Record phase 1 completion and the decisions it added
PLAN.md: UserMessage/Answered events in the common model, the --bind dev override (fail-closed default untouched), enrollment via the aiapp:// intent filter, Keystore-sealed token storage; phase 1 marked done with what was verified. AGENTS.md: real layout, commands, and the lessons that bit (tracing callsite cache in tests, adjustResize, CMP accessor deprecation). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017xn8nHw1tw1R6PtiY1eEtw
This commit is contained in:
1 parent
213bc72b64
commit
f3cebeea78
2 files changed
+73
-24
No files matched your search
@@ -30,31 +30,58 @@ can't come apart). Read local-updater's `README.md` and `AGENTS.md` for the
|
||||
conventions before diverging from them; module-by-module intent for this
|
||||
repo is in PLAN.md's "Backend layout" section.
|
||||
|
||||
- `server/` — Rust backend (to be created, phase 1).
|
||||
- `app/` — Compose Android app (to be created, phase 1).
|
||||
- `server/` — Rust backend (`ai-server`). `main.rs` bootstraps (TLS, the
|
||||
auth layer, token/QR enrollment, wg0 binding), `routes.rs` has the HTTP
|
||||
table in its module doc comment, `auth.rs` the bearer-token middleware,
|
||||
`config.rs` the persisted schema, `session/` the manager (registry
|
||||
pattern), `Driver` trait + event model, `EchoDriver`, and transcripts.
|
||||
- `app/` — Compose Android app, single `:androidApp` module, package
|
||||
`com.example.aiapp`, label "AI Sessions". `AppRoot.kt` is the navigation
|
||||
`when`; `Api.kt`/`EventStream.kt` the REST + SSE clients; `Events.kt` the
|
||||
event model mirror; `ServerConfig.kt` settings + Keystore-sealed token;
|
||||
screens in `SessionListScreen/SessionScreen/SpawnScreen/SettingsScreen`.
|
||||
- `gen-dev-cert.sh` / `certs/` — copied from local-updater's scheme
|
||||
(idempotent CA, reissued leaf; regenerating the CA strands the installed
|
||||
app — same one-way door).
|
||||
app — same one-way door). Dev SANs cover 127.0.0.1, 10.0.2.2 (emulator →
|
||||
host), and the LAN IP alongside the WireGuard address.
|
||||
|
||||
## Status
|
||||
|
||||
Pre-implementation. Phases are in PLAN.md; phase 1 (Skeleton) proves the
|
||||
whole pipe — TLS, token auth, wg0-bound listener, SSE with transcript
|
||||
cursors, both app screens — against a fake `EchoDriver` before any AI is
|
||||
involved. Every phase ends runnable and verified against the real thing.
|
||||
Phase 1 (Skeleton) done 2026-08-24 — the whole pipe works end-to-end
|
||||
against `EchoDriver`: TLS + token auth, SSE with transcript cursors
|
||||
surviving restarts, spawn/message/question/delete from the app. Next:
|
||||
phase 2 (Claude driver); phases are in PLAN.md.
|
||||
|
||||
## Checking your work
|
||||
|
||||
Fill in real commands as they're created; until then, the inherited posture:
|
||||
|
||||
- Server: `cargo test` + `cargo clippy --all-targets` from `server/` —
|
||||
the build stays warning-clean from the first commit.
|
||||
- App: from `app/`, `. ./android-env.sh && ./gradlew :androidApp:compileDebugKotlin`.
|
||||
- Tests where logic is pure (event normalization, transcript cursors, config
|
||||
persistence, llama-server refcounting); the app is UI over the API and is
|
||||
verified by running it.
|
||||
- Server: `./run-tests.sh` (or `cargo test`) + `cargo clippy --all-targets`
|
||||
from `server/` — the build stays warning-clean, keep it that way.
|
||||
- App: from `app/`, `. ./android-env.sh && ./gradlew :androidApp:compileDebugKotlin`;
|
||||
`./run-android.sh` builds, installs, and launches on the emulator.
|
||||
- Run the server for development with `--bind 127.0.0.1` (wg0 doesn't exist
|
||||
on this machine yet; the default fails closed). First run prints the
|
||||
enrollment QR/URI with the token — capture it from the log.
|
||||
- Prefer exercising the server directly over going through the UI:
|
||||
`curl --cacert certs/ca.pem -H "Authorization: Bearer …" https://…`.
|
||||
`curl --cacert certs/ca.pem -H "Authorization: Bearer …" https://127.0.0.1:8443/sessions`.
|
||||
The emulator app reaches it at `https://10.0.2.2:8443`; enroll it with
|
||||
`adb shell "am start -a android.intent.action.VIEW -d 'aiapp://enroll?host=10.0.2.2&port=8443&token=…'"`
|
||||
(quote so the device shell doesn't eat the `&`s).
|
||||
|
||||
## Things that have bitten
|
||||
|
||||
- **tracing caches callsite interest process-wide.** A test that hits a
|
||||
`tracing::warn!` with no subscriber installed can poison the interest
|
||||
cache for a concurrent test that captures logs (flaky "nothing was
|
||||
logged" failures). Keep every exercise of a logging code path under the
|
||||
one capturing subscriber — that's why the auth middleware has a single
|
||||
combined gating+logging test.
|
||||
- **The keyboard pans the window unless the activity opts into resize.**
|
||||
Without `android:windowSoftInputMode="adjustResize"`, opening the IME
|
||||
slides the whole window up (top bar off screen) instead of resizing —
|
||||
`imePadding()` alone doesn't fix it and the transcript looks empty.
|
||||
- **CMP 1.11 deprecates the `compose.*` dependency accessors** — declare
|
||||
`org.jetbrains.compose.<x>:<x>` directly (material3 has its own release
|
||||
train, separate from the CMP version).
|
||||
|
||||
## Environment notes (this machine, learned in local-updater)
|
||||
|
||||
|
||||
Reference in new issue
Block a user