows this.
.heightIn(max = (LocalConfiguration.current.screenHeightDp * 0.92f).dp)
.clip(RoundedCornerShape(PANEL_R))
.background(PanelBg.copy(alpha = 0.86f))
.border(1.dp, PanelBorder, RoundedCornerShape(PANEL_R))
@@ -247,13 +199,7 @@ private fun MenuPanel(
IconRound(Icons.AutoMirrored.Filled.ArrowBack, "Back") { resetForm(); page = HubPage.HUB }
Spacer(Modifier.width(12.dp))
Text(
when (page) {
HubPage.NODES -> "Nodes"
HubPage.FIPS -> "FIPS Mesh"
HubPage.BACKUP -> "Backup & Restore"
HubPage.SIGNER -> "Remote Signer"
HubPage.HUB -> "Menu"
},
if (page == HubPage.NODES) "Nodes" else "FIPS Mesh",
color = TextPrimary, fontSize = 20.sp, fontWeight = FontWeight.SemiBold, letterSpacing = 1.sp,
)
}
@@ -275,54 +221,14 @@ private fun MenuPanel(
HubCard(Icons.Default.Dns, "Nodes", activeServer?.displayName() ?: "Add or switch servers") {
page = HubPage.NODES
}
// Mesh oversight only when this session is actually on the
// mesh. Offering "FIPS Mesh" while connected to a plain node
// (whose traffic is going nowhere near the tunnel) advertises
// a connection the user doesn't have.
if (FipsNative.available && activeServer?.isFipsNode() == true) {
if (FipsNative.available) {
HubCard(Icons.Default.Bolt, "FIPS Mesh", "Mesh identity & status") { page = HubPage.FIPS }
}
if (onMeshParty != null) {
HubCard(Icons.Default.Groups, "Mesh Party", "Phone-to-phone chat & beam") { onMeshParty() }
}
// Backup & Restore (#128): the phone side of losing your phone
// or wiping it to cross a border — encrypted export file, no cloud.
HubCard(Icons.Default.SettingsBackupRestore, "Backup & Restore", "Encrypted export for a wiped phone") { page = HubPage.BACKUP }
// Remote Signer (#139): hold a nostr key on the phone and
// approve/deny remote signature requests (NIP-46).
HubCard(Icons.Default.Key, "Remote Signer", "Approve signatures for your node") { page = HubPage.SIGNER }
// Dark/Classic style lives on the remote/keyboard screen next to
// the settings button — not here.
// Small version chip at the hub's foot — the one place a
// connected user can always check what build they're on.
val hubContext = LocalContext.current
// Restart: the dashboard WebView is retained across
// remote ⇄ dashboard (that's the point), which also means a
// wedged page can't be cleared by leaving the screen. This
// throws the page away and relaunches the app clean — the mesh
// service keeps running.
HubCard(Icons.Default.RestartAlt, "Restart", "Reload the app from scratch") {
onDismiss()
restartCompanionApp(hubContext)
}
val versionLabel = remember {
runCatching {
hubContext.packageManager
.getPackageInfo(hubContext.packageName, 0).versionName
}.getOrNull()?.let { "Companion v$it" } ?: ""
}
if (versionLabel.isNotEmpty()) {
Text(
versionLabel,
color = TextMuted.copy(alpha = 0.6f),
fontSize = 11.sp,
letterSpacing = 1.sp,
textAlign = TextAlign.Center,
modifier = Modifier.fillMaxWidth().padding(top = 6.dp),
)
}
}
HubPage.NODES -> {
@@ -330,11 +236,6 @@ private fun MenuPanel(
val active = server.serialize() == activeServer?.serialize()
MenuItem(
label = server.displayName(),
// FIPS nodes carry their mesh ULA — the address Termux
// (or any other app) can reach over the split-tunnel,
// from anywhere. Tap to copy; the node's npub stays
// visible in the FIPS Mesh page.
subtitle = server.meshIp.takeIf { it.isNotBlank() },
selected = active,
onClick = { onSelectServer(server) },
onEdit = { startEdit(server) },
@@ -454,23 +355,11 @@ private fun MenuPanel(
HubPage.FIPS -> {
FipsSection(embedded = true)
}
HubPage.BACKUP -> {
BackupSection()
}
HubPage.SIGNER -> {
SignerSection(
pairUri = signerPairUri,
onScan = onSignerScan,
onPairHandled = onSignerPairHandled,
)
}
}
}
}
private enum class HubPage { HUB, NODES, FIPS, BACKUP, SIGNER }
private enum class HubPage { HUB, NODES, FIPS }
/** Big tappable destination card for the hub page: icon + title + subtitle. */
@Composable
@@ -657,52 +546,26 @@ private fun MenuItem(
onClick: () -> Unit,
onEdit: (() -> Unit)? = null,
onRemove: (() -> Unit)? = null,
/** Optional second line (the node's mesh ULA); tapping it copies. */
subtitle: String? = null,
) {
val clipboard = LocalClipboardManager.current
Row(
Modifier
.fillMaxWidth()
// Rows with a second line grow to fit it.
.then(if (subtitle == null) Modifier.height(ROW_H) else Modifier.heightIn(min = ROW_H))
.height(ROW_H)
.clip(RoundedCornerShape(ROW_R))
.background(if (selected) BitcoinOrange.copy(alpha = 0.12f) else RowBg)
.border(1.dp, if (selected) BitcoinOrange.copy(alpha = 0.4f) else RowBorder, RoundedCornerShape(ROW_R))
.clickable { onClick() }
.padding(horizontal = 16.dp)
.then(if (subtitle == null) Modifier else Modifier.padding(vertical = 8.dp)),
.padding(horizontal = 16.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween,
) {
Column(Modifier.weight(1f)) {
Text(
label,
color = if (selected) BitcoinOrange else labelColor,
fontSize = 16.sp,
fontWeight = FontWeight.Medium,
)
if (subtitle != null) {
Row(
Modifier
.padding(top = 2.dp)
.clip(RoundedCornerShape(6.dp))
.clickable { clipboard.setText(AnnotatedString(subtitle)) }
.padding(horizontal = 4.dp, vertical = 2.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Text(
subtitle,
color = TextMuted,
fontSize = 10.sp,
fontFamily = androidx.compose.ui.text.font.FontFamily.Monospace,
maxLines = 1,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
)
Text("⧉", color = TextMuted.copy(alpha = 0.7f), fontSize = 11.sp, modifier = Modifier.padding(start = 6.dp))
}
}
}
Text(
label,
color = if (selected) BitcoinOrange else labelColor,
fontSize = 16.sp,
fontWeight = FontWeight.Medium,
modifier = Modifier.weight(1f),
)
if (onEdit != null) {
Text(
"✎",
@@ -724,7 +587,7 @@ private fun MenuItem(
/** Glass text field with centered input text. */
@Composable
internal fun GlassField(
private fun GlassField(
value: String,
onValueChange: (String) -> Unit,
placeholder: String,
@@ -1,24 +1,14 @@
package com.archipelago.app.ui.components
import android.Manifest
import android.content.Context
import android.content.pm.PackageManager
import android.hardware.camera2.CameraCharacteristics
import android.hardware.camera2.CameraManager
import android.hardware.camera2.CameraMetadata
import android.hardware.camera2.CaptureRequest
import android.os.Process
import androidx.activity.compose.BackHandler
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.camera.camera2.interop.Camera2Interop
import androidx.camera.camera2.interop.ExperimentalCamera2Interop
import androidx.camera.core.CameraSelector
import androidx.camera.core.FocusMeteringAction
import androidx.camera.core.ImageAnalysis
import androidx.camera.core.ImageProxy
import androidx.camera.core.Preview
import androidx.camera.core.SurfaceOrientedMeteringPointFactory
import androidx.camera.lifecycle.ProcessCameraProvider
import androidx.camera.view.PreviewView
import androidx.compose.animation.AnimatedVisibility
@@ -26,26 +16,22 @@ import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.clickable
import androidx.compose.foundation.gestures.detectTapGestures
import androidx.compose.foundation.interaction.MutableInteractionSource
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.aspectRatio
import androidx.compose.foundation.layout.defaultMinSize
import androidx.compose.foundation.layout.WindowInsets
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.layout.safeDrawing
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.windowInsetsPadding
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.FlashOff
import androidx.compose.material.icons.filled.FlashOn
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
@@ -60,15 +46,10 @@ import androidx.compose.runtime.rememberUpdatedState
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.hapticfeedback.HapticFeedbackType
import androidx.compose.ui.input.pointer.pointerInput
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.platform.LocalHapticFeedback
import androidx.compose.ui.platform.LocalLifecycleOwner
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.unit.dp
import androidx.compose.ui.viewinterop.AndroidView
@@ -78,26 +59,23 @@ import com.archipelago.app.data.PairResult
import com.archipelago.app.data.ServerQrParser
import com.archipelago.app.ui.screens.GlassButton
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
import com.google.zxing.BarcodeFormat
import com.google.zxing.BinaryBitmap
import com.google.zxing.DecodeHintType
import com.google.zxing.MultiFormatReader
import com.google.zxing.NotFoundException
import com.google.zxing.PlanarYUVLuminanceSource
import com.google.zxing.common.GlobalHistogramBinarizer
import com.google.zxing.common.HybridBinarizer
import com.google.zxing.qrcode.QRCodeReader
import kotlinx.coroutines.delay
import java.util.concurrent.Executors
/**
* Scans the node pairing QR (docs/companion-pairing-qr.md) and reports the
* decoded server entry. Handles the camera permission itself; foreign/invalid
* codes show a hint in the status strip and scanning continues.
*
* Visually this is the SAME glass modal the web wallet uses (neode-ui's
* WalletScanModal) — scrim, glass card, square preview, orange viewfinder,
* status strip — so pairing from the app and scanning from the web UI look
* like one product rather than two different scanners.
* Full-screen camera overlay that scans the node pairing QR
* (docs/companion-pairing-qr.md) and reports the decoded server entry.
* Handles the camera permission itself; foreign/invalid codes show a hint
* and scanning continues.
*/
@Composable
fun QrScannerOverlay(
@@ -105,14 +83,28 @@ fun QrScannerOverlay(
onDismiss: () -> Unit,
onServerScanned: (PairResult.Success) -> Unit,
) {
val haptics = LocalHapticFeedback.current
val context = LocalContext.current
var hasPermission by remember {
mutableStateOf(
ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
)
}
var hintRes by remember { mutableStateOf<Int?>(null) }
var handled by remember { mutableStateOf(false) }
val permissionLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.RequestPermission()
) { granted -> hasPermission = granted }
LaunchedEffect(visible) {
if (visible) {
handled = false
hintRes = null
val granted = ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
hasPermission = granted
if (!granted) permissionLauncher.launch(Manifest.permission.CAMERA)
}
}
@@ -124,331 +116,125 @@ fun QrScannerOverlay(
}
}
QrGlassModal(
visible = visible,
title = stringResource(R.string.scan_node_qr),
status = hintRes?.let { stringResource(it) to true },
idleHint = stringResource(R.string.scan_qr_hint),
permissionRationale = stringResource(R.string.camera_permission_needed),
onDismiss = onDismiss,
onDecoded = { text ->
if (!handled) {
when (val result = ServerQrParser.parse(text)) {
is PairResult.Success -> {
handled = true
// Confirm the hit in the hand — the eye is still on the
// code, not on the screen.
haptics.performHapticFeedback(HapticFeedbackType.LongPress)
onServerScanned(result)
}
is PairResult.UnsupportedVersion -> hintRes = R.string.update_app_for_qr
is PairResult.Invalid -> hintRes = R.string.invalid_pairing_qr
}
}
},
)
}
/**
* The shared native scanner shell — one visual contract for every camera the
* app opens (pairing, wallet), mirroring neode-ui's WalletScanModal so the
* native and web scanners are indistinguishable:
* - black/60 scrim, dismiss on tap-outside
* - glass card (rounded 24, white/10 hairline) capped at 420dp
* - square preview with the 62% orange viewfinder and a darkened surround
* - a status strip that carries hints and errors
* - an optional footer (the wallet's "Upload image")
*/
@Composable
internal fun QrGlassModal(
visible: Boolean,
title: String,
// message + isError; null falls back to [idleHint].
status: Pair<String, Boolean>?,
idleHint: String,
permissionRationale: String,
onDismiss: () -> Unit,
onDecoded: (String) -> Unit,
footer: @Composable (() -> Unit)? = null,
) {
val context = LocalContext.current
var hasPermission by remember {
mutableStateOf(
ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
)
}
var torchOn by remember { mutableStateOf(false) }
var hasTorch by remember { mutableStateOf(false) }
val permissionLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.RequestPermission()
) { granted -> hasPermission = granted }
LaunchedEffect(visible) {
if (visible) {
val granted = ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
hasPermission = granted
if (!granted) permissionLauncher.launch(Manifest.permission.CAMERA)
} else {
torchOn = false
}
}
AnimatedVisibility(visible = visible, enter = fadeIn(), exit = fadeOut()) {
BackHandler { onDismiss() }
Box(
Modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.6f))
.clickable(
interactionSource = remember { MutableInteractionSource() },
indication = null,
onClick = onDismiss,
),
contentAlignment = Alignment.Center,
.background(Color.Black),
) {
Column(
Modifier
.padding(16.dp)
.widthIn(max = 420.dp)
.fillMaxWidth()
.clip(RoundedCornerShape(24.dp))
.background(Color(0xF212151C))
.border(1.dp, Color.White.copy(alpha = 0.10f), RoundedCornerShape(24.dp))
.clickable(
interactionSource = remember { MutableInteractionSource() },
indication = null,
onClick = {}, // swallow — only the scrim dismisses
)
.padding(24.dp),
) {
Row(
Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween,
) {
Text(
text = title,
style = MaterialTheme.typography.titleLarge,
fontWeight = FontWeight.SemiBold,
color = Color.White,
)
IconButton(onClick = onDismiss) {
Icon(
Icons.Default.Close,
stringResource(R.string.close),
tint = Color.White.copy(alpha = 0.7f),
)
}
}
Spacer(Modifier.height(8.dp))
Box(
Modifier
.fillMaxWidth()
.aspectRatio(1f)
.clip(RoundedCornerShape(12.dp))
.background(Color.Black.copy(alpha = 0.4f))
.border(1.dp, Color.White.copy(alpha = 0.10f), RoundedCornerShape(12.dp)),
contentAlignment = Alignment.Center,
) {
if (hasPermission) {
CameraQrPreview(
onDecoded = onDecoded,
torchOn = torchOn,
onTorchAvailable = { hasTorch = it },
)
// Viewfinder — 62% of the preview, matching the web
// modal's .scan-viewfinder, and matching the ROI the
// decoder actually reads (QR_ROI_FRACTION).
Box(
Modifier
.fillMaxSize(QR_ROI_FRACTION)
.border(
2.dp,
BitcoinOrange.copy(alpha = 0.85f),
RoundedCornerShape(16.dp),
),
)
if (hasTorch) {
IconButton(
onClick = { torchOn = !torchOn },
modifier = Modifier
.align(Alignment.TopEnd)
.padding(6.dp)
.clip(RoundedCornerShape(50))
.background(Color.Black.copy(alpha = 0.45f)),
) {
Icon(
if (torchOn) Icons.Default.FlashOn else Icons.Default.FlashOff,
stringResource(
if (torchOn) R.string.torch_off else R.string.torch_on,
),
tint = if (torchOn) BitcoinOrange else Color.White.copy(alpha = 0.85f),
)
if (hasPermission) {
CameraQrPreview(
onDecoded = { text ->
if (!handled) {
when (val result = ServerQrParser.parse(text)) {
is PairResult.Success -> {
handled = true
onServerScanned(result)
}
is PairResult.UnsupportedVersion -> hintRes = R.string.update_app_for_qr
is PairResult.Invalid -> hintRes = R.string.invalid_pairing_qr
}
}
} else {
Column(
Modifier.padding(horizontal = 24.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
text = permissionRationale,
color = Color.White.copy(alpha = 0.7f),
style = MaterialTheme.typography.bodyMedium,
textAlign = TextAlign.Center,
)
GlassButton(
text = stringResource(R.string.grant_camera_access),
onClick = { permissionLauncher.launch(Manifest.permission.CAMERA) },
modifier = Modifier.fillMaxWidth().height(48.dp),
)
}
}
}
Spacer(Modifier.height(16.dp))
},
)
// Aim frame
Box(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(8.dp))
.background(Color.White.copy(alpha = 0.05f))
.padding(12.dp)
.defaultMinSize(minHeight = 24.dp),
contentAlignment = Alignment.Center,
.align(Alignment.Center)
.size(260.dp)
.border(2.dp, BitcoinOrange.copy(alpha = 0.85f), RoundedCornerShape(20.dp)),
)
} else {
Column(
Modifier
.align(Alignment.Center)
.padding(horizontal = 32.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(16.dp),
) {
Text(
text = status?.first?.takeIf { it.isNotBlank() } ?: idleHint,
style = MaterialTheme.typography.bodySmall,
color = if (status?.second == true) {
Color(0xFFF87171)
} else {
Color.White.copy(alpha = 0.6f)
},
text = stringResource(R.string.camera_permission_needed),
color = TextPrimary,
style = MaterialTheme.typography.bodyLarge,
textAlign = TextAlign.Center,
)
GlassButton(
text = stringResource(R.string.grant_camera_access),
onClick = { permissionLauncher.launch(Manifest.permission.CAMERA) },
modifier = Modifier.fillMaxWidth().height(56.dp),
)
}
}
// Top bar: title + close
Row(
Modifier
.fillMaxWidth()
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(horizontal = 8.dp, vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween,
) {
Text(
text = stringResource(R.string.scan_node_qr),
color = TextPrimary,
style = MaterialTheme.typography.titleMedium,
modifier = Modifier.padding(start = 12.dp),
)
IconButton(onClick = onDismiss) {
Icon(Icons.Default.Close, stringResource(R.string.close), tint = TextPrimary)
}
}
// Bottom hints
Column(
Modifier
.align(Alignment.BottomCenter)
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(horizontal = 32.dp, vertical = 24.dp),
horizontalAlignment = Alignment.CenterHorizontally,
) {
hintRes?.let { res ->
Text(
text = stringResource(res),
color = BitcoinOrange,
style = MaterialTheme.typography.bodyMedium,
textAlign = TextAlign.Center,
)
Spacer(Modifier.height(8.dp))
}
if (hasPermission) {
Text(
text = stringResource(R.string.scan_qr_hint),
color = TextMuted,
style = MaterialTheme.typography.bodyMedium,
textAlign = TextAlign.Center,
)
}
if (footer != null) {
Spacer(Modifier.height(16.dp))
footer()
}
}
}
}
}
/**
* Warm the CameraX provider and the ZXing decode path before the user ever
* asks for a scan, so opening the scanner doesn't pay provider init + class
* loading on the critical path. Does NOT open the camera: no permission is
* needed, no LED lights up, nothing is recorded — [ProcessCameraProvider]
* init is process-wide and cached, and the synthetic decode below just walks
* a blank 32x32 frame to class-load the binarizer/detector.
*
* Called once per process from the kiosk WebView (first page load) and by the
* page via `ArchipelagoQr.prewarm()`.
*/
internal fun prewarmQrScanner(context: Context) {
if (!qrPrewarmed.compareAndSet(false, true)) return
val app = context.applicationContext
runCatching { ProcessCameraProvider.getInstance(app) }
// Off the UI thread: the first decode attempt loads a dozen ZXing classes.
Executors.newSingleThreadExecutor().let { exec ->
exec.execute {
runCatching {
val blank = ByteArray(32 * 32)
val reader = MultiFormatReader().apply {
setHints(mapOf(DecodeHintType.POSSIBLE_FORMATS to listOf(BarcodeFormat.QR_CODE)))
}
val source = PlanarYUVLuminanceSource(blank, 32, 32, 0, 0, 32, 32, false)
reader.decodeWithState(BinaryBitmap(HybridBinarizer(source)))
}
}
exec.shutdown()
}
}
private val qrPrewarmed = java.util.concurrent.atomic.AtomicBoolean(false)
/**
* Fraction of the preview's shorter edge that both the on-screen viewfinder
* and the decoder's region of interest use. Keeping them identical is the
* point: the user aims at the box, and the box is exactly what gets decoded.
*/
internal const val QR_ROI_FRACTION = 0.62f
/**
* Shared by the pairing scanner and the wallet scan modal.
*
* [torchOn] drives the flash; [onTorchAvailable] reports whether this camera
* has one at all (the caller only draws its toggle when it does).
*
* ## Why this looks the way it does
*
* The previous version hunted: a scheduled tick alternated the optical zoom
* between 1x and 1.5x and re-fired `startFocusAndMetering(...disableAutoCancel())`
* every 2 seconds. Both are camera-hostile:
*
* - Every zoom step restarts AE/AF convergence, so the sensor spends the
* seconds right after it delivering soft frames — precisely the frames the
* decoder needs to be sharp. The visible symptom is the "zooms in and out
* and takes ages" report.
* - `disableAutoCancel()` leaves AF **locked** at whatever it converged on
* instead of handing the lens back to continuous AF, so a re-aim never
* refocused on its own; the next timer tick then kicked off another full
* sweep from a locked position — a lens that hunts forever.
*
* A stock camera app does neither. It leaves CameraX's continuous AF alone,
* refocuses on tap, and never touches zoom. This does the same, with one
* concession to the "hand-held QR is a static scene" case: if nothing has
* decoded for a few seconds, ONE auto-cancelling focus nudge is issued (and
* then not again for a while), which re-arms continuous AF instead of
* fighting it.
*/
/** Shared by the pairing scanner and the wallet scan modal. */
@Composable
internal fun CameraQrPreview(
onDecoded: (String) -> Unit,
torchOn: Boolean = false,
onTorchAvailable: (Boolean) -> Unit = {},
) {
internal fun CameraQrPreview(onDecoded: (String) -> Unit) {
val context = LocalContext.current
val lifecycleOwner = LocalLifecycleOwner.current
val currentOnDecoded by rememberUpdatedState(onDecoded)
val currentOnTorchAvailable by rememberUpdatedState(onTorchAvailable)
var camera by remember { mutableStateOf<androidx.camera.core.Camera?>(null) }
val previewView = remember {
PreviewView(context).apply {
scaleType = PreviewView.ScaleType.FILL_CENTER
// TextureView, not the SurfaceView default: SurfaceView punches a
// hole in the window, which black-flashes inside Compose fades and
// ignores rounded-corner clipping (the glass modal).
// ignores rounded-corner clipping (wallet modal).
implementationMode = PreviewView.ImplementationMode.COMPATIBLE
}
}
// Set by the analyzer on every decode; the focus nudge below reads it to
// tell "nothing in view" from "reading fine, leave the camera alone".
val lastDecodeAt = remember { java.util.concurrent.atomic.AtomicLong(0L) }
// A tap-to-focus wins over the periodic centre AF for a few seconds.
val lastTapFocusAt = remember { java.util.concurrent.atomic.AtomicLong(0L) }
DisposableEffect(Unit) {
// Analysis runs at display priority: the decode thread competes with
// the FIPS mesh service's native workers in this same process, and a
// background-priority analyzer is exactly how a sharp, well-framed
// code still takes seconds to land.
val analysisExecutor = Executors.newSingleThreadExecutor { r ->
Thread {
Process.setThreadPriority(Process.THREAD_PRIORITY_DISPLAY)
r.run()
}.apply { name = "qr-analyzer" }
}
val analysisExecutor = Executors.newSingleThreadExecutor()
val mainExecutor = ContextCompat.getMainExecutor(context)
val providerFuture = ProcessCameraProvider.getInstance(context)
var provider: ProcessCameraProvider? = null
@@ -457,18 +243,15 @@ internal fun CameraQrPreview(
providerFuture.addListener({
val p = providerFuture.get()
provider = p
val previewBuilder = Preview.Builder()
tuneForBarcodes(previewBuilder, context)
val preview = previewBuilder.build().also {
val preview = Preview.Builder().build().also {
it.setSurfaceProvider(previewView.surfaceProvider)
}
// Dense Lightning-invoice QRs need BOTH enough pixels per module and
// sharp focus. 1280x720 left dense invoices undecodable while sparse
// address QRs still read — the "scanner doesn't pick up invoices"
// report. 1920x1080 roughly doubles module resolution. The analyzer
// never binarizes the full 2 MP: it reads the centre ROI at this
// resolution (for dense codes) and the whole frame at half of it
// (for coverage), so the big frame costs little.
// sharp focus. 1280x720 + a far-focused camera (e.g. Pixel 9a's main
// lens, which won't focus close) left dense invoices undecodable
// while sparse address QRs still read — the "scanner doesn't pick up
// invoices" report. 1920x1080 roughly doubles module resolution so a
// QR held at the camera's actual focus distance still resolves.
@Suppress("DEPRECATION")
val analysis = ImageAnalysis.Builder()
.setTargetResolution(android.util.Size(1920, 1080))
@@ -477,47 +260,25 @@ internal fun CameraQrPreview(
.also {
it.setAnalyzer(
analysisExecutor,
QrCodeAnalyzer { text ->
lastDecodeAt.set(System.currentTimeMillis())
mainExecutor.execute { currentOnDecoded(text) }
},
QrCodeAnalyzer { text -> mainExecutor.execute { currentOnDecoded(text) } },
)
}
try {
p.unbindAll()
val cam = p.bindToLifecycle(lifecycleOwner, CameraSelector.DEFAULT_BACK_CAMERA, preview, analysis)
camera = cam
currentOnTorchAvailable(cam.cameraInfo.hasFlashUnit())
// Start the clock at bind time so the nudge below waits for the
// user to actually aim before it does anything.
lastDecodeAt.set(System.currentTimeMillis())
// Centre point, normalized — valid before the view is measured.
val point = SurfaceOrientedMeteringPointFactory(1f, 1f).createPoint(0.5f, 0.5f)
// A one-shot AF action puts the lens in AUTO — i.e. LOCKED —
// until it auto-cancels. The default 5s lock is far too long
// here: it spans exactly the window where the user is swinging
// the phone towards the code, and a locked lens cannot follow
// them. Hand control back after 1s so CONTINUOUS_PICTURE (set
// explicitly in tuneForBarcodes) does the real work, which is
// what actually tracks a moving aim.
val focusAction = FocusMeteringAction.Builder(point, FocusMeteringAction.FLAG_AF)
.setAutoCancelDuration(1, java.util.concurrent.TimeUnit.SECONDS)
.build()
var lastNudgeAt = 0L
// Force a centre autofocus on a repeating tick. A hand-held QR is
// a static scene, so continuous-AF often never retriggers and the
// lens sits at its resting (far) focus — fatal for dense codes.
// A normalized centre point works before the view is measured.
val point = androidx.camera.core.SurfaceOrientedMeteringPointFactory(1f, 1f)
.createPoint(0.5f, 0.5f)
val focusAction = androidx.camera.core.FocusMeteringAction.Builder(
point,
androidx.camera.core.FocusMeteringAction.FLAG_AF,
).disableAutoCancel().build()
focusScheduler.scheduleWithFixedDelay({
val now = System.currentTimeMillis()
// The nudge only exists for the one case continuous AF
// genuinely misses: the phone held perfectly still on a
// code while the lens sits at its resting focus, with no
// scene change to trigger a sweep.
if (now - lastDecodeAt.get() > 2_000 &&
now - lastNudgeAt > 3_000 &&
now - lastTapFocusAt.get() > 3_000
) {
lastNudgeAt = now
runCatching { cam.cameraControl.startFocusAndMetering(focusAction) }
}
}, 1, 1, java.util.concurrent.TimeUnit.SECONDS)
runCatching { cam.cameraControl.startFocusAndMetering(focusAction) }
}, 0, 2, java.util.concurrent.TimeUnit.SECONDS)
} catch (_: Exception) {
// Camera unavailable — the user can dismiss and enter details manually.
}
@@ -525,251 +286,66 @@ internal fun CameraQrPreview(
onDispose {
focusScheduler.shutdownNow()
runCatching { camera?.cameraControl?.enableTorch(false) }
camera = null
provider?.unbindAll()
analysisExecutor.shutdown()
}
}
// Torch follows the caller's state (and switches off when the view goes).
LaunchedEffect(camera, torchOn) {
runCatching { camera?.cameraControl?.enableTorch(torchOn) }
}
AndroidView(
factory = { previewView },
modifier = Modifier
.fillMaxSize()
// Tap-to-focus: the ROI assumes the code is centred; a tap lets the
// user point at one that isn't, or re-trigger AF the instant
// they've framed it.
.pointerInput(camera) {
detectTapGestures { offset ->
val cam = camera ?: return@detectTapGestures
val factory = previewView.meteringPointFactory
val action = FocusMeteringAction.Builder(
factory.createPoint(offset.x, offset.y),
FocusMeteringAction.FLAG_AF or FocusMeteringAction.FLAG_AE,
).build()
lastTapFocusAt.set(System.currentTimeMillis())
runCatching { cam.cameraControl.startFocusAndMetering(action) }
}
},
)
AndroidView(factory = { previewView }, modifier = Modifier.fillMaxSize())
}
/**
* Configure the capture session the way a dedicated barcode scanner does,
* rather than the way a photo app does.
*
* The single most valuable knob is **CONTROL_AE_TARGET_FPS_RANGE**. Left
* alone, auto-exposure indoors happily drops the sensor to 10–15 fps and
* takes 60–100 ms exposures — every hand-held frame is then motion-blurred,
* and a blurred QR is not a slow decode, it is *no* decode. The user waves
* the phone about waiting for a lock that cannot happen. Pinning the lower
* bound of the AE range as high as the device allows caps exposure time
* (~33 ms at 30 fps), so frames come out sharp; AE compensates with gain
* instead, and ZXing tolerates noise far better than it tolerates blur.
* (Dark rooms get grainier as a result — that is what the torch button is
* for, and grainy-but-sharp still decodes where smooth-but-smeared never
* does.)
*
* CONTINUOUS_PICTURE is set explicitly so that when a tap-to-focus action
* expires, CameraX restores continuous AF rather than whatever the device
* defaults to; FAST noise/edge processing shaves ISP latency per frame.
*
* All of it is best-effort — an OEM that rejects a key just keeps its default.
*/
@androidx.annotation.OptIn(ExperimentalCamera2Interop::class)
private fun tuneForBarcodes(builder: Preview.Builder, context: Context) {
runCatching {
val ext = Camera2Interop.Extender(builder)
ext.setCaptureRequestOption(
CaptureRequest.CONTROL_AF_MODE,
CameraMetadata.CONTROL_AF_MODE_CONTINUOUS_PICTURE,
)
ext.setCaptureRequestOption(
CaptureRequest.NOISE_REDUCTION_MODE,
CameraMetadata.NOISE_REDUCTION_MODE_FAST,
)
ext.setCaptureRequestOption(
CaptureRequest.EDGE_MODE,
CameraMetadata.EDGE_MODE_FAST,
)
highestSteadyFpsRange(context)?.let {
ext.setCaptureRequestOption(CaptureRequest.CONTROL_AE_TARGET_FPS_RANGE, it)
}
}
}
/**
* The back camera's AE range with the highest floor, ignoring anything that
* runs past 30 fps (those are the high-speed/slow-motion modes, which cost
* light for frames we do not need).
*/
private fun highestSteadyFpsRange(context: Context): android.util.Range<Int>? = runCatching {
val manager = context.getSystemService(CameraManager::class.java) ?: return@runCatching null
val backId = manager.cameraIdList.firstOrNull { id ->
manager.getCameraCharacteristics(id)
.get(CameraCharacteristics.LENS_FACING) == CameraCharacteristics.LENS_FACING_BACK
} ?: return@runCatching null
manager.getCameraCharacteristics(backId)
.get(CameraCharacteristics.CONTROL_AE_AVAILABLE_TARGET_FPS_RANGES)
?.filter { it.upper <= 30 }
?.maxWithOrNull(compareBy({ it.lower }, { it.upper }))
}.getOrNull()
/**
* ZXing decoder over the camera's Y (luminance) plane.
*
* ## The rule this class exists to obey
*
* **Every frame costs the same, and every frame sees the whole scene.**
*
* That sounds obvious; the previous version violated both halves and produced
* a scanner with a very specific failure: it locked on instantly if the code
* was already in view when the camera opened, but crawled if you opened it
* and then moved to the code. The cause was an escalation ladder — each frame
* that failed to decode unlocked progressively more expensive searches, up to
* a TRY_HARDER pass over the full 2 MP frame plus an inverted retry, easily
* 150–300 ms of work.
*
* So the moment the user began hunting for the code, the analyzer dropped from
* ~30 attempts per second to ~4, each one on a motion-blurred frame. By the
* time they framed the code and held still, the pipeline was busy grinding
* through an exhaustive search of an old, blurry frame. Escalating on failure
* is exactly backwards: failure means the user is still aiming, which is when
* the scanner must be at its *fastest*, not its most thorough.
*
* ## What runs now, on every single frame
*
* 1. **Centre ROI at full resolution** ([QR_ROI_FRACTION], ~0.45 MP). Full
* sensor detail, so dense Lightning invoices keep their pixels-per-module.
* 2. **The whole frame at half resolution** (~0.5 MP). This is what fixes the
* "move to the code" case: coverage is no longer limited to the viewfinder
* box on the fast path, so a code that is merely *near* the middle decodes
* immediately instead of waiting for a slow tier to come around. A code
* big enough to be off-centre is big enough to survive the 2x downscale.
* 3. **One alternating second binarizer** — GlobalHistogram over the ROI on
* even frames, over the half-frame on odd ones. Hybrid is tuned for
* shadowed paper; most codes this app scans are on a *screen* (the node's
* pairing popup, another phone's wallet) where a global threshold is both
* cheaper and more reliable. Alternating keeps the per-frame budget flat.
*
* Two rare extras, both bounded so they can never dent the loop above: an
* inverted ROI pass every 8th frame (light-on-dark codes), and one TRY_HARDER
* pass over the half-frame at most once a second (skewed/damaged codes).
*
* Steady-state that is ~35 ms per frame — around 27 attempts per second, and
* it does not degrade the longer the user hunts.
*
* Buffers are allocated once and reused: the original path allocated a fresh
* ~2 MB array per frame, 60 MB/s of garbage at 30 fps, with GC pauses landing
* mid-decode.
*/
/** ZXing-based QR decoder over the camera's Y (luminance) plane. */
private class QrCodeAnalyzer(private val onDecoded: (String) -> Unit) : ImageAnalysis.Analyzer {
// QRCodeReader directly rather than MultiFormatReader: with a single
// format in play the dispatch and per-call state reset are pure overhead.
private val reader = QRCodeReader()
private val plainHints = mapOf<DecodeHintType, Any>(
DecodeHintType.POSSIBLE_FORMATS to listOf(BarcodeFormat.QR_CODE),
)
private val hardHints = mapOf<DecodeHintType, Any>(
DecodeHintType.POSSIBLE_FORMATS to listOf(BarcodeFormat.QR_CODE),
DecodeHintType.TRY_HARDER to true,
)
private var roiBuffer = ByteArray(0)
private var halfBuffer = ByteArray(0)
private var frame = 0L
private var lastHardAt = 0L
private fun read(
source: PlanarYUVLuminanceSource,
global: Boolean = false,
hard: Boolean = false,
inverted: Boolean = false,
): String? {
val src = if (inverted) source.invert() else source
val bitmap = BinaryBitmap(
if (global) GlobalHistogramBinarizer(src) else HybridBinarizer(src),
private val reader = MultiFormatReader().apply {
setHints(
mapOf(
DecodeHintType.POSSIBLE_FORMATS to listOf(BarcodeFormat.QR_CODE),
// Screen-displayed QRs come with moiré, glare, and soft focus at
// close range — the exhaustive search is worth the milliseconds.
