Releases: BeatoutC/sendmecongo
Release list
v0.5.2 — Android real-time receiver
sendmecongo moves files out of a physically isolated machine in one direction only — a fountain-coded QR stream on the screen, a phone camera on the other side, and a byte-identical file at the end. No network, no USB, no Bluetooth.
The Android receiver: no recording, just point and scan
Until now, receiving meant recording the screen with a camera app and handing the video to sendmecongo-recv. v0.5.2 ships an Android app that closes that loop in real time: it scans the QR stream straight off the camera preview. Point the phone at the screen, hold it there, done — there is no recording step and nothing to copy off the phone afterwards.
- Same protocol, same core. The receiver inside is the identical pure-Rust
sendmecongo-core(RaptorQ per RFC 6330, four CRC layers), compiled to an arm64 JNI.sobehind a one-screen Kotlin shell built on CameraX. - Phone presets in the sender.
mp15…mp40-30x2tune module size, per-code hold time, and repair percentage for a phone camera instead of a 4K recording. They ship in the send GUI dropdown as of this release — a v0.5.1 sender does not know them, so upgrade both ends. - Manual camera control where it matters. Fixed exposure (ISO 800 / 4 ms), 60fps target with 30fps fallback, 1440×1080 analysis resolution — enough pixels per module for two side-by-side V40 codes.
- Icon. The launcher icon is the recv light-cone, rendered from the same geometry code as the desktop icon (
sendmecongo-bench icon --variant recv), extracted to transparency for the adaptive foreground. - Signing. The APK is signed with a project keystore that is committed to the build repository on purpose — for a public tool this signature proves build reproducibility, not identity. Rebuilds produce the same signature.
Measured on real hardware (incompressible random data, every run verified byte-identical):
| Preset | QR | Lanes | sym/s | Nominal | Measured goodput |
|---|---|---|---|---|---|
mp40 |
V40-L | 1 | 10 | 29.3 KB/s | 29 KB/s |
mp40-30 |
V40-L | 1 | 30 | 87.9 KB/s | 80+ KB/s |
mp40-30x2 |
V40-L | 2 | 60 | 175.9 KB/s | 130 KB/s stable |
That last row is the headline: two codes side by side on screen, phone held landscape, 130 KB/s into a live camera — roughly 4× the first working single-lane build two days ago. The dual-lane push surfaced three real bugs, all fixed here: a Y-plane row-stride contract violation (the Kotlin side compacted rows the Rust side then re-addressed by stride — invisible at 640×480 where stride equals width, fatal at 1440), ImageAnalysis silently defaulting to 640×480, and a Rust panic crossing the JNI boundary and killing the whole process (now caught and surfaced as an error string).
Changes for the desktop apps
No functional change — version bump only, plus the new phone presets in the sender's dropdown. The DMGs are rebuilt from this same commit so both ends agree on the preset list.
Assets
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-recv-android-0.5.2.apk |
9.6 MB | 9E30E41B698D75683865A9809634BFF7BCDCC2EFF9DBABF9F35A9EF0D5AAA7CC |
sendmecongo-recv-0.5.2.dmg |
4.7 MB | B4D47BE579AFFAF98B9DBE7CE49171C5594E80C3D220A76AAAE7DD3B8BBB5A5B |
sendmecongo-send-0.5.2.dmg |
4.4 MB | B1DA91A861CA4047A973B2522A3DC9425F2E22064D495A85142F4BBF653D72EF |
The DMGs are Apple-Silicon-only, ad-hoc signed as before; the APK targets Android 10+ (API 29), arm64-v8a.
112 tests green across the workspace.
v0.5.1 — Windows icon fix
Windows icons.
sendmecongo moves files out of a physically isolated machine in one direction only — a fountain-coded QR stream on the screen, a phone camera on the other side, and a byte-identical file at the end. No network, no USB, no Bluetooth.
Changes in v0.5.1
Both icons were missing on Windows, and both went missing without saying anything.
- The
.exefile icon.winresemitscargo:rustc-link-lib=static=resourceon the GNU toolchain, and GNU ld only pulls an archive member in when it resolves an undefined symbol. A pure resource object defines none, so the resource — the icon and the version block — was dropped silently, leaving no.rsrcsection in the binary at all. The compiledresource.ois now handed to the linker directly; the guard keeps MSVC, which producesresource.libinstead, on its original path. A resource compile failure panics now instead of being swallowed bylet _ =. - The window icon.
with_icon(egui::IconData::default())is deliberate on macOS — it stops eframe from overwriting the bundle'sAppIcon.icns— but a bare.exehas no bundle behind it, so the title bar and the taskbar drew the generic application glyph even once the file icon was right. The sameapp.icothe build script embeds is now decoded for the window, and every non-Windows target still gets the empty icon it got before.
