This commit introduces several fixes and refinements to the hotspot sharing and APK handling features, improving stability, user experience, and robustness.
Key changes:
- **Hotspot Flow:**
- Automatically starts the hotspot after the user grants the required Wi-Fi permission, removing the need for a second button press.
- Ensures all `HotspotManager` callbacks in `HotspotViewModel` are executed within `viewModelScope` to prevent threading issues and ensure safe UI updates.
- Fixes a potential `BroadcastReceiver` leak in `HotspotManager` by tracking its registration state, preventing crashes and resource leaks when stopping the hotspot.
- Changes the hotspot `WakeLock` to be non-expiring to prevent the CPU from sleeping while the hotspot is active.
- **APK Handling & Installation:**
- Adds a pre-download disk space check in `UniversalApkManager` to prevent download failures on devices with insufficient storage.
- Improves the file move logic after download by falling back to a copy-and-delete strategy if a direct rename fails, making it more robust across different filesystems.
- Introduces `InstallResultReceiver` to provide clear Toast notifications to the user about the success or failure of an APK installation, including specific error reasons (e.g., "Not enough storage").
- **Performance & UI:**
- Caches the generated HTML in `ApkWebServer` to improve performance by avoiding regeneration on every request.
- Throttles the APK download progress updates to prevent UI jankiness from too-frequent state changes.
- Moves hardcoded strings in the "Share App" UI to `strings.xml` for better localization and maintenance.
This commit introduces the `nanohttpd` library, which will be used to implement an HTTP server for sharing the application's APK over a local hotspot.
The specific dependency added is `org.nanohttpd:nanohttpd:2.3.1`.
This commit introduces a comprehensive feature set for sharing the application, both offline via a Wi-Fi hotspot and online through standard Android sharing mechanisms.
Key additions:
- **Prepare for Sharing UI:**
- Adds a "Prepare App for Sharing" option in the settings sheet.
- This feature downloads a universal APK from a remote source, suitable for all Android devices.
- The UI displays the status: not downloaded, downloading (with progress), ready, or if an update is available.
- Users can download, update, or delete the cached universal APK.
- **Offline Sharing via Wi-Fi Hotspot:**
- Adds a "Share via Wi-Fi Hotspot" option.
- This launches a new `HotspotActivity` to share the prepared universal APK with nearby devices without an internet connection.
- A dialog informs the user if the APK hasn't been prepared yet.
- **Online & Local Sharing:**
- Adds an option to share via Bluetooth, email, etc., using the standard Android share sheet.
- This method shares the *installed* version of the app, which may be a split APK.
- An explanatory dialog is shown first, instructing the receiver on how to install split APKs if necessary.
- Implements logic to correctly package and share single or multiple split APK files using `FileProvider`.
This commit introduces a comprehensive feature for sharing the BitChat application offline using a self-hosted Wi-Fi Direct hotspot. This enables mesh network expansion by allowing users to distribute the app without requiring an internet connection.
Key components:
- **`HotspotManager`**: A new class that manages the creation and lifecycle of a Wi-Fi P2P (Wi-Fi Direct) group. It handles generating secure credentials (SSID/password), acquiring WakeLocks, and monitoring connected peers. It supports custom credentials on Android 10+ and falls back to system-generated ones on older versions.
- **`ApkWebServer`**: A lightweight HTTP server based on `NanoHTTPD` that serves the APK file and a user-friendly HTML landing page to connected devices.
- **`ApkSharingUtils`**: A utility to detect whether the app is installed as a single or split APK, collect the necessary files, and copy them to a cache directory for sharing.
- **`ApkInstaller`**: A utility using the `PackageInstaller` API to handle the installation of single or split APKs received from another user.
- **`HotspotActivity`**: A new Compose-based UI that guides the user through starting the hotspot, displays connection details (Wi-Fi credentials, QR codes for Wi-Fi and the download URL), and shows the number of connected peers. It also handles the necessary runtime permissions (`NEARBY_WIFI_DEVICES` or `ACCESS_FINE_LOCATION`).
- **Configuration**:
- Adds necessary Wi-Fi and P2P permissions to `AndroidManifest.xml`.
- Defines a `FileProvider` path for APK sharing in `file_paths.xml`.
- Adds numerous string resources for the new UI.
This commit introduces a comprehensive system for fetching, downloading, caching, and managing a "universal" APK of the app, intended for offline sharing with new users.
The core components are:
- `GitHubReleaseClient`: A new client to fetch the latest release information from the project's GitHub repository. It specifically looks for a universal APK asset in the release, parses its download URL, and attempts to extract its SHA256 checksum from the release notes.
- `UniversalApkManager`: Manages the entire lifecycle of the universal APK. It handles:
- Checking for new versions by comparing the cached APK version against the latest GitHub release.
