Skip to content

fix: message island tap opens the app through an activity, not a broadcast trampoline (#371, #382) - #386

Merged
D4vidDf merged 1 commit into
D4vidDf:dev/0_6_0from
noelpatata:fix/message-tap-trampoline-activity
Sep 25, 2026
Merged

D4vidDf merged 1 commit into
D4vidDf:dev/0_6_0from
noelpatata:fix/message-tap-trampoline-activity

Conversation

@noelpatata

Copy link
Copy Markdown
Contributor

#382 (beta1, Redmi 13) and #371 still get "tap just closes the island" on WhatsApp, even with the BAL opt-in from #366.

The tap on a MESSAGE island was a broadcast that then fired the app's content intent, so it's a notification trampoline, and from Android 12 the system can drop that launch. Whether the opt-in rescues it seems to depend on the ROM.

Now the island's content intent opens a tiny invisible IslandTapActivity (not exported, no history, own task, translucent). Since it was started straight from the notification it's in the foreground, so launching WhatsApp's intent from there is always allowed. Then it sends the same ISLAND_CLICKED broadcast so the service still cancels the original + the island like before.

Tests + assembleDebug OK. I can't fake a real island tap over adb on HyperOS, so it's not tested on device yet. If you can try it on a phone that had the bug that'd be great.

Fixes #382
Fixes #371

🤖 Generated with Claude Code

@D4vidDf
D4vidDf merged commit b3299c3 into D4vidDf:dev/0_6_0 Sep 25, 2026
2 checks passed
D4vidDf added a commit that referenced this pull request Oct 2, 2026
… Phase 5) (#328)

* feat(composer): add island template model, Room persistence, matcher and translator

Phase 4 (#272) data layer: ComposerTemplate/IslandTemplateDefinition model
covering the 10 Xiaomi templates and their slots (left graphic, text,
progress, buttons, rule), a Room-backed repository with a hand-written
1->2 migration (avoids destructive fallback wiping settings), a pure
ComposerTemplateMatcher cloned from RulesEngine, and a ComposerTemplateTranslator
hooked into NotificationReaderService just before the built-in translator
dispatch. A matched template now wins over native Live Updates and the
built-in per-type translators for STANDARD/MESSAGE/PROGRESS/DOWNLOAD/MEDIA
notifications.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* test(composer): add matcher and repository unit tests

Covers package/title/text regex matching, priority ordering, disabled
templates, invalid-regex safety, and JSON round-tripping every field of
IslandTemplateDefinition through the Room repository (fake in-memory DAO,
matching this repo's existing testing conventions). ComposerTemplateMatcher
is kept free of android.util.Log so it stays plain-JUnit testable.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* feat(composer): add island template composer UI and DesignScreen entry point

Phase 4 (#272) Compose layer: a shared IslandTemplatePreview live pill
plus 10 default-definition catalog wrappers for the Xiaomi templates,
slot editors (left graphic, text/badge, progress, action buttons, rule
binder with an app picker + advanced regex toggle), IslandComposerScreen
(type switcher + live preview + gated editors + save), and
ComposerTemplateListScreen (list/enable/delete), wired into DesignScreen
and HomeScreen's hand-rolled route enum alongside the existing
Widgets/Themes flows.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(composer): make ComposerTemplateMatcher regex cache thread-safe

NotificationReaderService dispatches each notification onto
Dispatchers.Default (a real thread pool), so this singleton's regex
cache can be hit concurrently by multiple notifications. Switch the
plain mutableMapOf to a ConcurrentHashMap to avoid data races on the
24/7 service path.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* feat(widget-studio): add AST model, variable engine, dimension validator, and pipeline hooks (#273)

Lays the data/service foundation for the KWGT-style micro-widget studio:
recursive CustomWidgetNode AST with kotlinx-serialization, a pure
WidgetVariableEngine and WidgetDimensionValidator (JUnit-tested), a
.hwidget file-based repository cloned from ThemeRepository, a RemoteViews
CustomWidgetRenderer, and a CustomWidgetTranslator consulted from
NotificationReaderService before the built-in translators (the minimal
translator-registry hook, since Phase 3's real TranslatorRegistry does not
exist yet).

