Releases: fkr-0/properpcloud
Release list
v0.2.0-rc.7
[0.2.0-rc.7] - 2026-09-25
Added
- Added a stable, source-neutral Players overview that deduplicates known playback targets across reconnect/discovery and exposes connectivity, playback state, current media, and safe local controls through the existing controller authority.
- Added audiobook playback state with durable per-book resume, chapter-aware navigation, playback speed, configurable skip intervals, sleep/end-of-chapter stopping behavior, and restore-without-autoplay semantics isolated from normal music queue modes.
- Added persistent directory bookmarks to the Android folder browser for quick return to known library locations.
Changed
- Simplified Android pCloud/server settings copy by removing developer-oriented OAuth/client-ID controls and credential-storage implementation banners from the normal user surface while preserving the existing authentication and vault behavior.
- Updated Android first-run/privacy/user documentation to reflect the production No library connected state; deterministic generated WAV media remains test-only on Android and available as a Linux verification source.
Fixed
- Android Play folder now queues the recursive subtree, so folders whose top level contains only subdirectories still reach playable descendants; direct-only playback remains an explicit secondary action.
- Folder and generic-file rows no longer expose the internal “stable source identity” wording in visible labels.
- Reissued the rc.6 playback-liveness hardening after closing a release-runner-only test discovery defect: the stdlib host gate runs exactly its 40 unittest modules instead of importing the separate pytest-only music-ingest suite. The executed unittest count remains 136, so clean GitHub runners do not require an accidental host
pytestinstallation before tag metadata validation. - Carries forward rc.6's bounded Media3 terminal-item skipping, source-neutral terminal-vs-transient stream-resolution classification, stable queue/timeline reconciliation across controller rebind, manual post-error recovery, and removal of the Android production demo source.
Testing
- The Players/audiobook implementation and subsequent settings-polish pass were independently reviewed; focused core-model/source-server tests and the 136-test local host gate are green before release-candidate packaging.
- Reproduced the rc.6 GitHub failure on exact tag/SHA and verified it was
ModuleNotFoundError: pytestduring stdlib discovery rather than a playback regression.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.2.0-rc.4
[0.2.0-rc.4] - 2026-08-28
Added
- Added filesystem-first filename search on Android and native desktop. Search opens from the
magnifying-glass control, updates automatically from three characters with a short debounce,
matches names case-insensitively, and keeps deterministic natural/stable ordering without
requiring embedded metadata. - Added persisted search match filters for directories, generic files, audio files, and playlist
files. Genericfilesremains the intentional superset, while audio/playlist filters can be
selected independently when generic files are disabled; duplicate stable identities are removed. - Added durable, separately configurable playback history with bounded retention. History is
disabled by default, stores stable source/node identities rather than stream capabilities, and
remains distinct from the queue/progress state required for crash/session restoration.
Fixed
- Hardened Android and desktop playback recovery for stale or failed provider stream locations.
Retriable HTTP/network failures now re-resolve the playable location from stable media identity,
rebuild/reprepare the current item, and preserve the intended queue item and position instead of
repeatedly handing Media3/mpv the already-failed direct URL. - Explicit Play after a terminal playback error now enters the same bounded recovery path, so a
bad HTTP status does not permanently poison later Play/Pause attempts. Recovery recognizes the
reviewed transient/auth/stale-link status set, follows nested causes, and keeps permanent client
failures fail-closed rather than retrying indefinitely. - Closed the Android Media3 experimental-API lint boundary at the application container so release
lint remains green without a baseline or global lint suppression.
Changed
- Queue state is persisted after successful queue/selection mutations and restored by stable
identity at startup. Expiring provider URLs are never used as durable queue identity. - Playback progress now checkpoints on a 30-second cadence and at lifecycle/transition boundaries
such as pause, item change, stop/close, completion, and forced shutdown paths, avoiding repeated
per-second paused writes while preserving bounded resume accuracy. - Android DataStore and desktop SQLite persistence were extended additively for the new player,
history, and search-preference state; malformed/stale positions are normalized conservatively and
existing persistence remains backward-compatible. - pCloud and local-folder library adapters now expose stable generic/playlist file nodes needed by
filename search instead of discarding every non-audio entry from the searchable library model.