DecodeHintType.TRY_HARDER to true,
)
)
return runCatching {
reader.decode(bitmap, if (hard) hardHints else plainHints).text
}.getOrNull().also { reader.reset() }
}
private var lastAttempt = 0L
override fun analyze(image: ImageProxy) {
// Decode ~7x/s, not on every frame: TRY_HARDER (plus the inverted
// retry) pegs a core when run at camera rate, and that CPU contention
// is what made the preview itself stutter. KEEP_ONLY_LATEST means the
// frames skipped here are simply dropped, so decodes stay current.
val now = System.currentTimeMillis()
if (now - lastAttempt < 140) {
image.close()
return
}
lastAttempt = now
try {
val plane = image.planes[0]
val buffer = plane.buffer
val stride = plane.rowStride
// YUV_420_888 permits an interleaved Y plane. Rare, but a device
// that does it would otherwise hand the decoder pure noise.
val pixelStride = plane.pixelStride
val width = image.width
val height = image.height
frame++
buffer.rewind()
val available = buffer.remaining()
// ── 1. Centre ROI, full resolution ──────────────────────────────
val side = (minOf(width, height) * QR_ROI_FRACTION).toInt().coerceAtLeast(1)
val left = (width - side) / 2
val top = (height - side) / 2
if (roiBuffer.size != side * side) roiBuffer = ByteArray(side * side)
for (row in 0 until side) {
val srcPos = (top + row) * stride + left * pixelStride
if (srcPos + side * pixelStride > available) break
if (pixelStride == 1) {
buffer.position(srcPos)
buffer.get(roiBuffer, row * side, side)
} else {
val dst = row * side
for (col in 0 until side) {
roiBuffer[dst + col] = buffer.get(srcPos + col * pixelStride)
}
}
}
val roi = PlanarYUVLuminanceSource(roiBuffer, side, side, 0, 0, side, side, false)
read(roi)?.let { onDecoded(it); return }
// ── 2. Whole frame, half resolution ─────────────────────────────
val hw = width / 2
val hh = height / 2
if (halfBuffer.size != hw * hh) halfBuffer = ByteArray(hw * hh)
var truncated = false
for (row in 0 until hh) {
val srcRow = row * 2 * stride
val dst = row * hw
for (col in 0 until hw) {
val srcPos = srcRow + col * 2 * pixelStride
if (srcPos >= available) { truncated = true; break }
halfBuffer[dst + col] = buffer.get(srcPos)
}
if (truncated) break
}
val half = PlanarYUVLuminanceSource(halfBuffer, hw, hh, 0, 0, hw, hh, false)
read(half)?.let { onDecoded(it); return }
// ── 3. Alternating second binarizer ─────────────────────────────
val second = if (frame % 2 == 0L) roi else half
read(second, global = true)?.let { onDecoded(it); return }
// ── Bounded extras ──────────────────────────────────────────────
if (frame % 8 == 0L) {
read(roi, inverted = true)?.let { onDecoded(it); return }
}
val now = System.currentTimeMillis()
if (now - lastHardAt >= 1_000) {
lastHardAt = now
read(half, hard = true)?.let { onDecoded(it); return }
// Copy into a rowStride-wide array; the last row of the plane buffer
// may be short of the full stride, so the tail stays zero-padded.
val data = ByteArray(plane.rowStride * image.height)
buffer.get(data, 0, minOf(buffer.remaining(), data.size))
val source = PlanarYUVLuminanceSource(
data, plane.rowStride, image.height,
0, 0, image.width, image.height,
false,
)
val result = try {
reader.decodeWithState(BinaryBitmap(HybridBinarizer(source)))
} catch (_: NotFoundException) {
// Dark-themed pages can render light-on-dark QRs — retry inverted.
reader.reset()
reader.decodeWithState(BinaryBitmap(HybridBinarizer(source.invert())))
}
onDecoded(result.text)
} catch (_: NotFoundException) {
// No QR in this frame — keep scanning.
} catch (_: Exception) {
// Malformed frame; skip it.
} finally {
reader.reset()
image.close()
}
}
@@ -1,14 +0,0 @@
package com.archipelago.app.ui.components
import kotlinx.coroutines.flow.MutableStateFlow
/**
* Cross-layer handoff for remote-signer pairing (#139): NavGraph's
* `nostrconnect://` deep link drops the URI here and routes to the session;
* WebViewScreen collects it, opens the hub menu, and NESMenu opens the
* signer sub-page with the request. Cleared once the signer section has
* consumed it (via NESMenu's onSignerPairHandled).
*/
object SignerLaunch {
val pendingUri = MutableStateFlow<String?>(null)
}
@@ -1,381 +0,0 @@
package com.archipelago.app.ui.components
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.KeyboardActions
import androidx.compose.foundation.text.KeyboardOptions
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Key
import androidx.compose.material.icons.filled.QrCodeScanner
import androidx.compose.material3.Icon
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.platform.LocalClipboardManager
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.text.AnnotatedString
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.input.ImeAction
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import com.archipelago.app.NativeCore
import com.archipelago.app.nostr.BunkerManager
import com.archipelago.app.nostr.NostrSignerPreferences
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.SuccessGreen
import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
import kotlinx.coroutines.launch
import org.json.JSONObject
import java.text.SimpleDateFormat
import java.util.Date
import java.util.Locale
/**
* Remote Signer (#139) — the hub's SIGNER sub-page (same container as
* Nodes/FIPS). The phone holds a nostr key; a NIP-46 client (the node's
* login QR, any nostrconnect:// app) pairs via [pairUri] or the scanner
* (hosted by NESMenu outside this panel), and every `sign_event` request
* lands as a legible approve/deny card. See
* docs/companion-nip46-remote-signer.md.
*/
@Composable
internal fun SignerSection(
pairUri: String?,
onScan: () -> Unit,
onPairHandled: () -> Unit,
) {
val context = LocalContext.current
val scope = rememberCoroutineScope()
val clipboard = LocalClipboardManager.current
val prefs = remember { NostrSignerPreferences(context) }
var keyInfo by remember { mutableStateOf<JSONObject?>(null) }
var keyError by remember { mutableStateOf<String?>(null) }
var importText by remember { mutableStateOf("") }
var showNsec by remember { mutableStateOf(false) }
var notice by remember { mutableStateOf<String?>(null) }
var noticeError by remember { mutableStateOf(false) }
val bunkerState by BunkerManager.state.collectAsState()
val pending by BunkerManager.pending.collectAsState()
fun say(msg: String, error: Boolean) {
notice = msg
noticeError = error
}
suspend fun loadKey() {
val secret = prefs.secret()
keyInfo = secret?.let {
val json = NativeCore.nostrSecretFromAny(it)
if (NativeCore.isErr(json)) null else JSONObject(json)
}
}
LaunchedEffect(Unit) {
BunkerManager.refreshState(context)
loadKey()
}
// Consume a pairing request (deep link or scanner) exactly once.
LaunchedEffect(pairUri) {
val uri = pairUri?.takeIf { it.isNotBlank() } ?: return@LaunchedEffect
if (keyInfo == null) loadKey()
val err = BunkerManager.pair(context, uri)
if (err != null) say(err, true) else say("Pairing started…", false)
onPairHandled()
}
Column(verticalArrangement = Arrangement.spacedBy(10.dp)) {
SectionCopy(
"Hold a nostr key on this phone and sign for it remotely — pair with your " +
"node's login QR (or any NIP-46 client), then approve each signature " +
"request as it arrives. Nothing signs without you."
)
if (bunkerState is BunkerManager.SignerState.Unavailable) {
Text(
"Signing is unavailable on this device (native core missing).",
color = Color(0xFFFF6B6B), fontSize = 12.sp,
)
}
val info = keyInfo
if (info == null) {
// ── No key yet: generate or import ──────────────────────────
keyError?.let { Text(it, color = Color(0xFFFF6B6B), fontSize = 11.sp) }
WideAction(text = "Generate signer key", onClick = {
scope.launch {
try {
keyInfo = prefs.generateSecret()
keyError = null
BunkerManager.refreshState(context)
} catch (e: Exception) {
keyError = e.message ?: "could not generate a key"
}
}
})
GlassField(
value = importText,
onValueChange = { importText = it },
placeholder = "or import nsec…",
keyboardOptions = KeyboardOptions(imeAction = ImeAction.Done),
keyboardActions = KeyboardActions(onGo = {
if (importText.isNotBlank()) {
scope.launch {
try {
keyInfo = prefs.importSecret(importText)
importText = ""
keyError = null
BunkerManager.refreshState(context)
} catch (e: Exception) {
keyError = e.message ?: "not a valid nsec"
}
}
}
}),
)
WideAction(text = "Import", onClick = {
if (importText.isBlank()) return@WideAction
scope.launch {
try {
keyInfo = prefs.importSecret(importText)
importText = ""
keyError = null
BunkerManager.refreshState(context)
} catch (e: Exception) {
keyError = e.message ?: "not a valid nsec"
}
}
})
} else {
// ── Identity ─────────────────────────────────────────────────
SectionHeader(Icons.Default.Key, "Signer identity")
MonoValue("npub", info.optString("npub")) {
clipboard.setText(AnnotatedString(info.optString("npub")))
}
if (showNsec) {
MonoValue("nsec", info.optString("nsec"), secret = true) {
clipboard.setText(AnnotatedString(info.optString("nsec")))
}
SectionHint("Anyone with the nsec can sign as you — clear the clipboard after copying.")
} else {
Text(
"Show nsec",
color = TextMuted, fontSize = 11.sp,
modifier = Modifier
.clip(RoundedCornerShape(8.dp))
.clickable { showNsec = true }
.padding(vertical = 2.dp, horizontal = 6.dp),
)
}
// ── Session ──────────────────────────────────────────────────
Spacer(Modifier.height(2.dp))
val label = when (val s = bunkerState) {
BunkerManager.SignerState.Unavailable -> "Unavailable on this device"
BunkerManager.SignerState.NoKey -> "No signer key yet"
BunkerManager.SignerState.Idle -> "Idle — pair to start"
is BunkerManager.SignerState.Connecting -> "Connecting to ${s.relay}…"
is BunkerManager.SignerState.AwaitingClient -> "Paired with \"${s.clientName}\" — waiting for the handshake to finish"
is BunkerManager.SignerState.Ready -> "Ready for \"${s.clientName}\""
is BunkerManager.SignerState.Failed -> s.reason
}
Text("Session", color = TextMuted, fontSize = 11.sp)
Text(
label,
color = if (bunkerState is BunkerManager.SignerState.Failed) Color(0xFFFF6B6B)
else if (bunkerState is BunkerManager.SignerState.Ready) SuccessGreen
else TextPrimary,
fontSize = 13.sp,
lineHeight = 17.sp,
)
WideAction(
text = "Scan pairing QR",
onClick = {
if (bunkerState is BunkerManager.SignerState.NoKey) {
say("Generate or import a signer key first.", true)
return@WideAction
}
onScan()
},
icon = Icons.Default.QrCodeScanner,
)
if (bunkerState is BunkerManager.SignerState.Ready ||
bunkerState is BunkerManager.SignerState.AwaitingClient ||
bunkerState is BunkerManager.SignerState.Connecting
) {
Text(
"End session",
color = TextMuted, fontSize = 11.sp,
modifier = Modifier
.clip(RoundedCornerShape(8.dp))
.clickable { BunkerManager.unpair() }
.padding(vertical = 2.dp, horizontal = 6.dp),
)
}
// ── Pending signature request — the whole point ──────────────
pending?.let { req ->
Spacer(Modifier.height(2.dp))
Column(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(14.dp))
.background(Color.White.copy(alpha = 0.04f))
.border(1.dp, BitcoinOrange.copy(alpha = 0.35f), RoundedCornerShape(14.dp))
.padding(12.dp),
verticalArrangement = Arrangement.spacedBy(6.dp),
) {
Text("Signature request", color = BitcoinOrange, fontSize = 13.sp, fontWeight = FontWeight.Bold)
SummaryRow("Client", req.clientName.ifBlank { req.clientPubkey.take(12) + "…" })
SummaryRow("Kind", kindLabel(req.kind))
req.createdAt?.let {
SummaryRow("Time", SimpleDateFormat("HH:mm:ss", Locale.US).format(Date(it * 1000)))
}
req.content?.takeIf { it.isNotBlank() }?.let { content ->
Text(
content,
color = TextPrimary, fontSize = 10.sp, lineHeight = 14.sp,
fontFamily = FontFamily.Monospace,
modifier = Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(10.dp))
.background(Color.Black.copy(alpha = 0.45f))
.padding(8.dp)
.heightIn(max = 160.dp),
)
}
if (req.tags.isNotEmpty()) {
Column(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(10.dp))
.background(Color.Black.copy(alpha = 0.45f))
.padding(8.dp),
verticalArrangement = Arrangement.spacedBy(2.dp),
) {
req.tags.take(6).forEach {
Text(
it,
color = TextMuted, fontSize = 9.sp,
fontFamily = FontFamily.Monospace,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
if (req.tags.size > 6) {
Text("+${req.tags.size - 6} more", color = TextMuted, fontSize = 9.sp)
}
}
}
Row(horizontalArrangement = Arrangement.spacedBy(10.dp)) {
Box(
Modifier
.weight(1f)
.height(40.dp)
.clip(RoundedCornerShape(12.dp))
.background(Color(0xFFE5484D).copy(alpha = 0.16f))
.border(1.dp, Color(0xFFE5484D).copy(alpha = 0.5f), RoundedCornerShape(12.dp))
.clickable { BunkerManager.deny() },
contentAlignment = Alignment.Center,
) { Text("Deny", color = Color(0xFFFF8A8D), fontSize = 13.sp, fontWeight = FontWeight.Bold) }
Box(
Modifier
.weight(1f)
.height(40.dp)
.clip(RoundedCornerShape(12.dp))
.background(BitcoinOrange.copy(alpha = 0.2f))
.border(1.dp, BitcoinOrange.copy(alpha = 0.6f), RoundedCornerShape(12.dp))
.clickable {
scope.launch {
val ok = BunkerManager.approve()
say(if (ok) "Signed and sent." else "Could not send the signature.", !ok)
}
},
contentAlignment = Alignment.Center,
) { Text("Approve", color = BitcoinOrange, fontSize = 13.sp, fontWeight = FontWeight.Bold) }
}
}
}
}
notice?.takeIf { it.isNotBlank() }?.let { msg ->
Text(
msg,
color = if (noticeError) Color(0xFFFF6B6B) else SuccessGreen,
fontSize = 12.sp,
textAlign = TextAlign.Center,
modifier = Modifier.fillMaxWidth(),
)
}
}
}
/** Kind number → legible label, so the approve/deny card reads like a sentence. */
private fun kindLabel(kind: Long?): String = when (kind) {
0L -> "Metadata (kind 0)"
1L -> "Text note (kind 1)"
3L -> "Contact list (kind 3)"
4L -> "Direct message (kind 4)"
7L -> "Reaction (kind 7)"
14L -> "Chat message (kind 14)"
22242L -> "Client authentication (kind 22242)"
30078L -> "App-stored data (kind 30078)"
null -> "Unknown kind"
else -> "Kind $kind"
}
/** Monospace value chip with a copy affordance (tap the row). */
@Composable
private fun MonoValue(label: String, value: String, secret: Boolean = false, onCopy: () -> Unit) {
Column(Modifier.fillMaxWidth()) {
Text(label, color = TextMuted, fontSize = 10.sp)
Row(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(10.dp))
.background(Color.Black.copy(alpha = 0.45f))
.clickable { onCopy() }
.padding(horizontal = 10.dp, vertical = 8.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Text(
value,
color = if (secret) Color(0xFFFFB86B) else TextPrimary,
fontSize = 10.sp,
fontFamily = FontFamily.Monospace,
modifier = Modifier.weight(1f),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
Text("⧉", color = TextMuted, fontSize = 13.sp, modifier = Modifier.padding(start = 8.dp))
}
}
}
@@ -1,119 +0,0 @@
package com.archipelago.app.ui.components
import androidx.compose.animation.core.RepeatMode
import androidx.compose.animation.core.animateFloat
import androidx.compose.animation.core.animateFloatAsState
import androidx.compose.animation.core.infiniteRepeatable
import androidx.compose.animation.core.keyframes
import androidx.compose.animation.core.rememberInfiniteTransition
import androidx.compose.animation.core.tween
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.BoxWithConstraints
import androidx.compose.foundation.layout.fillMaxHeight
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.graphics.graphicsLayer
import androidx.compose.ui.platform.LocalDensity
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
import com.archipelago.app.ui.theme.BitcoinOrange
/** green-400 — the same "done" colour the web install overlay lands on. */
private val DoneGreen = Color(0xFF4ADE80)
/**
* The Archipelago loading bar: a stripe that runs side to side inside a dim
* track and lands as a solid green bar when the work completes.
*
* This is a direct port of the platform's install-progress overlay
* (neode-ui SystemUpdate.vue `.install-overlay-bar-anim`): a third-width
* orange stripe on a white/10 track, 1.8s ease-in-out, going full green on
* success. Using the same loader natively is what makes the companion feel
* like the same product as the node UI rather than a stock Android app.
*
* @param done finished successfully — the bar fills solid green.
* @param stalled waiting on the user / something external — the bar parks
* half-full in a dimmed orange instead of animating, so it
* reads as "this needs you", not "still working".
*/
@Composable
fun SlidingLoader(
modifier: Modifier = Modifier,
done: Boolean = false,
stalled: Boolean = false,
height: Dp = 8.dp,
) {
val doneProgress by animateFloatAsState(
targetValue = if (done) 1f else 0f,
animationSpec = tween(320),
label = "loaderDone",
)
BoxWithConstraints(
modifier
.fillMaxWidth()
.height(height)
.clip(RoundedCornerShape(percent = 50))
.background(Color.White.copy(alpha = 0.10f)),
) {
val trackWidth = maxWidth
val stripeWidth = trackWidth / 3
val stripePx = with(LocalDensity.current) { stripeWidth.toPx() }
if (doneProgress < 1f) {
if (stalled) {
Box(
Modifier
.fillMaxWidth(0.5f)
.fillMaxHeight()
.clip(RoundedCornerShape(percent = 50))
.background(BitcoinOrange.copy(alpha = 0.6f)),
)
} else {
// Keyframes copied from the web overlay: -100% → 120% → 300%
// of the STRIPE's own width, which is what gives the bar its
// fast sweep out and lazy re-entry.
val transition = rememberInfiniteTransition(label = "loaderSlide")
val offset by transition.animateFloat(
initialValue = -1f,
targetValue = 3f,
animationSpec = infiniteRepeatable(
animation = keyframes {
durationMillis = 1800
(-1f) at 0
1.2f at 900
3f at 1800
},
repeatMode = RepeatMode.Restart,
),
label = "loaderOffset",
)
Box(
Modifier
.fillMaxWidth(1f / 3f)
.fillMaxHeight()
.graphicsLayer { translationX = offset * stripePx }
.clip(RoundedCornerShape(percent = 50))
.background(BitcoinOrange),
)
}
}
if (doneProgress > 0f) {
Box(
Modifier
.fillMaxWidth()
.fillMaxHeight()
.graphicsLayer { alpha = doneProgress }
.background(DoneGreen),
)
}
}
}
@@ -1,26 +1,58 @@
package com.archipelago.app.ui.components
import android.Manifest
import android.content.Context
import android.content.pm.PackageManager
import android.graphics.BitmapFactory
import android.net.Uri
import androidx.activity.compose.BackHandler
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.clickable
import androidx.compose.foundation.interaction.MutableInteractionSource
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.aspectRatio
import androidx.compose.foundation.layout.defaultMinSize
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.hapticfeedback.HapticFeedbackType
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.platform.LocalHapticFeedback
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.unit.dp
import androidx.core.content.ContextCompat
import com.archipelago.app.R
import com.archipelago.app.ui.screens.GlassButton
import com.archipelago.app.ui.theme.BitcoinOrange
import com.google.zxing.BarcodeFormat
import com.google.zxing.BinaryBitmap
import com.google.zxing.DecodeHintType
@@ -30,10 +62,10 @@ import com.google.zxing.RGBLuminanceSource
import com.google.zxing.common.HybridBinarizer
/**
* Native replacement for the web wallet's scan pane — the shared [QrGlassModal]
* shell (same visual design as neode-ui's WalletScanModal) with the camera and
* decoding running natively, so the preview doesn't lag the way getUserMedia
* does inside a WebView.
* Native replacement for the web wallet's scan pane — same visual design as
* neode-ui's WalletScanModal (dark glass card, square preview, orange
* viewfinder, status strip) but the camera and decoding run natively, so the
* preview doesn't lag the way getUserMedia does inside a WebView.
*
* Decoded text is handed back to the page ([onDecoded]) which does all the
* detection/spend logic; the page in turn streams status lines (animated-QR
@@ -48,7 +80,15 @@ fun WalletQrScannerModal(
onDismiss: () -> Unit,
) {
val context = LocalContext.current
val haptics = LocalHapticFeedback.current
var hasPermission by remember {
mutableStateOf(
ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
)
}
val permissionLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.RequestPermission()
) { granted -> hasPermission = granted }
// Local error from a failed image upload; a fresh web status replaces it.
var uploadError by remember { mutableStateOf<String?>(null) }
@@ -67,50 +107,155 @@ fun WalletQrScannerModal(
}
}
LaunchedEffect(visible) { if (visible) uploadError = null }
LaunchedEffect(status) { if (status != null) uploadError = null }
// Throttle repeat frames: a static QR decodes many times a second but the
// page only needs one; animated QRs still stream because each frame's
// text differs.
var lastText by remember { mutableStateOf("") }
var lastSentAt by remember { mutableStateOf(0L) }
LaunchedEffect(visible) {
if (visible) {
lastText = ""
lastSentAt = 0L
uploadError = null
val granted = ContextCompat.checkSelfPermission(context, Manifest.permission.CAMERA) ==
PackageManager.PERMISSION_GRANTED
hasPermission = granted
if (!granted) permissionLauncher.launch(Manifest.permission.CAMERA)
}
}
LaunchedEffect(status) { if (status != null) uploadError = null }
QrGlassModal(
visible = visible,
title = stringResource(R.string.scan_to_send),
status = uploadError?.let { it to true } ?: status,
idleHint = stringResource(R.string.scan_wallet_hint),
permissionRationale = stringResource(R.string.camera_permission_needed),
onDismiss = onDismiss,
onDecoded = { text ->
val now = System.currentTimeMillis()
if (text != lastText || now - lastSentAt > 250) {
// Buzz on the FIRST hit only: an animated QR streams a new
// frame every few ms, and one buzz each would be a drill in
// the hand.
if (lastText.isEmpty()) {
haptics.performHapticFeedback(HapticFeedbackType.LongPress)
AnimatedVisibility(visible = visible, enter = fadeIn(), exit = fadeOut()) {
BackHandler { onDismiss() }
Box(
Modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.6f))
.clickable(
interactionSource = remember { MutableInteractionSource() },
indication = null,
onClick = onDismiss,
),
contentAlignment = Alignment.Center,
) {
Column(
Modifier
.padding(16.dp)
.widthIn(max = 420.dp)
.fillMaxWidth()
.clip(RoundedCornerShape(24.dp))
.background(Color(0xF212151C))
.border(1.dp, Color.White.copy(alpha = 0.10f), RoundedCornerShape(24.dp))
.clickable(
interactionSource = remember { MutableInteractionSource() },
indication = null,
onClick = {}, // swallow — only the scrim dismisses
)
.padding(24.dp),
) {
// Header — mirrors the web modal's title row
Row(
Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween,
) {
Text(
text = stringResource(R.string.scan_to_send),
style = MaterialTheme.typography.titleLarge,
fontWeight = FontWeight.SemiBold,
color = Color.White,
)
IconButton(onClick = onDismiss) {
Icon(
Icons.Default.Close,
stringResource(R.string.close),
tint = Color.White.copy(alpha = 0.7f),
)
}
}
lastText = text
lastSentAt = now
onDecoded(text)
Spacer(Modifier.height(8.dp))
// Square camera preview with the orange viewfinder
Box(
Modifier
.fillMaxWidth()
.aspectRatio(1f)
.clip(RoundedCornerShape(12.dp))
.background(Color.Black.copy(alpha = 0.4f))
.border(1.dp, Color.White.copy(alpha = 0.10f), RoundedCornerShape(12.dp)),
contentAlignment = Alignment.Center,
) {
if (hasPermission) {
// Throttle repeat frames: a static QR decodes ~20x/s but
// the page only needs one; animated QRs still stream
// because each frame's text differs.
var lastText by remember { mutableStateOf("") }
var lastSentAt by remember { mutableStateOf(0L) }
CameraQrPreview(onDecoded = { text ->
val now = System.currentTimeMillis()
if (text != lastText || now - lastSentAt > 250) {
lastText = text
lastSentAt = now
onDecoded(text)
}
})
Box(
Modifier
.fillMaxSize(0.62f)
.border(
2.dp,
BitcoinOrange.copy(alpha = 0.85f),
RoundedCornerShape(16.dp),
),
)
} else {
Column(
Modifier.padding(horizontal = 24.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
text = stringResource(R.string.camera_permission_needed),
color = Color.White.copy(alpha = 0.7f),
style = MaterialTheme.typography.bodyMedium,
textAlign = TextAlign.Center,
)
GlassButton(
text = stringResource(R.string.grant_camera_access),
onClick = { permissionLauncher.launch(Manifest.permission.CAMERA) },
modifier = Modifier.fillMaxWidth().height(48.dp),
)
}
}
}
Spacer(Modifier.height(16.dp))
// Status strip — same slot the web modal uses for hints/errors
val message = uploadError ?: status?.first
val isError = uploadError != null || status?.second == true
Box(
Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(8.dp))
.background(Color.White.copy(alpha = 0.05f))
.padding(12.dp)
.defaultMinSize(minHeight = 24.dp),
contentAlignment = Alignment.Center,
) {
Text(
text = message?.takeIf { it.isNotBlank() }
?: stringResource(R.string.scan_wallet_hint),
style = MaterialTheme.typography.bodySmall,
color = if (isError) Color(0xFFF87171) else Color.White.copy(alpha = 0.6f),
textAlign = TextAlign.Center,
)
}
Spacer(Modifier.height(16.dp))
GlassButton(
text = stringResource(R.string.upload_qr_image),
onClick = { imagePicker.launch("image/*") },
modifier = Modifier.fillMaxWidth().height(48.dp),
)
}
},
footer = {
GlassButton(
text = stringResource(R.string.upload_qr_image),
onClick = { imagePicker.launch("image/*") },
modifier = Modifier.fillMaxWidth().height(48.dp),
)
},
)
}
}
}
/** Decode a QR from a picked image, downsampled so huge photos stay cheap. */
@@ -22,21 +22,16 @@ import com.archipelago.app.data.ServerEntry
import com.archipelago.app.data.ServerPreferences
import com.archipelago.app.data.ServerQrParser
import com.archipelago.app.fips.FipsManager
import com.archipelago.app.ui.components.SignerLaunch
import com.archipelago.app.ui.screens.FlareScreen
import com.archipelago.app.ui.screens.IntroScreen
import com.archipelago.app.ui.screens.NodePickerScreen
import com.archipelago.app.ui.screens.PartyScreen
import com.archipelago.app.ui.screens.RemoteInputScreen
import com.archipelago.app.ui.screens.ServerConnectScreen
import com.archipelago.app.ui.screens.WebViewScreen
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.launch
import kotlinx.coroutines.withContext
object Routes {
const val INTRO = "intro"
const val NODE_PICKER = "node_picker"
const val SERVER_CONNECT = "server_connect"
const val WEB_VIEW = "web_view"
const val REMOTE_INPUT = "remote_input"
@@ -44,38 +39,18 @@ object Routes {
const val FLARE = "flare"
}
/**
* Process-scoped "have we already asked which node?" flag.
*
* The picker is a COLD-START question: opening the app fresh (or after the
* mesh service and its process were killed) is exactly when the user may want
* a different node than last time. An Activity recreation inside a live
* process — rotation, theme change — must not re-ask, and neither must a
* simple return from the background, so the flag lives with the process
* rather than in saved state.
*/
private object LaunchGate {
@Volatile
var nodeChoiceMade: Boolean = false
}
@Composable
fun AppNavHost(
pairUri: String? = null,
onPairUriConsumed: () -> Unit = {},
onReady: () -> Unit = {},
) {
val context = LocalContext.current
val prefs = remember { ServerPreferences(context) }
val navController = rememberNavController()
val scope = rememberCoroutineScope()
// One combined emission — introSeen and activeServer resolving in separate
// frames used to flash the Connect screen at paired users on launch.
val launchState by prefs.launchState.collectAsState(initial = null)
val introSeen = launchState?.introSeen
val activeServer = launchState?.activeServer
val savedServers = launchState?.savedServers ?: emptyList()
val introSeen by prefs.introSeen.collectAsState(initial = null)
val activeServer by prefs.activeServer.collectAsState(initial = null)
// Pairing entry from a deep link that carried no password — prefills the
// connect form so the user lands on the password prompt for that server.
@@ -104,78 +79,45 @@ fun AppNavHost(
}
}
if (introSeen == null) return
// Ask which node when the user keeps more than one and this is a cold
// start. Anything else (single node, mid-process Activity recreation,
// a pairing deep link) goes straight through as before.
val needsNodeChoice = introSeen == true &&
!LaunchGate.nodeChoiceMade &&
savedServers.size > 1
// Paired + previously consented → the mesh comes back silently on launch,
// but ONLY once the session's node is known to be a FIPS node. Bringing
// the tunnel up before that took Android's single VPN slot away from
// whatever the user uses to reach a non-mesh node. Off the main
// dispatcher: this path dlopens the 7 MB fips core and does a binder
// round-trip (VpnService.prepare).
LaunchedEffect(needsNodeChoice, activeServer?.npub, activeServer?.meshIp) {
if (needsNodeChoice) return@LaunchedEffect
if (activeServer?.isFipsNode() != true) return@LaunchedEffect
withContext(Dispatchers.IO) { FipsManager.autoStartIfReady(context) }
// Paired + previously consented → the mesh comes back silently on launch.
LaunchedEffect(Unit) {
FipsManager.autoStartIfReady(context)
}
// Launch state resolved — MainActivity holds the system splash until now,
// so the first visible frame is the real UI, never a black gap.
LaunchedEffect(Unit) { onReady() }
if (introSeen == null) return
// Declared after the introSeen gate so it can't fire before the NavHost
// below has set the nav graph; pairUri stays pending until consumed here.
LaunchedEffect(pairUri) {
val raw = pairUri ?: return@LaunchedEffect
onPairUriConsumed()
when {
// Remote-signer pairing deep link (NIP-46): nostrconnect://…
// from the node's login QR — any QR scanner app can hand it over.
// The signer UI lives inside the hub menu: drop the URI where
// WebViewScreen picks it up and route to the session, which opens
// the hub on its signer sub-page.
raw.startsWith("nostrconnect://") -> {
when (val result = ServerQrParser.parse(raw)) {
is PairResult.Success -> {
// Pairing implies the app is installed and in use — skip the intro.
prefs.markIntroSeen()
SignerLaunch.pendingUri.value = raw
navController.navigate(Routes.WEB_VIEW) {
popUpTo(0) { inclusive = true }
}
}
else -> when (val result = ServerQrParser.parse(raw)) {
is PairResult.Success -> {
// Pairing implies the app is installed and in use — skip the intro.
prefs.markIntroSeen()
val merged = prefs.upsertServer(result.server)
FipsManager.registerNode(context, result.fips, merged.displayName())
if (merged.password.isNotBlank()) {
// Demo flow: password came with the link — connect in one step.
prefs.setActiveServer(merged)
navController.navigate(Routes.WEB_VIEW) {
popUpTo(0) { inclusive = true }
}
} else {
pairPrefill = merged
navController.navigate(Routes.SERVER_CONNECT) {
popUpTo(0) { inclusive = true }
}
val merged = prefs.upsertServer(result.server)
FipsManager.registerNode(context, result.fips, merged.displayName())
if (merged.password.isNotBlank()) {
// Demo flow: password came with the link — connect in one step.
prefs.setActiveServer(merged)
navController.navigate(Routes.WEB_VIEW) {
popUpTo(0) { inclusive = true }
}
} else {
pairPrefill = merged
navController.navigate(Routes.SERVER_CONNECT) {
popUpTo(0) { inclusive = true }
}
}
else -> {
// Invalid or too-new pairing link — ignore; normal startup continues.
}
}
else -> {
// Invalid or too-new pairing link — ignore; normal startup continues.
}
}
}
val startDestination = when {
introSeen == false -> Routes.INTRO
needsNodeChoice -> Routes.NODE_PICKER
activeServer != null -> Routes.WEB_VIEW
else -> Routes.SERVER_CONNECT
}
@@ -184,37 +126,6 @@ fun AppNavHost(
navController = navController,
startDestination = startDestination,
) {
composable(Routes.NODE_PICKER) {
NodePickerScreen(
servers = savedServers,
lastActive = activeServer,
onPick = { server ->
LaunchGate.nodeChoiceMade = true
scope.launch {
prefs.setActiveServer(server)
// The mesh follows the choice, and ONLY the choice.
// A non-mesh node gets the tunnel taken down: Android
// hands out one VPN slot, and holding it hostage is
// what broke reaching nodes behind a different VPN.
withContext(Dispatchers.IO) {
if (server.isFipsNode()) {
FipsManager.autoStartIfReady(context)
} else {
FipsManager.stopService(context)
}
}
navController.navigate(Routes.WEB_VIEW) {
popUpTo(0) { inclusive = true }
}
}
},
onAddNode = {
LaunchGate.nodeChoiceMade = true
navController.navigate(Routes.SERVER_CONNECT)
},
)
}
composable(Routes.INTRO) {
IntroScreen(
onMeshParty = {
@@ -107,11 +107,7 @@ fun FlareScreen(onBack: () -> Unit) {
}
val peer = peers.firstOrNull { it.npub == selectedNpub }
// derivedStateOf: filtering inline re-ran over the whole store on every
// recomposition — including one per keystroke in the composer.
val messages by remember(selectedNpub) {
androidx.compose.runtime.derivedStateOf { allMessages.filter { it.peerNpub == selectedNpub } }
}
val messages = allMessages.filter { it.peerNpub == selectedNpub }
val listState = rememberLazyListState()
LaunchedEffect(messages.size) {
if (messages.isNotEmpty()) listState.animateScrollToItem(messages.size - 1)
@@ -309,13 +305,7 @@ private fun MessageBubble(msg: FlareMessage) {
.padding(horizontal = 12.dp, vertical = 8.dp),
) {
if (msg.photoPath.isNotBlank()) {
// Decoded off-main and downsampled to the bubble width —
// full-size decode in remember{} ran on the UI thread mid-
// scroll and held ~8 MB per visible photo (OOM territory).
var bmp by remember(msg.photoPath) { mutableStateOf<android.graphics.Bitmap?>(null) }
LaunchedEffect(msg.photoPath) {
bmp = withContext(Dispatchers.IO) { decodeSampledPhoto(msg.photoPath, 600) }
}
val bmp = remember(msg.photoPath) { BitmapFactory.decodeFile(msg.photoPath) }
bmp?.let {
Image(
bitmap = it.asImageBitmap(),
@@ -346,19 +336,6 @@ private fun MessageBubble(msg: FlareMessage) {
}
/** Decode, downscale (≤1600px) and JPEG-compress a picked photo off-main. */
/** Decode a stored beamed photo at roughly [maxPx] on the long edge — the
* bubble renders at ~300 dp, so the stored 1600 px original is 25× the
* pixels needed. Blocking — call on IO. */
private fun decodeSampledPhoto(path: String, maxPx: Int): android.graphics.Bitmap? = try {
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
BitmapFactory.decodeFile(path, bounds)
var sample = 1
while (maxOf(bounds.outWidth, bounds.outHeight) / (sample * 2) >= maxPx) sample *= 2
BitmapFactory.decodeFile(path, BitmapFactory.Options().apply { inSampleSize = sample })
} catch (_: Exception) {
null
}
private suspend fun compressPhoto(context: android.content.Context, uri: Uri): ByteArray? =
withContext(Dispatchers.IO) {
try {
@@ -37,7 +37,6 @@ import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.alpha
import androidx.compose.ui.graphics.graphicsLayer
import androidx.compose.ui.draw.clip
import androidx.compose.ui.geometry.Offset
import androidx.compose.ui.geometry.Size
@@ -66,10 +65,9 @@ fun IntroScreen(
var showContent by remember { mutableStateOf(false) }
LaunchedEffect(Unit) {
// Content fades in WITH the logo, not after it — the serial
// 800ms + 300ms sequence held "Get Started" off-screen for 1.1s.
logoAlpha.animateTo(1f, animationSpec = tween(800))
delay(300)
showContent = true
logoAlpha.animateTo(1f, animationSpec = tween(450))
}
Box(
@@ -113,9 +111,7 @@ fun IntroScreen(
contentDescription = "Archipelago",
modifier = Modifier
.size(160.dp)
// graphicsLayer defers the alpha read to the draw phase —
// .alpha(value) recomposed the whole screen per frame.