Also adds the "island content sources" add-on: a permission-protected
UpdateSourceReceiver + Room-backed SourceRepository/allow-list feeding
{source.<id>.text}/{source.<id>.icon}, wired into PermanentIslandManager so
an allow-listed app can drive a micro-widget on the permanent island, plus
a Settings screen to manage the allow-list. Bumps the settings Room DB to
version 2 with an explicit migration for the two new tables.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* feat(widget-studio): add Compose canvas editor and Design tab entry point (#273)

Adds WidgetStudioScreen (a click-to-select spatial canvas with a numeric
property inspector, a separate pure-Compose preview renderer kept in sync
with the RemoteViews one via WidgetDimensionValidator) and
SavedCustomWidgetsScreen (list + .hwidget import/export), then wires both
into the Design tab's local router in HomeScreen.kt and a new "Widget
Studio (Beta)" entry in DesignScreen's FAB sheet.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* chore(widget-studio): remove unused imports in WidgetStudioScreen

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): fix .hwidget export FileProvider crash, drop dead code (#273)

CustomWidgetRepository.exportWidget() zipped into cacheDir/widget_exports,
but res/xml/file_paths.xml only declares a cache-path root named
"exports" - the Export button in WidgetStudioScreen would have thrown
"Failed to find configured root" from FileProvider.getUriForFile at
runtime. Reuse the same exports/ dir ThemeRepository already shares.

Also removes the unused, inaccurately-documented getWidgetSync() (its
doc comment claimed PermanentIslandManager used it; that class actually
calls the suspend getWidget()), and adds a soft (warning-only, matching
the existing overlap-check pattern) button-count check to
WidgetDimensionValidator since HyperOS islands realistically fit only
2-3 tappable buttons.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): own each source id per package and gate widget bindings like templates (#273)

- SourceRepository.update refuses a write for a source id currently owned by a
  different package (first allowed writer claims the id until its value expires),
  and lookup resolves to null once the owner has been revoked in Settings.
- UpdateSourceReceiver drops updates whose self-reported owner package is not
  installed, so the allow-list never shows phantom entries.
- NotificationReaderService: custom widget bindings now share the composer
  template eligibility (no CALL/NAVIGATION/SCREEN_RECORDING/TIMER) and also
  force the custom island path over native live updates; a rule-matched
  composer template keeps precedence over a per-package widget binding.
- DesignRoute enum: restore the comma lost while merging the two entry points.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): never store null in the binding cache, expire entries, never throw from hasBinding (#273)

Caching "no binding" as a null value in a ConcurrentHashMap threw an NPE from
resolveWidgetId() inside processStandardNotification, so every package without
a custom widget lost its island (reproduced on device with an ntfy notification:
no island, stack trace in HyperBridgeDebug). The cache now stores a small holder
with a nullable id and a timestamp, entries expire after 15 s so a widget bound
in the Studio is picked up without restarting the service, and hasBinding()
catches and logs any failure, treating it as unbound.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): put the rendered micro-widget in the island-expand slot and give the pill an icon (#273)

On a real HyperOS device the custom widget island showed an anonymous pill that
never expanded: setCustomRemoteView only fills the notification's custom view,
while the expanded island reads setCustomIslandExpandRemoteView, and without a
big-island info block the collapsed pill has no content. The translator now sets
both RemoteViews slots and uses the source app's icon for the collapsed pill
(same recipe as WidgetTranslator); the permanent island path sets both slots too.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): resolve {device.battery} and {time.now} on the notification path too (#273)

Only the permanent island filled the device values into VariableContext, so a
micro-widget bound to an app rendered "Bateria % ·" with an empty bar. The
battery/time helpers move to data/widget/DeviceVariables and both render paths
use them.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix(widget-studio): bump Room to v3 so a template-composer v2 database upgrades instead of crashing (#273)

The composer branch (#327) and this branch both declared version 2 with
different schemas, so installing this build over a composer build failed
with "Room cannot verify the data integrity" and the app killed itself.

MIGRATION_1_2 is now identical to #327 (composer_templates only) and the
source_apps / source_values tables move to a new MIGRATION_2_3.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* `test(ui)`: add preview for disconnected service state in DiagnosticsScreen

Adds `DiagnosticsScreenReconnectServicePreview` to allow previewing `DiagnosticsContent` when notification access is granted but the service is disconnected (`serviceConnected = false`).