Testing
- Added deterministic loopback-HTTP recovery coverage proving failed/stale stream resolution is
reacquired and resumed without persisting the ephemeral URL, plus Android explicit-recovery tests. - Added search/filter, queue/progress/history persistence, repository codec/SQLite, and desktop
process-smoke coverage. The release gate exercises filename search plus queue, progress, history,
and filter restoration after SQLite reopen. - Revalidated the complete Android/JVM/desktop/docs/Linux release stack, including packaged crash
recovery, local-tag recovery, MPRIS controls, locked-keyring handling, accessibility capture,
release metadata, and zero-vulnerability documentation dependencies.
Known limitations
- Search in this candidate is filename/name based. ID3 artist, title, year, and other embedded-tag
match types remain intentionally deferred until the filesystem-first path is established. - This candidate does not promote stable
0.2.0: physical power-cut durability, physical media-key
and suspend/resume observations, GNOME/KDE session evidence, protected EU/US provider validation
and soak, and the existing Linux accessibility/promotion boundaries remain explicit blockers.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.2.0-rc.2
[0.2.0-rc.2] - 2026-08-23
Testing
- Added a packaged native-desktop recovery smoke that externally sends
SIGKILLonly after
the recovery-armed atomic tag replacement completes, then starts a fresh packaged process,
supplies the selected scratch root again, rediscovers durable recovery authority, and verifies
exact-hash guarded rollback without retaining private paths, provider URLs, or credentials. - Revalidated the release candidate with the pinned Docker toolchain, desktop JVM/JUnit suite,
complete Linux CI smoke set, host specification checks, and fail-closed0.2.0readiness gates.
Changed
- Promotion evidence now distinguishes verified packaged process restart/reselection recovery
from still-unverified physical power-loss durability. - Linux screen-reader/AT-SPI promotion status now records the current Compose Multiplatform Linux
accessibility boundary as an upstream blocker instead of presenting it as an ordinary manual
check that could be completed on the existing packaged UI.
Known limitations
- Physical power-cut durability, physical media-key and suspend/resume observation, GNOME/KDE
session checks, protected EU/US provider accounts and retained provider soak, and the exact
post-tagv0.2.0Arch rebuild remain explicit promotion gates. - Real Linux AT-SPI/screen-reader traversal is blocked by the current Compose Multiplatform
Linux accessibility boundary; final promotion requires an explicit documented exception or a
supported Linux accessibility bridge/UI strategy rather than silently marking that gate passed.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.2.0-rc.1
[0.2.0-rc.1] - 2026-08-22
Added
- Folder metadata-suite playlist generation now supports deterministic direct-folder and
explicit subtree.m3u8plans with relative paths, natural filename, disc/track tag,
tagged-title, or modification-time ordering, trusted-durationEXTINF, safe tag-derived
display naming, stale-evidence preflight, and bounded playlist-only post-sync regeneration. - A shared local-root metadata-suite session adds revision-bound preview/confirmation for tag
and playlist work, keeps recursive playlist consent independent from recursive tag mutation,
revokes stale reviews/queued regeneration on reconciliation signals, and requires a fresh
post-write scan before deriving playlists after confirmed tag changes. - A neutral local-filesystem workbench host now proves explicit writable-root and atomic-move
capability, registers a real JVMWatchServicelease before scanning, invalidates reviews on
relevant events before debounce, reconciles overflow/invalid observers through full rescans,
and never turns watcher or post-sync activity into tag writes. - Native Compose Desktop can now bind an explicitly user-selected local directory to that host as
a separate filesystem-firstAudioSource, with opaque stable source/node IDs, direct browsing
and playback, live/stale reconciliation state, preview/dry-run/confirmation tag controls, and
independently gated direct or recursive playlist materialization. The selected private root is
session-scoped rather than persisted, and source switching closes the observer and local queue
authority. - A cheap host-side
make local-checkworkflow is now the default routine developer gate,
with optional portable-JVMmake fast-testwhen the pinned image is already available,
while GitHub Actions retains Robolectric, Android lint, APK assembly, docs, and the complete
make cimerge verification.
Planned
- Complete the remaining folder-scoped Tag workbench release boundary with a truthful Flatpak
document-portal directory lease/path mapping (without broad host/home access), Android SAF as a
separate platform adapter, and the remaining conflict/power-loss/rollback plus
accessibility/platform evidence before claiming the full workbench release-ready. 0.2.0promotion only after the protected EU/US provider, alternate desktop,
physical media-key/suspend, and real screen-reader gates are complete.- Verified offline pinning, saved roots, long-form controls, and Android Auto after
cross-platform queue/progress semantics stabilize.