.graphicsLayer { alpha = logoAlpha.value },
.alpha(logoAlpha.value),
)
Spacer(modifier = Modifier.height(48.dp))
@@ -1,226 +0,0 @@
package com.archipelago.app.ui.screens
import androidx.compose.foundation.Image
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.WindowInsets
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.safeDrawing
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.windowInsetsPadding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Bolt
import androidx.compose.material.icons.filled.Lock
import androidx.compose.material.icons.filled.LockOpen
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Brush
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.res.painterResource
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import com.archipelago.app.R
import com.archipelago.app.data.ServerEntry
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.SuccessGreen
import com.archipelago.app.ui.theme.SurfaceBlack
import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
/**
* "Which node?" — shown at launch when more than one node is saved.
*
* The companion used to dive straight back into whichever node was last
* active, which is wrong the moment a user keeps more than one: they arrive
* somewhere they didn't choose, and (worse) the FIPS tunnel came up before
* anyone said which network this session belongs to. Picking first makes the
* choice explicit and lets the mesh stay down for nodes that aren't on it.
*
* [onPick] carries the entry; the caller decides what the mesh does about it.
*/
@Composable
fun NodePickerScreen(
servers: List<ServerEntry>,
lastActive: ServerEntry?,
onPick: (ServerEntry) -> Unit,
onAddNode: () -> Unit,
) {
Box(
modifier = Modifier
.fillMaxSize()
.background(SurfaceBlack),
) {
Image(
painter = painterResource(id = R.drawable.bg_synthwave),
contentDescription = null,
modifier = Modifier.fillMaxSize(),
contentScale = ContentScale.Crop,
)
Box(
modifier = Modifier
.fillMaxSize()
.background(
Brush.verticalGradient(
colors = listOf(
Color.Black.copy(alpha = 0.65f),
Color.Black.copy(alpha = 0.5f),
Color.Black.copy(alpha = 0.85f),
),
)
),
)
Column(
modifier = Modifier
.fillMaxSize()
.windowInsetsPadding(WindowInsets.safeDrawing)
.verticalScroll(rememberScrollState())
.padding(horizontal = 24.dp)
.padding(top = 48.dp, bottom = 32.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(12.dp, Alignment.CenterVertically),
) {
Image(
painter = painterResource(id = R.drawable.ic_logo),
contentDescription = "Archipelago",
modifier = Modifier.size(88.dp),
)
Spacer(Modifier.height(4.dp))
Text(
text = stringResource(R.string.pick_node_title),
style = MaterialTheme.typography.headlineMedium,
color = TextPrimary,
textAlign = TextAlign.Center,
)
Text(
text = stringResource(R.string.pick_node_hint),
style = MaterialTheme.typography.bodyMedium,
color = TextMuted,
textAlign = TextAlign.Center,
)
Spacer(Modifier.height(8.dp))
servers.forEach { server ->
NodeCard(
server = server,
isLast = lastActive?.sameNode(server) == true,
onClick = { onPick(server) },
)
}
Spacer(Modifier.height(8.dp))
GlassButton(
text = stringResource(R.string.pick_node_add),
onClick = onAddNode,
modifier = Modifier.fillMaxWidth().height(52.dp),
)
}
}
}
@Composable
private fun NodeCard(
server: ServerEntry,
isLast: Boolean,
onClick: () -> Unit,
) {
Row(
modifier = Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(14.dp))
.background(Color.Black.copy(alpha = 0.6f))
.background(
Brush.verticalGradient(
colors = listOf(
Color.White.copy(alpha = 0.08f),
Color.White.copy(alpha = 0.02f),
),
)
)
.border(
1.dp,
if (isLast) BitcoinOrange.copy(alpha = 0.35f) else Color.White.copy(alpha = 0.1f),
RoundedCornerShape(14.dp),
)
.clickable { onClick() }
.padding(horizontal = 16.dp, vertical = 16.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(
imageVector = if (server.useHttps) Icons.Default.Lock else Icons.Default.LockOpen,
contentDescription = null,
modifier = Modifier.size(20.dp),
tint = if (server.useHttps) SuccessGreen else BitcoinOrange,
)
Spacer(Modifier.width(12.dp))
Column(Modifier.weight(1f)) {
Text(
text = server.displayName(),
style = MaterialTheme.typography.titleMedium,
color = TextPrimary,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
val secondary = buildString {
if (server.name.isNotBlank()) append(server.address)
if (server.port.isNotBlank()) {
if (isNotEmpty()) append(":${server.port}") else append("Port ${server.port}")
}
}
if (secondary.isNotBlank()) {
Text(
text = secondary,
style = MaterialTheme.typography.labelMedium,
color = TextMuted,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
// The one thing that actually changes behaviour on this screen: a mesh
// node brings the FIPS tunnel up, a plain one deliberately does not.
if (server.isFipsNode()) {
Row(verticalAlignment = Alignment.CenterVertically) {
Icon(
imageVector = Icons.Default.Bolt,
contentDescription = null,
modifier = Modifier.size(14.dp),
tint = BitcoinOrange,
)
Spacer(Modifier.width(4.dp))
Text(
text = "FIPS",
color = BitcoinOrange,
fontSize = 11.sp,
letterSpacing = 1.sp,
style = MaterialTheme.typography.labelMedium,
)
}
}
}
}
@@ -123,12 +123,9 @@ fun PartyScreen(
name = prefs.partyName()
// The hotspot/WiFi address can change while this screen is open
// (e.g. the user flips the hotspot on mid-demo) — keep it fresh.
// Tight only at first (the hotspot-flip window); interface walks
// allocate, so back off once the screen has been open a while.
var round = 0
while (true) {
localIp = withContext(Dispatchers.IO) { PartyQr.localWifiIpv4() }
delay(if (round++ < 10) 3_000 else 30_000)
delay(3_000)
}
}
@@ -141,16 +138,7 @@ fun PartyScreen(
port = PartyQr.PARTY_UDP_PORT,
)
}
// QR encode + bitmap fill off the composition: done in remember{} it ran
// on the UI thread PER KEYSTROKE of the name field (the payload embeds the
// name) — a ZXing encode plus a megabyte-plus allocation per character.
// The 250 ms delay is a free debounce via coroutine cancellation.
var qrBitmap by remember { mutableStateOf<android.graphics.Bitmap?>(null) }
LaunchedEffect(qrPayload) {
if (qrPayload == null) { qrBitmap = null; return@LaunchedEffect }
if (qrBitmap != null) delay(250)
qrBitmap = withContext(Dispatchers.Default) { renderQr(qrPayload) }
}
val qrBitmap = remember(qrPayload) { qrPayload?.let { renderQr(it) } }
BackHandler {
when {
@@ -349,12 +337,7 @@ fun PartyScreen(
contentAlignment = Alignment.Center,
) {
Column(horizontalAlignment = Alignment.CenterHorizontally) {
// Encoded off-main; done in remember{} it dropped the
// overlay's first fade-in frame.
var dlQr by remember { mutableStateOf<android.graphics.Bitmap?>(null) }
LaunchedEffect(Unit) {
dlQr = withContext(Dispatchers.Default) { renderQr(APP_DOWNLOAD_URL) }
}
val dlQr = remember { renderQr(APP_DOWNLOAD_URL) }
dlQr?.let { bmp ->
Box(
Modifier
@@ -381,7 +364,7 @@ fun PartyScreen(
"…or send the APK file directly",
color = BitcoinOrange,
fontSize = 13.sp,
modifier = Modifier.clickable { scope.launch { shareCompanionApk(context) } }.padding(8.dp),
modifier = Modifier.clickable { shareCompanionApk(context) }.padding(8.dp),
)
Spacer(Modifier.height(6.dp))
Text("Close", color = TextMuted, fontSize = 14.sp, modifier = Modifier.clickable { showShareQr = false }.padding(8.dp))
@@ -490,9 +473,8 @@ fun PartyScreen(
}
}
/** Render a QR payload as a bitmap (dark modules on white). 512 px covers the
* 240.dp display size at any density; 640 was a third more pixels for nothing. */
private fun renderQr(payload: String, size: Int = 512): Bitmap? = try {
/** Render a QR payload as a bitmap (dark modules on white). */
private fun renderQr(payload: String, size: Int = 640): Bitmap? = try {
val matrix = QRCodeWriter().encode(
payload,
BarcodeFormat.QR_CODE,
@@ -512,23 +494,16 @@ private fun renderQr(payload: String, size: Int = 512): Bitmap? = try {
}
/** Share this install's own APK via the system share sheet — a nearby friend
* gets the companion with no internet at all (Quick Share / Bluetooth).
* The ~27 MB copy runs on IO — inline in the click handler it froze the UI
* for seconds (ANR territory on slow flash). Copied once per install; the
* cached file is reused while its size still matches the source. */
private suspend fun shareCompanionApk(context: android.content.Context) {
* gets the companion with no internet at all (Quick Share / Bluetooth). */
private fun shareCompanionApk(context: android.content.Context) {
try {
val uri = withContext(Dispatchers.IO) {
val src = java.io.File(context.applicationInfo.sourceDir)
val dir = java.io.File(context.cacheDir, "share").apply { mkdirs() }
val out = java.io.File(dir, "archipelago-companion.apk")
if (!out.exists() || out.length() != src.length()) {
src.copyTo(out, overwrite = true)
}
androidx.core.content.FileProvider.getUriForFile(
context, "${context.packageName}.fileprovider", out,
)
}
val src = java.io.File(context.applicationInfo.sourceDir)
val dir = java.io.File(context.cacheDir, "share").apply { mkdirs() }
val out = java.io.File(dir, "archipelago-companion.apk")
src.copyTo(out, overwrite = true)
val uri = androidx.core.content.FileProvider.getUriForFile(
context, "${context.packageName}.fileprovider", out,
)
val send = android.content.Intent(android.content.Intent.ACTION_SEND).apply {
type = "application/vnd.android.package-archive"
putExtra(android.content.Intent.EXTRA_STREAM, uri)
@@ -33,6 +33,7 @@ import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.Edit
import androidx.compose.material.icons.filled.Lock
import androidx.compose.material.icons.filled.LockOpen
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
@@ -75,7 +76,6 @@ import com.archipelago.app.data.ServerEntry
import com.archipelago.app.data.ServerPreferences
import com.archipelago.app.fips.FipsManager
import com.archipelago.app.ui.components.MeshLoadingScreen
import com.archipelago.app.ui.components.SlidingLoader
import com.archipelago.app.ui.components.QrScannerOverlay
import com.archipelago.app.ui.theme.BitcoinOrange
import com.archipelago.app.ui.theme.ErrorRed
@@ -86,7 +86,6 @@ import com.archipelago.app.ui.theme.TextMuted
import com.archipelago.app.ui.theme.TextPrimary
import com.archipelago.app.ui.theme.TextSecondary
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.async
import kotlinx.coroutines.delay
import kotlinx.coroutines.launch
import kotlinx.coroutines.withContext
@@ -109,20 +108,6 @@ fun ServerConnectScreen(
val scope = rememberCoroutineScope()
val keyboard = LocalSoftwareKeyboardController.current
val savedServers by prefs.savedServers.collectAsState(initial = emptyList())
// Warm the mesh tunnel the moment the screen appears — starting it only
// after the LAN probe failed put full tunnel bring-up + session discovery
// inside the user's wait. By connect-tap time it's usually already up.
//
// Only when there is actually a mesh node to warm for, though: raising the
// tunnel on a phone whose saved nodes are all plain HTTP boxes takes
// Android's single VPN slot for nothing.
LaunchedEffect(savedServers.any { it.isFipsNode() }) {
if (savedServers.none { it.isFipsNode() }) return@LaunchedEffect
withContext(Dispatchers.IO) { FipsManager.autoStartIfReady(context) }
}
var name by remember { mutableStateOf("") }
var address by remember { mutableStateOf("") }
var port by remember { mutableStateOf("") }
@@ -136,13 +121,8 @@ fun ServerConnectScreen(
// Landing shows Scan/Manual choice; the form appears in manual mode or while editing.
var manualMode by remember { mutableStateOf(false) }
var showScanner by remember { mutableStateOf(false) }
// Is the connect currently running aimed at a mesh node? Drives whether
// the loader wears the FIPS brand — see MeshLoadingScreen.
var connectingOverMesh by remember { mutableStateOf(false) }
var connectingName by remember { mutableStateOf("") }
// Brief green landing on the loader before the kiosk takes over, matching
// the platform's install overlay.
var connectSucceeded by remember { mutableStateOf(false) }
val savedServers by prefs.savedServers.collectAsState(initial = emptyList())
fun clearForm() {
name = ""
@@ -191,60 +171,40 @@ fun ServerConnectScreen(
}
isConnecting = true
errorMessage = null
connectingOverMesh = server.isFipsNode()
connectingName = server.displayName()
connectSucceeded = false
scope.launch {
// LAN and mesh race IN PARALLEL — the serial LAN-then-mesh chain
// burned a guaranteed-dead 5 s LAN probe before the mesh path even
// started (the off-LAN QR-pairing case, exactly where speed shows).
// The scanned IP was only ever a dial hint; the node's real
var reachable = testConnection(server)
// LAN address didn't answer — phone off-LAN (5G) or DHCP moved the
// node. The scanned IP was only ever a dial hint; the node's real
// identity is its npub and its ULA is reachable from anywhere over
// the mesh. Mesh discovery + first session can take 15s+ through
// the public tree (per node diagnosis), and on a
// first-ever pairing the VPN consent dialog is on screen at the
// same time — so the mesh side keeps probing inside its budget
// while the tunnel (already started at screen entry, and kicked
// again here) warms up underneath.
val meshServer = server.meshIp.takeIf { it.isNotBlank() }?.let {
// the mesh. Bring the tunnel up and probe the ULA before failing.
if (!reachable && server.meshIp.isNotBlank()) {
FipsManager.autoStartIfReady(context)
server.copy(address = it, useHttps = false, port = "")
}
val reachable = kotlinx.coroutines.coroutineScope {
val lan = async { testConnection(server, timeoutMs = 4_000) }
val mesh = async {
if (meshServer == null) return@async false
val deadline = System.currentTimeMillis() + 45_000
var ok = false
while (!ok && System.currentTimeMillis() < deadline) {
ok = testConnection(meshServer, timeoutMs = 8_000)
if (!ok) delay(2000)
}
ok
}
val first = kotlinx.coroutines.selects.select<Boolean> {
lan.onAwait { it }
mesh.onAwait { it }
}
if (first) {
lan.cancel(); mesh.cancel()
true
} else {
// One side gave up — the verdict is whatever the other says.
if (lan.isCompleted) mesh.await() else lan.await()
val meshServer = server.copy(
address = server.meshIp,
useHttps = false,
port = "",
)
// Mesh discovery + first session can take 15s+ through the
// public tree (per node diagnosis), and on a
// first-ever pairing the VPN consent dialog is on screen at
// the same time — so probe patiently inside a 60s budget with
// per-attempt timeouts wide enough to ride out TCP
// retransmit backoff. The VPN service pre-warms the session
// in parallel (ArchyVpnService.startSessionWarmer).
val deadline = System.currentTimeMillis() + 60_000
while (!reachable && System.currentTimeMillis() < deadline) {
reachable = testConnection(meshServer, timeoutMs = 15_000)
if (!reachable) delay(3000)
}
}
isConnecting = false
if (reachable) {
// Land the loader green before handing over, so the last thing
// seen is "done", not a bar cut mid-sweep.
connectSucceeded = true
prefs.setActiveServer(server)
delay(320)
isConnecting = false
onConnected(server.toUrl())
} else {
isConnecting = false
errorMessage = context.getString(R.string.connection_failed)
}
}
@@ -333,7 +293,7 @@ fun ServerConnectScreen(
Spacer(modifier = Modifier.height(4.dp))
Text(
text = if (editingServer != null) stringResource(R.string.edit_server_title) else stringResource(R.string.connect_to_node),
text = if (editingServer != null) stringResource(R.string.edit_server_title) else "Connect to Server",
style = MaterialTheme.typography.headlineMedium,
color = TextPrimary,
textAlign = TextAlign.Center,
@@ -617,9 +577,10 @@ fun ServerConnectScreen(
}
if (isConnecting) {
SlidingLoader(
modifier = Modifier.fillMaxWidth(),
done = connectSucceeded,
CircularProgressIndicator(
modifier = Modifier.size(24.dp),
color = Color.White.copy(alpha = 0.6f),
strokeWidth = 2.dp,
)
}
@@ -656,11 +617,7 @@ fun ServerConnectScreen(
// establishing (LAN probe → tunnel up → ULA probe can take a while).
// The small inline spinner stays for context; this owns the screen.
if (isConnecting) {
MeshLoadingScreen(
mesh = connectingOverMesh,
nodeName = connectingName,
done = connectSucceeded,
)
MeshLoadingScreen()
}
}
}
@@ -729,17 +686,6 @@ private fun sanitizeAddress(input: String): String {
.trimEnd('/')
}
// Built once — the connect loop probed up to 20 times, and each attempt was
// paying a fresh SSLContext + SecureRandom init.
private val trustAllSslFactory: javax.net.ssl.SSLSocketFactory by lazy {
val trustAll = arrayOf<javax.net.ssl.TrustManager>(object : X509TrustManager {
override fun checkClientTrusted(chain: Array<java.security.cert.X509Certificate>?, authType: String?) {}
override fun checkServerTrusted(chain: Array<java.security.cert.X509Certificate>?, authType: String?) {}
override fun getAcceptedIssuers(): Array<java.security.cert.X509Certificate> = arrayOf()
})
SSLContext.getInstance("TLS").apply { init(null, trustAll, java.security.SecureRandom()) }.socketFactory
}
/** Test RPC connectivity. Accepts self-signed certs for local LAN servers.
* [timeoutMs] is per-phase (connect / read) — mesh probes need far more
* patience than LAN ones (first session through the tree can take 15s+). */
@@ -751,7 +697,14 @@ private suspend fun testConnection(server: ServerEntry, timeoutMs: Int = 5000):
// Trust self-signed certs for local HTTPS (Archipelago nodes rarely have CA certs)
if (connection is HttpsURLConnection) {
connection.sslSocketFactory = trustAllSslFactory
val trustAll = arrayOf<javax.net.ssl.TrustManager>(object : X509TrustManager {
override fun checkClientTrusted(chain: Array<java.security.cert.X509Certificate>?, authType: String?) {}
override fun checkServerTrusted(chain: Array<java.security.cert.X509Certificate>?, authType: String?) {}
override fun getAcceptedIssuers(): Array<java.security.cert.X509Certificate> = arrayOf()
})
val sc = SSLContext.getInstance("TLS")
sc.init(null, trustAll, java.security.SecureRandom())
connection.sslSocketFactory = sc.socketFactory
connection.hostnameVerifier = javax.net.ssl.HostnameVerifier { _, _ -> true }
}
File diff suppressed because it is too large Load Diff
@@ -2,95 +2,56 @@ package com.archipelago.app.ui.theme
import androidx.compose.material3.Typography
import androidx.compose.ui.text.TextStyle
import androidx.compose.ui.text.font.Font
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.unit.sp
import com.archipelago.app.R
/**
* The platform's brand face. neode-ui sets `font-archipelago: Montserrat` and
* uses it for every heading, title and button label, with body copy left to
* `Avenir Next, system-ui` — which on Android resolves to the system sans
* anyway. Mirroring that split exactly is what makes companion text read as
* the same product as the node UI.
*
* Montserrat is SIL OFL 1.1 (see Android/MONTSERRAT-OFL.txt); the files are
* the ones already vendored for the web UI, so both halves ship the same
* outlines.
*/
val Montserrat = FontFamily(
Font(R.font.montserrat_medium, FontWeight.Medium),
Font(R.font.montserrat_semibold, FontWeight.SemiBold),
Font(R.font.montserrat_bold, FontWeight.Bold),
Font(R.font.montserrat_extrabold, FontWeight.ExtraBold),
)
val Typography = Typography(
// ── Display / headings: Montserrat, tight and heavy like the web hero
// copy (the platform sets tracking negative on its big type).
displayLarge = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.ExtraBold,
fontWeight = FontWeight.Bold,
fontSize = 32.sp,
lineHeight = 40.sp,
letterSpacing = (-0.8).sp,
),
headlineLarge = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.Bold,
fontSize = 28.sp,
lineHeight = 36.sp,
letterSpacing = (-0.5).sp,
),
headlineLarge = TextStyle(
fontWeight = FontWeight.SemiBold,
fontSize = 28.sp,
lineHeight = 36.sp,
),
headlineMedium = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.Bold,
fontWeight = FontWeight.SemiBold,
fontSize = 24.sp,
lineHeight = 32.sp,
letterSpacing = (-0.4).sp,
),
titleLarge = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.SemiBold,
fontWeight = FontWeight.Medium,
fontSize = 20.sp,
lineHeight = 28.sp,
letterSpacing = (-0.2).sp,
),
titleMedium = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.SemiBold,
fontWeight = FontWeight.Medium,
fontSize = 16.sp,
lineHeight = 24.sp,
letterSpacing = 0.15.sp,
),
// ── Body: system sans, exactly as the web falls back to.
bodyLarge = TextStyle(
fontWeight = FontWeight.Normal,
fontSize = 16.sp,
lineHeight = 24.sp,
letterSpacing = 0.2.sp,
letterSpacing = 0.5.sp,
),
bodyMedium = TextStyle(
fontWeight = FontWeight.Normal,
fontSize = 14.sp,
lineHeight = 20.sp,
letterSpacing = 0.1.sp,
letterSpacing = 0.25.sp,
),
bodySmall = TextStyle(
fontWeight = FontWeight.Normal,
fontSize = 13.sp,
lineHeight = 18.sp,
),
// ── Buttons / labels: Montserrat again, matching .glass-button.
labelLarge = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.SemiBold,
fontSize = 14.sp,
lineHeight = 20.sp,
letterSpacing = 0.1.sp,
),
labelMedium = TextStyle(
fontFamily = Montserrat,
fontWeight = FontWeight.Medium,
fontSize = 12.sp,
lineHeight = 16.sp,
@@ -1,52 +1,36 @@
<?xml version="1.0" encoding="utf-8"?>
<!-- System splash icon — deliberately the SAME mark as the adaptive launcher
icon (ic_launcher_background.xml): dark disc + metallic ring + white
Archipelago grid. Tapping the icon and watching the splash should show
one badge, not two different logos.
Geometry is copied from the launcher: the Android 12 splash draws its icon
on a 288dp canvas whose inner 2/3 is the safe area — the same 0.667 ratio
the adaptive-icon mask uses — so the launcher's 0.65 (ring) / 0.55 (grid)
group scales land identically here. -->
<!-- Archipelago pixel-art "A" for splash screen -->
<vector xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:aapt="http://schemas.android.com/aapt"
android:width="288dp"
android:height="288dp"
android:viewportWidth="752"
android:viewportHeight="752">
android:width="108dp"
android:height="108dp"
android:viewportWidth="1024"
android:viewportHeight="1024">
<!-- Dark disc + gradient ring (#000 -> #666), matching logo.svg -->
<group
android:pivotX="376"
android:pivotY="376"
android:scaleX="0.65"
android:scaleY="0.65">
<path
android:fillColor="#0A0A0A"
android:strokeWidth="22.8834"
android:pathData="M11.441,375.669a364.227,364.227 0 1,0 728.454,0a364.227,364.227 0 1,0 -728.454,0z">
<aapt:attr name="android:strokeColor">
<gradient
android:type="linear"
android:startX="751.337"
android:startY="751.338"
android:endX="0"
android:endY="0.000976562">
<item android:offset="0" android:color="#FF000000" />
<item android:offset="1" android:color="#FF666666" />
</gradient>
</aapt:attr>
</path>
</group>
<!-- White Archipelago grid -->
<group
android:pivotX="376"
android:pivotY="376"
android:pivotX="512"
android:pivotY="512"
android:scaleX="0.55"
android:scaleY="0.55">
<path
android:fillColor="#FFFFFF"
android:pathData="M253.805,278.37V222.28H309.853V278.37H253.805ZM315.797,278.37V222.28H372.694V278.37H315.797ZM378.639,278.37V222.28H435.536V278.37H378.639ZM441.481,278.37V222.28H497.529V278.37H441.481ZM441.481,341.259V284.319H497.529V341.259H441.481ZM503.473,341.259V284.319H560.37V341.259H503.473ZM190.963,404.148V347.208H247.86V404.148H190.963ZM253.805,404.148V347.208H309.853V404.148H253.805ZM315.797,404.148V347.208H372.694V404.148H315.797ZM378.639,404.148V347.208H435.536V404.148H378.639ZM441.481,404.148V347.208H497.529V404.148H441.481ZM503.473,404.148V347.208H560.37V404.148H503.473ZM190.963,466.187V410.097H247.86V466.187H190.963ZM253.805,466.187V410.097H309.853V466.187H253.805ZM441.481,466.187V410.097H497.529V466.187H441.481ZM503.473,466.187V410.097H560.37V466.187H503.473ZM253.805,529.076V472.136H309.853V529.076H253.805ZM315.797,529.076V472.136H372.694V529.076H315.797ZM378.639,529.076V472.136H435.536V529.076H378.639ZM441.481,529.076V472.136H497.529V529.076H441.481Z" />
<path android:fillColor="#FFFFFF" android:pathData="M357.614,318h71.007v70.936h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M436.152,318h72.082v70.936h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M515.766,318h72.082v70.936h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M595.379,318h71.007v70.936h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M595.379,396.46h71.007v72.011h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M673.917,396.46h72.083v72.011h-72.083z" />
<path android:fillColor="#FFFFFF" android:pathData="M278,475.994h72.083v72.012h-72.083z" />
<path android:fillColor="#FFFFFF" android:pathData="M357.614,475.994h71.007v72.012h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M436.152,475.994h72.082v72.012h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M515.766,475.994h72.082v72.012h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M595.379,475.994h71.007v72.012h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M673.917,475.994h72.083v72.012h-72.083z" />
<path android:fillColor="#FFFFFF" android:pathData="M278,555.529h72.083v70.936h-72.083z" />
<path android:fillColor="#FFFFFF" android:pathData="M357.614,555.529h71.007v70.936h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M595.379,555.529h71.007v70.936h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M673.917,555.529h72.083v70.936h-72.083z" />
<path android:fillColor="#FFFFFF" android:pathData="M357.614,633.989h71.007v72.011h-71.007z" />
<path android:fillColor="#FFFFFF" android:pathData="M436.152,633.989h72.082v72.011h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M515.766,633.989h72.082v72.011h-72.082z" />
<path android:fillColor="#FFFFFF" android:pathData="M595.379,633.989h71.007v72.011h-71.007z" />
</group>
</vector>
Binary file not shown.
Binary file not shown.
@@ -49,12 +49,4 @@
<string name="scan_wallet_hint">Point the camera at a Lightning invoice, Bitcoin address, Cashu or Fedimint code</string>
<string name="upload_qr_image">Upload image</string>
<string name="no_qr_in_image">No QR code found in that image — try another, closer and well-lit</string>
<string name="torch_on">Turn on the torch</string>
<string name="torch_off">Turn off the torch</string>
<!-- Launch node picker (more than one node saved) -->
<string name="pick_node_title">Which node?</string>
<string name="pick_node_hint">Choose the Archipelago this session connects to. The FIPS mesh only comes up for mesh nodes.</string>
<string name="pick_node_add">Add another node</string>
<string name="connect_to_node">Connect to your node</string>
</resources>
+1 -369
View File
@@ -12,17 +12,6 @@ dependencies = [
"generic-array",
]
[[package]]
name = "aes"
version = "0.8.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b169f7a6d4742236a0a00c541b845991d0ac43e546831af1249753ab4c3aa3a0"
dependencies = [
"cfg-if",
"cipher",
"cpufeatures 0.2.17",
]
[[package]]
name = "aho-corasick"
version = "1.1.4"
@@ -92,41 +81,17 @@ checksum = "330a5ed07fa54e4702c9d6c4174f74427fc0ef6e214bbd677ae50a5099946470"
name = "archy-fips-core"
version = "0.1.0"
dependencies = [
"aes",
"anyhow",
"argon2",
"base64",
"bech32",
"cbc",
"chacha20 0.9.1",
"chacha20poly1305",
"fips",
"getrandom 0.2.17",
"hex",
"hkdf",
"hmac",
"jni",
"libc",
"paranoid-android",
"secp256k1 0.29.1",
"serde_json",
"sha2",
"tokio",
"tracing",
"tracing-subscriber",
"url",
]
[[package]]
name = "argon2"
version = "0.5.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3c3610892ee6e0cbce8ae2700349fcf8f98adb0dbfbee85aec3c9179d29cc072"
dependencies = [
"base64ct",
"blake2",
"cpufeatures 0.2.17",
"password-hash",
]
[[package]]
@@ -159,18 +124,6 @@ version = "1.1.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1505bd5d3d116872e7271a6d4e16d81d0c8570876c8de68093a09ac269d8aac0"
[[package]]
name = "base64"
version = "0.22.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6"
[[package]]
name = "base64ct"
version = "1.8.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2af50177e190e07a26ab74f8b1efbfe2ef87da2116221318cb1c2e82baf7de06"
[[package]]
name = "bech32"
version = "0.11.1"
@@ -219,15 +172,6 @@ version = "2.13.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da"
[[package]]
name = "blake2"
version = "0.10.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "46502ad458c9a52b69d4d4d32775c788b7a1b85e8bc9d482d92250fc0e3f8efe"
dependencies = [
"digest",
]
[[package]]
name = "block-buffer"
version = "0.10.4"
@@ -237,15 +181,6 @@ dependencies = [
"generic-array",
]
[[package]]
name = "block-padding"
version = "0.3.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a8894febbff9f758034a5b8e12d87918f56dfc64a8e1fe757d65e29041538d93"
dependencies = [
"generic-array",
]
[[package]]
name = "blocking"
version = "1.6.2"
@@ -265,15 +200,6 @@ version = "1.12.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "fc652a48c352aef3ea3aed32080501cf3ef6ed5da78602a020c991775b0aff04"
[[package]]
name = "cbc"
version = "0.1.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "26b52a9543ae338f279b96b0b9fed9c8093744685043739079ce85cd58f289a6"
dependencies = [
"cipher",
]
[[package]]
name = "cc"
version = "1.3.0"
@@ -480,17 +406,6 @@ dependencies = [
"windows-sys 0.61.2",
]
[[package]]
name = "displaydoc"
version = "0.2.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c6232dd377dcc64799954cbd3a9bb882e9cdc1308ccd87b1c098f1fb2eaf82a8"
dependencies = [
"proc-macro2",
"quote",
"syn 3.0.3",
]
[[package]]
name = "either"
version = "1.16.0"
@@ -561,7 +476,7 @@ dependencies = [
"libc",
"rand 0.10.2",
"rtnetlink",
"secp256k1 0.30.0",
"secp256k1",
"serde",
"serde_json",
"serde_yaml",
@@ -576,15 +491,6 @@ dependencies = [
"tun",
]
[[package]]
name = "form_urlencoded"
version = "1.2.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "cb4cb245038516f5f85277875cdaa4f7d2c9a0fa0468de06ed190163b1581fcf"
dependencies = [
"percent-encoding",
]
[[package]]
name = "futures"
version = "0.3.33"
@@ -770,110 +676,6 @@ dependencies = [
"digest",
]
[[package]]
name = "icu_collections"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "fa68d21081c4a05d5a901a1c62add574c77048b6a1c67be3b50ce0b60d4ca513"
dependencies = [
"displaydoc",
"potential_utf",
"utf8_iter",
"yoke",
"zerofrom",
"zerovec",
]
[[package]]
name = "icu_locale_core"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d56e28588da92eee5c3201a6eff33fabdd49b62269c8938d4ff050ce4d900deb"
dependencies = [
"displaydoc",
"litemap",
"tinystr",
"writeable",
"zerovec",
]
[[package]]
name = "icu_normalizer"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "12f9cf5f235641ed274641dd81c3f28d870e276763d0797aeeab72317b1c646f"
dependencies = [
"icu_collections",
"icu_normalizer_data",
"icu_properties",
"icu_provider",
"smallvec",
"zerovec",
]
[[package]]
name = "icu_normalizer_data"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1563da1ed3e0b3bf3d74c9b85917ac9c56464d2f57242270c09c9e752f8021a0"
[[package]]
name = "icu_properties"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7e7ca276ad3145661a65914e6daf131ca5120cd3dcee8f8f3214b8875184a148"
dependencies = [
"displaydoc",
"icu_collections",
"icu_locale_core",
"icu_properties_data",
"icu_provider",
"zerotrie",
"zerovec",
]
[[package]]
name = "icu_properties_data"
version = "2.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e590f038c1464a96894fd6d10127e90a8be4509f56ff7ecef851b15cee0b7caa"
[[package]]
name = "icu_provider"
version = "2.3.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d27bbb9d3abbefac45d55f647c9de1d44aafcd1186eb91879afef17c396c3e73"
dependencies = [
"displaydoc",
"icu_locale_core",
"writeable",
"yoke",
"zerofrom",
"zerotrie",
"zerovec",
]
[[package]]
name = "idna"
version = "1.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3b0875f23caa03898994f6ddc501886a45c7d3d62d04d2d90788d47be1b1e4de"
dependencies = [
"idna_adapter",
"smallvec",
"utf8_iter",
]
[[package]]
name = "idna_adapter"
version = "1.2.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "cb68373c0d6620ef8105e855e7745e18b0d00d3bdb07fb532e434244cdb9a714"
dependencies = [
"icu_normalizer",
"icu_properties",
]
[[package]]
name = "indexmap"
version = "2.14.0"
@@ -890,7 +692,6 @@ version = "0.1.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "879f10e63c20629ecabbb64a8010319738c66a5cd0c29b02d63d272b03751d01"
dependencies = [
"block-padding",
"generic-array",
]
@@ -987,12 +788,6 @@ dependencies = [
"libc",
]
[[package]]
name = "litemap"
version = "0.8.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "47d9d19d1d6efa0109d2f65ff4c85cddd50bd572e5a00127ab10987290bcefae"
[[package]]
name = "log"
version = "0.4.33"
@@ -1159,29 +954,12 @@ version = "2.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f38d5652c16fde515bb1ecef450ab0f6a219d619a7274976324d5e377f7dceba"
[[package]]
name = "password-hash"
version = "0.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "346f04948ba92c43e8469c1ee6736c7563d71012b17d40745260fe106aac2166"
dependencies = [
"base64ct",
"rand_core 0.6.4",
"subtle",
]
[[package]]
name = "paste"
version = "1.0.15"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "57c0d7b74b563b49d38dae00a0c37d4d6de9b432382b2892f0574ddcae73fd0a"
[[package]]
name = "percent-encoding"
version = "2.3.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220"
[[package]]
name = "pin-project-lite"
version = "0.2.17"
@@ -1210,15 +988,6 @@ dependencies = [
"universal-hash",
]
[[package]]
name = "potential_utf"
version = "0.1.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d83eb9bc6d8e5cf568e7a1101d60ee05e81ed50ea106026f3d18deeb046d7661"
dependencies = [
"zerovec",
]
[[package]]
name = "ppv-lite86"
version = "0.2.21"
@@ -1360,15 +1129,6 @@ dependencies = [
"winapi-util",
]
[[package]]
name = "secp256k1"
version = "0.29.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9465315bc9d4566e1724f0fffcbcc446268cb522e60f9a27bcded6b19c108113"
dependencies = [
"secp256k1-sys",
]
[[package]]
name = "secp256k1"
version = "0.30.0"
@@ -1512,12 +1272,6 @@ dependencies = [
"windows-sys 0.61.2",
]
[[package]]
name = "stable_deref_trait"
version = "1.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596"
[[package]]
name = "strsim"
version = "0.11.1"
@@ -1552,17 +1306,6 @@ dependencies = [
"unicode-ident",
]
[[package]]
name = "synstructure"
version = "0.13.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2"
dependencies = [
"proc-macro2",
"quote",
"syn 2.0.119",
]
[[package]]
name = "thiserror"
version = "1.0.69"
@@ -1612,16 +1355,6 @@ dependencies = [
"cfg-if",
]
[[package]]
name = "tinystr"
version = "0.8.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b1e27c91459209c2986af3dcf603a5a74a4368754ce37414f59acc971167f643"
dependencies = [
"displaydoc",
"zerovec",
]
[[package]]
name = "tokio"
version = "1.53.1"
@@ -1786,24 +1519,6 @@ version = "0.2.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "673aac59facbab8a9007c7f6108d11f63b603f7cabff99fabf650fea5c32b861"
[[package]]
name = "url"
version = "2.5.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ff67a8a4397373c3ef660812acab3268222035010ab8680ec4215f38ba3d0eed"
dependencies = [
"form_urlencoded",
"idna",
"percent-encoding",
"serde",
]
[[package]]
name = "utf8_iter"
version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b6c140620e7ffbb22c2dee59cafe6084a59b5ffc27a8859a5f0d494b5d52b6be"
[[package]]
name = "utf8parse"
version = "0.2.2"
@@ -1942,35 +1657,6 @@ dependencies = [
"windows-sys 0.61.2",
]
[[package]]
name = "writeable"
version = "0.6.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3ad82d2a33cdc9674dc7465672f271e096168fcdbe0f799d9e6db8c5892679dc"
[[package]]
name = "yoke"
version = "0.8.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "709fe23a0424b6a435d82152b1bd3fdfb0833487d5fa90d05d42762a9891fef5"
dependencies = [
"stable_deref_trait",
"yoke-derive",
"zerofrom",
]
[[package]]
name = "yoke-derive"
version = "0.8.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "de844c262c8848816172cef550288e7dc6c7b7814b4ee56b3e1553f275f1858e"
dependencies = [
"proc-macro2",
"quote",
"syn 2.0.119",
"synstructure",
]
[[package]]
name = "zerocopy"
version = "0.8.55"
@@ -1991,66 +1677,12 @@ dependencies = [
"syn 2.0.119",
]
[[package]]
name = "zerofrom"
version = "0.1.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0ec05a11813ea801ff6d75110ad09cd0824ddba17dfe17128ea0d5f68e6c5272"
dependencies = [
"zerofrom-derive",
]
[[package]]
name = "zerofrom-derive"
version = "0.1.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "11532158c46691caf0f2593ea8358fed6bbf68a0315e80aae9bd41fbade684a1"
dependencies = [
"proc-macro2",
"quote",
"syn 2.0.119",
"synstructure",
]
[[package]]
name = "zeroize"
version = "1.9.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
[[package]]
name = "zerotrie"
version = "0.2.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4ea269c3bd32f0a32c321907a2ae912ba6f4649bb0fc764a15627e99a7095a3f"
dependencies = [
"displaydoc",
"yoke",
"zerofrom",
]
[[package]]
name = "zerovec"
version = "0.11.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "bb0464e17806c1d976d5cba29399c7f08e516e279e2ba493f63123b5fca67dd8"
dependencies = [
"yoke",
"zerofrom",
"zerovec-derive",
]
[[package]]
name = "zerovec-derive"
version = "0.11.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "34df6fc39dbd26ddc9c10e6a2984476e13acce22e64e4487636ef494369225da"
dependencies = [
"proc-macro2",
"quote",
"syn 3.0.3",
]
[[package]]
name = "zmij"
version = "1.0.23"
-29
View File
@@ -37,35 +37,6 @@ tracing = "0.1"
# fcntl: force the VpnService TUN fd into blocking mode (see mesh::start).
libc = "0.2"
# ── Companion backup (#128) ───────────────────────────────────────────────
# ADR-005 envelope: the SAME crates and blob layout as the node's backup code
# (core/archipelago/src/backup/identity.rs) — Argon2id KDF + ChaCha20-Poly1305
# AEAD — applied to the companion's own JSON payload. Do not diverge from
# those parameters: a companion backup and a node backup must decrypt with
# the same code path on either side.
argon2 = "0.5"
chacha20poly1305 = "0.10"
base64 = "0.22"
# ── NIP-46 remote signer (#139) ───────────────────────────────────────────
# BIP340 schnorr signing + secp256k1 ECDH (NIP-44/NIP-04 conversation keys).
# Audited libsecp256k1 via cc; cargo-ndk provides the NDK clang on Android.
secp256k1 = "0.29"
# NIP-44 v2: HKDF-SHA256 (conversation/message keys) + HMAC-SHA256 (MAC).
sha2 = "0.10"
hmac = "0.12"
hkdf = "0.12"
# NIP-44 v2 stream cipher (raw ChaCha20, RFC 8439 — NOT the AEAD).
chacha20 = "0.9"
# NIP-04 fallback (deprecated in the spec but still sent by real clients):
# AES-256-CBC, key = raw ECDH x-coordinate.
aes = "0.8"
cbc = { version = "0.1", features = ["alloc"] }
# npub/nsec (bech32, BIP173 variant — NOT Bech32m).
bech32 = "0.11"
# nostrconnect:// URI parsing (repeated relay params + percent-decoding).
url = "2.5"
# The JNI surface only exists on Android; host builds skip it and drive the
# mesh module directly (tests).
[target.'cfg(target_os = "android")'.dependencies]
-246
View File
@@ -1,246 +0,0 @@
//! Companion app backup — the ADR-005 encrypted-backup envelope.