* fix: permanent island yields to a native island for its declared lifetime, not a flat 30 s (#335) (#337)

* fix: permanent island yields to a native island for its declared lifetime, not a flat 30 s (#335)

HyperOS 3 draws two islands side by side, the second one as an app-icon
bubble. Re-posting the permanent island 30 s after a native island appears
(#304) therefore shows a HyperBridge bubble next to any long-running native
island such as the Clock stopwatch.

Read the native island's own lifetime instead: Xiaomi's protocol declares
param_v2.param_island.islandTimeout in seconds with a documented default of
one hour. NativeIslandYieldPolicy turns a focus param into a yield window
(declared timeout, 1 h default, 0 without param_island, 30 s for MediaStyle
players and unreadable payloads), NativeIslandTracker keeps that window per
sighting, and the re-assert timer now follows the remaining windows when a
native island is forgotten.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix: permanent island also yields to bridged islands on HyperOS 3 (#335)

#243 kept the permanent island posted underneath bridged islands so it was
revealed the instant they collapsed. HyperOS 3 draws two islands at once,
the older one as a mini island with only the app icon, so the posted pill
becomes a HyperBridge bubble next to every WhatsApp island.

Route PermanentIslandManager.desiredActive() through the existing
PermanentIslandVisibilityPolicy, which already requires no active bridged
island, widget island or VPN island.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

* fix: time-limit the yield only for media players, other islands hide the pill while posted (#335)

Review feedback on #337: HyperOS turns every notification that carries a
MediaSession into an island player, so those are the only islands whose
notification outlives the island (a paused player, #255) and the only ones
that keep the short 30 s window. Any other native island now hides the
permanent island for as long as its notification is posted; the only bound
is the island lifetime it declares to HyperOS (param_island.islandTimeout,
default 1 h), after which HyperOS has already dropped the island.

- NativeIslandYieldPolicy: media wins over a focus param; an unreadable
  focus param means "hide until removed" instead of the old flat window.
- NotificationReaderService: a media player is a MediaStyle template, a
  notification with a MediaSession token, or one carrying
  miui.focus.param.media.

Co-Authored-By: Claude Fable 5.1 <[email protected]>

---------

Co-authored-by: noelpatata2 <[email protected]>

* chore: bump version to 0.6.0-dev5

Update `versionCode` to 38 and `versionName` to "0.6.0-dev5" in `app/build.gradle.kts`.

* ci: add GitHub Actions workflow for PR test gating and debug APK artifact (#349) (#352)

* ci: add GitHub Actions workflow for PR test gating and debug APK artifact (#349)

* ci: separate unit tests and debug apk build workflows with direct PR download links

* feat: add system update island integration and customization settings (#365)

* feat: add system update island integration and customization settings

Add support for the system updater package with a dedicated translator,
timeout policy, and customization screen for configuring layout design,
icon sources, and auto-hide timeouts.

* feat: support system updates without progress and refine timeout policy

* Add `hasProgress` check to SystemUpdateTimeoutPolicy to apply system update timeouts when progress is absent.
* Handle non-progress system updates in SystemUpdateTranslator with customized layout configurations.
* Refactor system update routing in NotificationReaderService and add unit tests.

* fix: only group bridged islands on Android 16+, where force grouping exists (#358) (#368)

The app group from #334 needs a real summary notification, and HyperOS shows
that summary as an ordinary "Hyper Bridge / Active Islands" row in the shade
while it hides the Focus children. So on any HyperOS 3 phone below Android 16
the row sits in the shade for as long as one island (the permanent one
included) exists, and users read it as a second island.

Force grouping at 2 (config_autoGroupAtCount) only exists from Android 16, so
the group and its summary are now a no-op below SDK 36. Android 16+ keeps the
#334 behaviour unchanged.