Known limitations
- This is a release candidate for hands-on testing, not the final
0.2.0promotion. - Physical power-cut durability, real packaged restart/reselection recovery, selected-folder
screen-reader/focus review, physical media keys and suspend/resume, GNOME/KDE observations,
and protected EU/US provider soak/account evidence remain explicit final-release blockers.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.1.10
[0.1.10] - 2026-08-05
Added
- Shared Android/Linux signed-link retry policy and desktop stream-failure classification
that distinguish unexpected playback loss from normal EOF, explicit stop, and process exit. - Keyboard-first library and queue focus with visible selection, F1 help, complete play,
append, inspect, reorder, and remove alternatives, and modal shortcut suppression. - Executable current-session Secret Service/MPRIS evidence, immutable Arch clean-build,
bounded resilience-soak, and fail-closed0.2.0promotion validation commands. - A canonical
0.2.0promotion matrix and release evidence schema separating automated,
current-session, visual, protected-provider, and explicitly accepted boundary states. - Isolated locked-keyring, 200% high-contrast capture, externally driven MPRIS control,
and packaged logind sleep-monitor gates with redacted retained evidence. - A normative folder-scoped Tag workbench specification for reviewing one directory at a
time, reconciling live changes, proposing deterministic corrections, and applying only
explicitly approved local edits through an atomic, verified, rollback-capable pipeline.
Changed
- The documentation header now exposes the latest published release from canonical
changelog data, and the landing page provides direct Android APK, AppImage, Flatpak,
checksum, evidence, source, and package-channel links. - The repository changelog is now generated as a first-class searchable documentation
page, and the Pages workflow rebuilds whenVERSIONorCHANGELOG.mdchanges. - Documentation synchronization removes duplicate copied page headings and validates the
rendered release badge, binary links, changelog route, and release-token closure. - Linux playback now performs one bounded capability re-resolution per stable media
identity and cooldown window, resuming from durable progress without automatically
restarting the mpv process or exposing provider URLs in state or diagnostics. - The roadmap now treats published
0.1.9AppImage/Flatpak evidence as complete and lists
only executable current-host, alternate-session, visual, soak, and protected-provider
blockers before0.2.0. - Desktop credential restoration performs bounded Secret Service lookup off the UI thread;
a locked collection leaves the client responsive and exposes a fixed recovery message. - The Linux client listens for logind
PrepareForSleep, force-checkpoints and pauses active
playback before sleep, then resolves a fresh capability and resumes once after wake. - Compose Desktop now exposes explicit heading, selection, current-track, and player-state
semantics plus a deterministic black/white/yellow high-contrast palette and non-color labels.
Security
- Current-session evidence uses a disposable random Secret Service value, clears it
immediately, and records neither the value nor the session D-Bus address. - The locked-keyring gate operates on a private ephemeral D-Bus/keyring, returns no
credential, enforces a five-second maximum, and never touches the real user collection. - Stream refresh status is fixed and redacted; signed URLs and provider response content
remain outside persistence, UI state, logs, and evidence.
Testing
- Added shared retry-policy, mpv EOF/stop/failure classification, shortcut resolution,
selection bounds, readiness-schema, session-audit, Arch-gate, and soak-contract tests. - Added sleep-transition policy, blocked-vault timeout, external MPRIS method, Flatpak
logind permission, accessibility semantics, and current-host evidence contract coverage.
Known limitations
- The Tag workbench is a reviewed specification in this release, not an implemented file
mutation surface. Existing Tag studio export behavior remains unchanged. 0.2.0still requires protected EU/US provider evidence, GNOME and KDE observations,
physical media-key and suspend/resume checks, and a real screen-reader review.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.1.9
[0.1.9] - 2026-08-03
Added
- Explicit unexpected-mpv-exit state with a user-controlled restart-and-resume action;
automatic player restart attempts remain exactly zero. - A real-host crash-recovery smoke that forcibly terminates mpv, verifies stable queue
identity, and requires resumed playback to remain within a five-second checkpoint bound. - A clean-profile runner for packaged desktop and AppImage smoke tests, including an
isolated temporary directory that prevents stale extract-and-run state, plus isolated
Flatpak application HOME/config/data/cache/state paths. - A deterministic AppImage smoke path that explicitly extracts into a private directory,
verifies the reviewedAppRun, embedded version metadata, and launcher containment,
then executes the packaged smoke instead of trusting runtime extract-and-run caching. - Retrying MPRIS identity and playback-status probes so transient D-Bus registration
races cannot fail an otherwise healthy Flatpak package run. - A complete release-graph validator covering immutable version/tag/commit provenance,
required artifact kinds and filenames, sizes, SHA-256 evidence, checksum closure,
release notes, symlink rejection, and forbidden secret/ephemeral fields. - An Arch
PKGBUILDrenderer that requires a real HTTPS source archive and calculates
its checksum instead of acceptingSKIPor unresolved placeholders. - A detailed GNOME/KDE/i3, accessibility, package, and soak evidence matrix whose
unverified cells remain explicit blockers for0.2.0.