- Downloading the APK with progress reporting.
- Verifying the downloaded file against the SHA256 checksum, if available.
- Caching the APK and its metadata (version, checksum, size) locally.
- Cleaning up old APK versions to conserve space.
This commit introduces a `QrCodeGenerator` utility object to create QR code bitmaps for both Wi-Fi credentials and URLs.
Key features:
- **`generateWifiQr`**: Creates a QR code using the standard `WIFI:` format, allowing other devices to connect to a hotspot by scanning the code. It properly escapes special characters in the SSID and password.
- **`generateUrlQr`**: Generates a standard QR code for any given URL.
- **Implementation**: Uses the `zxing` library to encode the data and converts the resulting `BitMatrix` into an Android `Bitmap`.
- Keep max lastSeen per user so relay's newest-first delivery doesn't
overwrite a fresh timestamp with a stale one
- Serialize event processing on Main dispatcher to eliminate
ConcurrentModificationException on geohashParticipants maps
- Immediately refresh people list on channel switch so sampling data
is reflected before the first relay response arrives
This change prevents the app's content from being visible in the recents screen on Android 13 (Tiramisu) and newer devices.
It achieves this by calling `setRecentsScreenshotEnabled(false)` in the `onCreate` method of `MainActivity` after checking the device's SDK version. This enhances user privacy by hiding potentially sensitive information from the system's app overview.
When a URL contains a # fragment (e.g. https://example.com/page#section),
the hashtag regex matches the fragment as a hashtag. The overlap removal
logic already removes hashtags overlapping geohashes, and geohashes
overlapping URLs, but did not remove hashtags overlapping URLs. Add the
missing overlapsUrl check to the hashtag condition.
* Pause Nostr geohash firehose in background to cut mobile data
The Bluetooth mesh uses no mobile data, but the Nostr relay layer ran
unbounded in the background: the live geohash channel subscription kept
streaming across 5 relays, the presence heartbeat broadcast every ~60s,
and a participant-refresh timer polled every 30s. Combined with
reconnect/re-subscribe replay on public relays, this could burn gigabytes
while idle.
GeohashViewModel now tears down the high-volume subscriptions when the app
is backgrounded (onStop) and restores them on foreground (onStart):
- drop the live channel message stream (currentGeohashSubId)
- drop sampling subscriptions
- cancel the presence heartbeat and participant-refresh timer
Gift-wrap DM subscriptions are intentionally kept alive in the background
since they are filtered to our pubkey (lightweight) so DMs still arrive.
The selected channel is tracked in activeChannelGeohash so the stream can
be rebuilt on foreground without losing the user's selection. The channel
subscription logic is extracted into subscribeChannelStream() /
subscribeChannelDM() helpers.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* separate the heartbeat firehose from message delivery
* correct comment
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: callebtc <93376500+callebtc@users.noreply.github.com>
* wifi aware wip
* wifi aware wip
* starting to work
* werk
* dms work
* wip
* fix(wifi-aware): use bindSocket and scoped IPv6 instead of bindProcessToNetwork
* Merge branch 'upstream/main' into fix/wifi-aware-socket-binding
* Fix Wi-Fi Aware connectivity and UI integration post-merge
- Replace bindProcessToNetwork with bindSocket for VPN compatibility.
- Implement Scoped IPv6 address resolution (aware0) for mesh routing.
- Bridge Wi-Fi Aware incoming messages to AppStateStore for UI visibility.
- Fix syntax errors and variable name conflicts in Debug UI.
* Enhance Wi-Fi Aware robustness and debug UI display
- Clean up transport resources (sockets, server sockets, network callbacks) immediately on peer disconnection.
- Implement resolveScopedAddress to show scoped IPv6 (e.g., %aware0) in Debug UI.
- Fix Map type mismatch warning in ChatViewModel bridge.
- Filter self-ID from peer cleanup tables to prevent recursive self-removal.
* Share GossipSyncManager across transports to prevent redundant message synchronization
- Registered BluetoothMeshService's GossipSyncManager as a singleton in MeshServiceHolder.
- Modified WifiAwareMeshService to use the shared GossipSyncManager if available.
- Added background cleanup for peer mappings on socket disconnection.
- Fixed Kotlin type mismatch during nickname map merging.
* Restore VPN acquisition logic and improve peer cleanup
- Revert removal of NET_CAPABILITY_NOT_VPN to allow hardware handle acquisition while VPN is active.
- Refactor handlePeerDisconnection to more reliably cleanup initial and routed IDs.
- Switch cleanup logging to debug level to reduce log noise.