Co-authored-by: noelpatata2 <[email protected]>

* feat(translators): Custom Translators Framework (.htrans), Visual Editor, Dynamic Engine, Theme Bundling & SAF Sharing (#271) (#353)

* feat(translator): add custom translator model, database persistence, and room migration (#344)

* feat(translator): define serializable CustomTranslator model and configuration schemas
* feat(db): create TranslatorEntity and TranslatorDao with database migration from v1 to v2
* test(translator): add unit tests for serialization roundtrip and entity conversion

* feat(translators): introduce dynamic custom translator framework (#345)

* feat(translators): add DynamicTranslator and TranslatorRegistry for declarative notification parsing
* feat(service): integrate custom translator evaluation and overrides into NotificationReaderService
* feat(theme): add synchronous theme lookup by ID in ThemeRepository
* fix(service): refine notification listener status check and watchdog binding on permission grant
* test(translators): add tests for registry priority, scope/condition matching, and regex extraction

* feat(ui): Design Hub Translators Section, App Config Screen Integration, Multi-Filtering & Visual Editor (#346)

* feat(translators): custom translators manager, visual editor, and app integration

* feat(translators): add visual translator editor with live island preview
* feat(translators): add translator manager screen with search and filtering
* feat(design): add translators carousel to design dashboard
* feat(settings): integrate app-specific custom translator controls in app config
* feat(service): expose NotificationReaderService instance for channel querying

* feat(translator): presentation modes, theme binding, and progress editor enhancements

* feat(translator): theme binding and installed themes support in editor and live preview
* feat(translator): presentation mode, template, widget, and icon slot selection sheets
* feat(translator): text template fields with dismissable variable chips and quick insertion
* feat(translator): progress slot type selector, regex presets, and progress guide sheet
* feat(i18n): string resources for presentation modes, themes, and progress configurations

* feat(translator): inline reply action source and dynamic button configuration UI

* feat(translator): add inline reply action source and broadcast handling
* feat(ui): redesign translator action slot editor into action buttons with reordering and visibility toggling
* feat(ui): add bottomsheet option pickers for action sources, smart types, display modes, and action guide
* feat(i18n): update translator string resources and spanish translations for action buttons

* feat(translator): overhaul behavior settings UI with engine mode selection and guide sheet

* feat(translator): add engine selection and behavior guide bottom sheets
* feat(translator): redesign behavior screen with sectioned cards and timeout sliders
* feat(i18n): add English and Spanish strings for behavior guide and engine settings

* feat(translator): compact pill customization, symmetrical island preview, and dynamic presentation

* feat(translator): add compact pill config models and dynamic presentation logic
* feat(ui): add pill customization editor, symmetrical preview layout, and selection sheets
* feat(i18n): add English and Spanish string resources for compact pill settings

* feat(translator): add HyperOS 3 island preview components and enhanced action handling

* feat(ui): add HyperOS 3 expanded island and compact pill Compose components with previews
* feat(ui): integrate interactive island preview switcher (expanded/compact pill) into translator editor
* feat(translator): add progress bar, timer, theme highlight override, and themed action icon handling in `DynamicTranslator`
* feat(translator): expand presentation template presets and update string resources

* feat(translator): custom icon selection and execution priority editor sheets

* feat(translator): add `iconName` property to translator metadata model
* feat(translator): add icon selection and execution priority bottomsheets with presets and guide
* feat(translator): render custom translator icons in editor and manager lists

* refactor(translator): remove preview shell from conditions content

* feat(translators): add advanced filter sheet, dynamic scope icon badges, and state sync

* feat(translators): introduce multi-criteria filter bottom sheet for filtering by scope, notification types, apps, authors, and icons
* feat(ui): update translator items and previews across screens with scope-colored icon badges and metadata chips
* fix(translators): sync enabled status and priority updates back into translator JSON content

* feat(translator): implement specialized dynamic templates, diagnostics integration, and allowlist bypass

* feat(translator): add dynamic layout templates for media, calls, timers, progress, and standard notifications in `DynamicTranslator`
* feat(translator): support avatar, sender, and large icon extraction for custom left slot graphics
* feat(service): evaluate custom translators before type enablement checks and bypass app allowlist for targeted packages
* feat(ui): integrate custom translator configurations and latest applied status into bug reports and diagnostics screens
* feat(translator): update translator registry to evaluate notification types alongside categories for accurate scope matching

* feat(translator): introduce system apps target scope and library allowance evaluation

* feat(translator): add `SYSTEM_APPS` target scope and `isLibraryAllowed` matching logic in translator registry
* feat(translator): split user launcher apps and system apps loading with dedicated selection bottom sheets in editor
* feat(service): update notification reader to process custom translators for explicitly targeted system apps
* feat(ui): add system apps scope color mappings, filter options, and metadata chips across manager and design screens
* feat(i18n): add English and Spanish string resources for system apps scope and filters

* Merge branch 'dev/0_6_0' into feature/271-custom-translators-framework (#347)

* `test(ui)`: add preview for disconnected service state in DiagnosticsScreen

Adds `DiagnosticsScreenReconnectServicePreview` to allow previewing `DiagnosticsContent` when notification access is granted but the service is disconnected (`serviceConnected = false`).