//!
//! Reuses the node's backup format exactly (ADR-005:
//! `core/archipelago/src/backup/identity.rs`): Argon2id key derivation with
//! default params, ChaCha20-Poly1305 AEAD, and the same blob layout
//! `base64(salt[16] || nonce[12] || ciphertext)`. A companion backup and a
//! node backup share one crypto story — the payload differs (the companion
//! serializes its servers, FIPS identity and signer key instead of a node
//! key), the envelope does not.
//!
//! The envelope is JSON with `version`, `kind`, `encrypted`, `blob` and
//! `timestamp`; [`decrypt`] ignores any extra fields, so node envelopes
//! (which carry `did`/`pubkey`/`kid`) decrypt here too.
use anyhow::{bail, Context, Result};
use argon2::Argon2;
use base64::engine::general_purpose::STANDARD as BASE64;
use base64::Engine;
use chacha20poly1305::aead::{Aead, KeyInit};
use chacha20poly1305::{ChaCha20Poly1305, Key, Nonce};
use serde_json::json;
/// Envelope version. Bump only when the blob layout itself changes — and
/// then only with a reader for the old layout (same policy as the node).
const BACKUP_VERSION: u32 = 1;
const SALT_LEN: usize = 16;
const NONCE_LEN: usize = 12;
const KEY_LEN: usize = 32;
/// Encrypt a JSON payload into an ADR-005 envelope.
///
/// The passphrase never leaves this call; the envelope carries only the
/// salt (Argon2id parameter), the AEAD nonce, and the ciphertext.
pub fn encrypt(payload: &str, passphrase: &str) -> Result<String> {
if payload.is_empty() {
bail!("backup payload is empty");
}
if passphrase.is_empty() {
bail!("backup passphrase must not be empty");
}
let mut salt = [0u8; SALT_LEN];
let mut nonce = [0u8; NONCE_LEN];
// Same CSPRNG discipline as identity generation (getrandom, see mesh.rs):
// OS RNG, never thread-local or derived-from-content randomness for key
// material or nonces.
getrandom::getrandom(&mut salt).context("OS RNG")?;
getrandom::getrandom(&mut nonce).context("OS RNG")?;
let key = derive_key(passphrase, &salt)?;
let cipher = ChaCha20Poly1305::new(Key::from_slice(&key));
let ciphertext = cipher
.encrypt(Nonce::from_slice(&nonce), payload.as_bytes())
.map_err(|_| anyhow::anyhow!("encryption failed"))?;
let mut blob = Vec::with_capacity(SALT_LEN + NONCE_LEN + ciphertext.len());
blob.extend_from_slice(&salt);
blob.extend_from_slice(&nonce);
blob.extend_from_slice(&ciphertext);
Ok(json!({
"version": BACKUP_VERSION,
"kind": "companion",
"encrypted": true,
"blob": BASE64.encode(&blob),
"timestamp": chrono_like_now(),
})
.to_string())
}
/// Decrypt an ADR-005 envelope back into its JSON payload.
///
/// Accepts `version: 1` envelopes regardless of `kind` or extra fields —
/// the node's identity backups use the same blob, and being able to decrypt
/// one here is free interop (the caller decides what to do with it).
pub fn decrypt(envelope: &str, passphrase: &str) -> Result<String> {
let obj: serde_json::Value =
serde_json::from_str(envelope).context("not a JSON backup envelope")?;
if obj.get("version").and_then(|v| v.as_u64()) != Some(BACKUP_VERSION as u64) {
bail!("unsupported backup version (expected {BACKUP_VERSION})");
}
let blob_b64 = obj
.get("blob")
.and_then(|v| v.as_str())
.context("missing 'blob' in backup envelope")?;
let blob = BASE64
.decode(blob_b64)
.context("invalid base64 in backup blob")?;
if blob.len() < SALT_LEN + NONCE_LEN {
bail!("backup blob too short");
}
let salt = &blob[..SALT_LEN];
let nonce = &blob[SALT_LEN..SALT_LEN + NONCE_LEN];
let ciphertext = &blob[SALT_LEN + NONCE_LEN..];
let key = derive_key(passphrase, salt)?;
let cipher = ChaCha20Poly1305::new(Key::from_slice(&key));
let plaintext = cipher
.decrypt(Nonce::from_slice(nonce), ciphertext)
.map_err(|_| anyhow::anyhow!("decryption failed — wrong passphrase or corrupted backup"))?;
String::from_utf8(plaintext).context("decrypted payload is not valid UTF-8")
}
fn derive_key(passphrase: &str, salt: &[u8]) -> Result<[u8; KEY_LEN]> {
let mut key = [0u8; KEY_LEN];
Argon2::default()
.hash_password_into(passphrase.as_bytes(), salt, &mut key)
.map_err(|e| anyhow::anyhow!("Argon2 key derivation failed: {e}"))?;
Ok(key)
}
/// RFC 3339 UTC timestamp without pulling chrono into the .so — the node's
/// envelope field is informational (display), not part of the authenticated
/// or derived material.
fn chrono_like_now() -> String {
let secs = std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.map(|d| d.as_secs())
.unwrap_or(0);
let days = secs / 86_400;
let rem = secs % 86_400;
let (h, m, s) = (rem / 3600, (rem % 3600) / 60, rem % 60);
// Civil-from-days (Howard Hinnant's algorithm), valid for 1970-2100+.
let z = days as i64 + 719_468;
let era = z.div_euclid(146_097);
let doe = z.rem_euclid(146_097);
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365;
let y = yoe + era * 400;
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100);
let mp = (5 * doy + 2) / 153;
let d = doy - (153 * mp + 2) / 5 + 1;
let mo = if mp < 10 { mp + 3 } else { mp - 9 };
let y = if mo <= 2 { y + 1 } else { y };
format!("{y:04}-{mo:02}-{d:02}T{h:02}:{m:02}:{s:02}Z")
}
#[cfg(test)]
mod tests {
use super::*;
const PAYLOAD: &str = r#"{"app":"archipelago-companion","servers":["192.168.1.10|false|1301||Lab Node|fd00::1|npub1abc"]}"#;
#[test]
fn round_trip() {
let envelope = encrypt(PAYLOAD, "correct horse battery staple").unwrap();
let decrypted = decrypt(&envelope, "correct horse battery staple").unwrap();
assert_eq!(decrypted, PAYLOAD);
}
#[test]
fn wrong_passphrase_fails() {
let envelope = encrypt(PAYLOAD, "right").unwrap();
let err = decrypt(&envelope, "wrong").unwrap_err();
assert!(
err.to_string().contains("wrong passphrase"),
"error should name the likely cause: {err}"
);
}
#[test]
fn envelope_shape_matches_node_format() {
let envelope = encrypt(PAYLOAD, "pw").unwrap();
let obj: serde_json::Value = serde_json::from_str(&envelope).unwrap();
assert_eq!(obj["version"], 1);
assert_eq!(obj["encrypted"], true);
assert!(obj["kind"].as_str().is_some());
assert!(obj["timestamp"].as_str().is_some());
// Blob layout is exactly the node's: base64(salt||nonce||ct) with the
// AEAD tag inside the ciphertext — at least 16+12+16+1 bytes.
let blob = BASE64
.decode(obj["blob"].as_str().unwrap())
.expect("blob is base64");
assert!(blob.len() >= SALT_LEN + NONCE_LEN + 16 + PAYLOAD.len());
}
#[test]
fn fresh_salt_and_nonce_every_time() {
let a = encrypt(PAYLOAD, "pw").unwrap();
let b = encrypt(PAYLOAD, "pw").unwrap();
let (oa, ob): (serde_json::Value, serde_json::Value) = (
serde_json::from_str(&a).unwrap(),
serde_json::from_str(&b).unwrap(),
);
assert_ne!(oa["blob"], ob["blob"], "salt/nonce must never repeat");
}
#[test]
fn tampered_blob_fails_to_decrypt() {
let envelope = encrypt(PAYLOAD, "pw").unwrap();
let mut obj: serde_json::Value = serde_json::from_str(&envelope).unwrap();
let blob = BASE64.decode(obj["blob"].as_str().unwrap()).unwrap();
let mut tampered = blob.clone();
// Flip a bit inside the ciphertext (past salt+nonce).
tampered[SALT_LEN + NONCE_LEN] ^= 0x01;
obj["blob"] = serde_json::Value::String(BASE64.encode(&tampered));
assert!(decrypt(&obj.to_string(), "pw").is_err());
}
/// Node identity backups use the same blob layout but carry their own
/// envelope fields (did/pubkey/kid). Decrypt must ignore those extras —
/// one envelope reader, two producers.
#[test]
fn node_style_envelope_with_extra_fields_decrypts() {
let envelope = encrypt(PAYLOAD, "pw").unwrap();
let mut obj: serde_json::Value = serde_json::from_str(&envelope).unwrap();
obj["kind"] = serde_json::Value::String("node-identity".into());
obj["did"] = serde_json::Value::String("did:key:z6Mktest".into());
obj["pubkey"] = serde_json::Value::String("aabbcc".into());
obj["kid"] = serde_json::Value::String("did:key:z6Mktest#key-1".into());
let decrypted = decrypt(&obj.to_string(), "pw").unwrap();
assert_eq!(decrypted, PAYLOAD);
}
#[test]
fn rejects_unknown_version_and_garbage() {
let err = decrypt("{\"version\":99,\"blob\":\"AAAA\"}", "pw").unwrap_err();
assert!(err.to_string().contains("version"));
assert!(decrypt("not json", "pw").is_err());
assert!(decrypt("{\"version\":1}", "pw").is_err());
}
#[test]
fn rejects_empty_passphrase_and_payload() {
assert!(encrypt(PAYLOAD, "").is_err());
assert!(encrypt("", "pw").is_err());
}
#[test]
fn timestamp_is_rfc3339_utc() {
let envelope = encrypt(PAYLOAD, "pw").unwrap();
let obj: serde_json::Value = serde_json::from_str(&envelope).unwrap();
let ts = obj["timestamp"].as_str().unwrap();
// 2026-08-31T12:34:56Z — 20 chars, RFC 3339 UTC.
assert_eq!(ts.len(), 20);
assert!(ts.ends_with('Z'));
assert_eq!(&ts[4..5], "-");
assert_eq!(&ts[10..11], "T");
assert!(ts.starts_with("20"));
}
}
+2 -177
View File
@@ -1,6 +1,5 @@
//! JNI surface for `com.archipelago.app.fips.FipsNative` and
//! `com.archipelago.app.NativeCore` — JSON over strings, no codegen (the
//! myco / nostr-vpn embedding pattern). Errors come back as
//! JNI surface for `com.archipelago.app.fips.FipsNative` — JSON over strings,
//! no codegen (the myco / nostr-vpn embedding pattern). Errors come back as
//! `{"error": "…"}` so Kotlin never sees a raw exception from native code.
use std::sync::Once;
@@ -128,177 +127,3 @@ pub extern "system" fn Java_com_archipelago_app_fips_FipsNative_statusJson(
) -> jstring {
out(&env, mesh::status_json())
}
// ─────────────────────────────────────────────────────────────────────────────
// com.archipelago.app.NativeCore — companion backup (#128) and NIP-46 remote
// signer crypto (#139). Same library, JSON-over-strings contract.
// ─────────────────────────────────────────────────────────────────────────────
/// Kotlin: `external fun backupEncrypt(payload: String, passphrase: String): String`
/// Returns the ADR-005 envelope JSON or `{"error": …}`.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_backupEncrypt(
mut env: JNIEnv,
_class: JClass,
payload: JString,
passphrase: JString,
) -> jstring {
init_logging();
let payload = jstr(&mut env, &payload);
let passphrase = jstr(&mut env, &passphrase);
let json = match crate::backup::encrypt(&payload, &passphrase) {
Ok(envelope) => envelope,
Err(e) => err_json(e),
};
out(&env, json)
}
/// Kotlin: `external fun backupDecrypt(envelope: String, passphrase: String): String`
/// Returns the decrypted payload JSON or `{"error": …}`.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_backupDecrypt(
mut env: JNIEnv,
_class: JClass,
envelope: JString,
passphrase: JString,
) -> jstring {
init_logging();
let envelope = jstr(&mut env, &envelope);
let passphrase = jstr(&mut env, &passphrase);
let json = match crate::backup::decrypt(&envelope, &passphrase) {
Ok(payload) => payload,
Err(e) => err_json(e),
};
out(&env, json)
}
/// Kotlin: `external fun nostrGenerateSecret(): String`
/// Returns `{"secret": hex, "pubkey": hex, "npub": …, "nsec": …}` or `{"error": …}`.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_nostrGenerateSecret(
env: JNIEnv,
_class: JClass,
) -> jstring {
init_logging();
let json = match crate::nostr::generate_secret() {
Ok(secret) => nostr_key_info_json(&secret),
Err(e) => err_json(e),
};
out(&env, json)
}
/// Kotlin: `external fun nostrSecretFromAny(secret: String): String`
/// Accepts hex or `nsec…`; returns key-info JSON or `{"error": …}`.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_nostrSecretFromAny(
mut env: JNIEnv,
_class: JClass,
secret: JString,
) -> jstring {
init_logging();
let secret = jstr(&mut env, &secret);
let json = match crate::nostr::secret_from_any(&secret) {
Ok(hex) => nostr_key_info_json(&hex),
Err(e) => err_json(e),
};
out(&env, json)
}
fn nostr_key_info_json(secret_hex: &str) -> String {
match (
crate::nostr::pubkey_hex(secret_hex),
crate::nostr::npub_from_pubkey(&crate::nostr::pubkey_hex(secret_hex).unwrap_or_default()),
crate::nostr::nsec_from_secret(secret_hex),
) {
(Ok(pubkey), Ok(npub), Ok(nsec)) => serde_json::json!({
"secret": secret_hex,
"pubkey": pubkey,
"npub": npub,
"nsec": nsec,
})
.to_string(),
(e, _, _) => err_json(e.unwrap_err()),
}
}
/// Kotlin: `external fun nostrParseConnectUri(uri: String): String`
/// Returns the parsed URI fields or `{"error": …}`.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_nostrParseConnectUri(
mut env: JNIEnv,
_class: JClass,
uri: JString,
) -> jstring {
init_logging();
let uri = jstr(&mut env, &uri);
let json = match crate::nostr::parse_connect_uri(&uri) {
Ok(info) => info.to_json().to_string(),
Err(e) => err_json(e),
};
out(&env, json)
}
/// Kotlin: `external fun nostrSignEvent(secretHex: String, eventJson: String): String`
/// Returns the signed event JSON or `{"error": …}`. The approve/deny decision
/// is made in Kotlin BEFORE this is called — native code never signs unasked.
#[no_mangle]
pub extern "system" fn Java_com_archipelago_app_NativeCore_nostrSignEvent(
mut env: JNIEnv,
_class: JClass,
secret_hex: JString,
event_json: JString,
) -> jstring {
init_logging();
let secret = jstr(&mut env, &secret_hex);
let event = jstr(&mut env, &event_json);
let json = match crate::nostr::sign_event(&secret, &event) {
Ok(signed) => signed,
Err(e) => err_json(e),
};
out(&env, json)
}
macro_rules! nostr_cipher {
($name:ident, $doc:literal, $fn:path) => {
#[doc = $doc]
#[no_mangle]
pub extern "system" fn $name(
mut env: JNIEnv,
_class: JClass,
secret_hex: JString,
peer_pub: JString,
text: JString,
) -> jstring {
init_logging();
let secret = jstr(&mut env, &secret_hex);
let peer = jstr(&mut env, &peer_pub);
let text = jstr(&mut env, &text);
let json = match $fn(&secret, &peer, &text) {
Ok(out) => serde_json::json!({ "result": out }).to_string(),
Err(e) => err_json(e),
};
out(&env, json)
}
};
}
nostr_cipher!(
Java_com_archipelago_app_NativeCore_nostrNip44Encrypt,
"Kotlin: `external fun nostrNip44Encrypt(secretHex: String, peerPub: String, plaintext: String): String` — returns `{\"result\": payload}` or `{\"error\": …}`.",
crate::nostr::nip44_encrypt
);
nostr_cipher!(
Java_com_archipelago_app_NativeCore_nostrNip44Decrypt,
"Kotlin: `external fun nostrNip44Decrypt(secretHex: String, peerPub: String, payload: String): String`",
crate::nostr::nip44_decrypt
);
nostr_cipher!(
Java_com_archipelago_app_NativeCore_nostrNip04Encrypt,
"Kotlin: `external fun nostrNip04Encrypt(secretHex: String, peerPub: String, plaintext: String): String`",
crate::nostr::nip04_encrypt
);
nostr_cipher!(
Java_com_archipelago_app_NativeCore_nostrNip04Decrypt,
"Kotlin: `external fun nostrNip04Decrypt(secretHex: String, peerPub: String, payload: String): String`",
crate::nostr::nip04_decrypt
);
-2
View File
@@ -11,9 +11,7 @@
//! JSON-over-strings, mirroring the myco / nostr-vpn embedding pattern:
//! `generateIdentity`, `deriveIdentity`, `start`, `stop`, `isRunning`.
pub mod backup;
pub mod mesh;
pub mod nostr;
#[cfg(target_os = "android")]
mod jni_glue;
-824
View File
@@ -1,824 +0,0 @@
//! NIP-46 phone-side remote signer ("bunker") crypto core.
//!
//! Everything that must be constant-time correct for the companion to act as
//! a nostr remote signer: key handling (nsec/npub bech32), BIP340 schnorr
//! event signing, NIP-44 v2 payload encryption (the mandated NIP-46
//! transport), NIP-04 fallback decryption (deprecated, but real clients
//! still speak it), and `nostrconnect://` URI parsing. The protocol session
//! — relay WebSocket, JSON-RPC dispatch, approve/deny UX — lives in Kotlin;
//! this module is the crypto and nothing but.
//!
//! Verified against the official NIP-44 vectors and BIP-340 reference
//! vectors (see tests below).
use anyhow::{bail, Context, Result};
use base64::engine::general_purpose::{STANDARD as BASE64, URL_SAFE as BASE64_URL};
use base64::Engine;
use bech32::{Bech32, Hrp};
use chacha20::cipher::{KeyIvInit, StreamCipher};
use chacha20::ChaCha20;
use hmac::{Hmac, Mac};
use hkdf::Hkdf;
use secp256k1::ecdh;
use secp256k1::schnorr::Signature;
use secp256k1::{
Keypair, Message, PublicKey, Secp256k1, SecretKey, XOnlyPublicKey,
};
use sha2::{Digest, Sha256};
type HmacSha256 = Hmac<Sha256>;
const NIP44_VERSION: u8 = 2;
const NIP44_SALT: &[u8] = b"nip44-v2";
const NIP44_MIN_PAYLOAD_LEN: usize = 99; // 1 ver + 32 nonce + 32 ct + 32 mac
const NIP44_MIN_B64_LEN: usize = 132;
// ── keys ──────────────────────────────────────────────────────────────────
/// Generate a fresh nostr secret key (hex) from the OS CSPRNG.
pub fn generate_secret() -> Result<String> {
loop {
let mut bytes = [0u8; 32];
getrandom::getrandom(&mut bytes).context("OS RNG")?;
// Reject zero and >= curve order — the valid scalar range (mirrors
// the mesh identity loop; rejection is astronomically unlikely).
if bytes.iter().all(|&b| b == 0) {
continue;
}
if SecretKey::from_slice(&bytes).is_ok() {
return Ok(hex::encode(bytes));
}
}
}
/// Parse a secret key from hex or bech32 `nsec…` form into hex.
pub fn secret_from_any(s: &str) -> Result<String> {
let s = s.trim();
if s.starts_with("nsec") {
return secret_from_nsec(s);
}
let bytes = hex::decode(s.trim()).context("secret key must be hex or nsec")?;
let sk = SecretKey::from_slice(&bytes).context("invalid nostr secret key")?;
Ok(hex::encode(sk.secret_bytes()))
}
pub fn secret_from_nsec(nsec: &str) -> Result<String> {
let (hrp, data) = bech32::decode(nsec).context("bad nsec encoding")?;
if hrp.as_str() != "nsec" {
bail!("not an nsec");
}
let sk = SecretKey::from_slice(&data).context("invalid nostr secret key")?;
Ok(hex::encode(sk.secret_bytes()))
}
pub fn nsec_from_secret(secret_hex: &str) -> Result<String> {
let bytes = hex::decode(secret_hex.trim()).context("bad secret hex")?;
let hrp = Hrp::parse("nsec").context("nsec hrp")?;
bech32::encode::<Bech32>(hrp, &bytes).context("nsec encoding")
}
/// x-only public key (hex) for a secret key.
/// NOTE: `Keypair::public_key()` in secp256k1 0.29 is the full compressed
/// (33-byte) key — nostr uses x-only pubkeys, so serialize `.x_only_public_key().0`.
pub fn pubkey_hex(secret_hex: &str) -> Result<String> {
let kp = keypair(secret_hex)?;
Ok(hex::encode(kp.public_key().x_only_public_key().0.serialize()))
}
pub fn npub_from_pubkey(pub_hex: &str) -> Result<String> {
let bytes = hex::decode(pub_hex.trim()).context("bad pubkey hex")?;
let hrp = Hrp::parse("npub").context("npub hrp")?;
bech32::encode::<Bech32>(hrp, &bytes).context("npub encoding")
}
/// Parse an x-only pubkey from hex or bech32 `npub…` form into hex.
pub fn pubkey_from_any(s: &str) -> Result<String> {
let s = s.trim();
let bytes = if s.starts_with("npub") {
let (hrp, data) = bech32::decode(s).context("bad npub encoding")?;
if hrp.as_str() != "npub" {
bail!("not an npub");
}
data
} else {
hex::decode(s).context("pubkey must be hex or npub")?
};
XOnlyPublicKey::from_slice(&bytes).context("invalid x-only pubkey")?;
Ok(hex::encode(bytes))
}
fn keypair(secret_hex: &str) -> Result<Keypair> {
let bytes = hex::decode(secret_hex.trim()).context("bad secret hex")?;
let sk = SecretKey::from_slice(&bytes).context("invalid nostr secret key")?;
Ok(Keypair::from_secret_key(&Secp256k1::new(), &sk))
}
// ── nostrconnect:// URI ───────────────────────────────────────────────────
#[derive(Debug, Clone)]
pub struct ConnectUri {
/// The client's pubkey, hex.
pub client_pubkey: String,
/// Relays the client is listening on (≥1 by spec; kept in URI order).
pub relays: Vec<String>,
/// One-time pairing secret the client expects to see echoed back.
pub secret: String,
/// Comma-separated permission grants the client requests (display hint
/// only — approval always stays with the human).
pub perms: Vec<String>,
pub name: String,
pub url: String,
pub image: String,
}
impl ConnectUri {
/// JSON shape for the JNI boundary (flat strings/arrays — easy to parse
/// with org.json on the Kotlin side).
pub fn to_json(&self) -> serde_json::Value {
serde_json::json!({
"clientPubkey": self.client_pubkey,
"relays": self.relays,
"secret": self.secret,
"perms": self.perms,
"name": self.name,
"url": self.url,
"image": self.image,
})
}
}
/// Parse `nostrconnect://<client-pubkey>?relay=…&secret=…&perms=…&name=…`.
///
/// Query values are percent-decoded; `relay` may repeat. The pubkey in the
/// host position may be hex or (non-spec but harmless) `npub…`.
pub fn parse_connect_uri(uri: &str) -> Result<ConnectUri> {
let uri = uri.trim();
let rest = uri
.strip_prefix("nostrconnect://")
.ok_or_else(|| anyhow::anyhow!("not a nostrconnect:// URI"))?;
let (host, query) = match rest.split_once('?') {
Some((h, q)) => (h, q),
None => bail!("nostrconnect URI has no query parameters"),
};
let client_pubkey = pubkey_from_any(host).context("nostrconnect URI: bad client pubkey")?;
let mut relays = Vec::new();
let mut secret = String::new();
let mut perms: Vec<String> = Vec::new();
let mut name = String::new();
let mut url = String::new();
let mut image = String::new();
for (k, v) in url::form_urlencoded::parse(query.as_bytes()) {
let v = v.into_owned();
match k.as_ref() {
"relay" => {
if v.starts_with("ws://") || v.starts_with("wss://") {
relays.push(v);
}
}
"secret" => secret = v,
"perms" => perms = v.split(',').filter(|s| !s.is_empty()).map(String::from).collect(),
"name" => name = v,
"url" => url = v,
"image" => image = v,
_ => {} // forward-compat: ignore unknown params
}
}
if relays.is_empty() {
bail!("nostrconnect URI carries no relay");
}
if secret.is_empty() {
bail!("nostrconnect URI carries no secret");
}
Ok(ConnectUri {
client_pubkey,
relays,
secret,
perms,
name,
url,
image,
})
}
// ── events (NIP-01 id + BIP340 signature) ─────────────────────────────────
/// Compute the NIP-01 event id: sha256 over the compact serialization
/// `[0, pubkey, created_at, kind, tags, content]`.
fn event_id(pubkey: &str, created_at: u64, kind: u64, tags: &serde_json::Value, content: &str) -> [u8; 32] {
let serialized = serde_json::json!([
0,
pubkey,
created_at,
kind,
tags,
content,
]);
let mut hasher = Sha256::new();
hasher.update(serialized.to_string().as_bytes());
hasher.finalize().into()
}
/// Sign an unsigned event `{kind, content, tags, created_at}` (pubkey filled
/// from the secret key; `pubkey` in the input ignored) and return the signed
/// event JSON. This is the `sign_event` NIP-46 method's core — the approve
/// happens before this call, never inside it.
pub fn sign_event(secret_hex: &str, event_json: &str) -> Result<String> {
let ev: serde_json::Value = serde_json::from_str(event_json).context("event is not JSON")?;
let kind = ev
.get("kind")
.and_then(|v| v.as_u64())
.context("event has no kind")?;
let created_at = ev
.get("created_at")
.and_then(|v| v.as_u64())
.context("event has no created_at")?;
let tags = ev
.get("tags")
.cloned()
.unwrap_or_else(|| serde_json::json!([]));
let content = ev
.get("content")
.and_then(|v| v.as_str())
.unwrap_or("")
.to_string();
let kp = keypair(secret_hex)?;
let pubkey = hex::encode(kp.public_key().x_only_public_key().0.serialize());
let id = event_id(&pubkey, created_at, kind, &tags, &content);
let mut aux = [0u8; 32];
getrandom::getrandom(&mut aux).context("OS RNG")?;
let sig = Secp256k1::new().sign_schnorr_with_aux_rand(
&Message::from_digest(id),
&kp,
&aux,
);
Ok(serde_json::json!({
"id": hex::encode(id),
"pubkey": pubkey,
"created_at": created_at,
"kind": kind,
"tags": tags,
"content": content,
"sig": hex::encode(sig.serialize()),
})
.to_string())
}
/// Verify a signed event's id and schnorr signature (tests + defensive use).
pub fn verify_event(event_json: &str) -> Result<()> {
let ev: serde_json::Value = serde_json::from_str(event_json).context("event is not JSON")?;
let pubkey = ev.get("pubkey").and_then(|v| v.as_str()).context("no pubkey")?;
let id_hex = ev.get("id").and_then(|v| v.as_str()).context("no id")?;
let sig_hex = ev.get("sig").and_then(|v| v.as_str()).context("no sig")?;
let kind = ev.get("kind").and_then(|v| v.as_u64()).context("no kind")?;
let created_at = ev.get("created_at").and_then(|v| v.as_u64()).context("no created_at")?;
let tags = ev.get("tags").cloned().unwrap_or_else(|| serde_json::json!([]));
let content = ev.get("content").and_then(|v| v.as_str()).unwrap_or("");
let expected = event_id(pubkey, created_at, kind, &tags, content);
if hex::encode(expected) != id_hex {
bail!("event id mismatch");
}
let pk = XOnlyPublicKey::from_slice(&hex::decode(pubkey)?)
.context("bad pubkey")?;
let sig = Signature::from_slice(&hex::decode(sig_hex)?)
.context("bad signature")?;
Secp256k1::new()
.verify_schnorr(&sig, &Message::from_digest(expected), &pk)
.context("signature verification failed")?;
Ok(())
}
// ── NIP-44 v2 ──────────────────────────────────────────────────────────────
/// ECDH shared x-coordinate (unhashed, 32 bytes) between our secret key and
/// the peer's x-only public key. Lifting the x-only key with even-y parity
/// is safe here: negating a point flips only y, so the shared x — the only
/// thing NIP-44/NIP-04 consume — is unchanged.
fn shared_x(secret_hex: &str, peer_pubkey_hex: &str) -> Result<[u8; 32]> {
let sk_bytes = hex::decode(secret_hex.trim()).context("bad secret hex")?;
let sk = SecretKey::from_slice(&sk_bytes).context("invalid secret key")?;
let peer_hex = pubkey_from_any(peer_pubkey_hex)?;
let peer = XOnlyPublicKey::from_slice(&hex::decode(&peer_hex)?)