* Fix wifi aware socket binding 2 (#536)
* Background persistence (#505)
* persistence step 1
* fix build
* messages in the background work, notifications not yet
* app state store
* DM icon shows up
* notification launches when app is closed!
* keep ui updated
* lifecycle fixes
* extensive logging, maybe revert later
* send nickname in announcement
* quit in notification
* setting in about sheet
* fix quit bitchat
* lifecycle fixes
* power mode based on background state
* stats for both direciotns
* fix graph persistence
* better counting
* count per device
* only compute when debug sheet is open? untested
* fix read receipts
* fix read receipts fully
* fix unread badge if messages have been read in focus
* foreground promotion fix
* fix app kill in notification
* adjust to new tor
* nice
* about sheet design
* bump version 1.6.0 (#524)
* Automated update of relay data - Sun Dec 14 06:06:53 UTC 2025
* bump targetSdk (#526)
* Automated update of relay data - Sun Dec 21 06:06:56 UTC 2025
* Automated update of relay data - Sun Dec 28 06:07:12 UTC 2025
* Prevent quit notification from reappearing (#530)
* shutdown sequence
* Prevent quit notification from reappearing
* Restrict force-finish broadcast
* Cancel quit shutdown on relaunch
* fix(wifi-aware): use bindSocket and scoped IPv6 instead of bindProcessToNetwork
* Merge branch 'upstream/main' into fix/wifi-aware-socket-binding
* Fix Wi-Fi Aware connectivity and UI integration post-merge
- Replace bindProcessToNetwork with bindSocket for VPN compatibility.
- Implement Scoped IPv6 address resolution (aware0) for mesh routing.
- Bridge Wi-Fi Aware incoming messages to AppStateStore for UI visibility.
- Fix syntax errors and variable name conflicts in Debug UI.
* Enhance Wi-Fi Aware robustness and debug UI display
- Clean up transport resources (sockets, server sockets, network callbacks) immediately on peer disconnection.
- Implement resolveScopedAddress to show scoped IPv6 (e.g., %aware0) in Debug UI.
- Fix Map type mismatch warning in ChatViewModel bridge.
- Filter self-ID from peer cleanup tables to prevent recursive self-removal.
* Share GossipSyncManager across transports to prevent redundant message synchronization
- Registered BluetoothMeshService's GossipSyncManager as a singleton in MeshServiceHolder.
- Modified WifiAwareMeshService to use the shared GossipSyncManager if available.
- Added background cleanup for peer mappings on socket disconnection.
- Fixed Kotlin type mismatch during nickname map merging.
* Restore VPN acquisition logic and improve peer cleanup
- Revert removal of NET_CAPABILITY_NOT_VPN to allow hardware handle acquisition while VPN is active.
- Refactor handlePeerDisconnection to more reliably cleanup initial and routed IDs.
- Switch cleanup logging to debug level to reduce log noise.
---------
Co-authored-by: GitHub Action <action@github.com>
Co-authored-by: aidenvalue <>
* Fix wifi aware routing (#534)
* Background persistence (#505)
* persistence step 1
* fix build
* messages in the background work, notifications not yet
* app state store
* DM icon shows up
* notification launches when app is closed!
* keep ui updated
* lifecycle fixes
* extensive logging, maybe revert later
* send nickname in announcement
* quit in notification
* setting in about sheet
* fix quit bitchat
* lifecycle fixes
* power mode based on background state
* stats for both direciotns
* fix graph persistence
* better counting
* count per device
* only compute when debug sheet is open? untested
* fix read receipts
* fix read receipts fully
* fix unread badge if messages have been read in focus
* foreground promotion fix
* fix app kill in notification
* adjust to new tor
* nice
* about sheet design
* bump version 1.6.0 (#524)
* Automated update of relay data - Sun Dec 14 06:06:53 UTC 2025
* bump targetSdk (#526)
* Automated update of relay data - Sun Dec 21 06:06:56 UTC 2025
* Automated update of relay data - Sun Dec 28 06:07:12 UTC 2025
* Prevent quit notification from reappearing (#530)
* shutdown sequence
* Prevent quit notification from reappearing
* Restrict force-finish broadcast
* Cancel quit shutdown on relaunch
* fix(wifi-aware): use bindSocket and scoped IPv6 instead of bindProcessToNetwork
* Merge branch 'upstream/main' into fix/wifi-aware-socket-binding
* Fix Wi-Fi Aware connectivity and UI integration post-merge
- Replace bindProcessToNetwork with bindSocket for VPN compatibility.
- Implement Scoped IPv6 address resolution (aware0) for mesh routing.
- Bridge Wi-Fi Aware incoming messages to AppStateStore for UI visibility.
- Fix syntax errors and variable name conflicts in Debug UI.
