<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meshbay.git/packages/meshbay-client, branch 0.19</title>
<subtitle>MeshBay — read-only public mirror</subtitle>
<id>https://git.meshbay.org/meshbay.git/atom?h=0.19</id>
<link rel='self' href='https://git.meshbay.org/meshbay.git/atom?h=0.19'/>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/'/>
<updated>2026-10-07T20:43:00Z</updated>
<entry>
<title>chore: bump version to 0.19.0</title>
<updated>2026-10-07T20:43:00Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-07T20:43:00Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=4c8e4fb8b8fcd3f78bf4e3e736a058c351aac973'/>
<id>urn:sha1:4c8e4fb8b8fcd3f78bf4e3e736a058c351aac973</id>
<content type='text'>
Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): stop the node at Quit in "only while open", whoever started it</title>
<updated>2026-10-07T20:22:51Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-07T20:17:27Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=b06338abf7a5be58151828acb801286c05a3d62a'/>
<id>urn:sha1:b06338abf7a5be58151828acb801286c05a3d62a</id>
<content type='text'>
Switching from "at sign-in" to "only while MeshBay is open" left the node the
sign-in launcher had started running after Quit: only a node this process had
started was stopped. In that mode the app owns the node, so Quit stops the
one that is there.

The start with the app and the sign-in's own start (ensureNode) also both ran
`autostart start` at launch -- three meshbay-node.exe were seen racing for the
port. The sign-in's start and node:start now wait for the launch's.

The end-to-end test covers the mode: Quit leaves no node, opening the app
starts one. It launches the app with the environment it was imported with:
the suite's conftest points HOME, USERPROFILE, LOCALAPPDATA and APPDATA at a
throwaway directory per test, and the app started under that crashed at once
(0x80000003), which first looked like a crash of the app itself.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: set the Windows node up at sign-in, and stop it for real</title>
<updated>2026-10-07T20:22:51Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-07T19:25:47Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e833fe1bfc8eb6f66cc5dc53997cc4158bab583f'/>
<id>urn:sha1:e833fe1bfc8eb6f66cc5dc53997cc4158bab583f</id>
<content type='text'>
Found by the first Windows beta tester, then reproduced on a clean install.

After a service-mode install nothing set the node up for the account that
signed in: the boot task started a node that quit ("hub.username not set"),
and the sidebar showed Node / Create group only once the hub held a node key.
The only way to the wizard that provisions was the home page's welcome card,
which an account already in a group never sees. The way out was
`meshbay-node init` and the key pasted on the profile page -- which is also
what PACKAGING-GUIDE.md told people to do.

- main.js `node:ensure`, called by app.js at sign-in: provisions, starts and
  links the node this build ships (Windows, bundled node only). A node set up
  for another account, or an account linked to another node, is left alone.
  node:start waits for it, so the two never race.
- The sidebar shows the Node section when a node exists on this machine.
- The Node page's status is the node's: its control API and the process
  list, not the service task's state (a node started from a terminal ran
  while the page said Stopped). Stop says Stopped only once no
  meshbay-node.exe is left, and stays offered for a process that answers
  nothing.
- CLI stop kills the pid that answered when a graceful stop does not finish,
  and fails with the reason when a node process is still there.
- The daemon ends its process 3s after _shutdown(): Python's exit waited for a
  busy indexer thread, with the control API already closed. Armed by main()
  only, never by a daemon run inside a test.
- node.toml is read as utf-8-sig (PowerShell 5.1 writes a BOM), and a config
  that cannot be read is logged instead of dying silently in service mode.
- "Pair this browser" queues the code for the next group of this node to
  open instead of saying "Paired successfully"; no banner before a group.
- test_e2e_windows_app.py (opt-in, MESHBAY_WIN_E2E=1) drives the installed
  app against a throwaway hub: fresh account to linked node, Stop, Start,
  Restart, checked against the real processes.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): remove firewall rules and boot task on uninstall, unasked</title>
<updated>2026-10-07T11:48:28Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-07T11:48:28Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=ade41b05cce4a555197116568664220c5b3be9fa'/>
<id>urn:sha1:ade41b05cce4a555197116568664220c5b3be9fa</id>
<content type='text'>
The Yes/No before it defaulted to No, so they stayed behind. Read both
unelevated and raise the UAC prompt only when one is left.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: read the node token per call and detect before polling the index dock</title>
<updated>2026-10-05T07:33:45Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-05T07:33:45Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=146cee08ec9c4313bec5f69bb7ed7fbf73770aac'/>
<id>urn:sha1:146cee08ec9c4313bec5f69bb7ed7fbf73770aac</id>
<content type='text'>
node:op only knew the daemon's token once a page had called detect(), and
kept it after the daemon replaced it on restart: the index dock stayed empty
on a node machine until the Node page was opened, every operation answered
401 after a node restart, and on a machine without a node each 30 s poll was
a rejected IPC call Electron printed to the terminal ("Node not detected").