* fix: permanent island yields to a native island for its declared lifetime, not a flat 30 s (#335) (#337)

* fix: permanent island yields to a native island for its declared lifetime, not a flat 30 s (#335)

HyperOS 3 draws two islands side by side, the second one as an app-icon
bubble. Re-posting the permanent island 30 s after a native island appears
(#304) therefore shows a HyperBridge bubble next to any long-running native
island such as the Clock stopwatch.

Read the native island's own lifetime instead: Xiaomi's protocol declares
param_v2.param_island.islandTimeout in seconds with a documented default of
one hour. NativeIslandYieldPolicy turns a focus param into a yield window
(declared timeout, 1 h default, 0 without param_island, 30 s for MediaStyle
players and unreadable payloads), NativeIslandTracker keeps that window per
sighting, and the re-assert timer now follows the remaining windows when a
native island is forgotten.


* fix: permanent island also yields to bridged islands on HyperOS 3 (#335)

#243 kept the permanent island posted underneath bridged islands so it was
revealed the instant they collapsed. HyperOS 3 draws two islands at once,
the older one as a mini island with only the app icon, so the posted pill
becomes a HyperBridge bubble next to every WhatsApp island.

Route PermanentIslandManager.desiredActive() through the existing
PermanentIslandVisibilityPolicy, which already requires no active bridged
island, widget island or VPN island.


* fix: time-limit the yield only for media players, other islands hide the pill while posted (#335)

Review feedback on #337: HyperOS turns every notification that carries a
MediaSession into an island player, so those are the only islands whose
notification outlives the island (a paused player, #255) and the only ones
that keep the short 30 s window. Any other native island now hides the
permanent island for as long as its notification is posted; the only bound
is the island lifetime it declares to HyperOS (param_island.islandTimeout,
default 1 h), after which HyperOS has already dropped the island.

- NativeIslandYieldPolicy: media wins over a focus param; an unreadable
  focus param means "hide until removed" instead of the old flat window.
- NotificationReaderService: a media player is a MediaStyle template, a
  notification with a MediaSession token, or one carrying
  miui.focus.param.media.


---------

Co-authored-by: noelpatata2 <[email protected]>

---------

Co-authored-by: noelpatata2 <[email protected]>
Co-authored-by: noelpatata2 <[email protected]>

* feat(translator): import, export, and share functionality for custom translators (#350)

* feat(translator): introduce `TranslatorRepository` for packaging, extracting, and sharing `.htrans` archives (JSON and icons) and raw JSON files
* feat(ui): add SAF-based import/export launchers and intent-based sharing actions to the translator manager screen
* feat(theme): automatically discover and import bundled custom translators when processing themes
* feat(i18n): add string resources for import, export, and sharing feedback messages

---------

Co-authored-by: noelpatata2 <[email protected]>
Co-authored-by: noelpatata2 <[email protected]>

* feat: add RAW_PARAM_V2 presentation mode with custom variables and actions (#369)

Introduce `RAW_PARAM_V2` presentation mode to allow Custom Translators to provide direct JSON payload templates for HyperOS.

- `CustomTranslator`: add configurations for custom variables (regex extraction, image sources, step mapping), custom actions (smart extraction, inline replies), and `RawParamV2Config`.
- `DynamicTranslator`: process custom variable and action extraction logic, including fallback chain evaluation for templates (e.g., `{notif.title | notif.text ?: 'Default'}`). Add validation and normalization for raw JSON templates and bundle assets dynamically.
- `HyperOsIslandPreview`: support parsing and previewing raw JSON templates to reflect dynamic values in the UI.
- `TranslatorEditorScreen`: adapt UI for `RAW_PARAM_V2` by showing a banner and hiding standard presentation configuration tabs (Pill, Progress, Actions) since they are handled within the JSON template.
- Add serialization, fallback chaining, and JSON validation tests.

