video().track() in the buffer format callback takes the libvlc input lock,
which stop() holds while it waits for the decoder thread running that
callback. Take the video track from the media info only.
* android, desktop: open group member profile without waiting for the core
Tapping a member avatar awaited apiGroupMemberInfo and apiGetGroupMemberCode
before the profile modal was created. Both are single-row queries, 1-2 ms when
the core is idle, but sendCmd is serialized against everything else the core is
doing, so while it is busy - startup, a batch of incoming events, a long database
operation - the tap produces nothing at all until the core drains.
The modal is now opened first and the two values arrive in state the tap handler
creates, so the profile opens at the speed of the UI. The card is shown from the
member that is already known at the tap, preferring the model's copy once it is
there, so the member no longer has to be written to the model before the modal
can be shown.
* plans: open member profile without waiting for the core
* android, desktop: keep member profile rows in place while they load
The security code and the connection stats arrive after the profile is shown, so
"Verify security code" and the Servers section appeared under the already
visible card and pushed the rows below them down.
They are now rendered from the first frame in their final positions, disabled,
and enabled in place when the data arrives - SectionItemView already drops the
clickable modifier when disabled, so nothing moves. Only what can be decided from
the member known at the tap is reserved: "Fix connection" is not, as it applies
only while a ratchet needs syncing and a placeholder for it would disappear on
nearly every open.
* android, desktop: reserve the network status row with the servers
The reserved Servers section had three rows where the loaded one has four, so
everything below it - "Block member" - moved down by one row when the stats
arrived.
Network status looks like agent state that cannot be predicted before loading,
but connSubStatus returns Just whenever the connection has receiving queues, and
that is the same list that decides whether "Receiving via" is rendered. The two
rows appear together, so the status row is now reserved with them.
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
* ui: blur media by resampling the preview, not a per-frame effect
Modifier.blur put a BlurEffect on a display-sized graphics layer, so the
Gaussian was re-evaluated on every frame the media was drawn. It also
requires RenderEffect, which Android applies only from API 31, so below
Android 12 media was drawn unblurred while the setting read as on.
A blur and a downscale discard the same thing - detail finer than their
radius - so the preview is now resampled to about one pixel per radius and
stretched back. That runs once when the item composes, needs no
RenderEffect, and removes the detail irreversibly rather than convolving
it. The first resampling step bounds both sides, so no image, however
shaped, can produce a large intermediate.
While the blur hides the media the file is also left unread, so an image
scrolled past is no longer read, decoded at its full size and kept in the
image cache only to be hidden again. blurHidesMedia() is the single
definition that both the drawing and the loading decision use, so they
cannot disagree about whether the media is on screen.
* plans: blur media by resampling the preview
* ui: shorten comments in media blur
* ui: smooth the media blur and match its strength to the old one
Stretching the resampled preview straight to the screen showed its pixel grid. Double it back
up until its longest side is at least half the reference width before drawing, so the last
stretch is short and the tents compose into a bell. The reference width moves from 360 to 400:
fitted against Gaussians, 360 blurred 5-75% more than Modifier.blur did, 400 is within 10% at
every setting.
Skia's raster blur runs at full resolution, so each bar blurred width x (bar + 6 sigma) pixels every frame: about
80 ms per frame for the two bars of a chat at the default radius, which cut scrolling to 5-9 fps on the software
renderer. Scaling the layer cannot help, because a layer's filter is evaluated in device space and the scale is
applied to the sigma too. The bar is now drawn into an offscreen surface up to 8x narrower and blurred there, which
measured 5-6x cheaper and within 0.25/255 of the original.
Blurring a copy means the bar no longer follows the content on its own, so the scroll containers bump a version on
the app bar handler and the bar depends on it.