.context("invalid peer pubkey")?;
// Lift x-only key to a full public key (even-y representative).
let full = PublicKey::from_x_only_public_key(peer, secp256k1::Parity::Even);
let point = ecdh::shared_secret_point(&full, &sk); // 64 bytes: x || y
let mut x = [0u8; 32];
x.copy_from_slice(&point[..32]);
Ok(x)
}
/// NIP-44 v2 conversation key: HKDF-extract(IKM = ECDH x, salt = 'nip44-v2').
fn conversation_key(secret_hex: &str, peer_pubkey_hex: &str) -> Result<[u8; 32]> {
let x = shared_x(secret_hex, peer_pubkey_hex)?;
let mut hk = HkdfExtractSha256::new(Some(NIP44_SALT));
hk.input_ikm(&x);
let (prk, _) = hk.finalize();
let mut ck = [0u8; 32];
ck.copy_from_slice(prk.as_slice());
Ok(ck)
}
/// HKDF-SHA256 extract step, exposing the raw PRK (Hkdf::expand hashes with
/// an info suffix even when info is empty, which is NOT the extract output;
/// finalize returns (PRK, ready-to-expand Hkdf)).
type HkdfExtractSha256 = hkdf::HkdfExtract<Sha256>;
/// Per-message keys: HKDF-expand(PRK = conversation key, info = nonce, L = 76)
/// sliced into chacha_key[32] chacha_nonce[12] hmac_key[32].
fn message_keys(ck: &[u8; 32], nonce: &[u8; 32]) -> ([u8; 32], [u8; 12], [u8; 32]) {
let hk = Hkdf::<Sha256>::from_prk(ck).expect("conversation key is 32 bytes");
let mut okm = [0u8; 76];
hk.expand(nonce, &mut okm).expect("76 <= 255 * hash len");
let mut chacha_key = [0u8; 32];
let mut chacha_nonce = [0u8; 12];
let mut hmac_key = [0u8; 32];
chacha_key.copy_from_slice(&okm[..32]);
chacha_nonce.copy_from_slice(&okm[32..44]);
hmac_key.copy_from_slice(&okm[44..76]);
(chacha_key, chacha_nonce, hmac_key)
}
/// NIP-44 padding: 2-byte big-endian plaintext length (6 bytes, `0x0000` +
/// u32, when ≥ 65536), zero-padded to the next power-of-two-ish chunk.
fn calc_padded_len(unpadded: usize) -> usize {
let unpadded: u64 = unpadded as u64;
if unpadded <= 32 {
return 32;
}
let next_power = 1u64 << ((63 - (unpadded - 1).leading_zeros()) + 1);
let chunk = if next_power <= 256 { 32 } else { next_power / 8 };
(chunk * ((unpadded - 1) / chunk + 1)) as usize
}
fn pad(plaintext: &[u8]) -> Result<Vec<u8>> {
if plaintext.is_empty() || plaintext.len() > u32::MAX as usize {
bail!("invalid plaintext length");
}
let prefix: Vec<u8> = if plaintext.len() >= 65536 {
let mut p = vec![0u8, 0u8];
p.extend_from_slice(&(plaintext.len() as u32).to_be_bytes());
p
} else {
(plaintext.len() as u16).to_be_bytes().to_vec()
};
let padded_len = calc_padded_len(plaintext.len());
let mut out = Vec::with_capacity(prefix.len() + padded_len);
out.extend_from_slice(&prefix);
out.extend_from_slice(plaintext);
out.resize(prefix.len() + padded_len, 0);
Ok(out)
}
fn unpad(padded: &[u8]) -> Result<Vec<u8>> {
if padded.len() < 2 {
bail!("invalid padding");
}
let first_two = u16::from_be_bytes([padded[0], padded[1]]);
let (unpadded_len, prefix_len) = if first_two == 0 {
if padded.len() < 6 {
bail!("invalid padding");
}
(u32::from_be_bytes([padded[2], padded[3], padded[4], padded[5]]) as usize, 6)
} else {
(first_two as usize, 2)
};
if unpadded_len == 0
|| padded.len() < prefix_len + unpadded_len
|| padded.len() != prefix_len + calc_padded_len(unpadded_len)
{
bail!("invalid padding");
}
Ok(padded[prefix_len..prefix_len + unpadded_len].to_vec())
}
/// Constant-time equality (length differs → false; content comparison never
/// short-circuits on a byte).
fn ct_eq(a: &[u8], b: &[u8]) -> bool {
if a.len() != b.len() {
return false;
}
let mut diff = 0u8;
for (x, y) in a.iter().zip(b.iter()) {
diff |= x ^ y;
}
diff == 0
}
/// NIP-44 v2 encrypt: returns `base64(0x02 || nonce || ciphertext || mac)`.
pub fn nip44_encrypt(secret_hex: &str, peer_pubkey_hex: &str, plaintext: &str) -> Result<String> {
let ck = conversation_key(secret_hex, peer_pubkey_hex)?;
let mut nonce = [0u8; 32];
getrandom::getrandom(&mut nonce).context("OS RNG")?;
let (chacha_key, chacha_nonce, hmac_key) = message_keys(&ck, &nonce);
let mut padded = pad(plaintext.as_bytes())?;
ChaCha20::new(&chacha_key.into(), &chacha_nonce.into()).apply_keystream(&mut padded);
let mut mac = <HmacSha256 as Mac>::new_from_slice(&hmac_key).expect("hmac accepts any key len");
mac.update(&nonce);
mac.update(&padded);
let tag = mac.finalize().into_bytes();
let mut out = Vec::with_capacity(1 + 32 + padded.len() + 32);
out.push(NIP44_VERSION);
out.extend_from_slice(&nonce);
out.extend_from_slice(&padded);
out.extend_from_slice(&tag);
Ok(BASE64.encode(&out))
}
/// NIP-44 v2 decrypt of a `base64(0x02 || …)` payload.
pub fn nip44_decrypt(secret_hex: &str, peer_pubkey_hex: &str, payload: &str) -> Result<String> {
if payload.starts_with('#') {
bail!("unknown NIP-44 version (non-base64 payload)");
}
let data = BASE64
.decode(payload.trim())
.context("payload is not base64")?;
if payload.len() < NIP44_MIN_B64_LEN || data.len() < NIP44_MIN_PAYLOAD_LEN {
bail!("invalid NIP-44 payload size");
}
if data[0] != NIP44_VERSION {
bail!("unknown NIP-44 version {}", data[0]);
}
let nonce: [u8; 32] = data[1..33].try_into().expect("slice is 32");
let ciphertext = &data[33..data.len() - 32];
let mac_bytes = &data[data.len() - 32..];
let ck = conversation_key(secret_hex, peer_pubkey_hex)?;
let (chacha_key, chacha_nonce, hmac_key) = message_keys(&ck, &nonce);
let mut mac = <HmacSha256 as Mac>::new_from_slice(&hmac_key).expect("hmac accepts any key len");
mac.update(&nonce);
mac.update(ciphertext);
let expected = mac.finalize().into_bytes();
if !ct_eq(&expected, mac_bytes) {
bail!("invalid NIP-44 MAC");
}
let mut buf = ciphertext.to_vec();
ChaCha20::new(&chacha_key.into(), &chacha_nonce.into()).apply_keystream(&mut buf);
let plaintext = unpad(&buf)?;
String::from_utf8(plaintext).context("decrypted payload is not UTF-8")
}
// ── NIP-04 (deprecated transport, still spoken by real clients) ────────────
/// NIP-04 encrypt: AES-256-CBC, key = raw ECDH x-coordinate (unhashed — the
/// spec's quirk), output `<base64 ct>?iv=<base64 iv>`.
pub fn nip04_encrypt(secret_hex: &str, peer_pubkey_hex: &str, plaintext: &str) -> Result<String> {
use aes::cipher::{BlockEncryptMut, KeyIvInit};
type Enc = cbc::Encryptor<aes::Aes256>;
let key = shared_x(secret_hex, peer_pubkey_hex)?;
let mut iv = [0u8; 16];
getrandom::getrandom(&mut iv).context("OS RNG")?;
let ct = Enc::new(&key.into(), &iv.into()).encrypt_padded_vec_mut::<aes::cipher::block_padding::Pkcs7>(plaintext.as_bytes());
Ok(format!("{}?iv={}", BASE64.encode(&ct), BASE64.encode(iv)))
}
/// NIP-04 decrypt of `<base64 ct>?iv=<base64 iv>`.
pub fn nip04_decrypt(secret_hex: &str, peer_pubkey_hex: &str, payload: &str) -> Result<String> {
use aes::cipher::{BlockDecryptMut, KeyIvInit};
type Dec = cbc::Decryptor<aes::Aes256>;
let (ct_b64, iv_b64) = payload
.trim()
.split_once("?iv=")
.ok_or_else(|| anyhow::anyhow!("not a NIP-04 payload (no iv)"))?;
let ct = BASE64.decode(ct_b64).context("bad NIP-04 ciphertext base64")?;
let iv: [u8; 16] = BASE64
.decode(iv_b64)
.context("bad NIP-04 iv base64")?
.try_into()
.map_err(|_| anyhow::anyhow!("NIP-04 iv must be 16 bytes"))?;
let key = shared_x(secret_hex, peer_pubkey_hex)?;
let pt = Dec::new(&key.into(), &iv.into())
.decrypt_padded_vec_mut::<aes::cipher::block_padding::Pkcs7>(&ct)
.map_err(|_| anyhow::anyhow!("NIP-04 decryption failed"))?;
String::from_utf8(pt).context("decrypted payload is not UTF-8")
}
/// URL-safe base64 for keys that cross the JNI boundary — unused by the
/// protocol but handy for the Kotlin side; keep the engine in one place.
pub fn b64_url(data: &[u8]) -> String {
BASE64_URL.encode(data)
}
#[cfg(test)]
mod tests {
use super::*;
// ── official NIP-44 vectors (paulmillr/nip44 nip44.vectors.json) ──────
#[test]
fn nip44_official_conversation_keys() {
let vectors: &[(&str, &str, &str)] = &[
("315e59ff51cb9209768cf7da80791ddcaae56ac9775eb25b6dee1234bc5d2268", "c2f9d9948dc8c7c38321e4b85c8558872eafa0641cd269db76848a6073e69133", "3dfef0ce2a4d80a25e7a328accf73448ef67096f65f79588e358d9a0eb9013f1"),
("98a5902fd67518a0c900f0fb62158f278f94a21d6f9d33d30cd3091195500311", "aae65c15f98e5e677b5050de82e3aba47a6fe49b3dab7863cf35d9478ba9f7d1", "9c00b769d5f54d02bf175b7284a1cbd28b6911b06cda6666b2243561ac96bad7"),
("86ae5ac8034eb2542ce23ec2f84375655dab7f836836bbd3c54cefe9fdc9c19f", "59f90272378089d73f1339710c02e2be6db584e9cdbe86eed3578f0c67c23585", "19f934aafd3324e8415299b64df42049afaa051c71c98d0aa10e1081f2e3e2ba"),
// sec1 == pub2 (ECDH with self)
("0000000000000000000000000000000000000000000000000000000000000001", "79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798", "3b4610cb7189beb9cc29eb3716ecc6102f1247e8f3101a03a1787d8908aeb54e"),
];
for (sec1, pub2, expected) in vectors {
let ck = conversation_key(sec1, pub2).unwrap();
assert_eq!(hex::encode(ck), *expected);
}
}
#[test]
fn nip44_official_message_keys() {
let ck_bytes: [u8; 32] = hex::decode("a1a3d60f3470a8612633924e91febf96dc5366ce130f658b1f0fc652c20b3b54")
.unwrap()
.try_into()
.unwrap();
let vectors: &[(&str, &str, &str, &str)] = &[
("e1e6f880560d6d149ed83dcc7e5861ee62a5ee051f7fde9975fe5d25d2a02d72", "f145f3bed47cb70dbeaac07f3a3fe683e822b3715edb7c4fe310829014ce7d76", "c4ad129bb01180c0933a160c", "027c1db445f05e2eee864a0975b0ddef5b7110583c8c192de3732571ca5838c4"),
("ea6eb84cac23c5c1607c334e8bdf66f7977a7e374052327ec28c6906cbe25967", "ff68db24b34fa62c78ac5ffeeaf19533afaedf651fb6a08384e46787f6ce94be", "50bb859aa2dde938cc49ec7a", "06ff32e1f7b29753a727d7927b25c2dd175aca47751462d37a2039023ec6b5a6"),
];
for (nonce_h, ck_exp, cn_exp, hk_exp) in vectors {
let nonce: [u8; 32] = hex::decode(nonce_h).unwrap().try_into().unwrap();
let (chacha_key, chacha_nonce, hmac_key) = message_keys(&ck_bytes, &nonce);
assert_eq!(hex::encode(chacha_key), *ck_exp);
assert_eq!(hex::encode(chacha_nonce), *cn_exp);
assert_eq!(hex::encode(hmac_key), *hk_exp);
}
}
#[test]
fn nip44_offical_padded_len() {
let vectors: &[(usize, usize)] = &[
(16, 32), (32, 32), (33, 64), (37, 64), (45, 64), (49, 64), (64, 64),
(65, 96), (100, 128), (111, 128), (200, 224), (250, 256), (320, 320),
(383, 384), (384, 384), (400, 448), (500, 512), (512, 512), (515, 640),
(700, 768), (800, 896), (900, 1024), (1020, 1024), (65536, 65536),
];
for (unpadded, padded) in vectors {
assert_eq!(calc_padded_len(*unpadded), *padded, "unpadded {unpadded}");
}
}
#[test]
fn nip44_official_encrypt_vectors() {
// (sec1, sec2, nonce, plaintext, payload) — decrypt with the peer's
// view (sec2, pub(sec1)) so this also proves key symmetry.
let vectors: &[(&str, &str, &str, &str, &str)] = &[
("0000000000000000000000000000000000000000000000000000000000000001",
"0000000000000000000000000000000000000000000000000000000000000002",
"0000000000000000000000000000000000000000000000000000000000000001",
"a",
"AgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABee0G5VSK0/9YypIObAtDKfYEAjD35uVkHyB0F4DwrcNaCXlCWZKaArsGrY6M9wnuTMxWfp1RTN9Xga8no+kF5Vsb"),
("0000000000000000000000000000000000000000000000000000000000000002",
"0000000000000000000000000000000000000000000000000000000000000001",
"f00000000000000000000000000000f00000000000000000000000000000000f",
"🍕🫃",
"AvAAAAAAAAAAAAAAAAAAAPAAAAAAAAAAAAAAAAAAAAAPSKSK6is9ngkX2+cSq85Th16oRTISAOfhStnixqZziKMDvB0QQzgFZdjLTPicCJaV8nDITO+QfaQ61+KbWQIOO2Yj"),
("5c0c523f52a5b6fad39ed2403092df8cebc36318b39383bca6c00808626fab3a",
"4b22aa260e4acb7021e32f38a6cdf4b673c6a277755bfce287e370c924dc936d",
"b635236c42db20f021bb8d1cdff5ca75dd1a0cc72ea742ad750f33010b24f73b",
"表ポあA鷗ŒéB逍Üߪąñ丂㐀𠀀",
"ArY1I2xC2yDwIbuNHN/1ynXdGgzHLqdCrXUPMwELJPc7s7JqlCMJBAIIjfkpHReBPXeoMCyuClwgbT419jUWU1PwaNl4FEQYKCDKVJz+97Mp3K+Q2YGa77B6gpxB/lr1QgoqpDf7wDVrDmOqGoiPjWDqy8KzLueKDcm9BVP8xeTJIxs="),
("eba1687cab6a3101bfc68fd70f214aa4cc059e9ec1b79fdb9ad0a0a4e259829f",
"dff20d262bef9dfd94666548f556393085e6ea421c8af86e9d333fa8747e94b3",
"2180b52ae645fcf9f5080d81b1f0b5d6f2cd77ff3c986882bb549158462f3407",
"( ͡° ͜ʖ ͡°)",
"AiGAtSrmRfz59QgNgbHwtdbyzXf/PJhogrtUkVhGLzQHv4qhKQwnFQ54OjVMgqCea/Vj0YqBSdhqNR777TJ4zIUk7R0fnizp6l1zwgzWv7+ee6u+0/89KIjY5q1wu6inyuiv"),
("d5633530f5bcfebceb5584cfbbf718a30df0751b729dd9a789b9f30c0587d74e",
"b74e6a341fb134127272b795a08b59250e5fa45a82a2eb4095e4ce9ed5f5e214",
"a3e219242d85465e70adcd640b564b3feff57d2ef8745d5e7a0663b2dccceb54",
"🙈 🙉 🙊 0️⃣ 1️⃣ 2️⃣ 3️⃣ 4️⃣ 5️⃣ 6️⃣ 7️⃣ 8️⃣ 9️⃣ 🔟 Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ冗",
"AqPiGSQthUZecK3NZAtWSz/v9X0u+HRdXnoGY7LczOtUf05aMF89q1FLwJvaFJYICZoMYgRJHFLwPiOHce7fuAc40kX0wXJvipyBJ9HzCOj7CgtnC1/cmPCHR3s5AIORmroBWglm1LiFMohv1FSPEbaBD51VXxJa4JyWpYhreSOEjn1wd0lMKC9b+osV2N2tpbs+rbpQem2tRen3sWflmCqjkG5VOVwRErCuXuPb5+hYwd8BoZbfCrsiAVLd7YT44dRtKNBx6rkabWfddKSLtreHLDysOhQUVOp/XkE7OzSkWl6sky0Hva6qJJ/V726hMlomvcLHjE41iKmW2CpcZfOedg=="),
];
for (sec1, sec2, nonce_hex, plaintext, payload) in vectors {
// Encrypt from A to B with the fixed nonce must reproduce the
// official payload byte-for-byte.
let pub1 = pubkey_hex(sec1).unwrap();
let made = {
let ck = conversation_key(sec1, &pubkey_hex(sec2).unwrap()).unwrap();
let nonce: [u8; 32] = hex::decode(nonce_hex).unwrap().try_into().unwrap();
let (chacha_key, chacha_nonce, hmac_key) = message_keys(&ck, &nonce);
let mut padded = pad(plaintext.as_bytes()).unwrap();
ChaCha20::new(&chacha_key.into(), &chacha_nonce.into()).apply_keystream(&mut padded);
let mut mac = <HmacSha256 as Mac>::new_from_slice(&hmac_key).unwrap();
mac.update(&nonce);
mac.update(&padded);
let tag = mac.finalize().into_bytes();
let mut out = vec![NIP44_VERSION];
out.extend_from_slice(&nonce);
out.extend_from_slice(&padded);
out.extend_from_slice(&tag);
BASE64.encode(&out)
};
assert_eq!(&made, payload, "encrypt vector for {plaintext:?}");
// Decrypt from B's view of A (key-role symmetry).
let got = nip44_decrypt(sec2, &pub1, payload).unwrap();
assert_eq!(got, *plaintext);
}
}
#[test]
fn nip44_round_trip_and_failures() {
let sk_a = generate_secret().unwrap();
let sk_b = generate_secret().unwrap();
let pub_b = pubkey_hex(&sk_b).unwrap();
let pub_a = pubkey_hex(&sk_a).unwrap();
let msg = "hello, remote signer";
let payload = nip44_encrypt(&sk_a, &pub_b, msg).unwrap();
assert_eq!(nip44_decrypt(&sk_b, &pub_a, &payload).unwrap(), msg);
// Round-trip long content across the 65536 prefix boundary.
let long = "x".repeat(70_000);
let payload = nip44_encrypt(&sk_a, &pub_b, &long).unwrap();
assert_eq!(nip44_decrypt(&sk_b, &pub_a, &payload).unwrap(), long);
// Wrong peer key must fail the MAC, not return garbage.
let stranger = generate_secret().unwrap();
assert!(nip44_decrypt(&sk_b, &pub_b, &payload).is_err());
let _ = stranger;
// Tampered payload fails.
let payload = nip44_encrypt(&sk_a, &pub_b, msg).unwrap();
let mut tampered = BASE64.decode(&payload).unwrap();
let n = tampered.len();
tampered[n - 1] ^= 0x01;
assert!(nip44_decrypt(&sk_b, &pub_a, &BASE64.encode(&tampered)).is_err());
// Truncated payload fails.
assert!(nip44_decrypt(&sk_b, &pub_a, "AAAA").is_err());
}
// ── BIP-340 official vectors (github.com/bitcoin/bips test vectors) ────
#[test]
fn bip340_reference_sign_vectors() {
// (seckey, pubkey, aux, msg, expected sig) — indices 0/1/2 of the
// official BIP-340 `bip-0340/test-vectors.csv` "should sign" set,
// transcribed from the file itself (x(3G) additionally verified
// by independent scalar-math in the review notes for this commit).
let vectors: &[(&str, &str, &str, &str, &str)] = &[
("0000000000000000000000000000000000000000000000000000000000000003",
"F9308A019258C31049344F85F89D5229B531C845836F99B08601F113BCE036F9",
"0000000000000000000000000000000000000000000000000000000000000000",
"0000000000000000000000000000000000000000000000000000000000000000",
"E907831F80848D1069A5371B402410364BDF1C5F8307B0084C55F1CE2DCA821525F66A4A85EA8B71E482A74F382D2CE5EBEEE8FDB2172F477DF4900D310536C0"),
("B7E151628AED2A6ABF7158809CF4F3C762E7160F38B4DA56A784D9045190CFEF",
"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
"0000000000000000000000000000000000000000000000000000000000000001",
"243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
"6896BD60EEAE296DB48A229FF71DFE071BDE413E6D43F917DC8DCF8C78DE33418906D11AC976ABCCB20B091292BFF4EA897EFCB639EA871CFA95F6DE339E4B0A"),
("C90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B14E5C9",
"DD308AFEC5777E13121FA72B9CC1B7CC0139715309B086C960E18FD969774EB8",
"C87AA53824B4D7AE2EB035A2B5BBBCCC080E76CDC6D1692C4B0B62D798E6D906",
"7E2D58D8B3BCDF1ABADEC7829054F90DDA9805AAB56C77333024B9D0A508B75C",
"5831AAEED7B44BB74E5EAB94BA9D4294C49BCF2A60728D8B4C200F50DD313C1BAB745879A5AD954A72C45A91C3A51D3C7ADEA98D82F8481E0E1E03674A6F3FB7"),
];
for (sk_hex, pk_hex, aux_hex, msg_hex, sig_hex) in vectors {
let sk_bytes = hex::decode(sk_hex).unwrap();
let sk = SecretKey::from_slice(&sk_bytes).unwrap();
let kp = Keypair::from_secret_key(&Secp256k1::new(), &sk);
assert_eq!(hex::encode(kp.public_key().x_only_public_key().0.serialize()).to_uppercase(), *pk_hex);
let msg: [u8; 32] = hex::decode(msg_hex).unwrap().try_into().unwrap();
let aux: [u8; 32] = hex::decode(aux_hex).unwrap().try_into().unwrap();
let sig = Secp256k1::new().sign_schnorr_with_aux_rand(
&Message::from_digest(msg),
&kp,
&aux,
);
assert_eq!(hex::encode(sig.serialize()).to_uppercase(), *sig_hex);
}
}
#[test]
fn event_signing_round_trip() {
let sk = generate_secret().unwrap();
let unsigned = r#"{"kind":22242,"content":"{\"challenge\":\"abc123\"}","tags":[["relay","ws://127.0.0.1:7777"]],"created_at":1725100000}"#;
let signed = sign_event(&sk, unsigned).unwrap();
verify_event(&signed).unwrap();
let ev: serde_json::Value = serde_json::from_str(&signed).unwrap();
assert_eq!(ev["kind"], 22242);
assert_eq!(ev["pubkey"], pubkey_hex(&sk).unwrap());
// Tampering with content breaks the id, which breaks verification.
let mut tampered = ev.clone();
tampered["content"] = serde_json::Value::String("nope".into());
assert!(verify_event(&tampered.to_string()).is_err());
}
#[test]
fn connect_uri_parsing() {
let uri = "nostrconnect://83f3b2ae6aa368e8275397b9c26cf550101d63ebaab900d19dd4a4429f5ad8f5?relay=wss%3A%2F%2Frelay1.example.com&perms=nip44_encrypt%2Csign_event%3A22242&name=My+Client&secret=0s8j2djs&relay=ws%3A%2F%2F192.168.1.20%3A7777";
let info = parse_connect_uri(uri).unwrap();
assert_eq!(info.client_pubkey, "83f3b2ae6aa368e8275397b9c26cf550101d63ebaab900d19dd4a4429f5ad8f5");
assert_eq!(
info.relays,
vec!["wss://relay1.example.com", "ws://192.168.1.20:7777"]
);
assert_eq!(info.secret, "0s8j2djs");
assert_eq!(info.perms, vec!["nip44_encrypt", "sign_event:22242"]);
assert_eq!(info.name, "My Client");
// npub client keys and unknown params tolerated — the npub is
// generated through our own encoder so the test carries no
// hand-transcribed bech32 string.
let sk1 = "0000000000000000000000000000000000000000000000000000000000000001";
let npub = npub_from_pubkey(&pubkey_hex(sk1).unwrap()).unwrap();
let pubkey = pubkey_from_any(&npub).unwrap();
let uri = format!("nostrconnect://{npub}?relay=wss://r&secret=s&future=1");
let info = parse_connect_uri(&uri).unwrap();
assert_eq!(info.client_pubkey, pubkey);
assert_eq!(info.relays, vec!["wss://r"]);
assert!(parse_connect_uri("bunker://abc?relay=wss://r&secret=s").is_err());
assert!(parse_connect_uri("nostrconnect://zz?relay=wss://r&secret=s").is_err());
assert!(parse_connect_uri("nostrconnect://83f3b2ae6aa368e8275397b9c26cf550101d63ebaab900d19dd4a4429f5ad8f5?name=x").is_err());
}
#[test]
fn nip04_round_trip_and_cross_check() {
let sk_a = generate_secret().unwrap();
let sk_b = generate_secret().unwrap();
let pub_b = pubkey_hex(&sk_b).unwrap();
let pub_a = pubkey_hex(&sk_a).unwrap();
let payload = nip04_encrypt(&sk_a, &pub_b, "old client hello").unwrap();
assert!(payload.contains("?iv="));
assert_eq!(nip04_decrypt(&sk_b, &pub_a, &payload).unwrap(), "old client hello");
// Wrong key must fail (PKCS#7 padding check) rather than return garbage.
assert!(nip04_decrypt(&sk_a, &pub_a, &payload).is_err());
assert!(nip04_decrypt(&sk_b, &pub_b, &payload).is_err());
assert!(nip04_decrypt(&sk_b, &pub_a, "not-a-payload").is_err());
}
#[test]
fn key_encoding_round_trip() {
let sk = generate_secret().unwrap();
let nsec = nsec_from_secret(&sk).unwrap();
assert!(nsec.starts_with("nsec1"));
assert_eq!(secret_from_nsec(&nsec).unwrap(), sk);
assert_eq!(secret_from_any(&nsec).unwrap(), sk);
assert_eq!(secret_from_any(&sk).unwrap(), sk);
let pk = pubkey_hex(&sk).unwrap();
let npub = npub_from_pubkey(&pk).unwrap();
assert!(npub.starts_with("npub1"));
assert_eq!(pubkey_from_any(&npub).unwrap(), pk);
assert_eq!(pubkey_from_any(&pk).unwrap(), pk);
// The famous even-y lift edge case: pubkey of sk=1 is x(G) (y is odd);
// shared_x with oneself is exactly x(G) — pins the unhashed-x ECDH and
// the even-parity lift in one assertion (x is invariant under y-negation,
// so the lift is safe for NIP-44/NIP-04 keys).
let g_x = "79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798";
assert_eq!(
pubkey_hex("0000000000000000000000000000000000000000000000000000000000000001").unwrap(),
g_x
);
assert_eq!(
hex::encode(
shared_x("0000000000000000000000000000000000000000000000000000000000000001", g_x).unwrap()
),
g_x
);
assert!(secret_from_nsec("npub1").is_err());
}
/// The mesh ULA is a PURE function of the node's public key:
/// `fd ‖ sha256(x-only pubkey)[0..15]` (fips identity/node_addr.rs →
/// identity/address.rs). That is what makes "address by npub" work —
/// Termux's fipssh helper, and any future DNS-style resolver, just
/// computes what the fips daemon's DNS answers.
#[test]
fn npub_derives_the_same_mesh_ula_as_the_fips_identity() {
for seed in [0x42u8, 0x07, 0x31] {
// 0xff… would exceed the curve order — secret keys must be valid scalars.
let secret = [seed; 32];
let id = fips::Identity::from_secret_bytes(&secret).unwrap();
let npub = id.npub();
let expected = id.address().to_ipv6().to_string();
let pubkey_hex = pubkey_from_any(&npub).unwrap();
let pk = hex::decode(&pubkey_hex).unwrap();
let mut hasher = Sha256::new();
hasher.update(&pk);
let hash = hasher.finalize();
let mut ula = [0u8; 16];
ula[0] = 0xfd;
ula[1..].copy_from_slice(&hash[..15]);
assert_eq!(std::net::Ipv6Addr::from(ula).to_string(), expected, "npub {npub}");
}
}
}
-145
View File
@@ -1,145 +0,0 @@
#!/data/data/com.termux/files/usr/bin/sh
# fipssh — SSH to an Archipelago FIPS mesh node BY NPUB.
#
# The mesh ULA is a pure function of the node's public key (verified against
# the fips crate itself — archy-fips-core's npub_derives_the_same_mesh_ula
# test, and the Android tools commit that shipped this script):
#
# ula = fd || sha256(x-only pubkey)[0..15]
#
# so the npub IS the address: no DNS server, no mesh query, works offline.
# The node's fips daemon answers the same question through its DNS resolver
# (core/archipelago/src/fips/dial.rs) — this is the phone-side equivalent.
#
# Setup (Termux): pkg install python openssh
# Usage:
# fipssh <user>@npub1… [ssh args…] connect
# fipssh npub1… connect as $FIPSSH_USER
# fipssh --resolve npub1… print the ULA and exit
#
# The companion's split tunnel carries the connection (fd00::/8 routes the
# whole device while the mesh is up) — at home on LAN, away via the anchors.
# The node still has to allow port 22 through its fips0 firewall: see
# docs/HANDOFF-2026-08-31-ssh-over-mesh.md (the interim 90-ssh.nft drop-in,
# restricted to your phone's ULA, until the node-side toggle ships).
set -eu
usage() {
sed -n '2,20p' "$0" | sed 's/^# \{0,1\}//'
exit 1
}
RESOLVE_ONLY=0
if [ "${1:-}" = "--resolve" ]; then
RESOLVE_ONLY=1
shift
fi
[ $# -ge 1 ] || usage
TARGET="$1"
shift 2>/dev/null || true
case "$TARGET" in
*npub1*)
case "$TARGET" in
*@npub1*) USER_PART="${TARGET%%@*}"; N_PUB="${TARGET#*@}" ;;
npub1*)
USER_PART="${FIPSSH_USER:-}"
N_PUB="$TARGET"
if [ -z "$USER_PART" ] && [ "$RESOLVE_ONLY" = 0 ]; then
echo "fipssh: no user given (use user@npub… or set FIPSSH_USER)" >&2
exit 1
fi
;;
*) echo "fipssh: expected [user@]npub1…, got '$TARGET'" >&2; exit 1 ;;
esac
;;
*) echo "fipssh: '$TARGET' is not an npub (expected [user@]npub1…)" >&2; exit 1 ;;
esac
command -v python3 >/dev/null 2>&1 || {
echo "fipssh: python3 not found — run: pkg install python" >&2
exit 1
}
ULA=$(python3 - "$N_PUB" <<'PYEOF'
import hashlib, ipaddress, sys
CHARSET = "qpzry9x8gf2tvdw0s3jn54khce6mua7l"
def bech32_polymod(values):
gen = [0x3B6A57B2, 0x26508E6D, 0x1EA119FA, 0x3D4233DD, 0x2A1462B3]
chk = 1
for value in values:
top = chk >> 25
chk = (chk & 0x1FFFFFF) << 5 ^ value
for i in range(5):
chk ^= gen[i] if ((top >> i) & 1) else 0
return chk
def bech32_hrp_expand(hrp):
return [ord(c) >> 5 for c in hrp] + [0] + [ord(c) & 31 for c in hrp]
def bech32_verify_checksum(hrp, data):
return bech32_polymod(bech32_hrp_expand(hrp) + data) == 1
def bech32_decode(s):
if any(ord(c) < 33 or ord(c) > 126 for c in s):
raise ValueError("bad character")
if s.lower() != s and s.upper() != s:
raise ValueError("mixed case")
s = s.lower()
pos = s.rfind("1")
if pos < 1 or pos + 7 > len(s) or len(s) > 90:
raise ValueError("bad separator")
hrp = s[:pos]
data = [CHARSET.find(c) for c in s[pos + 1:]]
if -1 in data:
raise ValueError("bad data character")
if not bech32_verify_checksum(hrp, data):
raise ValueError("bad checksum — typo in the npub?")
return hrp, data[:-6]
def convertbits(data, frombits, tobits):
acc = 0
bits = 0
ret = bytearray()
maxv = (1 << tobits) - 1
for value in data:
if value < 0 or (value >> frombits):
raise ValueError("bad value")
acc = (acc << frombits) | value
bits += frombits
while bits >= tobits:
bits -= tobits
ret.append((acc >> bits) & maxv)
if bits >= frombits or ((acc << (tobits - bits)) & maxv):
raise ValueError("bad padding")
return bytes(ret)
npub = sys.argv[1]
hrp, data = bech32_decode(npub)
if hrp != "npub":
raise ValueError(f"expected hrp 'npub', got '{hrp}'")
pubkey = convertbits(data, 5, 8)
if len(pubkey) != 32:
raise ValueError(f"npub data must be 32 bytes, got {len(pubkey)}")
# ula = fd || sha256(pubkey)[0..15] — mirrors fips identity/node_addr.rs +
# identity/address.rs (FIPS_ADDRESS_PREFIX = 0xfd).
ula = bytes([0xFD]) + hashlib.sha256(pubkey).digest()[:15]
print(ipaddress.IPv6Address(ula).compressed)
PYEOF
) || exit 1
if [ "$RESOLVE_ONLY" = 1 ]; then
echo "$ULA"
exit 0
fi
exec ssh "${USER_PART}@${ULA}" "$@"
-384
View File
@@ -1,384 +0,0 @@
#!/usr/bin/env python3
"""
NIP-46 test client for the Archipelago companion's Remote Signer (#139).
Plays the role the node's login flow will play (rust-nostr nostr-connect
client): generates a nostrconnect:// pairing QR, connects to a relay, waits
for the phone's bunker `connect` (secret echo), acks it, then exercises
get_public_key + sign_event and VERIFIES the returned schnorr signature with
independent pure-Python BIP-340 code (no shared code with the phone's Rust).
Run it on your computer next to the phone:
python3 -m venv /tmp/nip46env
/tmp/nip46env/bin/pip install websockets qrcode
/tmp/nip46env/bin/python Android/tools/nip46-test-client.py [--relay wss://relay.damus.io]
…then on the phone: hub menu (three-finger hold) → Remote Signer →
Generate key (once) → Scan pairing QR → point at the terminal QR → Approve.
Pure Python (no deps for the crypto; websockets + qrcode for transport/QR).