* fix: message island tap opens the app again on Android 15+ (#359) (#366)

For MESSAGE islands the tap is routed through our own broadcast so we
can cancel the source notification afterwards. That makes HyperBridge,
not the system, the *sender* of the app's content PendingIntent.

Since API 34 a sender no longer lends its background-activity-launch
privilege unless it opts in via ActivityOptions, and since API 35 the
creator denies it by default. Google Messages targets 35+, so its
launch was silently dropped while the cancel still ran: notification
gone, app not opened, message still unread. WhatsApp only worked
because it still targets an older SDK.

Opt in with MODE_BACKGROUND_ACTIVITY_START_ALLOW_ALWAYS (ALLOWED below
API 36) when sending the original intent from the click receiver.

Co-authored-by: noelpatata2 <[email protected]>

* fix: drop the island group summary once no island is left (#372) (#373)

The "Hyper Bridge / Active Islands" summary is only released from
onNotificationRemoved, and that callback only arrives while the listener
is bound. Anything that takes the last island down outside that window --
a reboot, HyperOS killing the service, an app update, stop() cancelling
the VPN island as the service dies -- leaves the summary behind with
nothing under it, and the orphan sweep in syncNotifications skips
summaries on purpose. On HyperOS the Focus children are hidden from the
shade, so that orphaned summary is the only row left: it reads as an
island that never goes away and cannot be dismissed without turning the
whole group off.

Make the summary a function of what is actually posted instead of a
function of the events we happened to see:

- BridgeIslandGroup.reconcile() releases the summary when no child is
  left and re-posts it when children outlive it (swiped-away summary,
  process death between the two posts). syncNotifications calls it, so
  it runs on listener connect and on every sync tick.
- The VPN controller and the permanent island schedule the release right
  where they cancel, since both cancel while the service is going down.

The release stays debounced, so a Shizuku cancel+repost of the only
child is still not mistaken for an empty group.

Co-authored-by: noelpatata2 <[email protected]>

* chore: bump version to 0.6.0-beta1

Update `versionName` to "0.6.0-beta1" in `app/build.gradle.kts`.

* feat(design): island templates as translator presentations (#272, Phase 4)

Rework of the Composer along the lines David asked for in #327: templates are
not a feature of their own any more, they are presets for the Phase 3
translator pipeline, and every preview goes through the component added for
TranslatorScreen.

- IslandTemplateCatalog: the ten official Xiaomi templates as named
  PresentationConfig presets. Reuses the ids the editor's picker already
  offered (so tpl_call_kit / tpl_media_compact keep the meaning
  DynamicTranslator gives them) and adds the two that were missing, boarding
  pass and courier tracking. Picking one produces an ordinary CustomTranslator
  with presentation.mode = TEMPLATE, so templates inherit matching, priority,
  theming and .htrans import/export instead of a parallel store.
- HyperOsIslandPreview gains an IslandPreviewSample (so each template previews
  with content that suits it), a showChrome flag for thumbnail use, and
  resolves TEMPLATE presets before rendering. The three copies of the token
  replacement chain collapse into one helper, which also fixes the compact
  pill showing a raw {notif.title}.
- Design tab: a Designs section listing the active designs, and Add design ->
  from a template (gallery of the ten, each previewed) or a custom design,
  which stays disabled until the Widget Studio lands. After picking a template
  the only question asked is the notification type.
- Translator editor: the template sheet is the same gallery, and picking a
  template now also opens the slot editors, so each element can be bound to
  notification data alongside the match conditions already there.
- DynamicTranslator fills the slots from the preset for a translator that only
  carries a templateId, so an imported .htrans renders as its template.

Tests: 12 new IslandTemplateCatalog cases; :app:testDebugUnitTest is 416 green
and :app:assembleDebug builds.

* fix(design): templates are materialized once, then rendered exactly as saved (#272)

effectivePresentation() merged the preset slot by slot, comparing each whole slot to the
class defaults, and refilled an empty action list from the preset. Two silent losses:
editing one text field of a translator that still carried a bare templateId dropped the
preset's other fields (the payment template's highlight / OTP text), and deleting a
preset's only action brought it back on every render.