* Enhance Wi-Fi Aware robustness and debug UI display
- Clean up transport resources (sockets, server sockets, network callbacks) immediately on peer disconnection.
- Implement resolveScopedAddress to show scoped IPv6 (e.g., %aware0) in Debug UI.
- Fix Map type mismatch warning in ChatViewModel bridge.
- Filter self-ID from peer cleanup tables to prevent recursive self-removal.
* Share GossipSyncManager across transports to prevent redundant message synchronization
- Registered BluetoothMeshService's GossipSyncManager as a singleton in MeshServiceHolder.
- Modified WifiAwareMeshService to use the shared GossipSyncManager if available.
- Added background cleanup for peer mappings on socket disconnection.
- Fixed Kotlin type mismatch during nickname map merging.
* Restore VPN acquisition logic and improve peer cleanup
- Revert removal of NET_CAPABILITY_NOT_VPN to allow hardware handle acquisition while VPN is active.
- Refactor handlePeerDisconnection to more reliably cleanup initial and routed IDs.
- Switch cleanup logging to debug level to reduce log noise.
* fix wifi aware routing
---------
Co-authored-by: GitHub Action <action@github.com>
Co-authored-by: aidenvalue <>
* unify connection tracker for ble and wifi (#537)
* unify connection tracker for ble and wifi
* cleanup nicely
* Wifi aware skip bluetooth (#538)
* unify connection tracker for ble and wifi
* bluetooth optional
* refactor mesh core
* tests
* share gossip
* refresh peer list more often
* patches: wifi aware mesh refactor core (#549)
* Refactor WifiAware memory management and lifecycle handling
* Fix Wi-Fi Aware reconnection by ensuring callback unregistration and session watchdog
* fix(wifiaware): allow WifiAwareController to restart service if session drops
* Enhance WiFi Aware logging with network request timeouts and detailed callback status
* Ensure explicit release of WiFi Aware network callbacks on failure or disconnection
---------
Co-authored-by: aidenvalue <>
* fix: wifi aware mesh private dms (#561)
* fix(wifi-aware): restore peer check and remove aggressive session restarts
* synchronized access to sockets.
* clear old peer socket `onClientConnected` if one was found.
* address second round of review
* fix: Restart publish session on termination in WifiAwareMeshService
* fix: cleanup connection tracker resources when handling peer disconnection without active socket
---------
Co-authored-by: aidenvalu3 <>
* fix(mesh): address memory leaks and background persistence issues in Wi-Fi Aware
- Move message persistence and background notifications for Wi-Fi Aware into the service layer via MeshCore hooks.
- Fix memory leak in MainActivity by properly detaching WifiAwareMeshDelegate on pause.
- Ensure BluetoothMeshService is initialized before WifiAwareMeshService to guarantee shared GossipSyncManager instance.
- Deduplicate persistence logic from MainActivity delegate.
* wifi aware working
* more robust
* fragments work
* new files
* wifi improvements
* handshake works
* improve
* wifi mesh more robust
* fix review
* check for support
* wifi aware fixes
---------
Co-authored-by: aidenvalue <>
Co-authored-by: GitHub Action <action@github.com>
Co-authored-by: aidenvalu3 <erendentman@gmail.com>
Co-authored-by: a1denvalu3 <43107113+a1denvalu3@users.noreply.github.com>
Co-authored-by: CC <cc@ggg.local>
* fix(sync): resolve hash alignment and early break bugs on GCS filter trimming
* fix(sync): filter out zero bucket and deduplicate buckets before encoding
* fix(sync): preserve zero-bucket mapping by clamping 0 to 1 during encoding and decoding
* fix: add input validation for protocol decoding and fragment reassembly
* fix:subtract the old entry's size before adding the new one, so duplicate/retransmitted fragments don't inflate the counter
* fix: FragmentManager.handleFragment() can be entered concurrently (e.g., fragments for the same fragmentID arriving from multiple peers/relays). In order for this to happen multiple devices would be needed to connect to the mesh. even with a per-fragmentID byte cap, an attacker could open many fragment IDs at once and force the device to buffer lots of fragment data overall (risking memory pressure/OOM). In this fix we made fragments atomic and thread safe. When a fragment index is retransmitted, we compute the size delta (new - old) so duplicates don’t inflate counters and can’t be used to bypass limits. Under heavy load/attack the app will drop/reject fragment sets earlier instead of growing memory usage without bound to reduce risk of oom. tested on pixel 6 and pixel 8.
* fix: add fragmenttest
* Add 'Send private message' action to chat user sheet
* Change 'Send private message' action color to purple
* Fix: Resolve short ID against all participants, not just cached nicknames
* Fix: Correctly open private chat sheet for mesh peers
---------
Co-authored-by: a1denvalu3 <>