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
* badges: webapp (#7433)
* badges: service migrations, store and catalog
* badges: BTCPay provider and settlement poller
* badges: web listener and /api endpoints
* web: checkout single-page app
* badges: tests and BTCPay fixtures
* badges: README and ini reference
* badges: fix hex16 build on GHC 8.10.7
* badges: Stripe card lane
* badges: fix Stripe card checkout, add theming
* badges: add a discount row to the order summary
* badges: site navbar, embedding, theme, Forget move
* badges: use SB code prefix in web checkout
* badges: rename sxb app namespace to sb
* badges: embed checkout nav via site; keep original app navbar
* badges: post iframe height, apply site background when embedded
* badges: embed dark surfaces, steadier iframe height
* badges: hide app footer when embedded
* badges: size embedded body to content, not viewport
* badges: declare color-scheme to stop reload flash
* badges: fade shell in on load, no reload blank
* badges: prerender app shell into index.html
* badges: pre-paint theme, hide shell on deep reload
* badges: logo returns to landing client-side
* badges: embedded wizard back, buy-a-code, resume
* badges: signal app-managed screens, resume across reload
* badges: rebuild wizard history on deep load so Back walks it
* badges: carry welcome-page height as the iframe floor
* badges: keep selection on Buy a code; rename to Your codes
* badges: read web shell as UTF-8, not locale
* badges: resume the exact paid order after Stripe card redirect
* badges: move docker deploy under scripts
* badges: add serve_webapp toggle and webapp export
* badges: wire split webapp deploy in docker config
* badges: quiet agent logs by default
* badges: resume card redirect in the embedded frame
* badges: migrate Stripe adapter to PaymentIntents
* badges: correct Stripe restricted key scopes in ini example
* badges: card via Payment Element and PaymentIntents
* badges: fix stale Checkout Session wording in Stripe adapter
* badges: fix stale CheckoutActions reference in card comment
* badges: order shell stylesheet before bootstrap script
* badges: remove development card stand-in
* badges: theme the Stripe card form with the site palette
* badges: exclude web from the Haskell build stage
* badges: unify invoice cancel and mark canceled
* badges: default log level to info
* badges: unify closed-invoice buy-again button
* badges: mute agent connection logs at info level
* badges: show purchase time in local timezone in Your codes
* badges: log service events on own channel, quiet agent
* badges: fold service migrations into one baseline
* badges: run compose on postgres over host network
* badges: use high-res hero art
* badges: add web CI to catch stale builds
* badges: rebuild web shell from committed source
* badges: normalize invoice-code link and columns
* badges: drop unused columns, rename index
* badges: note deferred receipt_hash in migrations
* badges: apply code-review fixes
* badges: reduce comments across service and web
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* badges: improve web page (#7546)
* badges: improve web page
* improve layout
* improve layout
* fix
* small changes
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* badges: read one issuer key from the ini
* badges: move and group the service tests
* badges: service fixes (#7567)
* badges: match the redeem error wording in tests
* badges: drop unused imports in the bot tests
* badges: cancel Stripe orders when they expire
* badges: correct the Stripe config and docs
* badges: refuse to revoke a redeemed code
* badges: make the fake Stripe cancel like Stripe
* badges: limit replayed webhook deliveries
---------
Co-authored-by: sh <37271604+shumvgolove@users.noreply.github.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
Co-authored-by: shum <github.shum@liber.li>
Co-authored-by: spaced4ndy <8711996+spaced4ndy@users.noreply.github.com>
* core: support message signing in p2p groups
* improve
* add member key
* distribute keys and sign
* refactor
* better query
* map
* sign in relay groups too
* clean up
* list
* fix test
* update bot types
* some refactor
* remove unnecessary condition
* simplify
* refactor
* simplify
* move
* clean up
* diff
* diff
* limit attempts for key sending
* optimize
* fix test
* split
* fuse
* null
* only mark as "key sent" when forwarder supports binary encoding
* fix bot apis
* fix some tests
* add key distribution steps, and fix some tests
* fix test
* increase timeout
* fix tests
* fix more tests
* simplify
* disable test output
* mark keys sent with invitations
* fix test
* fix test, query plans
* unify signing of connection info packets
* revert change to createNewGroup
* create key at group/member creation
* rename, remove liftIO
* clean up
* fix type
* remove ad hoc key sending
* update bot api
* diff
* reduce diff
* failing test
* fix sending messages in groups with members before version 18
* remove test delays
* update query plans
* update test
* add tests
* fix tests
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* desktop: fix rotated video squashed on playback and preview rotated twice
vlc applies the display matrix before a frame reaches the vmem callback, so the
buffer has to be requested with the sides swapped for the transposed orientations,
and the snapshot must not be rotated again by hand. Read the snapshot on the event
thread, where the render callback writes it, and draw the inline playback surface
with FillWidth so a video narrower than the item fills it like its preview does.
Bound the requested buffer: the size comes from a received file, so it is capped by
area, cannot be zero, and a frame that does not fill the bitmap is dropped.
* desktop: harden the video frame path against crafted files
Only transpose the buffer for the track's own sides - the size libvlc passes is
already rotated, so swapping it would recreate the squash for a file declaring a
rotation with a zero-sized track. Copy the frame inside the render callback, on
vlc's thread, where the native buffer is guaranteed to exist, and hand only the
copy to the event thread. Drop a frame rendered with a format the bitmap was not
sized by, or arriving before any buffer was allocated. Divide the pixel budget by
a side pinned at 1 instead of scaling both sides, so a 2000000000x1 declaration
cannot take 45 times the budget. Publish the bitmap only when skia took the
pixels, size the copy after a rewind, and log a failed snapshot conversion
instead of throwing it into callers that have no handler for it.
* desktop: add bounded animated image decoder
Skia's Codec is already on the desktop classpath through skiko and decodes
both GIF and animated WebP. The frames come from a file somebody else
composed, so the decoder is bounded before it allocates: the raster is
measured in bytes with the sides multiplied as Long, each side is capped
separately so an extreme aspect ratio cannot slip under the byte budget, and
the encoded size is checked before the bytes are copied into native memory.