No protocol, codec or layout change — on macOS both fixes either compile out or return exactly what they returned before.
109 tests green across the workspace, plus a clean cargo check --workspace --target x86_64-pc-windows-msvc --no-default-features.
Assets — macOS (Apple Silicon, .app inside a DMG)
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send-0.5.1.dmg |
4.42 MB | E032E5E4040D01F4FA0755E1CD926559247126C5F9D83B7511970D9800AE09E3 |
sendmecongo-recv-0.5.1.dmg |
4.71 MB | 0A3B15A952320202C709D1A8FB4AC4DB0DCA844196B2A6A6DFEAA3E14CF5E767 |
Assets — Windows x86_64, standalone exe
These were built from this same icon fix and are hosted on the v0.5.0 page, which is the release number they carry.
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send.exe |
18.51 MB | 207996AE9D63D56C2918376D07759A98E6DA3DAA9B428FD9576EE3220CA2C4DB |
sendmecongo-recv.exe |
19.90 MB | B7466EE2B0F97137FED4C0D86EA070436BC3B4824F82EDC96910912D83BACC31 |
v0.5.0 — resumable transfer + agent skill
Resumable transfer, the agent CLI contract, and vendor-tolerant container parsing.
sendmecongo moves files out of a physically isolated machine in one direction only — a fountain-coded QR stream on the screen, a phone camera on the other side, and a byte-identical file at the end. No network, no USB, no Bluetooth.
Changes in v0.5.0
Resumable transfer (M2.1–M2.3)
- The receiver checkpoints every run — complete or not — as
<recording>.smr.jsonplus<recording>.smr.binnext to the video, and--resumere-feeds those symbol payloads before the video is opened. The merge key is(session, object_len, symbol_size), so frames from a different preset are dropped at the protocol level. A partial run exits with code 2. - A partial run now lands on a checkpoint screen: a per-block symbol grid, a retake ETA at the matching preset's rate, and a typeable SMR1 repair code (Crockford base32 + CRC-8, ~23 characters for a single block). Starting a recording whose namesake checkpoint exists resumes it automatically.
- The sender replays repair only: a repair-code box in the GUI (validated live against the prepared container and preset) and
--repair-codein the player. A validated code replays only fresh repair symbols past the original broadcast's batch, so a retake takes seconds instead of a full cycle. Codes are re-validated before any window opens.
Agent-driven operation (M2.4–M2.5)
- Machine contract on both ends:
--prepare-onlydry run,--jsonaligned across send and recv (status: done|partial,received_file,resume_code,eta_seconds),--playaccepted anywhere on the command line, and--file/--resume-codealiases. Documented indocs/AGENT.md. skills/sendmecongo/SKILL.md— a prompt plus the repo URL is enough for an agent to drive sending and receiving end to end.
Container parsing, from recordings that real users actually had
- Android recordings carrying vendor blobs around the
moovare readable again. Huawei appends a private metadata run after the movie whose first eight bytes parsed as a 1.8 GB box, so a perfectly good recording was refused withbox size out of rangeeven though themoovhad been found one step earlier. Two more shapes were fixed alongside it: a blob parked before themoovmade a readable file reportnot an MP4/MOV file, and a tail whose bytes happened to line up as amoofmade an ordinary recording reportfragmented movie, unsupported. - A bad size at the top level now ends the walk and keeps what was already found, while a tree we are already inside still has to be sane. What a file is gets decided from the
moovfirst: samples in hand mean a plain movie, whatever the tail parses as. - Legacy
AGQ/AGC1headers are still accepted, so older test recordings keep decoding.
Tooling
tools/verify-recv.sh --smoke— a baseline-free pass that only asks whether each recording opens and runs to the end (exit 0 and 2 pass, 1 fails). System-camera recordings cannot have a byte-for-byte baseline, because their original never leaves the isolated machine, so they could not enter the acceptance matrix at all — which is how these container bugs reached a user instead of a red test. Both passes now feed the receiver through a symlink underout/, so resume checkpoints stop landing inrecordings/.- README pipeline diagram renders as mermaid.
- 107 unit tests green across the workspace.