"""
import argparse
import asyncio
import base64
import hashlib
import hmac
import json
import os
import secrets
import struct
import sys
import time
import urllib.parse
import websockets # pip install websockets
# ── secp256k1 / BIP-340 (independent of the phone's Rust code) ──────────────
P = 2**256 - 2**32 - 977
N = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141
GX = 0x79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798
GY = 0x483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8
G = (GX, GY)
def _add(pt1, pt2):
if pt1 is None:
return pt2
if pt2 is None:
return pt1
x1, y1 = pt1
x2, y2 = pt2
if x1 == x2 and (y1 + y2) % P == 0:
return None
if pt1 == pt2:
lam = (3 * x1 * x1) * pow(2 * y1, -1, P) % P
else:
lam = (y2 - y1) * pow(x2 - x1, -1, P) % P
x3 = (lam * lam - x1 - x2) % P
return (x3, (lam * (x1 - x3) - y1) % P)
def _mul(k, pt):
r = None
while k:
if k & 1:
r = _add(r, pt)
pt = _add(pt, pt)
k >>= 1
return r
def lift_x(x):
if x >= P:
return None
y_sq = (pow(x, 3, P) + 7) % P
y = pow(y_sq, (P + 1) // 4, P)
if y * y % P != y_sq:
return None
return (x, y if y % 2 == 0 else P - y)
def tagged(tag: bytes, data: bytes) -> bytes:
"""BIP-340 tagged hash: sha256(hash(tag) || hash(tag) || data)."""
th = hashlib.sha256(tag).digest()
return hashlib.sha256(th + th + data).digest()
def bip340_sign(msg: bytes, seckey: int, aux: bytes) -> bytes:
d = seckey if seckey <= N - 1 else seckey - N
pub = _mul(d, G)
if pub[1] % 2 != 0:
d = N - d
t = bytes(a ^ b for a, b in zip(d.to_bytes(32, "big"), tagged(b"BIP0340/aux", aux)))
rand = tagged(b"BIP0340/nonce", t + pub[0].to_bytes(32, "big") + msg)
k = int.from_bytes(rand, "big") % N
assert k > 0
R = _mul(k, G)
if R[1] % 2 != 0:
k = N - k
e = int.from_bytes(tagged(b"BIP0340/challenge", R[0].to_bytes(32, "big") + pub[0].to_bytes(32, "big") + msg), "big") % N
return R[0].to_bytes(32, "big") + ((k + e * d) % N).to_bytes(32, "big")
def bip340_verify(msg: bytes, pubkey_x: bytes, sig: bytes) -> bool:
"""Check s·G − e·P == R with even-y R and x(R) == r (BIP-340)."""
if len(sig) != 64 or len(pubkey_x) != 32:
return False
pub = lift_x(int.from_bytes(pubkey_x, "big"))
if pub is None:
return False
r = int.from_bytes(sig[:32], "big")
s = int.from_bytes(sig[32:], "big")
if r >= P or s >= N:
return False
e = int.from_bytes(tagged(b"BIP0340/challenge", sig[:32] + pubkey_x + msg), "big") % N
sg = _mul(s, G)
ep = _mul(e, pub)
neg_ep = (ep[0], (P - ep[1]) % P)
rp = _add(sg, neg_ep)
return rp is not None and rp[0] == r and rp[1] % 2 == 0
def ecdh_x(secret_hex: str, peer_x_hex: str) -> bytes:
"""Raw ECDH x-coordinate against an x-only peer key (even-y lift)."""
peer = lift_x(int(peer_x_hex, 16))
assert peer is not None, "peer pubkey not on curve"
pt = _mul(int(secret_hex, 16) % N, peer)
return pt[0].to_bytes(32, "big")
# ── NIP-44 v2 (pure python, spec-literal) ────────────────────────────────────
def hkdf_extract(salt: bytes, ikm: bytes) -> bytes:
return hmac.new(salt, ikm, hashlib.sha256).digest()
def hkdf_expand(prk: bytes, info: bytes, length: int) -> bytes:
t = b""
out = b""
i = 1
while len(out) < length:
t = hmac.new(prk, t + info + bytes([i]), hashlib.sha256).digest()
out += t
i += 1
return out[:length]
def _rotl(x: int, n: int) -> int:
return ((x << n) | (x >> (32 - n))) & 0xFFFFFFFF
def _qr(s, a, b, c, d):
s[a] = (s[a] + s[b]) & 0xFFFFFFFF; s[d] ^= s[a]; s[d] = _rotl(s[d], 16)
s[c] = (s[c] + s[d]) & 0xFFFFFFFF; s[b] ^= s[c]; s[b] = _rotl(s[b], 12)
s[a] = (s[a] + s[b]) & 0xFFFFFFFF; s[d] ^= s[a]; s[d] = _rotl(s[d], 8)
s[c] = (s[c] + s[d]) & 0xFFFFFFFF; s[b] ^= s[c]; s[b] = _rotl(s[b], 7)
def chacha20_block(key: bytes, counter: int, nonce: bytes) -> bytes:
consts = [0x61707865, 0x3320646E, 0x79622D32, 0x6B206574]
state = consts + list(struct.unpack("<8I", key)) + [counter] + list(struct.unpack("<3I", nonce))
working = list(state)
for _ in range(10):
_qr(working, 0, 4, 8, 12); _qr(working, 1, 5, 9, 13)
_qr(working, 2, 6, 10, 14); _qr(working, 3, 7, 11, 15)
_qr(working, 0, 5, 10, 15); _qr(working, 1, 6, 11, 12)
_qr(working, 2, 7, 8, 13); _qr(working, 3, 4, 9, 14)
return struct.pack("<16I", *[(x + y) & 0xFFFFFFFF for x, y in zip(working, state)])
def chacha20(key: bytes, nonce: bytes, data: bytes) -> bytes:
counter = 0 # NIP-44: "ChaCha20 (RFC 8439) with starting counter set to 0"
out = bytearray()
for i in range(0, len(data), 64):
ks = chacha20_block(key, counter, nonce)
chunk = data[i:i + 64]
out += bytes(a ^ b for a, b in zip(chunk, ks))
counter += 1
return bytes(out)
def calc_padded_len(n: int) -> int:
if n <= 32:
return 32
power = 1 << ((n - 1).bit_length())
chunk = 32 if power <= 256 else power // 8
return chunk * ((n - 1) // chunk + 1)
def nip44_encrypt(secret_hex: str, peer_hex: str, plaintext: str) -> str:
ck = hkdf_extract(b"nip44-v2", ecdh_x(secret_hex, peer_hex))
nonce = secrets.token_bytes(32)
okm = hkdf_expand(ck, nonce, 76)
key, iv, mac_key = okm[:32], okm[32:44], okm[44:76]
pt = plaintext.encode()
padded = (len(pt).to_bytes(2, "big") if len(pt) < 65536 else b"\x00\x00" + len(pt).to_bytes(4, "big")) + pt
padded += b"\x00" * (calc_padded_len(len(pt)) - len(pt))
ct = chacha20(key, iv, padded)
mac = hmac.new(mac_key, nonce + ct, hashlib.sha256).digest()
return base64.b64encode(bytes([2]) + nonce + ct + mac).decode()
def nip44_decrypt(secret_hex: str, peer_hex: str, payload: str) -> str:
data = base64.b64decode(payload)
assert data[0] == 2, "only NIP-44 v2 supported"
nonce, ct, mac = data[1:33], data[33:-32], data[-32:]
ck = hkdf_extract(b"nip44-v2", ecdh_x(secret_hex, peer_hex))
okm = hkdf_expand(ck, nonce, 76)
key, iv, mac_key = okm[:32], okm[32:44], okm[44:76]
assert hmac.compare_digest(hmac.new(mac_key, nonce + ct, hashlib.sha256).digest(), mac), "bad MAC"
padded = chacha20(key, iv, ct)
ln = int.from_bytes(padded[:2], "big")
body = padded[2:2 + ln] if ln else padded[6:6 + int.from_bytes(padded[2:6], "big")]
return body.decode()
# ── nostr events ─────────────────────────────────────────────────────────────
def event_id(pubkey_hex: str, created_at: int, kind: int, tags, content: str) -> str:
serialized = json.dumps([0, pubkey_hex, created_at, kind, tags, content], separators=(",", ":"))
return hashlib.sha256(serialized.encode()).hexdigest()
def sign_event(secret_hex: str, event: dict) -> dict:
eid = event_id(event["pubkey"], event["created_at"], event["kind"], event["tags"], event["content"])
ev = dict(event)
ev["id"] = eid
ev["sig"] = bip340_sign(bytes.fromhex(eid), int(secret_hex, 16), os.urandom(32)).hex()
return ev
# ── the client session ────────────────────────────────────────────────────────
def compact(d) -> str:
return json.dumps(d, separators=(",", ":"))
async def run(relay: str):
client_secret = os.urandom(32).hex()
client_secret_int = int(client_secret, 16) % N
client_pub_hex = _mul(client_secret_int, G)[0].to_bytes(32, "big").hex()
pair_secret = secrets.token_hex(16)
nonce = secrets.token_hex(8)
uri = (
f"nostrconnect://{client_pub_hex}"
f"?relay={urllib.parse.quote(relay, safe='')}"
f"&secret={pair_secret}"
f"&name=Archipelago+Test+Client"
)
print(f"· client key : {client_pub_hex}")
print(f"· relay : {relay}")
print()
print("Scan this QR with: Companion → hub (3-finger) → Remote Signer → Scan pairing QR")
print()
try:
import qrcode
qr = qrcode.QRCode(border=1)
qr.add_data(uri)
qr.make(fit=True)
qr.print_ascii(invert=True)
except ImportError:
print(uri)
print()
print("Waiting for the phone to pair (connect, ack, get_public_key, sign_event)…")
async with websockets.connect(relay, max_size=2**22) as ws:
await ws.send(compact(["REQ", "test", {"kinds": [24133], "#p": [client_pub_hex], "since": int(time.time()) - 60}]))
signer_pub = None
acked = False
requests = []
def send_frame(content: dict):
assert signer_pub is not None
ev = {
"pubkey": client_pub_hex,
"created_at": int(time.time()),
"kind": 24133,
"tags": [["p", signer_pub]],
"content": nip44_encrypt(client_secret, signer_pub, compact(content)),
}
return asyncio.ensure_future(ws.send(compact(["EVENT", sign_event(client_secret, ev)])))
async def request(method, params, rid):
send_frame({"id": rid, "method": method, "params": params})
timeout = time.time() + 120
got_pubkey = None
signed_event = None
while time.time() < timeout:
try:
raw = await asyncio.wait_for(ws.recv(), timeout=timeout - time.time())
except (asyncio.TimeoutError, TimeoutError):
break
arr = json.loads(raw)
if not isinstance(arr, list) or len(arr) < 3 or arr[0] != "EVENT":
continue
ev = arr[2]
if ev.get("kind") != 24133 or ev.get("pubkey") == client_pub_hex:
continue
author = ev["pubkey"]
try:
msg = json.loads(nip44_decrypt(client_secret, author, ev["content"]))
except Exception:
continue
if "method" in msg and msg["method"] == "connect":
params = msg.get("params", [])
if params and params[0] == author and (len(params) < 2 or params[1] == pair_secret):
signer_pub = author
print(f"✓ phone paired — signer pubkey {author[:16]}…")
send_frame({"id": msg["id"], "result": "ack"})
acked = True
await asyncio.sleep(0.5)
await request("get_public_key", [], nonce + "-gpk")
else:
print("✗ phone sent connect but the secret didn't match")
return 1
continue
if "result" in msg or "error" in msg:
rid = msg.get("id", "")
if "error" in msg:
print(f"✗ error for {rid}: {msg['error']}")
if rid.endswith("-sign"):
return 1
continue
result = msg.get("result", "")
if rid.endswith("-gpk"):
got_pubkey = result
print(f"✓ get_public_key → {result}")
await request(
"sign_event",
[compact({
"kind": 1,
"content": "Hello from the Archipelago NIP-46 test client — approved by hand.",
"tags": [],
"created_at": int(time.time()),
})],
nonce + "-sign",
)
elif rid.endswith("-sign"):
signed_event = json.loads(result)
print(f"✓ sign_event → signed event {signed_event.get('id', '')[:16]}…")
break
if not acked:
print("✗ the phone never connected (2-minute timeout)")
return 1
if got_pubkey is None or got_pubkey != signer_pub:
print("✗ get_public_key missing or mismatched")
return 1
if signed_event is None:
return 1
ev = signed_event
expected_id = event_id(ev["pubkey"], ev["created_at"], ev["kind"], ev["tags"], ev["content"])
ok_id = expected_id == ev["id"]
ok_sig = bip340_verify(bytes.fromhex(expected_id), bytes.fromhex(ev["pubkey"]), bytes.fromhex(ev["sig"]))
print(f"· event id correct : {ok_id}")
print(f"· schnorr signature: {'VERIFIED ✓' if ok_sig else 'INVALID ✗'}")
if ok_id and ok_sig:
print()
print("END-TO-END PASS — the companion signed as the identity the phone holds,")
print("and the signature verifies under an independent BIP-340 implementation.")
return 0
return 1
def main():
ap = argparse.ArgumentParser()
ap.add_argument("--relay", default="wss://relay.damus.io", help="any nostr relay both devices can reach")
args = ap.parse_args()
sys.exit(asyncio.run(run(args.relay)))
if __name__ == "__main__":
main()
+5 -148
View File
@@ -1,126 +1,5 @@
# Changelog
## v1.8.9-alpha (2026-09-01)
- **Lightning sends work again after the LND 0.21.2 update.** LND 0.21 removed the old synchronous payment route the node's backend paid through (`/v1/channels/transactions`) — every Lightning send answered the literal "Not Found" and the wallet showed "Payment failed: Not Found". The backend now pays through the supported Router.SendPaymentV2 route, keeps the same settle-then-report behaviour (a slow multi-hop payment is still tracked to completion, never falsely declared failed), and translates LND's failure reasons into plain advice. A new gate test speaks the payment route directly against the running LND, so an image/backend skew like this can never ship silently again.
- **The node no longer pins HSTS — HTTP access is a supported mode, and it stays working.** The HTTPS listener used to send `Strict-Transport-Security: max-age=31536000; includeSubDomains`; browsers that visited HTTPS once cached that and then silently upgraded the still-open HTTP dashboard's calls to HTTPS, which is a scheme change — cross-origin — so every request died as "CORS blocked / Failed to fetch" while the node was perfectly healthy. The HTTPS listener now actively clears the cached policy (`max-age=0`) and port 80 sends no HSTS at all, which is deliberate: the node's certificate is optional and self-signed, and devices that haven't installed the CA must keep plain-HTTP access (that's what Settings → Node certificate is for). If your browser already cached the old policy, visiting the dashboard over HTTPS once after this update clears it; a gate test now refuses any config that reintroduces the pin.
- **App frames open over HTTPS again — including the ones that "did not connect."** The launcher asked the signed catalog for each app's port policy under the name you click ("Mempool Web", "Bitcoin Knots"), but the catalog declares those ports under the manifest that owns them (the Mempool web container, Bitcoin UI). The lookup missed, the launcher handed the iframe an `http://` address, and the browser blocked it as mixed content — the app tile went blank or spun forever. Port resolution now follows launch aliases (mempool-web, bitcoin-knots/bitcoin-core, lnd, electrs and friends), falls back to a port-wide catalog scan when the id is unknown, and the catalog is warmed as soon as the dashboard loads rather than only in the App Store, so the very first app you open already knows which ports serve TLS.
- **Signing in to IndeeHub with Nostr works over HTTPS.** The NIP-07 bridge compared the app frame's origin for exact equality with the recorded `http://` app URL — a frame the browser upgraded to HTTPS (or any scheme change) was silently ignored, and replies addressed to the stale origin were refused outright, so Nostr sign-in quietly did nothing. The bridge now matches host and port (scheme intentionally ignored) and always replies to the frame's real origin.
- **Nginx Proxy Manager starts again.** Converting it to a platform manifest dropped two things its image needs: the `/etc/letsencrypt` mount its boot script hard-requires, and the `NET_BIND_SERVICE` capability its internal nginx needs to bind ports 80/443/81 under the orchestrator's `--cap-drop=ALL`. The result was an endless start/die loop (a node watched it restart 3,176 times). Both are declared in its manifest now, its certs live on unchanged under the same persistent app directory, and the signed catalog carries the fix so installed nodes heal on the next update.
- **Portainer's first-run token is in the app page, not buried in "server logs."** New Portainer versions mint a one-time setup token on a fresh install and print it only to the container logs — on an appliance that meant telling the user to go read a server log to get into their own app. The token now appears in the same launch interstitial as app login credentials (with a copy button), only while first-run setup is actually pending; once the admin account exists the card disappears on its own.
## v1.8.8-alpha (2026-09-01)
- **SSH over the mesh is now a first-class setting.** Settings gains an "SSH over mesh" card: off by default, and when you allow it the node's mesh firewall opens port 22 — either to every mesh peer (behind an explicit "I understand" confirmation, because that's a real exposure) or only to the mesh addresses you list. The rule is owned by the node (the `90-ssh.nft` drop-in), so it survives upgrades and daemon reinstalls, and the card tells you up front whether sshd is running, whether it listens on IPv6 (the mesh is IPv6-only — this is what a broken attempt looks like before it happens), and whether password login is on (keys-only is the recommended pairing). From Termux on your phone, `fipssh <user>@<node-npub>` connects once the toggle is on — the npub is the durable address, and the command is shown with a copy button on the card.
- **The App Store now lists apps — not parts of apps.** The signed catalog carries every manifest because the node's update layer needs their pins, and the store briefly listed them all: Mempool API, LND UI, Bitcoin UI, the Pine voice engines, the IndeeHub and Immich backends, the mesh router and friends. Components are hidden from the store listing (they still appear where they belong — the Services tab of My Apps, once installed), and four entries that never earned a tile are gone outright: MorphOS server (old), the Web5 DID wallet, Lightning Stack (an untracked upstream bundle — LND covers the need), and CryptPad (never tested).
- **App icons now persist everywhere, in the proper container style.** Two fixes: installed apps render the icon from their own manifest — Cuprate no longer falls back to the generic A-mark on its Services tile — and the store grids (the Discover page) apply the same icon container treatment (backdrop, border, shadow) as My Apps, the detail pages, and Home. Manifest-declared UI apps also classify correctly again: Alby Hub installs into My Apps with a working tile, not into Services, because a probe miss no longer buries an app the manifest itself says has a frontend.
- **Installing from the store keeps you on the store page.** The install progress lives on the tile itself and the app appears in My Apps when it lands — no more being yanked to My Apps mid-browse.
## v1.8.7-alpha (2026-08-31)
- **What's New really does stop at v1.8.0 now.** The first correction removed old generated release blocks but missed six much older hand-written v1.2 sections at the bottom of the modal. Those sections are gone, and the release check now recognizes and rejects that legacy format too, so the history floor cannot falsely pass again.
- **The installer carries the same corrected release and Companion 0.5.28.** Its artifact gate now checks the companion APK version and the v1.8.0 What's New floor inside the finished ISO, so a stale frontend or phone app cannot be published under the current release label.
- **Crash dumps work on fresh installs as well as upgraded nodes.** The installer gate checks every kdump package inside the finished ISO, and `makedumpfile` is installed explicitly rather than accidentally relying on a recommended dependency that the minimal image deliberately omits.
- **Apps open over HTTPS when your node does.** Connect to your node over HTTPS and the apps you open — Vaultwarden in its own tab, BTCPay, Grafana, and the rest, on a remote browser or in the phone's in-app browser — now open on the same secure connection instead of silently dropping to plain HTTP. The node's app gate already served TLS on every app port; the dashboard was handing out `http://` addresses regardless of how you reached it. Ports the gate does not front (plain-HTTP publishes, and the API ports like Cuprate's RPC) deliberately stay on `http` — `https` there would simply fail to connect. Plain-HTTP access (the kiosk, LAN browsing) is unchanged.
- **Every app in the store is now a first-class platform app.** The last stragglers — Nginx Proxy Manager, Tailscale, Ollama, CryptPad, and AdGuard Home — now carry full manifests: the node's app gate fronts their web ports (TLS on the same port, the node login where appropriate, embedding fixes, Tor), installs go through the orchestrator like every other app, and their pins live in the signed catalog. Ollama stays loopback-only — it is the assistant's local model backend, not a web app. The four apps retired earlier (FIPS, Nostr VPN, Routstr, Penpot) are finally dropped from the catalog, and Cuprate's manifest — which carried a duplicated metadata block that strict parsers reject — is fixed.
- **Newly signed apps appear in the App Store immediately.** The App Store now serves the release-signed catalog the node has already fetched and verified — so publishing a signed app (like Cuprate) makes it appear for every updated node without waiting for a dashboard release. The unsigned community catalog remains only as a fallback for nodes that can't reach the registry. The same signed catalog now also decides which ports serve TLS, so nothing is upgraded to `https` that can't answer it.
## v1.8.6-alpha (2026-08-31)
- **Companion 0.5.28 is included in the node download this time, with the work that missed v1.8.5.** The companion hub can back up and restore its node list, act as a NIP-46 remote signer, and shows each paired node's FIPS mesh address with tap-to-copy. For Termux users, the included `fipssh` helper turns a durable node npub into its mesh address, so `fipssh user@npub1…` can reach SSH once that node has explicitly allowed port 22. The node-side “SSH over mesh” firewall toggle is not claimed here—it still needs implementation and remains off by default.
- **What's New now starts cleanly at v1.8.0 and is guaranteed to be newest-first.** Older alpha history no longer overwhelms the useful recent changes, the three stray v1.7 entries that appeared above current releases are gone, and the release check now fails if either the ordering or the v1.8.0 history floor drifts again.
- **A release can no longer advertise itself before its files exist.** New releases are prepared behind a pending manifest; the publisher uploads the backend and frontend, downloads both back and verifies their size and hash, and only then promotes the signed manifest to the path nodes read. The manifest generator also includes every curated What's New item instead of silently stopping after the first ten physical changelog lines.
## v1.8.5-alpha (2026-08-30)
- **Cuprate — an independent Monero node — is now an app.** Monero consensus validated by a second, unrelated codebase (Rust), the same layer of security-in-depth Bitcoin gets from Knots. Review caught two problems before anything shipped: the unrestricted RPC that can move funds stayed bound to the container's loopback (never published to the node, let alone the LAN — anything on the node could previously have reached it), and its restricted RPC moved off port 18089 to avoid colliding with Penpot. Honest caveat: upstream has cut no stable release yet, so the pin tracks an exact preview build (0.1.0-preview-18-g618ff14) and moves to their first tagged release when there is one.
- **A frozen node now explains itself — and comes back on its own.** The host now captures a memory dump into /var/crash when the kernel panics *or* wedges (a hung kiosk used to sit dead until someone power-cycled it; now it dumps, reboots itself, and leaves the evidence behind), and records failing-memory signals (ECC errors) into a database as they happen. This is the first change delivered by a new host-update channel: the node's own updater now carries OS-level packages and settings to already-deployed machines — the crash-kernel's memory reservation is the one part that waits for a reboot, and the node says so rather than pretending.
- **Uninstalling an app can no longer report success when it failed.** The declarative path used to swallow every teardown error and report the app uninstalled, leaving the tile behind and the truth in the logs. A failed uninstall now stops and shows the real per-app errors, so "still there" is never presented as "gone".
- **Pictures to internet-only mesh contacts work now.** Sending an attachment inline always took the radio path and failed with "Peer is federation-only (no radio twin)" for contacts reachable only over the internet — and the size-adviser kept recommending a radio transfer those peers can't receive. Both fixed: inline sends route over the federation when that's the only way to reach the peer, and the advice no longer offers radio-only transfers to radio-unreachable contacts.
- **Disk cleanup finally has honest numbers.** Space "free" on a drive was counted including the slice the filesystem keeps reserved for root — roughly 5% of the disk, 92 GB on one dev box — so the automatic cleanup that's supposed to kick in at 90% never triggered and stale container images piled up unnoticed. Reserved space now counts as used, which is what the threshold was always meant to measure.
- **Three small screens that were lying to you, fixed.** The "Bitcoin is synced — fund your wallet" toast no longer appears on a node where the wallet it means (LND) isn't installed — it points at installing LND instead. The seed-reveal screen hides its third prompt unless the password actually fails to decrypt (the backup passphrase only exists if you set one). And multi-version store cards stop quoting a version number you'll be asked to choose on the next screen anyway.
- **Mesh notifications survive a refresh, and a stale router no longer hides the fix.** Radio message unread counts are now remembered per contact instead of guessed from session state (the "one new message showed 11 unread" bug), cover Meshtastic, MeshCore and Reticulum alike, and deep-link to the right conversation; a single new message announces itself once. Separately, when the cached router address goes stale, the error card gains a "Reconfigure router" action instead of a Retry loop that can never succeed.
- **The app updater now knows what upstream shipped.** Every app's manifest records where it comes from — including the odd corners (GitLab-only projects, ghcr-only images) — and a checker sweeps all of them against upstream releases, so a pin that quietly rots for months is now visible instead of invisible. The first full sweep found 27 pins behind; the safe patch-level ones shipped with this release (strfry, BTCPay Server 2.4.3, the two nginx frontends), and the major jumps that may carry data migrations are deliberately held for their own careful passes.
## v1.8.4-alpha (2026-08-20)
- **Apps with their own login can now skip the node's login screen — Gitea and BTCPay Server do so out of the box.** Some apps bring a complete account system of their own, and putting the node's password page in front of them broke real workflows: git clients can't answer a browser login, and a BTCPay checkout link handed to a customer must open for that customer. These apps are now served directly on their own login, while the node still fronts the connection for everything else it does (embedding fixes, the "app is restarting" page, Tor). Every app gets a new **Settings → app → Access control** switch, so you can put the node login back in front of any app — or take it away from one — with one click, effective immediately. App developers declare the default in their manifest (`auth: open`), documented in the developer guide.
- **The phone remote now works inside apps on the TV — tap, scroll, and type everywhere.** The companion remote and keyboard drove the dashboard beautifully but died at the edge of any app screen (Gitea, BTCPay, and friends): for the browser, each app is a separate website embedded in the page, and simulated input is forbidden from crossing that wall. The on-screen display now accepts the remote's input the way a real mouse and keyboard arrive — below the page, through the browser itself — so it lands anywhere on screen, app screens and tabs included. Taps click, two-finger scrolling scrolls the app, and typing goes into whichever field you tapped. Existing kiosks pick this up with the update, no reinstall needed.
- **While you're driving with the phone remote, the old mouse pointer gets out of the way.** The computer's own pointer used to sit frozen wherever the physical mouse last left it — a second, dead cursor next to the live orange one. It now hides while the remote is in use and returns half a minute after the last remote input.
- **"Are you sure?" questions no longer freeze the remote.** A handful of confirmations (clearing mesh history, rebooting, deleting a backup, uninstalling an app) used the browser's built-in popup, which stops the whole page — including remote input — until someone clicks it with a real mouse. From the couch, that meant asking a question you couldn't answer. All of them are now proper in-app windows in the house style, fully driveable by remote.
- **A mesh radio now connects no matter which port it's plugged into — or replugged into.** Moving a radio to a different USB port could leave the mesh silently down: the node only checked a short fixed list of port names (a radio landing outside it was invisible), a hand-set serial-port override quietly outranked the device you'd just approved in the "Radio detected" window, and one whole family of boards (Espressif-based radios like recent Heltec/T-Deck models) never received a stable device name at all — the exact combination found live on a fleet machine this week. All three are fixed: every serial port is scanned, choosing a radio in the detection window clears any stale override, and Espressif boards get the same stable name as everyone else.
- **Mesh signal strength is honest now.** Every peer heard over Reticulum radio reported a signal strength of exactly 0 — which is also what you'd see with no radio at all, and what peers reached over the internet showed. Real receptions now show their true signal reading, and anything that arrived over a relay or the internet says so by showing none — so "the radio is working" and "the internet is doing the radio's job" no longer look identical. (The reading depends on the radio's firmware reporting it; boards that don't report per-packet signal stats show "unknown" rather than a made-up number, and the new radio diagnostics show at a glance whether yours reports them.)
- **A background error that repeated every 90 seconds, forever, is gone.** After setting up a node from its recovery phrase, the node kept introducing itself to its federation partners with its old temporary identity papers while signing with its new ones — every partner rejected the introduction, and both sides logged an error about it every minute and a half until the next restart. The identity switch now updates everything at once, a rejected introduction is no longer misreported as delivered, and a partner who has already answered is no longer re-asked on every cycle.
## v1.8.3-alpha (2026-08-14)
- **The network map on TVs: no more blank page, no more frozen page — and it moves again.** The map's entrance animation needed a smoothness that TV kiosk hardware can't always deliver, so the page could sit blank until a refresh; the previous fix cured the freeze by stopping the animation entirely, which went too far. Now the map appears instantly with everything already in place, then resumes its calm orbital motion at a gentler pace suited to TVs. Resizing or rotating any screen also redraws the map properly instead of leaving it tiny, stretched, or empty.
- **The dashboard's corner logo is back to normal.** The new glossy paint finish was meant for the big emblem on the screensaver, intro, and login screens — it had quietly spread to the small logo in the dashboard header, where it looked wrong. Each screen now gets exactly the treatment intended for it.
- **App icons no longer vanish in My Apps.** The freshly restyled Alby Hub and phoenixd icons could render as blank squares in some views — a subtlety in how the icon files declared their size. Fixed at the source, and the icon tool app developers use now produces immune files.
## v1.8.2-alpha (2026-08-13)
- **An app that can't be shown inside the dashboard now becomes a tab app by itself.** A few apps refuse to render inside another page no matter what — they break out with their own code or insist on owning the whole browser window. Opening one used to mean staring at a grey pane. Now the dashboard notices, offers the app in its own tab, and remembers: from then on that app's button opens a tab directly (with the little launch icon that tab apps carry), first click, every time. If a later update makes the app embeddable after all, the dashboard notices that too and goes back to embedding it.
- **The logo emblem got its glossy black paint finish — properly this time.** The circle behind the A on the screensaver, intro, and login now wears a deep wet-paint look: warm light blooming from the top edge, fine grain so the dark tones stay smooth instead of banding, and no more ring border. (An earlier rougher version of this experiment briefly shipped by accident and then vanished depending on which screen you were on — this is the finished, deliberate one, everywhere.)
- **New app icons now match the store's look, on every screen.** Alby Hub and phoenixd arrived with edge-to-edge logos that ignored the breathing room every other app icon has, and the app detail page skipped the icon backdrop entirely. Both icons are re-set on the standard canvas, the detail page now applies the same icon treatment as the store tiles, and app developers get a one-command tool that puts any logo onto the house canvas automatically.
## v1.8.1-alpha (2026-08-13)
- **Apps that refused to open inside the dashboard now embed like everything else.** Some apps ship browser headers that forbid being shown inside another page — correct hardening on the open web, but inside Archipelago it produced a dead grey pane when you opened them from My Apps (Alby Hub was the first to hit it). The app gate, which already checks your login on every request to an app, now removes just those framing headers on the way through; each app's own content-security rules pass through untouched. No more per-app proxy workarounds.
- **The network map no longer freezes kiosk TVs.** The animated federation map at 4K was too much for the deliberately conservative graphics settings the on-screen display used on every machine — settings chosen years back to stop audio crackle on much older hardware. Two fixes: on kiosk screens the map now opens in its flat 2D view (the 3D globe is one tap away, and remembered) and animates at half rate — invisible from the couch, half the work. And the display itself now recognizes what machine it runs on: older kiosk boxes keep the proven careful settings, modern ones finally get real GPU rendering.
- **New Settings → Display → Graphics choice for the on-screen display.** Auto (recommended) picks the right rendering mode for the machine by itself; Compatibility forces the most conservative mode if a screen ever stutters, tears, or crackles; Quality forces full GPU rendering on hardware the automatic detection doesn't recognize. Changing it restarts the on-screen display, like the size presets.
## v1.8.0-alpha (2026-08-12)
- **Archipelago is now open source.** The full source code of the node you are running — the orchestrator, the dashboard, the app platform, the mesh, the release tooling — is published for anyone to read, build and audit at source.archipelago-foundation.org/lfg2025/archy. A node that holds your money, your files and your communications should not ask to be taken on faith: from this release onward you, or anyone you trust, can see exactly what it does and follow every change we make in the open.
- **Installing an update is reliable again, and tells you what happened when it isn't.** Some nodes could download an update but never apply it — the button stayed on "Install", and no amount of retrying worked. The cause: applying the update consumed the downloaded files as it went, so if any one step hit a snag partway through, the leftover files were incomplete and every later attempt failed the safety re-check forever, needing a technician to recover. Applying no longer consumes the download — a failed apply can always be retried from the same files — and the pieces are now applied in a fixed order with the program itself last, so a hiccup can't leave a half-swapped node. When an apply does fail, the screen now shows the real reason and what to do ("download the update again"), and offers Download again instead of a dead "Install" button, rather than a generic "it failed".
- **Video on the kiosk stops tearing.** The kiosk's display had no vertical sync at all, so fast motion — IndeedHub films especially — showed horizontal tearing lines. The display driver now syncs every frame to the panel (no extra hardware needed, existing kiosks pick it up with this update), and on machines with a GPU, video decoding moves off the CPU onto the video hardware — smoother playback that also leaves more headroom for audio, not less.
- **The Back button finally does what you expect.** Pressing Back — the mouse's side button on a kiosk, a swipe on a phone, the toolbar button in any browser — used to navigate the screen underneath an open window, or leave the dashboard entirely. Back now closes the topmost open window first, one per press, exactly like a native app; closing a window yourself never leaves a phantom entry that makes you press Back twice.
- **No more bare IP addresses in your update or app-registry settings.** The update mirrors and the app registry each listed the same server twice — once by its proper name, once as a raw `http://146…` address left over from before the domain existed. The raw-address entries are retired: new nodes never see them, and existing nodes clean them out of their saved lists automatically on the next read. Everything now goes through the named, TLS-protected origin — which was always the same machine.
- **The phone companion app downloads over the proper domain.** The download QR pointed at a raw address over plain HTTP; it now points at the same file on the https domain. Scanning it gets you an encrypted download from a named server.
- **The Receive window now tells you when the money is on its way.** Previously it showed a QR code and left you to check elsewhere whether anything happened. Now, the moment the sender's transaction is broadcast, the QR gives way to a clock: the amount, the transaction ID (tap to copy), and a note that the funds arrive on their own — with a single Done button. If you keep the window open, the clock becomes a green check at the first confirmation. Verified live on a real node: payment detected within seconds of broadcast.
## v1.7.129-alpha (2026-08-10)
- **Every app is now supervised the same way — the last stragglers moved under systemd.** Five apps (Jellyfin, Nextcloud, Home Assistant, Uptime Kuma, Vaultwarden) still ran outside the node's per-app service management for a technical reason: their networking style died with whatever process started it, so they were kept alive by a separate workaround. That workaround is retired: these apps now migrate themselves onto the same managed units as everything else — own service, restart-on-anything, a ten-second breather between restarts so their networking can release its ports cleanly. The migration happens automatically on the node's next housekeeping pass, touches no app data, and was watched live on a real node: both test apps moved over on the first pass and came back healthy.
- **Leftover companion screens are cleaned up again — driven by real records this time.** When an app is uninstalled, its helper screen (the UI tile that fronts it) should go too. That cleanup was switched off in an earlier release after it wrongly removed the Bitcoin screen from a node whose Bitcoin was installed — it had been guessing "installed" from what happened to be running, and a separate bug made a running app look absent. The node now keeps a durable record of what you have installed, written at install time and cleared only by a real uninstall, and the cleanup consults only that record. If the record can't be read, the cleanup does nothing at all — "I couldn't check" is never treated as "nothing is installed" — and a helper must be orphaned for a sustained period before it is touched.
- **A warning that fired every minute on every node is gone.** The app catalog and the node disagreed about where Grafana's software comes from, so the node ignored the catalog's answer and logged a complaint roughly every 75 seconds, forever. The catalog was right — Grafana is served from the fleet's own registry, like Bitcoin Knots — and the node's records now agree with it.
- **The federation map became a real map.** The network view is now a 3D orbital scene of your federation — nodes as a point-cloud globe with calm motion, auto-fit centring, and a 2D top-down toggle that portrait and mobile screens use by default, with the scene filling the viewport instead of sitting in a letterbox. Inbound peer requests appear live on the map as blinking nodes you can accept or reject in place, and revisiting the view no longer replays the whole intro — the scene updates in place.
- **An app that's mid-restart shows a page that says so — and comes back by itself.** When an app's screen was briefly unreachable behind the gate, the browser got a bare error; it now gets a named page for that app that retries on its own until the app answers.
- Known gaps, disclosed rather than buried: three voice-assistant ports remain open without authentication. Non-browser clients — phone apps for Vaultwarden, Home Assistant or Jellyfin, and git over the web — meet the login page and need an access token. The 5x real-node lifecycle gate was not run for this release; the supervision migration and the cleanup re-enable were verified live on one node (both apps migrated and healthy, cleanup correctly idle).
## v1.7.128-alpha (2026-08-10)
- **The discovery list stops showing ghosts.** Every reinstall of a node mints a new discovery identity, and the old identity's announcement could never be removed from the public relays — nothing holds its key anymore — so the "Discoverable nodes" list slowly filled with entries that led nowhere. Announcements now expire: your node re-announces itself twice a day, each announcement carries a 48-hour expiry that relays honour, anything older than that is ignored when reading, and switching discovery off — or factory-resetting the node — actively overwrites the announcement before it can become a ghost. Old ghosts from earlier versions stop being shown immediately and age off the relays on their own.
- **You can name your node when you make it discoverable.** Turning discovery on now asks for an optional display name — it travels inside the public announcement, so other nodes' discovery lists show "Dorian's basement node" instead of a bare npub. The name is public by construction, capped at 32 characters, and blank is fine: you list as npub only. Toggling discovery off and on remembers the name; you can clear it the same way you set it.
- **The discoverability panel now shows what the network actually sees: your node's npub.** It previously showed your Tor address — which is precisely the thing the announcement never contains (your address stays private until you approve a peer). The npub, the identity other nodes discover you by and send peering requests to, is now displayed there with a copy button.
- **The seed screen stops flashing while the node starts.** During first boot, the lock icon and "server starting" text blinked in and out every few seconds while the node came up — each silent retry briefly emptied the screen. The waiting state now holds steady, with its elapsed timer, until the node answers.
- **A node that already has an identity now explains itself on the seed screen.** Reaching seed creation on a provisioned node used to surface a developer message about "the authenticated system.factory-reset". It now says what you can actually do: sign in normally, or factory-reset the node from Settings to start it over.
- Known gaps, disclosed rather than buried: three voice-assistant ports remain open without authentication. Non-browser clients — phone apps for Vaultwarden, Home Assistant or Jellyfin, and git over the web — meet the login page and need an access token. The 5x real-node lifecycle gate was not run for this release; the changes were verified by operator UAT on a live node.
## v1.7.127-alpha (2026-08-09)
- **Your node now has its own assistant.** This is the first release to ship AIUI: a conversational screen that can answer from your node's own content — your films, music and files come first, the open web second — and can act on the node itself: install or remove an app, check what's running, or queue up your media, all through a fixed list of vetted actions rather than free rein. It is off-limits to your data until you say otherwise: every data category starts closed, grants are made in Settings → AI Data Access and live on the node itself, and anything that changes the node asks you to confirm in the dashboard's own chrome first — a declined action stays declined. What leaves the node is screened: your API key is stored encrypted and never written in plain text, credential-shaped strings are scrubbed from app logs before the model sees them, your public address and Wi-Fi name are stripped from network answers, web search is gated behind your login session, and cloud-bound text passes a secret scan on the way out. Three model backends are supported — Anthropic's API, a local Ollama, and pay-per-use Routstr with a hard prepaid budget ceiling — and mesh peers can reach the same loop with `!ai`.