Anything outside the bounds, or any failure, keeps the still image the chat
already renders.
Nothing calls this yet.
* desktop: animate GIFs in chat items and full screen
Both views drew the first frame only. The full screen view also decoded its
still on every recomposition, which an animation recomposes once per frame,
so that decode is remembered against the data it comes from.
The chat list preview stays a still image: it is a 36dp box that the desktop
layout keeps on screen the whole time, so animating it would hold a raster and
spend a frame of work per listed chat, without pause.
Removes the two markers left for this work.
* desktop: don't decode animation frames that cannot be seen
With media blur on, a blurred image is only revealed while the mouse is over
it, so every frame was decoded, uploaded and then blurred away again for
nobody - and the blur is a render effect re-run per frame. Frames now decode
only while the image can be seen, which also stops motion showing through a
blur that is there to hide it.
Passing the blur state to the view is why the shared signature changes; coil
drives its own animation on Android, so there is nothing to pause there.
* docs: move animated images plan to plans/
* docs: drop file path references from animated images plan
* docs: correct animated images plan against the code
* desktop: correct animated image comments
* desktop: reduce animated image comments
* desktop: correct and bound animated image decoding
* docs: correct animated images plan against measurements
* desktop: fuse the animation prior frame decision
* docs: cover desktop animated images in spec and product
* desktop: drop the unused animated image component
* desktop: return the animation frame instead of its state
* docs: correct the animated images documentation
* desktop: don't decode animations under the full screen viewer
* desktop: bound the frames an animation rebuilds
* desktop: pause animations under any full screen modal
* desktop: stop animations that alternate expensive frames
* desktop: read what playing a frame needs only once
* desktop: close the codec of an animation outside the bounds
* desktop: wait out what an animation frame cost to decode
* docs: correct animated images claims against the code
* desktop: bound the frame count where the others are bounded
* desktop: don't wait out a stall an animation frame did not spend
* desktop: say what the slow frame constants stand for
* desktop: don't decode animations behind a minimised window
* desktop: make the animation frame wait testable
* desktop: bound the file size where the others are bounded
* desktop: pin the frame wait clamp in its test
* desktop: keep the frame wait clamp private
* desktop: reduce animated image comments
---------
Co-authored-by: sh <github.shum@liber.li>
* desktop: fix stretched video preview and playback for AV1 videos
libvlc passes the padded size the decoder allocated to the buffer format
callback, not the size of the picture. dav1d pads to a multiple of 128, so
a 1920x1080 AV1 video arrives as 1920x1152, and vlc scales the picture to
fill it - the preview sent with the message, and desktop playback, were
6.7% too tall. H264 pads much less, so it was barely visible there.
Ask for the size of the track being played instead. It is already populated
when the buffer format is negotiated, and matching the track that is playing
matters for files with more than one video track, where the first track is
not necessarily the one being decoded. Falls back to the previous behaviour
when the track is not known.
* plans: desktop video preview aspect ratio
* android, desktop: open group member profile without loading all members
Clicking member avatar in chat loaded the whole member list (apiListMembers)
before showing member profile, and it was repeated on every click - in a group
with 10000 members it takes several seconds.
The full list is not needed to show the profile of one member, so instead the
opened member is added to the model, the same way as in iOS app.
* plans: member profile in large groups
* plans: correct relay warning section - it is not affected by the change
* core, ui: auto-accept group invitations per user profile
Add a per-profile toggle for auto-accepting group invitations, and regroup it
with the existing contact-requests setting under a single Auto-accept section
in Privacy & Security, relabelled "Contact requests in groups".
The join is fully async. processGroupInvitation already had an async accept
path, used when the invitation matches a group link the user opened:
prepareAgentJoin + createMemberConnectionAsync + joinAgentConnectionAsync,
with the outcome reported later against the CFJoinConn command id. Auto-accept
takes that same path instead of going through APIJoinGroup, so it works while
the app is closed and never blocks message processing.
An auto-accepted invitation still records a CIRcvGroupInvitation item in the
chat with the inviting contact, so there is a record of who added the user to
which group.
Two details worth noting for review:
hostContact is reported to clients only for group links. Clients respond to it
by replacing the transient host connection view with the group and removing
that chat - correct for a group link, where the contact is a placeholder, but
wrong for a plain invitation, where it is a real contact.
A resent invitation returns the existing group, because createGroupInvitation
is idempotent on inv_queue_info. The join therefore only runs while the
membership is still GSMemInvited, so a resend cannot open a second connection.
* booldef
* order
* refactor
* update translation key
* query plans
* ios: export translations
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny Poberezkin <2769109+epoberezkin@users.noreply.github.com>
* directory: only create group links after approval
* update test
* update messages
* diff
* get group and link in one query
* reduce database reads
* better errors
* typos
* query plans
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>