Changed
- The Linux gate now includes forced crash recovery and packaged clean-profile smokes in
addition to unit, application-image, normal mpv/SQLite, and MPRIS checks. - Tagged AppImage and Flatpak jobs run application smokes with isolated user state, and
publication revalidates the finalized artifact graph againstGITHUB_SHA. - Player IPC polling reports fixed local health messages and cannot expose provider
response data through process-exit diagnostics.
Security
- A crashed player is never restarted automatically; recovery requires an observable
user action that re-resolves the current stream and uses durable progress. - Release publication rejects artifact symlinks, unsafe paths, missing or extra checksum
entries, mismatched evidence, and secret-bearing evidence keys. - Arch package preparation rejects insecure source URLs and floating/skipped checksums.
Testing
- Added pure exit-state tests, real mpv termination/restart coverage, clean-profile
environment tests, release-graph mutation tests, Arch renderer tests, and a simulated
delayed Flatpak playback-status registration regression.
Known limitations
- Clean-profile workflow wiring is automated, but final AppImage/Flatpak evidence still
belongs to the immutable tagged release run. - GNOME, KDE Plasma, and i3 keyring/MPRIS/suspend cells, the manual accessibility matrix,
a four-hour soak, the final Archmakepkg --cleanbuild, and protected EU/US provider
validation remain external blockers for0.2.0.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.1.8
[0.1.8] - 2026-08-03
Added
- A shared queue-restoration algorithm that repairs stale snapshots by stable identity,
preserves the selected surviving item, and chooses a deterministic nearest fallback. - Desktop Secret Service regression coverage for missing tooling, caller-buffer clearing,
and invalid key rejection. - Host-side tests for the Flatpak-to-host mpv argument boundary.
Changed
- Android and Linux now persist partially repaired queues immediately and report omitted
entries rather than rediscovering the same stale state on every launch. - Desktop progress is force-checkpointed before queue mutation, on playback failure,
during disconnect, and on orderly shutdown instead of only at five-second boundaries. - mpv JSON IPC commands carry request IDs, ignore unrelated messages, enforce bounded
responses, and require an explicit successful command result. - Desktop pCloud disconnect removes the active source locally first, stops pCloud
playback, persists a disconnect tombstone and clears affected queue state before
attempting Secret Service cleanup and typed remote session revocation. - AppStream metadata now records release history and release validation requires the
currentVERSIONto be represented.
Security
- Secret Service subprocesses are bounded and terminated on timeout, caller credential
buffers are cleared infinally, lookup keys are constrained, and oversized results
are rejected. - The Flatpak host-mpv bridge rejects arbitrary host command flags and accepts only the
deterministic properpcloud playback contract plus its private runtime socket. - mpv failures expose a fixed command error rather than response data that may include an
ephemeral signed stream location.
Testing
- Added shared restoration tests for missing predecessors, missing selected entries,
end-of-queue fallback, and fully unavailable queues. - Added Android orchestration coverage proving the repaired selection and rewritten
persisted index. - Expanded desktop mpv protocol tests for event filtering, response correlation, and
redacted command failures.
Known limitations
- Protected pCloud account validation and the GNOME/KDE/i3 compatibility matrix remain
external gates; this patch makes no new live-provider claim. - Automatic mpv crash restart, long-duration soak evidence, broad desktop accessibility,
and reproducible Arch packaging are intentionally assigned to0.1.9.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.1.7
[0.1.7] - 2026-08-03
Added
- Secret-safe local OAuth configuration that reads only the public
PCLOUD_CLIENT_IDfrom an ignored.env. - A committed
.env.exampleand host-side regression tests for dotenv parsing,
quoting, environment precedence, duplicate keys, and malformed identifiers.
Changed
- Tagged builds now receive properpcloud's registered public pCloud application ID
through the GitHub repository variable, enabling the ordinary OAuth button. - Android account settings describe direct username/password sign-in only as a
collapsed fallback when OAuth is configured.