node:op now reads the config and token from disk on every call, and the dock
asks detect() before its first operation and after any failure.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>chore: license MeshBay — LGPL protocol layer, AGPL for the rest</title>
<updated>2026-10-05T07:20:38Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-05T06:59:06Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=cce8a911553597ada33e275bc9b29fd34121074d'/>
<id>urn:sha1:cce8a911553597ada33e275bc9b29fd34121074d</id>
<content type='text'>
The protocol layer is LGPL-3.0-or-later in every language it exists in, so
any client may use it whatever its own licence: meshbay-common, and the files
marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js,
transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop;
Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is
AGPL-3.0-or-later, which the RPM specs and package.json already declared
without a licence file to back them.

Two AGPL section 7 permissions:
- group applications may be under any licence when they use the interface
  only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt);
  the reference application is 0BSD so that copying it brings no AGPL code;
- the Android application may be conveyed linked with Google Play services.

Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from
what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and
the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its
BSD licence does not mention — and the vendored browser libraries get their
licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata,
RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt.

test_licensing.py holds the line: the LGPL layer imports nothing under the
AGPL, the reference application nothing outside the application interface,
and every SPDX line is one of the known ones.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>feat(cast): music on the TV, the music bar as its remote</title>
<updated>2026-10-05T00:29:27Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-05T00:29:27Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=ee9798fe3b88face2fa34f14874770f509c788a5'/>
<id>urn:sha1:ee9798fe3b88face2fa34f14874770f509c788a5</id>
<content type='text'>
A cast button in Music's toolbar and in the music bar. With a television
chosen, each decrypted track goes to the relay with its cover — found as the
album card finds it — and plays there as music with its title, artist and
album; the bar's play, pause, seek, previous and next drive the receiver, its
clock is the receiver's, and the end of a track there moves the queue on.
A film or a photo taking the television pauses the bar; stopping the cast
carries the track on locally.

Photos and tracks now share one path: a whole file sent to the relay in
pieces (binary frames on Android, written to disk there), served at /file
with byte ranges and its cover at /cover, and loaded as what the relay says
it is. cast:image is gone; cast:chromecast:seek is new.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>feat(cast): photos on the TV, and a television chosen once for the session</title>
<updated>2026-10-04T23:16:12Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-04T23:16:12Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=243bcf017b4957237b3ddf556bd0a37296eb8798'/>
<id>urn:sha1:243bcf017b4957237b3ddf556bd0a37296eb8798</id>
<content type='text'>
A cast button in Videos' toolbar, at the top of Photos, in an album's bar and
in the lightbox, in a group and in Search alike. A television chosen there is
kept for the session: a film opened plays on it with the player as its remote
from the start, and a photo opened in the lightbox is shown on it, scaled to
1920x1080, upright, as JPEG. The lightbox gains a slideshow.

The relay serves one photo at /image behind the stream's token, on the desktop
and on Android; the shell, not the page, decides that the receiver loads it as
a picture.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>feat(android): music keeps playing with the screen off</title>
<updated>2026-10-04T20:46:00Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-04T20:46:00Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=652465910dcdcc761aa2e078ff1a82625e2a0aa5'/>
<id>urn:sha1:652465910dcdcc761aa2e078ff1a82625e2a0aa5</id>
<content type='text'>
While a track plays, the page asks the shell to stay awake
(playback:keep-alive): on Android the cast's foreground service and
visible WebView, with a notification; on desktop a power save blocker.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>chore: bump version to 0.18.0</title>
<updated>2026-10-03T13:06:44Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-03T13:06:44Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=01c4db74f3f234373a3e97da9cdc1bd8458a9f8b'/>
<id>urn:sha1:01c4db74f3f234373a3e97da9cdc1bd8458a9f8b</id>
<content type='text'>
Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