@@ -355,12 +234,6 @@
- More TV-screen polish: the built-in assistant shows its dark theme instead of bright white panels, the on-screen hint for switching between the kiosk and a terminal now points at the right keys, the welcome logo no longer occasionally renders as garbled characters, and an accidental tap of the power button no longer shuts the node down — hold it to power off on purpose.
- Behind the scenes: fixed the installer image build so it no longer stops on a component that was removed from the product, and so it correctly includes the private relay it was meant to bundle.
## v1.7.107-alpha (2026-07-20)
- Wi-Fi setup now heals itself on older nodes. Some nodes set up before a mid-year fix couldn't connect to a Wi-Fi network from the screen — it failed with a permissions error — because the piece that lets the node manage networking on your behalf was missing. Nodes now put that piece in place automatically on startup, so "scan, pick a network, type the password, connect" works without reinstalling.
- Your node rejoins the mesh faster after an update. Applying this update briefly restarts the mesh service, and previously a node could sit disconnected from other nodes for up to five minutes before it retried. It now notices the restart and reconnects within seconds.
- Behind the scenes: fixed the installer image build so it no longer stops on a component that was removed from the product, and so it correctly includes the private relay it was meant to bundle — two separate faults that had been failing the build.
## v1.7.106-alpha (2026-07-20)
- Nodes on the same network now find each other directly. Your node announces itself on your local network and connects straight to other Archipelago nodes nearby, instead of every connection having to be introduced by a public rendezvous server out on the internet. Peers in the same home or office stay connected to each other even when that server is unreachable, and they reach each other faster.
@@ -740,13 +613,11 @@
- Orchestrator-backed app starts now run the same pre-start repairs as the legacy Podman path, so Nginx Proxy Manager stale `81:81` container metadata is removed and recreated before the orchestrator tries to start it.
- Live diagnostics on a fleet node confirmed host nginx is healthy while Nginx Proxy Manager has no listeners on `8081`, `8084`, or `8444`, causing host nginx `502` responses for NPM proxy paths.
- The gap this closes: apps launched through the orchestrator previously skipped the legacy start-time repair path entirely, so the same stale metadata the old flow cleaned up silently broke the new one. Both paths now converge on the same repairs.
## v1.7.64-alpha (2026-05-18)
- Update apply rate limiting is relaxed for authenticated admins from 2 attempts per 10 minutes to 10 attempts per minute, preventing the System Update page from getting stuck behind `429 Too Many Requests` during legitimate OTA retry/troubleshooting flows.
- The corrected backend artifact rebuild protection from `v1.7.63-alpha` remains in place, so this release is built from a fresh Rust backend binary before publishing.
- For operators mid-incident this changes the recovery loop: a failed apply can now be retried immediately from the System Update page instead of waiting out a throttle window while a node sits half-updated.
## v1.7.63-alpha (2026-05-18)
@@ -856,18 +727,6 @@
- Debian 13/Trixie ISO and disk-install paths now force security updates from `trixie-security` during image/install creation so rebuilt release media includes patched base packages.
- Broad `.198` lifecycle audit passes with the current qualified app set; known absent blockers remain `electrumx`, `photoprism`, `dwn`, and `ollama`.
## v1.7.51-alpha (2026-04-30)
- Stack installs now adopt containers that already exist instead of failing on them — a repair or reinstall over leftover containers completes, and the adopted container's readiness is waited on like any fresh start.
- Failed installs come with evidence: the install path waits for its containers, and when one doesn't become healthy it captures that container's logs, so the error on screen names the real culprit instead of a bare timeout.
- Bitcoin RPC bindings are ensured as part of install, and the startup self-heal path gained additional ground for already-deployed nodes.
## v1.7.50-alpha (2026-04-30)
- The OTA bridge older nodes needed: deployed binaries only knew how to apply two artifacts (the backend binary and the frontend archive), so the scripts, app specs and docker assets newer releases carry never reached them. This release packs those payloads inside the frontend tarball — the one channel old binaries do apply — and the new backend promotes them into /opt once it starts.
- Runtime payloads are staged into timestamped directories and promoted atomically; a failed extraction cleans up its staging area instead of leaving half-written state for the next update to trip over.
- This is the release that un-sticks the fleet's update pipeline: from here on, an OTA can carry more than the two artifacts, and app installs on updated nodes use the specs that match their backend.
## v1.7.49-alpha (2026-04-30)
- Bitcoin Knots/Core UI now reports connection, reconnecting, syncing, and error states from a backend status bridge instead of showing a stale "Unable to connect" message while the node is warming up.
@@ -879,15 +738,12 @@
## v1.7.48-alpha (2026-04-29)
- archipelago.service no longer fails to start with "Failed to set up mount namespacing: /run/containers: No such file or directory" on nodes where that runtime directory wasn't pre-created — the failure surfaced in systemd's mount-namespace setup before the service itself ever ran.
- ExecStartPre now creates /run/containers before the service starts, so the node's service manager finds the directory it needs on every boot; ISO installs from this version forward have the fix baked in.
- Existing nodes pick the fix up with a one-time `systemctl edit archipelago` adding the mkdir — after which the boot failure does not recur.
- archipelago.service no longer fails to start with "Failed to set up mount namespacing: /run/containers: No such file or directory" on nodes where /run/containers wasn't pre-created. ExecStartPre now creates it. Existing nodes need a one-time `systemctl edit archipelago` to add the mkdir; ISO installs from this version forward have the fix baked in.
## v1.7.47-alpha (2026-04-29)
- Bitcoin Knots/Core sync is now significantly faster. The container now uses every available core for script verification (was capped at 2) and has 8GB of memory instead of 4GB so its 4GB UTXO cache has headroom for the mempool and peer connections. Existing nodes pick up the new limits on next install/update; freshly-installed nodes start at full speed.
- ElectrumX initial indexing is faster too. Its CPU cap is removed, container memory is 4GB, and its internal cache is now 3GB (default was 1.2GB).
- The result: a fresh node's first hours are measurably shorter — initial block download and ElectrumX indexing were the two longest post-install waits, and both now run at the hardware's limit.
## v1.7.46-alpha (2026-04-29)
@@ -910,9 +766,10 @@
## v1.7.44-alpha (2026-04-28)
- Container orchestration migration completed, with release hardening across the app lifecycle — installs, updates and removals now run through one orchestrator path instead of the split legacy/Podman flows.
- OTA updates now rebuild and sync the app UI containers they carry, so an updated app serves the UI image that matches its backend instead of whatever happened to be on disk.
- LND UI port handling is aligned across all runtime specs, and release packaging moved to tarball-only payloads with the ISO build recipes archived — update payloads now carry only the files existing nodes need.
43de3b73 feat(orchestrator): complete container migration and release hardening
ce39430b feat(self-update): sync and rebuild UI containers on OTA
72dec5aa fix(lnd-ui): align container port across all specs
83aacdf2 chore(release): archive ISO build recipes, tarball-only releases
All notable changes to Archipelago will be documented in this file.
Submodule aiui/.claude/worktrees/agitated-hofstadter added at 10e12a329f
Submodule aiui/.claude/worktrees/funny-hofstadter added at 1c5185a15c
Submodule aiui/.claude/worktrees/happy-colden added at 666e1232f4
Submodule aiui/.claude/worktrees/hardcore-beaver added at a817fa199f
Submodule aiui/.claude/worktrees/heuristic-raman added at e8e002debc
Submodule aiui/.claude/worktrees/priceless-colden added at aaaef7d710
@@ -93,11 +93,10 @@ describe('useAI', () => {
expect(activeModel.value).toBe('echo')
})
it('lists available providers with models, Routstr first', () => {
it('lists available providers with models', () => {
const { availableProviders } = useAI()
expect(availableProviders.value.length).toBe(4)
expect(availableProviders.value.length).toBe(3)
const ids = availableProviders.value.map(p => p.id)
expect(ids[0]).toBe('routstr')
expect(ids).toContain('claude')
expect(ids).toContain('openrouter')
expect(ids).toContain('mock')
@@ -119,7 +119,7 @@
<Transition name="picker">
<div
v-if="showModelPicker"
class="fixed z-[9999] path-glass-card header-overlay-panel p-3 space-y-3 animate-fade-up-fast shadow-2xl min-w-[220px] max-h-[70vh] overflow-y-auto"
class="fixed z-[9999] path-glass-card header-overlay-panel p-3 space-y-3 animate-fade-up-fast shadow-2xl min-w-[220px]"
:style="modelPickerDropdownStyle"
@click.stop
>
@@ -332,7 +332,7 @@ const modelDisplayName = computed(() => {
})
function selectModel(providerId: string, modelId: string) {
setProvider(providerId as 'routstr' | 'claude' | 'openrouter' | 'mock')
setProvider(providerId as 'claude' | 'openrouter' | 'mock')
setModel(modelId)
showModelPicker.value = false
}
+5 -118
View File
@@ -13,14 +13,12 @@ import { useCodeContext } from '@/composables/useCodeContext'
import { apiFetch } from '@/utils/api-fetch'
import { useSettingsStore } from '@/stores/settings'
type Provider = 'routstr' | 'claude' | 'openrouter' | 'mock'
type Provider = 'claude' | 'openrouter' | 'mock'
// API paths are relative to the base URL so they work both in dev (/) and Archy (/aiui/)
const BASE = import.meta.env.BASE_URL || '/'
const CLAUDE_PATH = `${BASE}api/claude/v1/messages`
const OPENROUTER_PATH = `${BASE}api/openrouter`
const ROUTSTR_MODELS_PATH = `${BASE}api/routstr/models`
const ROUTSTR_CHAT_PATH = `${BASE}api/routstr/chat/completions`
import { mockFilms } from '@/mocks/films'
import { mockSongs } from '@/mocks/songs'
@@ -150,41 +148,8 @@ function looksLikeMissingApiKey(err: string): boolean {
)
}
// ─── Routstr model catalog (fetched from the node's session-gated proxy) ───
// The node forwards the live Routstr aggregator's /v1/models; entries carry
// sats_pricing so completions are Cashu-paid against the operator's budget.
const routstrModels = ref<{ id: string; name: string }[]>([])
let routstrModelsFetched = false
async function refreshRoutstrModels() {
if (routstrModelsFetched) return
routstrModelsFetched = true
try {
const res = await apiFetch(ROUTSTR_MODELS_PATH)
if (!res.ok) return
const data = await res.json()
if (Array.isArray(data?.data)) {
routstrModels.value = data.data
.filter((m: Record<string, unknown>) => typeof m.id === 'string')
.map((m: Record<string, unknown>) => ({
id: m.id as string,
name: (m.name as string) || (m.id as string),
}))
}
} catch {
routstrModelsFetched = false // allow a retry on the next send/open
}
}
const availableProviders = computed(() => {
const providers: { id: Provider; name: string; models: { id: string; name: string }[] }[] = [
{
id: 'routstr',
name: 'Routstr (sats)',
models: routstrModels.value.length > 0
? routstrModels.value
: [{ id: 'routstr-unavailable', name: 'No models — node offline?' }],
},
{
id: 'claude',
name: 'Claude (Max)',
@@ -416,71 +381,6 @@ async function streamOpenRouter(
}, onError, signal)
}
/**
* Routstr: one paid, NON-streaming, OpenAI-shaped completion through the
* node's session-gated `/aiui/api/routstr/` forwarder. The node quotes a
* price from the live catalog, pays with a Cashu token against the
* operator's budget (Settings → System → Routstr AI budget), redeems the
* change, and passes the provider's JSON back. The full answer is emitted
* as a single token — streaming across a paid hop is the planned follow-up.
*/
async function streamRoutstr(
messages: ChatMessage[],
onToken: (text: string) => void,
onError: (err: string) => void,
systemPrompt: string,
signal?: AbortSignal,
): Promise<void> {
const wireMessages = [
{ role: 'system' as const, content: systemPrompt },
...messages.map((m) => ({ role: m.role as 'user' | 'assistant', content: m.content })),
]
const res = await apiFetch(ROUTSTR_CHAT_PATH, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
model: activeModel.value,
messages: wireMessages,
stream: false,
}),
signal,
})
const bodyText = await res.text().catch(() => '')
if (!res.ok) {
// The node's refusals carry a plain-language error.message (budget not
// set, budget spent, wallet can't fund) — surface it verbatim.
let msg = `Routstr error ${res.status}`
try {
const parsed = JSON.parse(bodyText)
// Node refusals use {error:{message}}; the upstream provider nests
// its own as {detail:{error:{message}}} or a plain {detail:"..."}.
const detail = parsed?.detail
msg =
parsed?.error?.message ??
detail?.error?.message ??
(typeof detail === 'string' ? detail : undefined) ??
msg
} catch { /* keep the status-only message */ }
onError(msg)
return
}
if (signal?.aborted) return
try {
const parsed = JSON.parse(bodyText)
const text = parsed?.choices?.[0]?.message?.content
if (typeof text === 'string' && text.length > 0) {
onToken(text)
} else {
onError('Routstr returned an empty response')
}
} catch {
onError('Routstr returned a malformed response')
}
}
/**
* Embedded-mode chat delegation (D-01/D-17): when AIUI is running inside
* Archy, the model call, the tool-calling loop, and the model key all live
@@ -719,11 +619,7 @@ export async function streamWithModel(
activeModel.value = model
try {
if (provider === 'routstr') {
// Explicitly chosen Routstr wins even embedded in Archy — the whole
// point of the picker entry is that it is a selection, not a fallback.
await streamRoutstr(history, onToken, onError, 'You are a helpful assistant.', signal)
} else if (useArchy().isEmbedded.value) {
if (useArchy().isEmbedded.value) {
// D-17: embedded mode delegates the loop, the tools and the key to
// Archy — provider/model selection here doesn't apply node-side.
await streamViaArchy(history, onToken, onError, signal)
@@ -742,9 +638,8 @@ export async function streamWithModel(
export function useAI() {
const chatStore = useChatStore()
// Fetch Wavlake + Routstr catalogs on first use (non-blocking)
// Fetch Wavlake catalog on first use (non-blocking)
refreshWavlakeCatalog()
refreshRoutstrModels()
function stopGeneration() {
if (currentAbort) {
@@ -817,11 +712,7 @@ export function useAI() {
const genParams = getConversationParams(chatStore)
try {
if (provider === 'routstr') {
// Explicitly chosen Routstr wins even embedded in Archy — a
// selection, not a fallback.
await streamRoutstr(history, onToken, onError, systemPrompt, signal)
} else if (useArchy().isEmbedded.value) {
if (useArchy().isEmbedded.value) {
// D-17: embedded mode delegates the loop, the tools and the key to
// Archy — provider/model selection here doesn't apply node-side.
await streamViaArchy(history, onToken, onError, signal)
@@ -937,11 +828,7 @@ export function useAI() {
const genParams = getConversationParams(chatStore)
try {
if (provider === 'routstr') {
// Explicitly chosen Routstr wins even embedded in Archy — a
// selection, not a fallback.
await streamRoutstr(history, onToken, onError, systemPrompt, signal)
} else if (useArchy().isEmbedded.value) {
if (useArchy().isEmbedded.value) {
// D-17: embedded mode delegates the loop, the tools and the key to
// Archy — provider/model selection here doesn't apply node-side.
await streamViaArchy(history, onToken, onError, signal)
+337 -409
View File
@@ -11,47 +11,16 @@
},
"apps": [
{
"id": "adguardhome",
"title": "AdGuard Home",
"version": "v0.107.79",
"description": "Network-wide ad and tracker blocking: a DNS server that filters every device on your LAN, with a web console for rules and client management.",
"icon": "",
"author": "AdGuard",
"category": "networking",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/adguardhome:v0.107.79",
"repoUrl": "https://github.com/AdguardTeam/AdGuardHome"
},
{
"id": "alby-hub",
"title": "Alby Hub",
"version": "1.23.0",
"description": "Self-custodial Lightning wallet hub. Runs its own Lightning node on your Archipelago and connects your apps to it over Nostr Wallet Connect — one hub, every app pays through it.",
"icon": "/assets/img/app-icons/alby-hub.svg",
"author": "Alby",
"id": "bitcoin-knots",
"title": "Bitcoin Knots",
"version": "28.1.0",
"description": "Full Bitcoin Knots node with dynamic prune/full-mode startup based on host disk.",
"icon": "/assets/img/app-icons/bitcoin-knots.webp",
"author": "Bitcoin Knots",
"category": "money",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/alby-hub:v1.24.0",
"repoUrl": "https://github.com/getAlby/hub"
},
{
"id": "barkd",
"title": "Ark Wallet",
"version": "0.3.0",
"description": "Ark protocol wallet daemon (barkd). Lets the node hold self-custodial off-chain bitcoin via an Ark server; the wallet talks to it over a local REST API. Signet by default while Ark matures.",
"icon": "/assets/img/app-icons/bark.png",
"author": "Second",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/barkd:0.3.0",
"repoUrl": "https://gitlab.com/ark-bitcoin/bark",
"containerConfig": {
"ports": [
"3535:3535"
],
"volumes": [
"/var/lib/archipelago/barkd:/data"
]
}
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/bitcoin-knots:29.3.knots20260210",
"repoUrl": "https://github.com/bitcoinknots/bitcoin"
},
{
"id": "bitcoin-core",
@@ -66,16 +35,76 @@
"repoUrl": "https://github.com/bitcoin/bitcoin"
},
{
"id": "bitcoin-knots",
"title": "Bitcoin Knots",
"version": "28.1.0",
"description": "Full Bitcoin Knots node with dynamic prune/full-mode startup based on host disk.",
"icon": "/assets/img/app-icons/bitcoin-knots.webp",
"author": "Bitcoin Knots",
"id": "lnd",
"title": "LND",
"version": "0.18.4",
"description": "Lightning Network implementation by Lightning Labs. Enables instant, low-cost Bitcoin payments.",
"icon": "/assets/img/app-icons/lnd.png",
"author": "Lightning Labs",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/bitcoin-knots:29.3.knots20260210",
"repoUrl": "https://github.com/bitcoinknots/bitcoin"
"dockerImage": "source.archipelago-foundation.org/lfg2025/lnd:v0.18.4-beta",
"repoUrl": "https://github.com/lightningnetwork/lnd",
"requires": [
"bitcoin-knots"
]
},
{
"id": "btcpay-server",
"title": "BTCPay Server",
"version": "2.4.2",
"description": "Self-hosted Bitcoin payment processor. Accept Bitcoin payments without intermediaries.",
"icon": "/assets/img/app-icons/btcpay-server.png",
"author": "BTCPay Server Foundation",
"category": "commerce",
"tier": "core",
"dockerImage": "docker.io/btcpayserver/btcpayserver:2.4.2",
"repoUrl": "https://github.com/btcpayserver/btcpayserver",
"requires": [
"bitcoin-knots"
]
},
{
"id": "mempool",
"title": "Mempool Explorer",
"version": "3.0.0",
"description": "Bitcoin mempool and blockchain explorer. Real-time transaction and block visualization.",
"icon": "/assets/img/app-icons/mempool.webp",
"author": "Mempool",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/mempool-frontend:v3.0.1",
"repoUrl": "https://github.com/mempool/mempool",
"requires": [
"bitcoin-knots",
"electrumx"
]
},
{
"id": "electrumx",
"title": "ElectrumX",
"version": "1.18.0",
"description": "Electrum server indexing Bitcoin chain data for lightweight wallet queries.",
"icon": "/assets/img/app-icons/electrumx.png",
"author": "Luke Childs",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/electrumx:v1.18.0",
"repoUrl": "https://github.com/spesmilo/electrumx",
"requires": [
"bitcoin-knots"
]
},
{
"id": "indeedhub",
"title": "IndeeHub",
"version": "1.0.0",
"description": "Bitcoin documentary streaming platform featuring God Bless Bitcoin and other educational content about Bitcoin, sovereignty, and decentralized technology. Sign in with your Nostr identity.",
"icon": "/assets/img/app-icons/indeedhub.png",
"author": "IndeeHub",
"category": "community",
"dockerImage": "source.archipelago-foundation.org/lfg2025/indeedhub:1.0.0",
"repoUrl": "https://github.com/indeedhub/indeedhub"
},
{
"id": "botfights",
@@ -102,128 +131,15 @@
]
}
},
{
"id": "btcpay-server",
"title": "BTCPay Server",
"version": "2.4.3",
"description": "Self-hosted Bitcoin payment processor. Accept Bitcoin payments without intermediaries.",
"icon": "/assets/img/app-icons/btcpay-server.png",
"author": "BTCPay Server Foundation",
"category": "commerce",
"tier": "core",
"dockerImage": "docker.io/btcpayserver/btcpayserver:2.4.3",
"repoUrl": "https://github.com/btcpayserver/btcpayserver",
"requires": [
"bitcoin-knots"
]
},
{
"id": "cuprate",
"title": "Cuprate",
"version": "0.1.0-preview",
"description": "Alternative Monero node implementation in Rust. Independently validates Monero consensus rules, providing a layer of security and redundancy for the network.",
"icon": "/assets/img/app-icons/cuprate.svg",
"author": "Cuprate contributors",
"category": "money",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/cuprate:0.1.0-preview-18-g618ff14",
"repoUrl": "https://github.com/Cuprate/cuprate"
},
{
"id": "electrumx",
"title": "ElectrumX",
"version": "1.18.0",
"description": "Electrum server indexing Bitcoin chain data for lightweight wallet queries.",
"icon": "/assets/img/app-icons/electrumx.png",
"author": "Luke Childs",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/electrumx:v1.18.0",
"repoUrl": "https://github.com/spesmilo/electrumx",
"requires": [
"bitcoin-knots"
]
},
{
"id": "fedimint",
"title": "Fedimint Guardian",
"version": "0.10.0",
"description": "Federated Bitcoin minting service with built-in Guardian UI. Privacy-preserving Bitcoin custody.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/fedimintd:v0.10.1",
"repoUrl": "https://github.com/fedimint/fedimint"
},
{
"id": "fedimint-clientd",
"title": "Fedimint Client",
"version": "0.8.0",
"description": "Fedimint ecash client daemon (fmcd). Lets the node hold Fedimint ecash and join federations; the wallet talks to it over a local REST API.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/fmcd:0.8.1",
"repoUrl": "https://github.com/minmoto/fmcd"
},
{
"id": "fedimint-gateway",
"title": "Fedimint Gateway",
"version": "0.10.0",
"description": "Fedimint gateway service with automatic LND-or-LDK backend selection.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/gatewayd:v0.10.1",
"repoUrl": "https://github.com/fedimint/fedimint",
"containerConfig": {
"ports": [
"8176:8176",
"9737:9737"
],
"volumes": [
"/var/lib/archipelago/fedimint-gateway:/data",
"/var/lib/archipelago/lnd:/lnd:ro"
]
}
},
{
"id": "filebrowser",
"title": "File Browser",
"version": "2.63.23",
"description": "Baseline Archipelago file manager service.",
"icon": "/assets/img/app-icons/file-browser.webp",
"author": "File Browser",
"category": "data",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/filebrowser:v2.63.23",
"repoUrl": "https://github.com/filebrowser/filebrowser",
"containerConfig": {
"ports": [
"8083:80"
],
"volumes": [
"/var/lib/archipelago/filebrowser:/srv",
"/var/lib/archipelago/filebrowser-data:/data"
],
"args": [
"--database=/data/database.db",
"--root=/srv",
"--address=0.0.0.0",
"--port=80"
]
}
},
{
"id": "gitea",
"title": "Gitea",
"version": "1.27.3",
"version": "1.23",
"description": "Self-hosted Git service with built-in container registry, CI/CD, and package hosting.",
"icon": "/assets/img/app-icons/gitea.svg",
"author": "Gitea",
"category": "development",
"dockerImage": "source.archipelago-foundation.org/lfg2025/gitea:1.27.3",
"dockerImage": "docker.io/gitea/gitea:1.23",
"repoUrl": "https://gitea.com",
"containerConfig": {
"ports": [
@@ -248,188 +164,42 @@
"tier": "optional"
},
{
"id": "grafana",
"title": "Grafana",
"version": "10.2.0",
"description": "Analytics and monitoring platform. Visualize metrics and create dashboards.",
"icon": "/assets/img/app-icons/grafana.png",
"author": "Grafana Labs",
"id": "filebrowser",
"title": "File Browser",
"version": "2.27.0",
"description": "Baseline Archipelago file manager service.",
"icon": "/assets/img/app-icons/file-browser.webp",
"author": "File Browser",
"category": "data",
"tier": "recommended",
"dockerImage": "source.archipelago-foundation.org/lfg2025/grafana:10.2.0",
"repoUrl": "https://github.com/grafana/grafana",
"containerConfig": {
"ports": [
"3000:3000"
],
"volumes": [
"/var/lib/archipelago/grafana:/var/lib/grafana"
],
"env": [
"GF_PATHS_DATA=/var/lib/grafana",
"GF_USERS_ALLOW_SIGN_UP=false"
]
}
},
{
"id": "homeassistant",
"title": "Home Assistant",
"version": "2026.8.3",
"description": "Open source home automation platform. Control and monitor your smart home devices.",
"icon": "/assets/img/app-icons/homeassistant.png",
"author": "Home Assistant",
"category": "home",
"dockerImage": "source.archipelago-foundation.org/lfg2025/home-assistant:2026.8.3",
"repoUrl": "https://github.com/home-assistant/core",
"containerConfig": {
"ports": [
"8123:8123"
],
"volumes": [
"/var/lib/archipelago/home-assistant:/config"
],
"env": [
"TZ=UTC"
]
}
},
{
"id": "immich",
"title": "Immich",
"version": "2.7.4",
"description": "Self-hosted photo and video backup with mobile apps and search.",
"icon": "/assets/img/app-icons/immich.png",
"author": "Immich",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/immich-server:release",
"repoUrl": "https://github.com/immich-app/immich"
},
{
"id": "indeedhub",
"title": "IndeeHub",
"version": "1.0.0",
"description": "Bitcoin documentary streaming platform featuring God Bless Bitcoin and other educational content about Bitcoin, sovereignty, and decentralized technology. Sign in with your Nostr identity.",
"icon": "/assets/img/app-icons/indeedhub.png",
"author": "IndeeHub",
"category": "community",
"dockerImage": "source.archipelago-foundation.org/lfg2025/indeedhub:1.0.0",
"repoUrl": "https://github.com/indeedhub/indeedhub"
},
{
"id": "jellyfin",
"title": "Jellyfin",
"version": "10.8.13",
"description": "Free media server. Stream movies, music, and photos.",
"icon": "/assets/img/app-icons/jellyfin.webp",
"author": "Jellyfin",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/jellyfin:10.11.11",
"repoUrl": "https://github.com/jellyfin/jellyfin",
"containerConfig": {
"ports": [
"8096:8096"
],
"volumes": [
"/var/lib/archipelago/jellyfin/config:/config",
"/var/lib/archipelago/jellyfin/cache:/cache"
]
}
},
{
"id": "lnd",
"title": "LND",
"version": "0.21.2",
"description": "Lightning Network implementation by Lightning Labs. Enables instant, low-cost Bitcoin payments.",
"icon": "/assets/img/app-icons/lnd.png",
"author": "Lightning Labs",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/lnd:v0.21.2-beta",
"repoUrl": "https://github.com/lightningnetwork/lnd",
"requires": [
"bitcoin-knots"
]
},
{
"id": "mempool",
"title": "Mempool Explorer",
"version": "3.0.0",
"description": "Bitcoin mempool and blockchain explorer. Real-time transaction and block visualization.",
"icon": "/assets/img/app-icons/mempool.webp",
"author": "Mempool",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/mempool-frontend:v3.3.1",
"repoUrl": "https://github.com/mempool/mempool",
"requires": [
"bitcoin-knots",
"electrumx"
]
},
{
"id": "netbird",
"title": "NetBird",
"version": "2.38.0",
"description": "Self-hosted WireGuard mesh VPN control plane with dashboard, embedded identity provider, management API, signal, relay, and STUN. The user-facing entry point — a TLS proxy in front of the dashboard + server.",
"icon": "/assets/img/app-icons/netbird.svg",
"author": "NetBird",
"category": "networking",
"tier": "recommended",
"dockerImage": "docker.io/library/nginx:1.31.4-alpine",
"repoUrl": "https://github.com/netbirdio/netbird",
"dockerImage": "source.archipelago-foundation.org/lfg2025/filebrowser:v2.27.0",
"repoUrl": "https://github.com/filebrowser/filebrowser",
"containerConfig": {
"ports": [
"8087:80",
"8086:80",
"3478:3478/udp"
"8083:80"
],
"volumes": [
"/var/lib/archipelago/netbird:/var/lib/netbird"
"/var/lib/archipelago/filebrowser:/srv",
"/var/lib/archipelago/filebrowser-data:/data"
],
"notes": "Installed as a two-container stack: netbird dashboard on 8087 and netbird-server control plane on 8086 plus UDP 3478. For production clients, publish a DNS name over HTTPS with gRPC/WebSocket routing."
}
},
{
"id": "nextcloud",
"title": "Nextcloud",
"version": "29",
"description": "Your own private cloud. File sync, calendars, contacts.",
"icon": "/assets/img/app-icons/nextcloud.webp",
"author": "Nextcloud",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/nextcloud:29",
"repoUrl": "https://github.com/nextcloud/server",
"containerConfig": {
"ports": [
"8085:80"
],
"volumes": [
"/var/lib/archipelago/nextcloud:/var/www/html"
"args": [
"--database=/data/database.db",
"--root=/srv",
"--address=0.0.0.0",
"--port=80"
]
}
},
{
"id": "nginx-proxy-manager",
"title": "Nginx Proxy Manager",
"version": "2.12.1",
"description": "Reverse proxy with SSL. Beautiful web interface for managing proxies. On a node, this manages its admin UI and upstream configuration — the proxy's own :80/:443 listeners are not published (the node's web server owns those ports).",
"icon": "/assets/img/app-icons/nginx.svg",
"author": "Nginx Proxy Manager",
"category": "networking",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/nginx-proxy-manager:latest",
"repoUrl": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"id": "nostr-rs-relay",
"title": "Nostr Relay (Rust)",
"version": "0.10.0",
"version": "0.8.0",
"description": "High-performance Nostr relay written in Rust. Host your own decentralized social media relay and earn networking profits.",
"icon": "/assets/img/app-icons/nostrudel.svg",
"author": "Nostr RS Relay",
"category": "community",
"tier": "recommended",
"dockerImage": "scsibug/nostr-rs-relay:0.10.0",
"dockerImage": "scsibug/nostr-rs-relay:0.8.9",
"repoUrl": "https://github.com/scsibug/nostr-rs-relay",
"containerConfig": {
"ports": [
@@ -445,85 +215,25 @@
}
},
{
"id": "ollama",
"title": "Ollama",
"version": "0.5.4",
"description": "Run large language models locally. Download and run AI models like Llama, Mistral on your own hardware — served on the node's loopback for the AI assistant (Settings → Claude Auth → model backend), never exposed to the network.",
"icon": "/assets/img/app-icons/ollama.png",
"author": "Ollama",
"category": "community",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/ollama:latest",
"repoUrl": "https://github.com/ollama/ollama"
},
{
"id": "phoenixd",
"title": "phoenixd",
"version": "0.9.0",
"description": "Headless Lightning daemon by ACINQ (the Phoenix wallet team). No screen of its own — it exposes a small local API that other apps and tools use to send and receive Lightning payments. Channel liquidity is managed automatically for a fee.",
"icon": "/assets/img/app-icons/phoenixd.svg",
"author": "ACINQ",
"category": "money",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/phoenixd:0.9.0",
"repoUrl": "https://github.com/ACINQ/phoenixd"
},
{
"id": "photoprism",
"title": "PhotoPrism",
"version": "240915",
"description": "AI-powered photo management with facial recognition.",
"icon": "/assets/img/app-icons/photoprism.svg",
"author": "PhotoPrism",
"id": "vaultwarden",
"title": "Vaultwarden",
"version": "1.30.0",
"description": "Self-hosted password vault with zero-knowledge encryption.",
"icon": "/assets/img/app-icons/vaultwarden.webp",
"author": "Vaultwarden",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/photoprism:240915",
"repoUrl": "https://github.com/photoprism/photoprism",
"tier": "recommended",
"dockerImage": "source.archipelago-foundation.org/lfg2025/vaultwarden:1.30.0-alpine",
"repoUrl": "https://github.com/dani-garcia/vaultwarden",
"containerConfig": {
"ports": [
"2342:2342"
"8082:80"
],
"volumes": [
"/var/lib/archipelago/photoprism:/photoprism/storage"
],
"env": [
"PHOTOPRISM_ADMIN_PASSWORD=archipelago",
"PHOTOPRISM_DEFAULT_LOCALE=en"
"/var/lib/archipelago/vaultwarden:/data"
]
}
},
{
"id": "pine",
"title": "Pine",
"version": "1.3.0",
"description": "A private voice assistant for your home. Pine runs speech-to-text (Whisper), text-to-speech (Piper) and wake-word detection (openWakeWord) on your own node and pairs with a PineVoice satellite speaker, so Home Assistant Assist works locally with nothing sent to the cloud. Ask it about your node — block height, sync, peers, Lightning balance — and, when a Claude API key is set, anything else.",
"icon": "/assets/img/app-icons/pine.svg",
"author": "Archipelago",
"category": "home",
"dockerImage": "docker.io/library/nginx:1.31.4-alpine",
"repoUrl": "https://github.com/rhasspy/wyoming"
},
{
"id": "portainer",
"title": "Portainer",
"version": "2.45.0",
"description": "Container management web UI for the local Podman socket.",
"icon": "/assets/img/app-icons/portainer.webp",
"author": "Portainer",
"category": "development",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/portainer:2.45.0",
"repoUrl": "https://github.com/portainer/portainer",
"containerConfig": {
"ports": [
"9000:9000"
],
"volumes": [
"/var/lib/archipelago/portainer:/data",
"/run/user/1000/podman/podman.sock:/var/run/docker.sock"
],
"notes": "Uses the manifest-owned Podman socket bind mount preparation path."