Security
.env*files are excluded from Git and Docker build contexts. Client tooling
exports only the public application ID and never reads or passes
PCLOUD_CLIENT_SECRETto Gradle, containers, binaries, CI, or release artifacts.
Testing
- The build path is validated from dotenv/environment configuration through Make,
Docker, Gradle, and AndroidBuildConfig, with malformed configuration failing
closed before client compilation.
Known limitations
- Protected live OAuth authorization, denial, regional logout, and device-log
redaction evidence remains a maintainer/device gate outside public CI.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.
v0.1.6
[0.1.6] - 2026-08-02
Added
- A clearly labelled interim direct pCloud sign-in path implementing the provider's
documented HTTPSuserinfoauthentication with explicit Europe/United States choice. - Token-kind-aware session persistence and SDK authentication for OAuth bearer tokens
and direct-loginauthtokens. - A safer account-settings layout that separates recommended OAuth, interim direct
sign-in, and advanced developer configuration. - The supplied raster properpcloud logo in README and in-app About branding.
Changed
- Tagged releases no longer require a pCloud client ID while the developer console is
unavailable; a configured ID is still validated and immediately enables preferred OAuth. - Legacy-auth SDK reads move all method parameters and the
authtoken from URL queries
into HTTPS form POST bodies. - Disconnect invalidates OAuth and legacy tokens with their respective documented
transport conventions while preserving local-first removal.
Security
- Direct-login passwords are held only in short-lived UI/request state, removed from the
form before the request starts, never persisted/logged/exported/backed up, and sent only
to the explicitly selected allowlisted regional pCloud API over HTTPS POST. - Direct authentication disables redirects, bounds response size and time, avoids
cross-region credential probing, and retains only numeric provider rejection codes. - Direct-login tokens request a 90-day absolute lifetime and 30-day inactivity lifetime
rather than the provider's longest possible lifetime.
Testing
- Added direct-login result, buffer-clearing, network/redaction, legacy SDK request
transformation, regional-host rejection, and Compose account-settings coverage.
Known limitations
- pCloud's public direct-login documentation does not describe a two-factor challenge;
affected accounts may require OAuth once application registration becomes available. - Live direct-login and OAuth validation require a disposable provider account and remain
outside public CI; the release is an evaluation build signed with an Android debug key.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Live pCloud OAuth/direct-login and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
v0.1.2
[0.1.2] - 2026-08-02
Added
- Dedicated now-playing destination with large artwork fallback, title and filename
context, seekable elapsed/remaining timeline, transport controls, queue position,
up-next preview, and one-tap queue/folder/metadata navigation. - Canonical metadata domain records for provenance, confidence, tag snapshots,
Keep/Clear/Setpatches, revision-or-hash-guarded edit plans, and deterministic
common-field, candidate, and track-sequencing batch operations. metadata-tagsmodule using a replaceable jaudiotagger adapter for real local tag
inspection, copy-on-write staging, SHA-256 guarding, tag reread, and field verification.metadata-onlinemodule with an identified, HTTPS MusicBrainz recording client,
serialized request-rate gate, secure XML parser, Cover Art Archive references, and
opt-in AcoustID/Chromaprint lookup contracts without embedded service keys.- Comprehensive Android UX modernization and metadata maintenance specifications,
including the guarded pCloud remote-replacement state machine and audit boundaries.
Changed
- Mini-player now opens the first-class player and displays thin playback progress.
- Queue rows use one compact overflow menu while retaining move-up/down alternatives,
containing-folder navigation, metadata inspection, and removal. - Provider inspection uses a grouped adaptive bottom sheet instead of an oversized
blocking dialog. - Settings disclose the exact metadata-tool status and the fact that remote file
replacement remains disabled until conditional upload and readback are implemented.
Security
- Local metadata edits never modify source bytes in place; failed candidates are
removed and intended fields must pass reread verification. - MusicBrainz XML parsing rejects document types and external entities, and online
matching remains explicit, rate-limited, provenance-preserving, and non-mutating. - Added jaudiotagger's LGPL 2.1-or-later notice and complete license text to the
repository and APK asset set.
Testing
- Added metadata plan, sequencing, revision/hash guard, real WAV staged-edit,
MusicBrainz query/parser, rate-gate, and dedicated now-playing Compose tests.
Known limitations
- The metadata editor UI, Android Chromaprint implementation, artwork writes, and
expected-revision pCloud replacement are specified but intentionally not enabled. - Live pCloud account validation, production signing, physical-device accessibility,
and Android 17 runtime validation remain external release gates.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Live pCloud OAuth and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.