[0.1.10] - 2026-08-05
Added
- Shared Android/Linux signed-link retry policy and desktop stream-failure classification
that distinguish unexpected playback loss from normal EOF, explicit stop, and process exit. - Keyboard-first library and queue focus with visible selection, F1 help, complete play,
append, inspect, reorder, and remove alternatives, and modal shortcut suppression. - Executable current-session Secret Service/MPRIS evidence, immutable Arch clean-build,
bounded resilience-soak, and fail-closed0.2.0promotion validation commands. - A canonical
0.2.0promotion matrix and release evidence schema separating automated,
current-session, visual, protected-provider, and explicitly accepted boundary states. - Isolated locked-keyring, 200% high-contrast capture, externally driven MPRIS control,
and packaged logind sleep-monitor gates with redacted retained evidence. - A normative folder-scoped Tag workbench specification for reviewing one directory at a
time, reconciling live changes, proposing deterministic corrections, and applying only
explicitly approved local edits through an atomic, verified, rollback-capable pipeline.
Changed
- The documentation header now exposes the latest published release from canonical
changelog data, and the landing page provides direct Android APK, AppImage, Flatpak,
checksum, evidence, source, and package-channel links. - The repository changelog is now generated as a first-class searchable documentation
page, and the Pages workflow rebuilds whenVERSIONorCHANGELOG.mdchanges. - Documentation synchronization removes duplicate copied page headings and validates the
rendered release badge, binary links, changelog route, and release-token closure. - Linux playback now performs one bounded capability re-resolution per stable media
identity and cooldown window, resuming from durable progress without automatically
restarting the mpv process or exposing provider URLs in state or diagnostics. - The roadmap now treats published
0.1.9AppImage/Flatpak evidence as complete and lists
only executable current-host, alternate-session, visual, soak, and protected-provider
blockers before0.2.0. - Desktop credential restoration performs bounded Secret Service lookup off the UI thread;
a locked collection leaves the client responsive and exposes a fixed recovery message. - The Linux client listens for logind
PrepareForSleep, force-checkpoints and pauses active
playback before sleep, then resolves a fresh capability and resumes once after wake. - Compose Desktop now exposes explicit heading, selection, current-track, and player-state
semantics plus a deterministic black/white/yellow high-contrast palette and non-color labels.
Security
- Current-session evidence uses a disposable random Secret Service value, clears it
immediately, and records neither the value nor the session D-Bus address. - The locked-keyring gate operates on a private ephemeral D-Bus/keyring, returns no
credential, enforces a five-second maximum, and never touches the real user collection. - Stream refresh status is fixed and redacted; signed URLs and provider response content
remain outside persistence, UI state, logs, and evidence.
Testing
- Added shared retry-policy, mpv EOF/stop/failure classification, shortcut resolution,
selection bounds, readiness-schema, session-audit, Arch-gate, and soak-contract tests. - Added sleep-transition policy, blocked-vault timeout, external MPRIS method, Flatpak
logind permission, accessibility semantics, and current-host evidence contract coverage.
Known limitations
- The Tag workbench is a reviewed specification in this release, not an implemented file
mutation surface. Existing Tag studio export behavior remains unchanged. 0.2.0still requires protected EU/US provider evidence, GNOME and KDE observations,
physical media-key and suspend/resume checks, and a real screen-reader review.
Artifact status
The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.
The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.
The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.
Linux packages
The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.