Assets — macOS (Apple Silicon, .app inside a DMG)
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send-0.5.0.dmg |
4.42 MB | 75B24C1543B3C05733867786DD6AA7FF043AD98AD849646E1B79BCB0BC9B4FAA |
sendmecongo-recv-0.5.0.dmg |
4.71 MB | 863971B3F3A77F7BBF9ED76BB6E733BE101C9501B5497018EBD162A7B7EE2558 |
Assets — Windows x86_64, standalone exe
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send.exe |
18.51 MB | 207996AE9D63D56C2918376D07759A98E6DA3DAA9B428FD9576EE3220CA2C4DB |
sendmecongo-recv.exe |
19.90 MB | B7466EE2B0F97137FED4C0D86EA070436BC3B4824F82EDC96910912D83BACC31 |
v0.4.2 — Windows standalone release
Windows standalone release with native GUI support and embedded icons.
sendmecongo moves files out of a physically isolated machine in one direction only — a fountain-coded QR stream on the screen, a phone camera on the other side, and a byte-identical file at the end. No network, no USB, no Bluetooth.
Changes in v0.4.2
- Added Windows standalone binaries with static CRT (
+crt-static), requiring zero runtime dependencies. - Embedded multi-resolution application icons for both
sendmecongo-send.exeandsendmecongo-recv.exe. - Fixed Windows receiver launch behavior: double-clicking
sendmecongo-recv.exeopens the GUI window directly without popping up a stray background console window. - Preserved CLI capability via Windows parent console attachment.
- Fixed QR encoding in the
megabitpreset: payloads near full capacity could hit a spuriousDataTooLongerror mid-transfer, aborting the sender window 10–20 s into a large transfer with exit code 2. Frames are now encoded in pure byte mode. (#60693e7) - Windows: real monitor enumeration (
EnumDisplayMonitors) replaces the hardcoded 1920×1080 fallback, and both processes opt into per-monitor-v2 DPI awareness, so the player window lands correctly and renders sharply on scaled or secondary displays. (#3f6440d)
Assets — macOS (Apple Silicon, .app inside a DMG)
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send-0.4.2.dmg |
4.61 MB | 59A6ADBDF5F7DDFC341896D1B732CB07CF33327C1ECBCFAE2A7D8EA0731A967F |
sendmecongo-recv-0.4.2.dmg |
4.83 MB | 83882FF0C20C6D3D2B474812484E8F9139DC2556FA9BB2369E5DF27B1C4B63C5 |
Assets — Windows x86_64, standalone exe
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-send.exe |
8.79 MB | A1A4B0BA877C3389F8C3F38068A7268FF1186FC5CDDDCF2C373C2C02570B9A2C |
sendmecongo-recv.exe |
9.25 MB | 79B61E95D1D6CF89BE62FFDA0C99FCC258FCC6A2CCAAD0AD2A88B7D1A359EE6F |
v0.4.1 — first public release
First public release.
sendmecongo moves files out of a physically isolated machine in one direction only — a fountain-coded QR stream on the screen, a phone camera on the other side, and a byte-identical file at the end. No network, no USB, no Bluetooth.
What's in it
| Binary | Runs on | What it is |
|---|---|---|
sendmecongo-send |
the isolated machine | GUI + fullscreen player, one exe, two modes |
sendmecongo-recv |
the receiver's machine | standalone recovery tool — nothing to install, no Python, no FFmpeg |
sendmecongo-bench |
dev box | capacity calibration, frame export, erasure simulation |
- SMQ1 protocol (SMC1 container + SMQ frames), RaptorQ fountain coding (RFC 6330), four CRC layers, recovery stops as soon as K' symbols arrive.
- Measured 100.2 KB/s end-to-end (turbo60,
--size 1600, 4K60 recording), every run byte-identical. - GUI and CLI in Simplified Chinese / Traditional Chinese / English.
- Dual-licensed MIT OR Apache-2.0.
Assets (macOS, Apple Silicon only)
| File | Size | SHA-256 |
|---|---|---|
sendmecongo-recv-0.4.1.dmg |
4.6 MB | 87963520b7fe46c4a34617905dadc125dbe2e4d81847b4456375de699183af77 |
sendmecongo-send-0.4.1.dmg |
4.4 MB | 16ac7938c18a22cc04f6e35987ba9d3e7ad69013263eea78db993bdb1418bdfe |
The receiver's DMG is the one to hand to someone else: mount it, drag the app to Applications, drag the recording into the window.
The apps are ad-hoc signed (no Apple Developer account), so Gatekeeper challenges the first launch after a download: right-click → Open on older macOS, Settings → Privacy & Security → Open Anyway on macOS 15+. Copied from a USB stick there is no challenge. The DMG also contains a one-line quarantine-clearing .command as a fallback.
Intel Macs are not supported — the binaries are arm64 only, deliberately.