}
},
{
"id": "searxng",
"title": "SearXNG",
@@ -544,6 +254,157 @@
]
}
},
{
"id": "fedimint",
"title": "Fedimint Guardian",
"version": "0.10.0",
"description": "Federated Bitcoin minting service with built-in Guardian UI. Privacy-preserving Bitcoin custody.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/fedimintd:v0.10.0",
"repoUrl": "https://github.com/fedimint/fedimint"
},
{
"id": "fedimint-clientd",
"title": "Fedimint Client",
"version": "0.8.0",
"description": "Fedimint ecash client daemon (fmcd). Lets the node hold Fedimint ecash and join federations; the wallet talks to it over a local REST API.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"tier": "core",
"dockerImage": "source.archipelago-foundation.org/lfg2025/fmcd:0.8.1",
"repoUrl": "https://github.com/minmoto/fmcd"
},
{
"id": "fedimint-gateway",
"title": "Fedimint Gateway",
"version": "0.10.0",
"description": "Fedimint gateway service with automatic LND-or-LDK backend selection.",
"icon": "/assets/img/app-icons/fedimint.png",
"author": "Fedimint",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/gatewayd:v0.10.0",
"repoUrl": "https://github.com/fedimint/fedimint",
"containerConfig": {
"ports": [
"8176:8176",
"9737:9737"
],
"volumes": [
"/var/lib/archipelago/fedimint-gateway:/data",
"/var/lib/archipelago/lnd:/lnd:ro"
]
}
},
{
"id": "barkd",
"title": "Ark Wallet",
"version": "0.3.0",
"description": "Ark protocol wallet daemon (barkd). Lets the node hold self-custodial off-chain bitcoin via an Ark server; the wallet talks to it over a local REST API. Signet by default while Ark matures.",
"icon": "/assets/img/app-icons/bark.png",
"author": "Second",
"category": "money",
"dockerImage": "source.archipelago-foundation.org/lfg2025/barkd:0.3.0",
"repoUrl": "https://gitlab.com/ark-bitcoin/bark",
"containerConfig": {
"ports": [
"3535:3535"
],
"volumes": [
"/var/lib/archipelago/barkd:/data"
]
}
},
{
"id": "jellyfin",
"title": "Jellyfin",
"version": "10.8.13",
"description": "Free media server. Stream movies, music, and photos.",
"icon": "/assets/img/app-icons/jellyfin.webp",
"author": "Jellyfin",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/jellyfin:10.8.13",
"repoUrl": "https://github.com/jellyfin/jellyfin",
"containerConfig": {
"ports": [
"8096:8096"
],
"volumes": [
"/var/lib/archipelago/jellyfin/config:/config",
"/var/lib/archipelago/jellyfin/cache:/cache"
]
}
},
{
"id": "immich",
"title": "Immich",
"version": "2.7.4",
"description": "Self-hosted photo and video backup with mobile apps and search.",
"icon": "/assets/img/app-icons/immich.png",
"author": "Immich",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/immich-server:release",
"repoUrl": "https://github.com/immich-app/immich"
},
{
"id": "homeassistant",
"title": "Home Assistant",
"version": "2026.7.3",
"description": "Open source home automation platform. Control and monitor your smart home devices.",
"icon": "/assets/img/app-icons/homeassistant.png",
"author": "Home Assistant",
"category": "home",
"dockerImage": "source.archipelago-foundation.org/lfg2025/home-assistant:2026.7.3",
"repoUrl": "https://github.com/home-assistant/core",
"containerConfig": {
"ports": [
"8123:8123"
],
"volumes": [
"/var/lib/archipelago/home-assistant:/config"
],
"env": [
"TZ=UTC"
]
}
},
{
"id": "pine",
"title": "Pine",
"version": "1.3.0",
"description": "A private voice assistant for your home. Pine runs speech-to-text (Whisper), text-to-speech (Piper) and wake-word detection (openWakeWord) on your own node and pairs with a PineVoice satellite speaker, so Home Assistant Assist works locally with nothing sent to the cloud. Ask it about your node — block height, sync, peers, Lightning balance — and, when a Claude API key is set, anything else.",
"icon": "/assets/img/app-icons/pine.svg",
"author": "Archipelago",
"category": "home",
"dockerImage": "docker.io/library/nginx:1.27-alpine",
"repoUrl": "https://github.com/rhasspy/wyoming"
},
{
"id": "grafana",
"title": "Grafana",
"version": "10.2.0",
"description": "Analytics and monitoring platform. Visualize metrics and create dashboards.",
"icon": "/assets/img/app-icons/grafana.png",
"author": "Grafana Labs",
"category": "data",
"tier": "recommended",
"dockerImage": "grafana/grafana:10.2.0",
"repoUrl": "https://github.com/grafana/grafana",
"containerConfig": {
"ports": [
"3000:3000"
],
"volumes": [
"/var/lib/archipelago/grafana:/var/lib/grafana"
],
"env": [
"GF_PATHS_DATA=/var/lib/grafana",
"GF_USERS_ALLOW_SIGN_UP=false"
]
}
},
{
"id": "tailscale",
"title": "Tailscale",
@@ -572,6 +433,51 @@
]
}
},
{
"id": "portainer",
"title": "Portainer",
"version": "2.19.4",
"description": "Container management web UI for the local Podman socket.",
"icon": "/assets/img/app-icons/portainer.webp",
"author": "Portainer",
"category": "development",
"tier": "optional",
"dockerImage": "source.archipelago-foundation.org/lfg2025/portainer:2.39.1",
"repoUrl": "https://github.com/portainer/portainer",
"containerConfig": {
"ports": [
"9000:9000"
],
"volumes": [
"/var/lib/archipelago/portainer:/data",
"/run/user/1000/podman/podman.sock:/var/run/docker.sock"
],
"notes": "Uses the manifest-owned Podman socket bind mount preparation path."
}
},
{
"id": "netbird",
"title": "NetBird",
"version": "2.38.0",
"description": "Self-hosted WireGuard mesh VPN control plane with dashboard, embedded identity provider, management API, signal, relay, and STUN. The user-facing entry point — a TLS proxy in front of the dashboard + server.",
"icon": "/assets/img/app-icons/netbird.svg",
"author": "NetBird",
"category": "networking",
"tier": "recommended",
"dockerImage": "docker.io/library/nginx:1.27-alpine",
"repoUrl": "https://github.com/netbirdio/netbird",
"containerConfig": {
"ports": [
"8087:80",
"8086:80",
"3478:3478/udp"
],
"volumes": [
"/var/lib/archipelago/netbird:/var/lib/netbird"
],
"notes": "Installed as a two-container stack: netbird dashboard on 8087 and netbird-server control plane on 8086 plus UDP 3478. For production clients, publish a DNS name over HTTPS with gRPC/WebSocket routing."
}
},
{
"id": "uptime-kuma",
"title": "Uptime Kuma",
@@ -601,22 +507,44 @@
}
},
{
"id": "vaultwarden",
"title": "Vaultwarden",
"version": "1.37.2",
"description": "Self-hosted password vault with zero-knowledge encryption.",
"icon": "/assets/img/app-icons/vaultwarden.webp",
"author": "Vaultwarden",
"id": "photoprism",
"title": "PhotoPrism",
"version": "240915",
"description": "AI-powered photo management with facial recognition.",
"icon": "/assets/img/app-icons/photoprism.svg",
"author": "PhotoPrism",
"category": "data",
"tier": "recommended",
"dockerImage": "source.archipelago-foundation.org/lfg2025/vaultwarden:1.37.2-alpine",
"repoUrl": "https://github.com/dani-garcia/vaultwarden",
"dockerImage": "source.archipelago-foundation.org/lfg2025/photoprism:240915",
"repoUrl": "https://github.com/photoprism/photoprism",
"containerConfig": {
"ports": [
"8082:80"
"2342:2342"
],
"volumes": [
"/var/lib/archipelago/vaultwarden:/data"
"/var/lib/archipelago/photoprism:/photoprism/storage"
],
"env": [
"PHOTOPRISM_ADMIN_PASSWORD=archipelago",
"PHOTOPRISM_DEFAULT_LOCALE=en"
]
}
},
{
"id": "nextcloud",
"title": "Nextcloud",
"version": "29",
"description": "Your own private cloud. File sync, calendars, contacts.",
"icon": "/assets/img/app-icons/nextcloud.webp",
"author": "Nextcloud",
"category": "data",
"dockerImage": "source.archipelago-foundation.org/lfg2025/nextcloud:29",
"repoUrl": "https://github.com/nextcloud/server",
"containerConfig": {
"ports": [
"8085:80"
],
"volumes": [
"/var/lib/archipelago/nextcloud:/var/www/html"
]
}
}
-91
View File
@@ -1,91 +0,0 @@
app:
id: adguardhome
name: AdGuard Home
version: v0.107.79
upstream:
kind: github
repo: AdguardTeam/AdGuardHome
description: >-
Network-wide ad and tracker blocking: a DNS server that filters every
device on your LAN, with a web console for rules and client management.
container:
image: source.archipelago-foundation.org/lfg2025/adguardhome:v0.107.79
pull_policy: if-not-present
network: pasta
dependencies:
- storage: 1Gi
resources:
memory_limit: 512Mi
disk_limit: 1Gi
security:
capabilities: [NET_BIND_SERVICE]
readonly_root: false
no_new_privileges: true
network_policy: isolated
ports:
- host: 3030
container: 3000
protocol: tcp
bind: 127.0.0.1
# 3030, not AdGuard Home's conventional 3000: Grafana owns :3000 on a
# node, and both being installable means the host ports must not
# collide (the orchestrator refuses/loads warn on overlap).
# open: the setup wizard and admin console carry AdGuard Home's own
# login; the gate fronts the port (TLS, header fixes) without a
# second cookie challenge.
auth: open
auth_rationale: >-
AdGuard Home enforces its own admin login on the console, and the
first-run wizard must answer before any account exists.
- host: 53
container: 53
protocol: udp
# none: plain DNS must answer every unauthenticated query from LAN
# devices — a login page in front of :53 breaks every client on the
# network by design.
auth: none
auth_rationale: >-
Plain DNS answers unauthenticated by protocol: resolvers and clients
send queries directly; a login challenge would make DNS unreachable.
- host: 53
container: 53
protocol: tcp
auth: none
auth_rationale: >-
DNS-over-TCP fallback (truncated responses, zone transfers); same
protocol-level requirement as the UDP port.
volumes:
- type: bind
source: /var/lib/archipelago/adguardhome
target: /opt/adguardhome
options: [rw]
environment: []
health_check:
type: tcp
endpoint: localhost:3030
interval: 30s
timeout: 5s
retries: 3
interfaces:
main:
name: Admin console
description: AdGuard Home web console
type: ui
port: 3030
protocol: http
path: /
metadata:
author: AdGuard
category: networking
repo: https://github.com/AdguardTeam/AdGuardHome
tier: optional
-3
View File
@@ -2,9 +2,6 @@ app:
id: aiui
name: AI Assistant
version: 0.1.0
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: Conversational AI interface for Archipelago. Quarantined — communicates only via context broker.
internal: true # System-managed, not shown in App Store
-81
View File
@@ -1,81 +0,0 @@
app:
id: alby-hub
name: Alby Hub
version: 1.23.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: getAlby/hub
description: Self-custodial Lightning wallet hub. Runs its own Lightning node on your Archipelago and connects your apps to it over Nostr Wallet Connect — one hub, every app pays through it.
category: money
container:
image: source.archipelago-foundation.org/lfg2025/alby-hub:v1.24.0
pull_policy: if-not-present
dependencies:
- storage: 1Gi
resources:
cpu_limit: 1
memory_limit: 512Mi
disk_limit: 2Gi
security:
capabilities: []
readonly_root: true
no_new_privileges: true
network_policy: bridge
ports:
- host: 8187
container: 8080
protocol: tcp
bind: 127.0.0.1
auth: gated
volumes:
- type: bind
source: /var/lib/archipelago/alby-hub
target: /data
options: [rw]
environment:
- WORK_DIR=/data
- PORT=8080
# LDK peers are dialed outbound-only in v1; no inbound p2p port is
# advertised, so no extra port mapping is needed for payments to work.
- LOG_LEVEL=info
health_check:
type: http
endpoint: http://localhost:8080
path: /
interval: 30s
timeout: 5s
retries: 5
interfaces:
main:
name: Web UI
description: Alby Hub wallet interface
type: ui
port: 8187
protocol: http
metadata:
icon: /assets/img/app-icons/alby-hub.svg
repo: https://github.com/getAlby/hub
tier: optional
launch:
# Embedded: the gate neutralizes Alby Hub's X-Frame-Options: DENY on
# proxied responses. Nodes older than the gate fix show a blocked
# frame — flip to true only if targeting such nodes.
open_in_new_tab: false
features:
- Self-custodial Lightning node (LDK) with a friendly wallet UI
- Connect wallets and apps via Nostr Wallet Connect (NWC)
- Per-app budgets and isolated sub-wallets
- Works with the Alby browser extension and mobile app
-6
View File
@@ -2,12 +2,6 @@ app:
id: archy-btcpay-db
name: BTCPay Postgres
version: "15.17"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: dockerhub
repo: library/postgres
description: Postgres backend for BTCPay and NBXplorer.
container:
-6
View File
@@ -2,12 +2,6 @@ app:
id: archy-mempool-db
name: Mempool MariaDB
version: 11.4.10
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: dockerhub
repo: library/mariadb
description: MariaDB backend for the mempool explorer stack.
container:
+1 -7
View File
@@ -2,17 +2,11 @@ app:
id: archy-mempool-web
name: Mempool Web
version: 3.0.1
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: mempool/mempool
description: Frontend web UI for mempool explorer.
container_name: mempool
container:
image: source.archipelago-foundation.org/lfg2025/mempool-frontend:v3.3.1
image: source.archipelago-foundation.org/lfg2025/mempool-frontend:v3.0.1
pull_policy: if-not-present
network: archy-net
-6
View File
@@ -2,12 +2,6 @@ app:
id: archy-nbxplorer
name: NBXplorer
version: 2.6.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: dgarage/NBXplorer
description: BTCPay blockchain indexer service.
container:
-8
View File
@@ -2,14 +2,6 @@ app:
id: barkd
name: Ark Wallet
version: 0.3.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. bark ships on GitLab only
# (no GitHub mirror), so the gitlab fetcher is the one that can see it.
# NOTE: a version bump is code work, not a pin move — the REST shapes are
# coded in core/archipelago/src/wallet/ark_client.rs (see Dockerfile note).
upstream:
kind: gitlab
repo: ark-bitcoin/bark
description: Ark protocol wallet daemon (barkd). Lets the node hold self-custodial off-chain bitcoin via an Ark server; the wallet talks to it over a local REST API. Signet by default while Ark matures.
container:
+1 -7
View File
@@ -2,12 +2,6 @@ app:
id: bitcoin-core
name: Bitcoin Core
version: 28.4.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: bitcoin/bitcoin
description: Reference Bitcoin Core node with dynamic prune/full-mode startup based on host disk.
container_name: bitcoin-core
@@ -55,7 +49,7 @@ app:
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
fi;
if [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=550 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
else
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
fi
+1 -7
View File
@@ -2,12 +2,6 @@ app:
id: bitcoin-knots
name: Bitcoin Knots
version: 28.1.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: bitcoinknots/bitcoin
description: Full Bitcoin Knots node with dynamic prune/full-mode startup based on host disk.
container_name: bitcoin-knots
@@ -61,7 +55,7 @@ app:
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
fi;
if [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=550 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
else
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
fi
-3
View File
@@ -2,9 +2,6 @@ app:
id: bitcoin-ui
name: Bitcoin UI
version: 1.0.0
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: |
Archipelago-native HTTP proxy + static site for interacting with the
Bitcoin Core / Bitcoin Knots JSON-RPC. Runs nginx inside a container
-3
View File
@@ -2,9 +2,6 @@ app:
id: botfights
name: BotFights
version: 1.2.11
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: Bot competition arena with 2-player arcade fighting mode. AI bots battle in trivia challenges while humans duke it out with controllers. Built for Bitcoiners.
category: community
+3 -19
View File
@@ -1,17 +1,11 @@
app:
id: btcpay-server
name: BTCPay Server
version: 2.4.3
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: btcpayserver/btcpayserver
version: 2.4.2
description: Self-hosted Bitcoin payment processor. Accept Bitcoin payments without intermediaries.
container:
image: docker.io/btcpayserver/btcpayserver:2.4.3
image: docker.io/btcpayserver/btcpayserver:2.4.2
pull_policy: if-not-present
network: archy-net
secret_env:
@@ -52,17 +46,7 @@ app:
container: 49392
protocol: tcp
bind: 127.0.0.1
# open, not gated: BTCPay has its own account system, and its public
# surfaces (checkout/invoice pages, payment buttons, webhooks) must be
# reachable by anonymous payers and machines — a dashboard login in
# front of a checkout link breaks the product. The gate still fronts
# the port; the operator can force the dashboard login back on from
# Settings → BTCPay Server → Access control.
auth: open
auth_rationale: >-
BTCPay enforces its own login for administration, and its checkout,
invoice and webhook endpoints are designed to be reached by
anonymous payers and payment processors.
auth: gated
volumes:
- type: bind
-6
View File
@@ -2,12 +2,6 @@ app:
id: core-lightning
name: Core Lightning (CLN)
version: 23.08.2
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: ElementsProject/lightning
description: Lightning Network implementation in C. Lightweight alternative to LND.
container:
-172
View File
@@ -1,172 +0,0 @@
app:
id: cuprate
name: Cuprate
# Matches the crate's own Cargo.toml version (binaries/cuprated/Cargo.toml).
# Cuprate has no stable release yet — this is explicitly work-in-progress
# software (see upstream README). The image tag below pins the exact
# commit built, since "0.1.0-preview" alone is not reproducible.
version: 0.1.0-preview
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: Cuprate/cuprate
description: Alternative Monero node implementation in Rust. Independently validates Monero consensus rules, providing a layer of security and redundancy for the network.
category: money
container:
# Built from the upstream Dockerfile at the tip of main, 18 commits past
# the cuprated-0.1.0-preview tag (commit 618ff14, 2026-08-19) — there is
# no newer tagged release as of this writing. Re-pin to a tagged release
# once upstream cuts one.
image: source.archipelago-foundation.org/lfg2025/cuprate:0.1.0-preview-18-g618ff14
pull_policy: if-not-present
network: archy-net
# The image's own ENTRYPOINT is ["/usr/local/bin/cuprated"]; these are
# appended as its argv, matching the project's own systemd unit
# (cuprated.service) invocation exactly.
custom_args: ["--config-file", "/home/cuprate/Cuprated.toml"]
# The image (FROM scratch) creates uid:gid 1000:1000 for the `cuprate`
# user at build time and runs as it unconditionally (USER 1000:1000,
# no shell to switch users at runtime) — same pattern as
# apps/phoenixd, apps/electrumx, apps/nostr-rs-relay, apps/portainer,
# apps/barkd. The bind-mounted data dir must be owned by that literal
# uid or cuprated dies on a permission error the first time it writes.
data_uid: "1000:1000"
dependencies:
# Monero mainnet is ~250GiB unpruned as of 2026 and growing a few GB a
# month; cuprated's pruning support is not confirmed stable yet (the
# `pruning` crate exists in the workspace but nothing in this config
# surface toggles it), so this sizes for a full unpruned chain plus
# headroom rather than assuming pruning is available.
- storage: 300Gi
resources:
cpu_limit: 0
memory_limit: 4Gi
disk_limit: 300Gi
security:
# FROM scratch, no package manager/shell, ownership fixed at build time
# — unlike bitcoin-knots this needs no runtime chown/setuid dance, so it
# can run fully read-only with an empty capability set.
capabilities: []
readonly_root: true
no_new_privileges: true
network_policy: isolated
ports:
# P2P. Cuprate's own default listen address is already 0.0.0.0
# (p2p.clear_net.listen_on), so no config override is needed — only the
# host-side port differs from Monero's canonical 18080 because that
# number is already taken on this fleet by lnd's REST port.
- host: 18183
container: 18080
protocol: tcp
auth: none
auth_rationale: >-
Monero p2p gossip. Peers are anonymous by design and speak the Monero wire protocol, not HTTP.
# Unrestricted RPC (full node control) is deliberately NOT published.
# cuprated has no RPC authentication, and for a published port to reach
# it the service would have to bind 0.0.0.0 inside the container — at
# which point every other app can reach it directly on 18081, since
# ports[].bind only restricts the HOST side and podman bridges route to
# each other (verified live 2026-08-22: a peer container on archy-net
# got an unauthenticated get_info, from a *different* network). That is
# unlike bitcoin-knots, whose 0.0.0.0 RPC still demands the rpcuser /
# rpcpassword it writes from generated secrets. So unrestricted RPC is
# left at cuprated's own default — container loopback only, reachable by
# nothing — which is also what upstream intends by refusing a non-local
# bind without an explicit i_know_what_im_doing override.
# Restricted RPC: Monero's own purpose-built safe-for-public subset —
# what wallets use when connecting to a "remote node". Disabled by
# cuprated's own default; enabled via files[] below. A dashboard login
# would break wallet clients connecting programmatically, same
# reasoning as electrumx's port. The daemon still uses its canonical
# container port 18089, but Penpot already owns host port 18089, so this
# maps the public host port to the free 18090 instead.
- host: 18090
container: 18089
protocol: tcp
auth: none
auth_rationale: >-
Monero restricted RPC — the subset upstream considers safe for public/remote-node use. Wallets (Feather, monero-wallet-rpc, GUI) connect directly over plain HTTP JSON-RPC and cannot hold a dashboard session cookie.
volumes:
- type: bind
source: /var/lib/archipelago/cuprate
target: /home/cuprate
options: [rw]
# Settings that need to differ from cuprated's own documented defaults
# (verified against `cuprated --generate-config` and `--dry-run` locally,
# 2026-08-21):
# - target_max_memory: cuprated's own default auto-detects total *host*
# RAM via sysinfo, which inside a memory-limited container would let
# it size caches far past what resources.memory_limit above actually
# grants — same class of problem bitcoin-knots' -dbcache sizing
# comment addresses. Set explicitly, comfortably under the 4Gi limit.
# - rpc.restricted.enable: cuprated ships this off by default; flip on
# so the auth:none host port above actually serves something instead
# of refusing every connection. port stays at its documented default
# (canonical 18089), and advertise stays false — this node is not
# opting in to being listed as a public remote node over the p2p
# network, just reachable if someone points a wallet at it directly.
# - rpc.unrestricted.address + the allow-public flag: cuprated's own
# default (127.0.0.1) looks like the obviously-correct choice for a
# port meant to stay loopback-only, but verified live (2026-08-21)
# that a service bound literally to 127.0.0.1 *inside* the container
# is unreachable through the host's published port — connections
# reset regardless of how long the daemon has been up. Binding
# 0.0.0.0 inside and letting ports[].bind: 127.0.0.1 below be the
# actual restriction is the same pattern apps/bitcoin-knots already
# uses for its own RPC port (-rpcbind=0.0.0.0:8332 internally, gate
# restricts it externally) — not a new risk, the same one already
# reviewed and accepted for Bitcoin's RPC.
# - tracing.stdout.level / tracing.file.{level,max_log_files}: an
# operator reading Cuprated.toml on disk should be able to see and
# tune the log level directly instead of the file silently omitting
# the whole [tracing] table (verified live on amishparadise
# 2026-09-01: the deployed file had no [tracing] section at all, and
# the level was only discoverable by running `cuprated
# --generate-config` and diffing). file.level is set to "info", NOT
# cuprated's own raw default of "debug" — matches the reference dev
# config this app was built and tested against
# (ssmithx@archy-dev-pa:/home/ssmithx/cuprate/Cuprated.toml,
# verified 2026-09-01), which deliberately runs file logging quieter
# than the binary default. max_log_files similarly follows that
# reference (14, not the binary default of 7).
files:
- path: /var/lib/archipelago/cuprate/Cuprated.toml
content: |
network = "Mainnet"
target_max_memory = 3000000000
[rpc.restricted]
enable = true
[tracing.stdout]
level = "info"
[tracing.file]
level = "info"
max_log_files = 14
overwrite: false
health_check:
type: tcp
# Restricted RPC — the only RPC surface published now.
endpoint: localhost:18090
interval: 30s
timeout: 5s
retries: 3
start_period: 5m
metadata:
icon: /assets/img/app-icons/cuprate.svg
category: money
tier: optional
author: Cuprate
repo: https://github.com/Cuprate/cuprate
+6
View File
@@ -0,0 +1,6 @@
node_modules
dist
*.log
.git
.gitignore
README.md
+39
View File
@@ -0,0 +1,39 @@
FROM node:20-alpine AS builder
WORKDIR /app
# Copy package files
COPY package*.json ./
RUN npm ci
# Copy source code
COPY . .
# Build the application
RUN npm run build
# Production stage
FROM node:20-alpine
WORKDIR /app
# Copy built application
COPY --from=builder /app/dist ./dist
COPY --from=builder /app/node_modules ./node_modules
COPY --from=builder /app/package.json ./
COPY --from=builder /app/public ./public
# Create non-root user
RUN addgroup -g 1000 appuser && \
adduser -D -u 1000 -G appuser appuser && \
mkdir -p /app/wallet && \
chown -R appuser:appuser /app
USER appuser
EXPOSE 8080
ENV WALLET_STORAGE=/app/wallet
ENV DWN_ENDPOINT=http://web5-dwn:3000
CMD ["node", "dist/index.js"]
+35
View File
@@ -0,0 +1,35 @@
# DID Wallet
Web5 wallet with Decentralized Identifier (DID) support.
## Building
```bash
# From the apps directory
./build.sh did-wallet
# Or manually
cd did-wallet
docker build -t archipelago/did-wallet:latest .
```
## Development
```bash
cd did-wallet
npm install
npm run dev
```
## Ports
- **8083**: Web UI (dev: 18083)
## Running Locally
```bash
docker run -p 8083:8080 \
-v /tmp/archipelago-dev/did-wallet:/app/wallet \
-e DWN_ENDPOINT=http://localhost:13000 \
archipelago/did-wallet:latest
```
+56
View File
@@ -0,0 +1,56 @@
app:
id: did-wallet
name: Web5 DID Wallet
version: 1.0.0
description: Web5 wallet with Decentralized Identifier (DID) support. Manage your digital identity and Web5 assets.
container:
image: archipelago/did-wallet:1.0.0
image_signature: cosign://...
pull_policy: if-not-present
dependencies:
- storage: 2Gi
resources:
cpu_limit: 1
memory_limit: 512Mi
disk_limit: 2Gi
security:
capabilities: []
readonly_root: true
no_new_privileges: true
user: 1000
seccomp_profile: default
network_policy: isolated
apparmor_profile: did-wallet
ports:
- host: 8088
container: 8080
protocol: tcp # Web UI
bind: 127.0.0.1
auth: gated
volumes:
- type: bind
source: /var/lib/archipelago/did-wallet
target: /app/wallet
options: [rw]
environment:
- WALLET_STORAGE=/app/wallet
health_check:
type: http
endpoint: http://127.0.0.1:8080
path: /health
interval: 30s
timeout: 5s
retries: 3
web5_integration:
did_support: true
wallet_functionality: true
bitcoin_integration: true
+2747
View File
File diff suppressed because it is too large Load Diff
+21
View File
@@ -0,0 +1,21 @@
{
"name": "did-wallet",
"version": "1.0.0",
"description": "Web5 DID Wallet for Archipelago",
"main": "dist/index.js",
"scripts": {
"build": "tsc",
"start": "node dist/index.js",
"dev": "ts-node src/index.ts"
},
"dependencies": {
"express": "^4.18.2",
"@web5/api": "^0.9.0"
},
"devDependencies": {
"@types/express": "^4.17.21",
"@types/node": "^20.10.0",
"typescript": "^5.3.3",
"ts-node": "^10.9.2"
}
}
+23
View File
@@ -0,0 +1,23 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>DID Wallet</title>
<style>
body {
font-family: system-ui, -apple-system, sans-serif;
max-width: 800px;
margin: 0 auto;
padding: 20px;
}
</style>
</head>
<body>
<h1>Web5 DID Wallet</h1>
<p>Decentralized Identity Wallet for Archipelago</p>
<div id="app">
<p>Wallet interface coming soon...</p>
</div>
</body>
</html>
+37
View File
@@ -0,0 +1,37 @@
import express from 'express';
const app = express();
const port = 8080;
// Middleware
app.use(express.json());
app.use(express.static('public'));
// Health check endpoint
app.get('/health', (req, res) => {
res.json({ status: 'ok', service: 'did-wallet' });
});
// Wallet API endpoints
app.get('/api/wallet/info', (req, res) => {
res.json({
status: 'ok',
wallet: {
dids: [],
balance: 0
}
});
});
app.post('/api/wallet/did/create', async (req, res) => {
// Placeholder for DID creation
res.json({
status: 'ok',
did: 'did:key:placeholder'
});
});
// Start server
app.listen(port, '0.0.0.0', () => {
console.log(`DID Wallet listening on port ${port}`);
});
+16
View File
@@ -0,0 +1,16 @@
{
"compilerOptions": {
"target": "ES2020",
"module": "commonjs",
"lib": ["ES2020"],
"outDir": "./dist",
"rootDir": "./src",
"strict": true,
"esModuleInterop": true,
"skipLibCheck": true,
"forceConsistentCasingInFileNames": true,
"resolveJsonModule": true
},
"include": ["src/**/*"],
"exclude": ["node_modules", "dist"]
}
-3
View File
@@ -2,9 +2,6 @@ app:
id: electrs-ui
name: Electrs UI
version: 1.0.0
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: |
Archipelago-native HTTP frontend for electrs/electrumx status. Runs
nginx inside a container, serves static assets, and proxies
-6
View File
@@ -2,12 +2,6 @@ app:
id: electrumx
name: ElectrumX
version: 1.18.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: spesmilo/electrumx
description: Electrum server indexing Bitcoin chain data for lightweight wallet queries.
container:
-6
View File
@@ -2,12 +2,6 @@ app:
id: fedimint-clientd
name: Fedimint Client
version: 0.8.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: fedimint/fedimint-clientd
description: Fedimint ecash client daemon (fmcd). Lets the node hold Fedimint ecash and join federations; the wallet talks to it over a local REST API.
container:
+1 -7
View File
@@ -2,16 +2,10 @@ app:
id: fedimint-gateway
name: Fedimint Gateway
version: 0.10.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: fedimint/fedimint
description: Fedimint gateway service with automatic LND-or-LDK backend selection.
container:
image: source.archipelago-foundation.org/lfg2025/gatewayd:v0.10.1
image: source.archipelago-foundation.org/lfg2025/gatewayd:v0.10.0
pull_policy: if-not-present
network: archy-net
entrypoint: ["sh", "-lc"]
+1 -7
View File
@@ -2,16 +2,10 @@ app:
id: fedimint
name: Fedimint Guardian
version: 0.10.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: fedimint/fedimint
description: Federated Bitcoin minting service with built-in Guardian UI. Privacy-preserving Bitcoin custody.
container:
image: source.archipelago-foundation.org/lfg2025/fedimintd:v0.10.1
image: source.archipelago-foundation.org/lfg2025/fedimintd:v0.10.0
pull_policy: if-not-present
network: archy-net
entrypoint: ["sh", "-lc"]
+2 -8
View File
@@ -1,17 +1,11 @@
app:
id: filebrowser
name: File Browser
version: 2.63.23
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: filebrowser/filebrowser
version: 2.27.0
description: Baseline Archipelago file manager service.
container:
image: source.archipelago-foundation.org/lfg2025/filebrowser:v2.63.23
image: source.archipelago-foundation.org/lfg2025/filebrowser:v2.27.0
pull_policy: if-not-present
network: archy-net
custom_args: ["--config", "/data/.filebrowser.json"]
-3
View File
@@ -2,9 +2,6 @@ app:
id: fips-ui
name: FIPS Mesh
version: 1.0.0
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: |
Archipelago-native dashboard for the FIPS mesh transport. Runs nginx
inside a container with host networking, serves a static dashboard on
+3 -18
View File
@@ -1,18 +1,12 @@
app:
id: gitea
name: Gitea
version: "1.27.3"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: go-gitea/gitea
version: "1.23"
description: Self-hosted Git service with built-in container registry, CI/CD, and package hosting.
category: development
container:
image: source.archipelago-foundation.org/lfg2025/gitea:1.27.3
image: docker.io/gitea/gitea:1.23
pull_policy: if-not-present
dependencies:
@@ -33,16 +27,7 @@ app:
container: 3000
protocol: tcp
bind: 127.0.0.1
# open, not gated: Gitea carries a complete login of its own, and git
# clients speak HTTP basic-auth — a cookie challenge in front of
# git-over-HTTP breaks every clone/push. The gate still fronts the
# port (iframe header fixes, retry page, Tor); the operator can force
# the dashboard login back on from Settings → Gitea → Access control.
auth: open
auth_rationale: >-
Gitea enforces its own account login on every page and API route;
git clients authenticate with basic-auth/tokens and cannot complete
a browser login challenge.
auth: gated
- host: 2222
container: 22
protocol: tcp
+1 -7
View File
@@ -2,16 +2,10 @@ app:
id: grafana
name: Grafana
version: 10.2.0
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: grafana/grafana
description: Analytics and monitoring platform. Visualize metrics and create dashboards.
container:
image: source.archipelago-foundation.org/lfg2025/grafana:10.2.0
image: grafana/grafana:10.2.0
image_signature: cosign://...
pull_policy: if-not-present
data_uid: "472:472"
+2 -8
View File
@@ -1,17 +1,11 @@
app:
id: homeassistant
name: Home Assistant
version: 2026.8.3
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: home-assistant/core
version: 2026.7.3
description: Open source home automation platform. Control and monitor your smart home devices.
container:
image: source.archipelago-foundation.org/lfg2025/home-assistant:2026.8.3
image: source.archipelago-foundation.org/lfg2025/home-assistant:2026.7.3
pull_policy: if-not-present
network: pasta
-6
View File
@@ -2,12 +2,6 @@ app:
id: immich-postgres
name: Immich Postgres
version: "14-vectorchord0.4.3-pgvectors0.2.0"
# Upstream is the Immich-built Postgres image, published only on ghcr.io
# (no GitHub release tags, no Docker Hub repo) — the ghcr fetcher in
# scripts/check-upstream-releases.py is the only one that can see it.
upstream:
kind: ghcr
repo: immich-app/postgres
description: Postgres (pgvecto.rs / vectorchord) backend for Immich.
# Container named immich_postgres (underscore) to match the runtime's existing
-6
View File
@@ -2,12 +2,6 @@ app:
id: immich-redis
name: Immich Redis
version: "7-alpine"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: dockerhub
repo: valkey/valkey
description: Valkey (Redis-compatible) cache for Immich.
# Container named immich_redis (underscore) to match runtime per-app references
-6
View File
@@ -2,12 +2,6 @@ app:
id: immich
name: Immich
version: "2.7.4"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: immich-app/immich
description: Self-hosted photo and video backup with mobile apps and search.
# app_id "immich" = the user-facing launcher (matches the catalog entry's title
-3
View File
@@ -2,9 +2,6 @@ app:
id: indeedhub-api
name: IndeedHub API
version: "1.0.0"
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: IndeedHub backend API (Nostr auth, media, payments).
category: community
-3
View File
@@ -2,9 +2,6 @@ app:
id: indeedhub-ffmpeg
name: IndeedHub FFmpeg Worker
version: "1.0.0"
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: IndeedHub background media transcoding worker.
category: community
-6
View File
@@ -2,12 +2,6 @@ app:
id: indeedhub-minio
name: IndeedHub MinIO
version: "RELEASE.2024-11-07T00-52-20Z"
# MinIO's release tags are date-opaque (RELEASE.YYYY-MM-DD…), so the
# checker reports them as UNCOMPARABLE rather than ordering them — the
# latest tag is still shown for hand comparison, which is the point.
upstream:
kind: github
repo: minio/minio
description: MinIO S3-compatible object storage for IndeedHub media.
category: community
-6
View File
@@ -2,12 +2,6 @@ app:
id: indeedhub-postgres
name: IndeedHub Postgres
version: "16.13-alpine"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: dockerhub
repo: library/postgres
description: Postgres database backend for IndeedHub.
category: community
-6
View File
@@ -2,12 +2,6 @@ app:
id: indeedhub-redis
name: IndeedHub Redis
version: "7.4.8-alpine"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: dockerhub
repo: library/redis
description: Redis queue/cache backend for IndeedHub.
category: community
+1 -7
View File
@@ -2,12 +2,6 @@ app:
id: indeedhub-relay
name: IndeedHub Nostr Relay
version: "0.9.0"
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: scsibug/nostr-rs-relay
description: nostr-rs-relay backing IndeedHub's Nostr identity + comments.
category: community
@@ -17,7 +11,7 @@ app:
container_name: indeedhub-relay
container:
image: source.archipelago-foundation.org/lfg2025/nostr-rs-relay:0.10.0
image: source.archipelago-foundation.org/lfg2025/nostr-rs-relay:0.9.0
pull_policy: if-not-present
network: indeedhub-net
network_aliases: [relay]
-3
View File
@@ -2,9 +2,6 @@ app:
id: indeedhub
name: IndeeHub
version: "1.0.0"
# Built by this project — there is no upstream release feed to watch.
upstream:
kind: internal
description: Bitcoin documentary streaming platform featuring God Bless Bitcoin and other educational content about Bitcoin, sovereignty, and decentralized technology. Sign in with your Nostr identity.
category: community
+1 -7
View File
@@ -2,16 +2,10 @@ app:
id: jellyfin
name: Jellyfin
version: 10.8.13
# Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from.
upstream:
kind: github
repo: jellyfin/jellyfin
description: Free media server. Stream movies, music, and photos.
container:
image: source.archipelago-foundation.org/lfg2025/jellyfin:10.11.11
image: source.archipelago-foundation.org/lfg2025/jellyfin:10.8.13
pull_policy: if-not-present
network: pasta
+5
View File
@@ -0,0 +1,5 @@
# Lightning Stack - uses official image
FROM lightninglabs/lightning-stack:v0.12.0
# Default configuration is in the image
# No additional setup needed

Some files were not shown because too many files have changed in this diff Show More