A template is now either bare (only a templateId: rendered as the preset) or concrete
(rendered as saved). The editor materializes it when a translator is loaded, when the mode
is switched to TEMPLATE, and when a template is picked (applyTemplate), so every edit and
deletion sticks.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>

* fix(widget-studio): enforce the tree limits and treat .hwidget imports as untrusted (#273)

- WidgetDimensionValidator only reported MAX_DEPTH / MAX_NODE_COUNT and kept every node, and
  no caller rejected on its errors. The clamp now cuts the tree at those limits, so the
  renderer, the condition pruner and the clamp itself never recurse past them.
- Import checks widget.json's bracket nesting before decoding: kotlinx decodes the node tree
  recursively and a StackOverflowError is an Error, which no catch in the path stopped.
- The widget id from widget.json is a folder name that gets deleteRecursively()'d: an id like
  "../../databases" wiped app data. Unsafe ids are replaced with a generated one, and
  get/delete/export ignore them.
- Unpacked size and widget.json size are capped (zip bomb), and the zip-slip prefix check
  now includes the separator.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>

* fix(widget-studio): content sources check the real sender and sanitize the source id (#273)

- UPDATE_SOURCE trusted a self-reported owner_package, and the permission is normal, so any
  app could write an allowed app's source. The owner is now the platform-reported sender
  (getSentFromPackage, sender shares its identity via BroadcastOptions); owner_package is
  optional and must match.
- The source id was used unsanitized as sources/<id>.png: '../' escaped the icons dir.
  Ids are now [A-Za-z0-9._-], max 64, no leading dot. Text is capped at 512 chars.
- Expired rows are pruned together with their icon files instead of leaving them behind.
- Widget PendingIntents used the node id as request code, so two islands from one design
  (or two designs sharing a node id) overwrote each other's intent: Dismiss on one closed
  the other. The request code now includes the design id and bridge id.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>

* fix(design): payment template highlights the OTP the translator actually extracts (#272)

The preset used {regex.1}, which nothing in DynamicTranslator's variable map ever fills,
so the payment island's highlight / pill text rendered blank. It now uses
{smart_action.OTP.code}, filled by the existing OTP extraction. A test pins every preset
to variables the translator provides.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>

* fix: native-island yield uses a monotonic clock and a guarded re-assert timer (#379)

Since #337 a focus island can hold the permanent island for its declared lifetime (up to
an hour), so NativeIslandTracker's wall clock matters: a timezone change, manual edit or
NTP step inside the window stretched or cut it short, and the window never self-heals
because note() keeps the first-seen time. It now defaults to elapsedRealtime.

nativeYieldJob is rescheduled from listener callbacks and from the IO sync loop; the
cancel/replace is now done under a lock so a timer can't be orphaned between them.

Co-authored-by: noelpatata2 <[email protected]>

* revert: drop the bridged-island notification group (#334, #368, #373) (#380)

* Revert "fix: drop the island group summary once no island is left (#372) (#373)"

This reverts commit 435b0bf.

* Revert "fix: only group bridged islands on Android 16+, where force grouping exists (#358) (#368)"

This reverts commit 7fe8c03.

* Revert "fix: keep bridged islands in one app group so Android 16+ cannot force-group and silence them (#331) (#334)"

This reverts commit 2c0d183.

---------

Co-authored-by: noelpatata2 <[email protected]>

* fix: VPN disconnect button opts in to background activity launch (#359 follow-up) (#377)

VpnIslandController.disconnect() sent the provider's disconnect PendingIntent from our
receiver without the BAL opt-in #366 added for the message island tap. OpenVPN for
Android's disconnect is an activity (DisconnectVPN), so on Android 15+ the launch was
dropped silently, send() did not throw, and the island sat on "disconnecting" until the
verify timeout. Both call sites now share PendingIntent.sendAllowingBackgroundLaunch().

Co-authored-by: noelpatata2 <[email protected]>

* chore: bump version to 0.6.0-beta3

Update `versionCode` to 40 and `versionName` to "0.6.0-beta3" in `app/build.gradle.kts`.

* fix: message island tap opens the app through an activity, not a broadcast trampoline (#371, #382) (#386)

Co-authored-by: noelpatata2 <[email protected]>

---------

Co-authored-by: noelpatata2 <[email protected]>
Co-authored-by: Claude Fable 5.1 <[email protected]>
Co-authored-by: david <[email protected]>
Co-authored-by: noelpatata <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants