docs(p0): compact MVP spec for Android Oboe focus

This commit is contained in:
Edison Jwa
2026-05-20 14:52:33 +09:00
parent 8c253f1d4d
commit 7d6d56e330
63 changed files with 8000 additions and 46507 deletions
@@ -1,65 +0,0 @@
# CHANORA_CFG_Baseline_Approval_Record_v0.9.2.2.1
**Document type:** Configuration / Baseline Approval Record
**Version:** 0.9.2
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/baseline-approval-record.md` ---
## 1. Baseline
| Field | Value |
|---|---|
| Baseline name | Chanora MVP Baseline Candidate |
| Baseline version | 0.9.0 |
| Package | `CHANORA_Documentation_Baseline_Candidate_v0.9.2.2.1.zip` |
| Approval target | Promote to `v1.0 Final / Approved Baseline` after review approval |
## 2. Approval Decision
| Decision | Value |
|---|---|
| Approved | Pending |
| Approved with conditions | Pending |
| Rejected | Pending |
## 3. Approvers
| Role | Name | Decision | Date | Signature / Evidence |
|---|---|---|---|---|
| Product owner | TBD | Pending | TBD | TBD |
| System architect | TBD | Pending | TBD | TBD |
| Software architect | TBD | Pending | TBD | TBD |
| Software lead | TBD | Pending | TBD | TBD |
| QA / verification owner | TBD | Pending | TBD | TBD |
| Security reviewer | TBD | Pending | TBD | TBD |
| UX owner | TBD | Pending | TBD | TBD |
| Platform owner | TBD | Pending | TBD | TBD |
## 4. Open Issues
| Issue ID | Description | Disposition |
|---|---|---|
| TBD | TBD | TBD |
## 5. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Baseline approval record template for normalized package. |
## Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. |
## Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
@@ -1,92 +0,0 @@
# Cfg Baseline Candidate Validation Report
**Document type:** Configuration / Validation Report
**Version:** 0.9.3
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/baseline-candidate-validation-report.md` ---
## 1. Package
```text
chanora-docs-repo-format-v0.9.3
```
## 2. File Count
| Type | Count |
|---|---:|
| Markdown files | 37 (added `docs/architecture/desktop-ptt-architecture.md`) |
## 3. Defined ID Counts
| ID family | Defined IDs |
|---|---:|
| SysRS | 302 |
| SysDes | 148 |
| SRS | 203 |
| SAD | 80 |
| SDD | 93 |
## 4. Undefined Reference Check
| ID family | Undefined references |
|---|---:|
| SysRS | 0 |
| SysDes | 0 |
| SRS | 0 |
| SAD | 0 |
| SDD | 0 |
## 5. Direct-Layer Rule Check
| Rule | Result |
|---|---:|
| SRS direct SysRS references | 0 |
| SAD direct SysRS references | 0 |
| SAD direct SysDes references | 0 |
| SDD direct SysRS references | 0 |
| SDD direct SysDes references | 0 |
| SDD direct SRS references | 0 |
## 6. Language Check
| Check | Result |
|---|---:|
| CJK characters in en-only doc set | 0 |
(Localised user-facing strings in `apps/chanora_flutter/lib/l10n/app_zh.arb` are out of scope of this report per DEC-015.)
## 7. Apple Gate Coverage Check
| Item | Coverage |
|---|---|
| Runtime deployment target | iOS 13+ remains separate runtime policy |
| App Store Connect upload SDK gate | Xcode 26+ and iOS 26 / iPadOS 26 SDK+ for upload on or after 2026-04-28 |
| Link chain | SysRS-287 -> SysDes-134 -> SRS-186 -> SAD-062 -> SDD-072 |
| Internal Alpha / local development distinction | Captured in Platform Release Policy |
| TestFlight / App Store upload distinction | Captured in Platform Release Policy |
## 8. Desktop Push-to-Talk Coverage Check
| Item | Coverage |
|---|---|
| Focused PTT mandatory on Win / macOS / Linux | SysRS-296 -> SysDes-142, SysDes-144 -> SRS-201 -> SAD-075 -> SDD-089 |
| Global PTT capability-dependent | SysRS-297 -> SysDes-142 -> SRS-195 -> SAD-071 -> SDD-081 |
| Capability exposed to UI + release record | SysRS-298 -> SysDes-143/147/148 -> SRS-196 -> SAD-076/078 -> SDD-082/088/091 |
| Windows ladder | SysRS-299 -> SysDes-145 -> SRS-197 -> SAD-072 -> SDD-083/084 |
| macOS permission-aware | SysRS-300 -> SysDes-145 -> SRS-198 -> SAD-073 -> SDD-085 |
| Linux GNOME-Wayland portal | SysRS-301 -> SysDes-145 -> SRS-199 -> SAD-074 -> SDD-086 |
| No raw key history in diagnostics | SysRS-302 -> SysDes-146 -> SRS-202 -> SAD-077 -> SDD-090 |
| Mouse side buttons (DEC-026) | SRS-200 -> SAD-072/073/074 -> SDD-083/085/086 |
| Missed-key-up watchdog (DEC-028) | SRS-203 -> SAD-079 -> SDD-092 |
| Owner-resolved review questions PTT-OPEN-001..006 | DEC-023..028 in `product-decision-register.md` |
## 9. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Validation report for Apple App Store Connect upload SDK gate correction, full file update, and coverage check. |
| 0.9.3 | 2026-05-15 | Validation report for desktop Push-to-Talk update: added 7 SysRS / 7 SysDes / 9 SRS / 9 SAD / 12 SDD entries, added `desktop-ptt-architecture.md`, recorded six new owner decisions DEC-023..028; ID totals advance to 302 / 148 / 203 / 79 / 92; direct-layer rule and undefined-reference counts remain zero. |
| 0.9.4 | 2026-05-15 | P0 traceability audit follow-up: added `SAD-080` and `SDD-093` to close the SRS-200 coverage gap surfaced by the audit. ID totals advance to 302 / 148 / 203 / 80 / 93; direct-layer-rule and undefined-reference counts remain zero. No code change in this revision; the existing mouse-side-button support previously implemented under the broader `SRS-195..203 -> SAD-071..079 -> SDD-081..092` umbrella is now tied to the dedicated SAD/SDD pair. |
@@ -1,103 +0,0 @@
# CHANORA_CFG_Decision_Impact_Assessment_v0.9.2.2.1
**Document type:** Configuration / Decision Impact Assessment
**Version:** 0.9.2
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/decision-impact-assessment.md` ---
## 1. Purpose
This document records how key unresolved product and architecture decisions affect requirements, architecture, detailed design, verification, release readiness, security, privacy, and legal work products.
## 2. High-Impact Decision Assessment
| Decision | Recommended decision | Impact if changed later |
|---|---|---|
| Minimum iOS version | iOS 13 | Test matrix, platform support policy, app store build configuration, platform behavior tests. |
| Minimum Android version | API 28 (per DEC-004, Accepted 2026-05-14; raised from the original API 24 recommendation) | Device support, permissions, audio routing, Google Play compatibility, platform tests. |
| Android target SDK | Google Play-required API level on upload date; current release gate uses API 35+ unless newer policy applies |
| Apple App Store SDK gate | Xcode 26+ with iOS 26 / iPadOS 26 SDK+ for App Store Connect upload on or after 2026-04-28 unless newer Apple upload policy applies | Google Play submission eligibility and platform permission behavior. |
| Multiple active connections | Exclude from MVP | If added later, affects state model, audio routing, UI layout, reconnection logic, storage, verification. |
| AEC/AGC/NS/HPF defaults | Enabled by default where supported | Affects UX, CPU, platform-specific audio settings, verification matrix. |
| Audio processing path | Platform-native first; fallback later | Affects audio architecture, Rust/native dependencies, latency, CPU, platform compatibility. |
| Trademark/legal review | Required before public/store release | Blocks public release if unresolved. |
| Local DB | SQLite or equivalent | Affects storage schema, migrations, backup/delete policy, tests. |
| Bridge | Stable typed generated/schema-controlled bridge | Affects API stability, async event flow, maintainability, code generation, tests. |
| Diagnostics upload | No automatic upload in MVP | Affects privacy policy, security review, support process. |
| Crash reporting | Disabled unless later approved | Affects privacy/legal docs, dependency and supply-chain review. |
## 3. Document Update Rules
| If decision changes | Update required |
|---|---|
| Minimum iOS/Android version changes | SysRS, SysDes, SRS, SAD, SDD, SYS.4, SWE.6, Release Readiness |
| Apple SDK submission gate changes | SysRS, SysDes, SRS, SAD, SDD, SWE.6, Release Readiness |
| Android target SDK changes | SRS, SWE.6, Release Readiness, Platform Guide |
| Multiple connections added to MVP | SysRS, SysDes, SRS, SAD, SDD, SWE.4, SWE.5, SWE.6, SYS.4 |
| Audio defaults change | SysRS, SysDes, SRS, SAD, SDD, SWE.4, SWE.5, SWE.6 |
| Audio implementation path changes | SysDes, SAD, SDD, SWE.4, SWE.5, SYS.4 |
| Legal/trademark policy changes | Release Readiness, Legal Review, Privacy Policy, External References |
| DB choice changes | SysDes, SRS, SAD, SDD, SWE.4, SWE.5 |
| Bridge choice changes | SysDes, SAD, SDD, SWE.4, SWE.5 |
| Diagnostics upload enabled | SysRS, SysDes, SRS, SAD, SDD, Threat Model, Privacy Policy, Redaction Audit, Release Readiness |
| Crash reporting enabled | SysRS, SysDes, SRS, SAD, SDD, Privacy Policy, Dependency Report, Release Readiness |
## 4. Recommended Decision Closure Sequence
1. Confirm release type and staged platform policy.
2. Confirm mobile minimum versions and Android target SDK policy.
3. Confirm one active server connection for MVP.
4. Confirm audio processing defaults.
5. Confirm audio implementation path.
6. Confirm diagnostics/crash reporting privacy policy.
7. Confirm SQLite/equivalent local database.
8. Confirm bridge choice.
9. Confirm legal/trademark/public wording review requirement.
10. Confirm license model before public release.
## 5. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Initial decision impact assessment for key product and architecture decisions. |
## Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ for App Store Connect upload on or after 2026-04-28, platform baselines and decision traceability propagated across the document set. |
## Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
## Desktop Push-to-Talk Decision Impact Addendum (Baseline Candidate 0.9.3)
The owner rulings recorded as DEC-023 through DEC-028 on 2026-05-15 affect the documents below. If any of those decisions are revisited the documents listed must be re-validated for consistency.
| Decision | Affects |
|---|---|
| DEC-023 Windows Global PTT P0 | `docs/architecture/desktop-ptt-architecture.md`, `docs/architecture/sad.md` SAD-072, `docs/architecture/sdd.md` SDD-083/084, `docs/requirements/srs.md` SRS-197, `docs/release/release-readiness-go-nogo-record.md` RR-PTT-001 |
| DEC-024 macOS Global PTT P0 + permission UX | `docs/architecture/desktop-ptt-architecture.md`, `docs/architecture/sad.md` SAD-073, `docs/architecture/sdd.md` SDD-085, `docs/requirements/srs.md` SRS-198, `docs/release/release-readiness-go-nogo-record.md` RR-PTT-002/003 |
| DEC-025 Linux GNOME-Wayland only | `docs/architecture/desktop-ptt-architecture.md`, `docs/architecture/sad.md` SAD-074, `docs/architecture/sdd.md` SDD-086, `docs/requirements/srs.md` SRS-199, `docs/release/platform-release-policy.md`, `docs/release/release-readiness-go-nogo-record.md` RR-PTT-004/005 |
| DEC-026 Mouse side buttons | `docs/architecture/desktop-ptt-architecture.md`, `docs/requirements/srs.md` SRS-200, `docs/architecture/sad.md` SAD-072/073, `docs/architecture/sdd.md` SDD-083/085 |
| DEC-027 PTT diagnostics privacy | `docs/privacy/privacy-policy.md`, `docs/security/diagnostic-redaction-audit-report.md`, `docs/security/threat-model.md`, `docs/requirements/srs.md` SRS-202, `docs/architecture/sad.md` SAD-077, `docs/architecture/sdd.md` SDD-090 |
| DEC-028 Missed-key-up watchdog P0 | `docs/architecture/desktop-ptt-architecture.md`, `docs/requirements/srs.md` SRS-203, `docs/architecture/sad.md` SAD-079, `docs/architecture/sdd.md` SDD-092, `docs/release/release-readiness-go-nogo-record.md` RR-PTT-007 |
| Version | Date | Description |
|---|---|---|
| 0.9.3 | 2026-05-15 | Recorded the desktop-PTT decision impacts for DEC-023..028. |
## Baseline Candidate 0.9.9 Update
| Version | Date | Description |
|---|---|---|
| 0.9.9 | 2026-05-17 | Updated §2 "Minimum Android version" row from API 24 to **API 28** to reconcile with DEC-004 (Accepted 2026-05-14). Document Update Rules (§3) and Decision Closure Sequence (§4) remain valid as-is. |
@@ -1,60 +0,0 @@
# Development Environment
**Document type:** Governance / Development Environment
**Version:** 0.1.0
**Status:** Draft
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/development-environment.md`
---
## 1. Purpose
This document records the intended local development environment for Chanora.
## 2. Required Toolchains
The exact versions shall be finalized when the Flutter and Rust workspaces are created.
Expected tools:
| Tool | Purpose |
|---|---|
| Flutter SDK | Cross-platform UI |
| Dart SDK | Flutter development |
| Rust toolchain | Core, protocol, audio, storage, diagnostics |
| Cargo | Rust package/build tool |
| just | Local command runner |
| Python 3 | Documentation validation scripts |
| Xcode | iOS/iPadOS/macOS development and App Store Connect upload builds |
| Android Studio / Android SDK | Android development |
| CMake / native build tools | Native dependencies if required |
## 3. Platform Notes
| Platform | Notes |
|---|---|
| iOS / iPadOS | App Store Connect upload on or after 2026-04-28 requires Xcode 26+ and iOS 26 / iPadOS 26 SDK+. |
| Android | Store upload must target the Google Play-required API level on upload date. |
| Desktop | Windows, macOS, and Linux build requirements shall be finalized during scaffold and release planning. |
## 4. Local Commands
Local commands are defined in `justfile`.
Initial commands:
```bash
just format
just lint
just test
just verify-docs
just security-scan
```
## 5. Change History
| Version | Date | Description |
|---|---|---|
| 0.1.0 | 2026-05-14 | Initial development environment document. |
-93
View File
@@ -1,93 +0,0 @@
# Document Index
**Document type:** Configuration / Documentation Control
**Version:** 0.9.9
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/document-index.md`
---
## 1. Purpose
This document lists the normalized latest files included in the Chanora repository documentation package.
## 2. Current Baseline Candidate Files
| File | Status |
|---|---|
| `docs/architecture/sad.md` | Baseline Candidate |
| `docs/architecture/sdd.md` | Baseline Candidate |
| `docs/architecture/sysdes.md` | Baseline Candidate |
| `docs/architecture/desktop-ptt-architecture.md` | Baseline Candidate |
| `docs/governance/baseline-approval-record.md` | Baseline Candidate |
| `docs/governance/baseline-candidate-validation-report.md` | Baseline Candidate |
| `docs/governance/decision-impact-assessment.md` | Baseline Candidate |
| `docs/governance/document-naming-convention.md` | Baseline Candidate |
| `docs/governance/document-review-report.md` | Baseline Candidate |
| `docs/governance/git-commit-message-convention.md` | Baseline Candidate |
| `docs/governance/path-migration-map.md` | Baseline Candidate |
| `docs/governance/product-decision-register.md` | Baseline Candidate |
| `docs/governance/repo-format-validation-report.md` | Baseline Candidate |
| `docs/governance/traceability-matrix.md` | Baseline Candidate |
| `docs/i18n/localization-architecture.md` | Baseline Candidate |
| `docs/legal/trademark-and-attribution-review.md` | Baseline Candidate |
| `docs/privacy/privacy-policy.md` | Baseline Candidate |
| `docs/references/aspice-swe2-swe3-integration-note.md` | Baseline Candidate |
| `docs/references/external-references.md` | Baseline Candidate |
| `docs/release/platform-release-policy.md` | Baseline Candidate |
| `docs/release/release-readiness-go-nogo-record.md` | Baseline Candidate |
| `docs/requirements/srs.md` | Baseline Candidate |
| `docs/requirements/sysrs.md` | Baseline Candidate |
| `docs/security/dependency-and-supply-chain-report.md` | Baseline Candidate |
| `docs/security/diagnostic-redaction-audit-report.md` | Baseline Candidate |
| `docs/security/secure-storage-audit-report.md` | Baseline Candidate |
| `docs/security/security-privacy-legal-guideline.md` | Baseline Candidate |
| `docs/security/threat-model.md` | Baseline Candidate |
| `docs/ui-ux/adaptive-layout-platform-guide.md` | Baseline Candidate |
| `docs/ui-ux/material3-component-catalog.md` | Baseline Candidate |
| `docs/ui-ux/material3-design-tokens.md` | Baseline Candidate |
| `docs/ui-ux/material3-guideline.md` | Baseline Candidate |
| `docs/verification/swe4-unit-verification-plan.md` | Baseline Candidate |
| `docs/verification/swe5-software-integration-verification-plan.md` | Baseline Candidate |
| `docs/verification/swe6-software-verification-plan.md` | Baseline Candidate |
| `docs/verification/sys4-system-integration-verification-plan.md` | Baseline Candidate |
| `docs/verification/verification-master-plan.md` | Baseline Candidate |
## 3. Core Engineering Hierarchy
```text
SysRS -> SysDes -> SRS -> SAD -> SDD
```
## 4. Verification Work Product Mapping
```text
SDD -> SWE.4
SAD + SDD -> SWE.5
SRS -> SWE.6
SysDes -> SYS.4
```
## 5. Repo File Naming Rules
| Rule | Decision |
|---|---|
| Product prefix in file names | Not used under `docs/` |
| Case style | lowercase kebab-case |
| Version in file name | Not used |
| Version location | Inside document metadata |
| Release package version | Used in ZIP/package name |
## 6. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Converted documentation package to repository-oriented docs folder structure and updated internal filename references. |
| 0.9.3 | 2026-05-15 | Added `docs/architecture/desktop-ptt-architecture.md` to the controlled document set. |
| 0.9.5 | 2026-05-15 | Bumped controlled-set version to 0.9.5 for the v1 audio + PTT lifecycle refactor: SysRS-303..304, SysDes-149..151, SRS-204..207, SAD-081..083, SDD-094..097, and two new governance decisions DEC-029 (Flutter global-hotkey packages rejected for PTT) and DEC-030 (Voice Activity Detection deferred to P1). No controlled files added or removed; existing files updated in place under strict layered sourcing. |
| 0.9.6 | 2026-05-16 | Added DEC-031 (missed-key-up watchdog disabled on P0; redesign deferred to P1) and new controlled document `docs/verification/windows-p0-acceptance.md` carrying the 15-row human-must acceptance plan for the v1.0.0-rc.8 Windows ship. No spec items added; DEC-028 retained as historical context, superseded by DEC-031 for the v1 ship. |
| 0.9.7 | 2026-05-16 | Added controlled document `docs/verification/linux-p0-acceptance.md` carrying the 15-row human-must acceptance plan for the v1.0.0-rc.8 Linux (GNOME on Wayland) ship. Auto-test sign-off rows filled from the Arch host `100.74.219.114` verification pass: `cargo check --workspace --release` clean, `cargo test --workspace --lib` 78 / 0 / 1, `cargo test -p chanora_audio --test linux_portal_smoke -- --ignored` 1 / 0, `cargo test -p chanora_audio --test ptt_privacy` 1 / 0. No spec items added; the existing SDD-086 GNOME-Wayland portal backend is what this document signs off. |
| 0.9.8 | 2026-05-16 | Added controlled documents `docs/verification/macos-p0-acceptance.md` (15-row checklist for Apple Silicon macOS, SDD-085 CGEventTap backend now fully live with IOHIDCheckAccess + CGEventTapCreate + per-1.5s permission watcher) and `docs/verification/ios-p0-acceptance.md` (12-row checklist for physical iPhone via the free Apple Personal Team, SDD-094..097 audio lifecycle, AVAudioSession `.playAndRecord/.voiceChat` configured Swift-side in AppDelegate). The macOS PTT backend descriptor advertises L2/L3 only when Input Monitoring is granted, otherwise L0Focused per SRS-198 honest capability advertising. iOS PTT is L0Focused by design (DEC-025 explicitly does not pursue a global PTT analogue on iOS). No new spec items. |
| 0.9.9 | 2026-05-16 | Added controlled document `docs/verification/ipad-p0-acceptance.md` carrying the 15-row checklist for iPad P0 sign-off (same TS-3.3 reach, three iPad-specific rows: wide-mode landscape layout under the existing 840 dp LayoutBuilder breakpoint, Split View / Slide Over no-crash assertion since `UIApplicationSupportsMultipleScenes` stays `false` in P0, and AirPlay 2 audio routing). The iPad build artefact is the **same** `Runner.app` produced for iPhone — `TARGETED_DEVICE_FAMILY = "1,2"` in `ios/Runner.xcodeproj/project.pbxproj` is the Universal family. DEC-025 was originally iPhone-only for the mobile target; this row formally extends P0 coverage to iPad (still within the same iOS toolchain, no new Rust or Flutter code). No spec items added. |
@@ -1,66 +0,0 @@
# Document Naming Convention
**Document type:** Configuration / Documentation Control
**Version:** 0.9.2
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/document-naming-convention.md`
---
## 1. Purpose
This document defines the official repository documentation naming convention for Chanora.
## 2. Repository Path Pattern
Markdown documents under the repository shall use this pattern:
```text
docs/<category>/<lowercase-kebab-case-title>.md
```
Examples:
```text
docs/requirements/sysrs.md
docs/architecture/sad.md
docs/verification/swe4-unit-verification-plan.md
docs/release/release-readiness-go-nogo-record.md
docs/security/threat-model.md
```
## 3. Rules
| Rule | Decision |
|---|---|
| Product prefix | Do not use `CHANORA_` inside repo file names. |
| Version in filename | Do not include document version in repo file names. |
| Filename style | Use lowercase kebab-case. |
| Directory style | Use lowercase kebab-case. |
| Version metadata | Keep version inside the Markdown document. |
| Status metadata | Keep status inside the Markdown document. |
| Release artifacts | ZIP/package names may include project name and version. |
## 4. Top-Level Documentation Categories
| Directory | Purpose |
|---|---|
| `docs/requirements/` | SysRS and SRS |
| `docs/architecture/` | SysDes, SAD, SDD |
| `docs/verification/` | SWE.4, SWE.5, SWE.6, SYS.4, verification master plan |
| `docs/release/` | Release readiness and platform release policy |
| `docs/security/` | Threat model, secure storage, redaction, dependency/supply-chain, security guidelines |
| `docs/privacy/` | Privacy policy |
| `docs/legal/` | Trademark and attribution review |
| `docs/ui-ux/` | UI/UX, Material 3, design tokens, component catalog, adaptive layout |
| `docs/i18n/` | Localization architecture |
| `docs/governance/` | Index, traceability, approval, validation, review, decisions, commit convention |
| `docs/references/` | External references and research notes |
## 5. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Replaced release-package naming convention with repository docs naming convention. |
-90
View File
@@ -1,90 +0,0 @@
# Cfg Document Review Report V0.9.2.2.1
**Document type:** Configuration / Review Report
**Version:** 0.9.2
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/document-review-report.md` ---
## 1. Executive Summary
The normalized package is suitable as a **Baseline Candidate v0.9** for human review.
The package fixes the earlier draft-package issues:
- superseded original filenames are not included in the normalized package;
- all filenames follow a consistent naming convention;
- the package contains only baseline-candidate files;
- non-English text from the earlier draft metadata has been removed;
- undefined system-design references have been removed from the verification planning package;
- a naming convention, approval record template, document index, and validation report are included.
The package is still **not Final** until human review and approval are completed.
## 2. Recommended Status
| Decision | Result |
|---|---|
| Ready for Final / Approved Baseline | No |
| Ready for Baseline Candidate review | Yes |
| Recommended current status | Baseline Candidate v0.9 |
| Next target status after approval | Final / Approved Baseline v1.0 |
## 3. Positive Review Findings
| Area | Result |
|---|---|
| File naming | Normalized |
| Package scope | Latest baseline-candidate files only |
| Core hierarchy | `SysRS -> SysDes -> SRS -> SAD -> SDD` |
| Verification mapping | `SDD -> SWE.4`, `SAD + SDD -> SWE.5`, `SRS -> SWE.6`, `SysDes -> SYS.4` |
| SRS direct-source rule | SRS does not directly link to system-requirement IDs |
| SAD direct-source rule | SAD links directly to SRS only |
| SDD direct-source rule | SDD links directly to SAD only |
| English-only baseline | Passed automated CJK check |
| Approval metadata | Approval record template included |
## 4. Remaining Review Actions Before Final
| ID | Severity | Action |
|---|---|---|
| REV-ACT-001 | Major | Human stakeholders must review and approve the baseline candidate. |
| REV-ACT-002 | Major | Review comments must be recorded and dispositioned. |
| REV-ACT-003 | Major | Open issues must be accepted, deferred, or resolved. |
| REV-ACT-004 | Major | Approval record must be completed with names, roles, dates, and decisions. |
| REV-ACT-005 | Major | After approval, promote package and documents from `v0.9.2` to `v1.0`. |
## 5. Finalization Recommendation
Do not call this package Final until the approval record is completed.
Recommended workflow:
```text
Baseline Candidate v0.9.1
-> Human review
-> Review comment disposition
-> Approval record completed
-> Promote to v1.0 Final / Approved Baseline
```
## 6. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Review report for normalized baseline candidate package. |
## Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. |
## Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
@@ -1,185 +0,0 @@
# CHANORA_CFG_Git_Commit_Message_Convention_v0.9.2.2.1
**Document type:** Configuration / Engineering Convention
**Version:** 0.9.2
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/git-commit-message-convention.md` ---
## 1. Purpose
This document defines the Git commit message convention for Chanora.
Chanora shall use a Conventional Commits style format with project-specific scopes.
## 2. Commit Format
```text
<type>(<scope>): <summary>
```
Optional body:
```text
<type>(<scope>): <summary>
<body>
Refs: <issue or requirement IDs>
```
Breaking change format:
```text
<type>(<scope>)!: <summary>
BREAKING CHANGE: <description>
```
## 3. Commit Types
| Type | Meaning |
|---|---|
| `feat` | New user-visible or system-visible capability |
| `fix` | Bug fix |
| `docs` | Documentation-only change |
| `style` | Formatting change without behavior change |
| `refactor` | Code restructuring without intended behavior change |
| `perf` | Performance improvement |
| `test` | Test addition or test update |
| `build` | Build system, dependency, packaging, CI artifact change |
| `ci` | CI/CD pipeline change |
| `chore` | Maintenance task |
| `revert` | Revert a previous commit |
| `release` | Release preparation, version bump, release metadata |
| `sec` | Security-specific change |
| `i18n` | Localization, internationalization, Unicode, locale behavior |
| `ux` | UI/UX behavior or interaction change |
## 4. Recommended Scopes
| Scope | Area |
|---|---|
| `flutter` | Flutter app in general |
| `ui` | UI components and screens |
| `theme` | Material 3, design tokens, theme extensions |
| `adaptive` | Adaptive layout and window classes |
| `voice` | Voice UI or voice control behavior |
| `audio` | Audio capture, playback, processing, DSP |
| `core` | Rust Core orchestration |
| `protocol` | `tsclientlib` integration and protocol adapter |
| `bridge` | Flutter/Rust bridge and DTOs |
| `state` | State synchronization, reducers, snapshots, events |
| `storage` | Local database or non-secret persistence |
| `secure-storage` | Keychain/Keystore/secret storage |
| `diagnostics` | Logs, redaction, diagnostic export |
| `i18n` | Localization, Unicode, locale formatting, RTL |
| `android` | Android-specific behavior |
| `ios` | iOS-specific behavior |
| `windows` | Windows-specific behavior |
| `macos` | macOS-specific behavior |
| `linux` | Linux-specific behavior |
| `build` | Build tooling |
| `ci` | CI pipeline |
| `release` | Release packaging and release metadata |
| `docs` | Documentation |
| `req` | Requirements documents |
| `sysdes` | System architectural design |
| `srs` | Software requirements |
| `sad` | Software architecture |
| `sdd` | Software detailed design |
| `ver` | Verification documents |
## 5. Examples
```text
feat(voice): add push-to-talk state handling
```
```text
fix(protocol): recover channel tree after reconnect snapshot
```
```text
docs(sad): add interface catalog and performance view
```
```text
i18n(ui): add fallback behavior for missing localization keys
```
```text
sec(diagnostics): redact server password from export bundle
```
```text
test(audio): add unit tests for audio meter level clamping
```
```text
release(android): prepare internal alpha build metadata
```
## 6. Requirement and Document References
When relevant, the commit body should reference affected IDs.
Allowed examples:
```text
Refs: SRS-156, SAD-013, SDD-017
```
```text
Refs: SWE4-UV-011
```
Do not force every commit to reference a requirement. Use references when the change affects requirements, architecture, detailed design, verification, release, security, or traceability.
## 7. Pull Request Title Rule
Pull request titles should follow the same format as commit messages when possible:
```text
feat(voice): add persistent VoiceBar controls
```
## 8. Branch Naming
Recommended branch format:
```text
<type>/<short-topic>
```
Examples:
```text
feature/voicebar-controls
fix/reconnect-state-sync
docs/baseline-candidate-v09
release/internal-alpha-001
hotfix/diagnostic-redaction
```
## 9. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Initial Git commit message convention for Chanora. |
## Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. |
## Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
-200
View File
@@ -1,200 +0,0 @@
# Legal review readiness — DEC-012 sign-off checklist
| Version | Date | Status |
|---|---|---|
| 0.1.0 | 2026-05-15 | Initial draft alongside v1.0.0-rc.1 |
## Purpose
DEC-012 in `product-decision-register.md` records the legal /
trademark / licensing review as the **only** outstanding gate before
the MVP public release per DEC-001 sequencing. That decision was
accepted as a *release gate* on 2026-05-14; the actual review work
has not been performed.
This document is the engineering-side handoff package for that
review. It enumerates exactly what the reviewer needs to confirm,
points to the artefacts in this repository that answer each item,
and lists the work the reviewer must perform that the engineering
side cannot.
Engineering does **not** make legal decisions. Items marked
"engineering: done" mean the underlying technical artefact is in
place; the corresponding legal confirmation is still required.
## Scope
Reviewer is expected to confirm or correct each of the following
before `v1.0.0-rc.1` is promoted to `v1.0.0` and any release
artefact is published publicly or to a store.
### 1. Trademark — "Chanora"
* **DEC-018** accepted "Chanora" as the public product name.
* Engineering: name appears in `Cargo.toml`, `pubspec.yaml`, the
About dialog, the AppBar title via the `appTitle` localisation
key, and every commit message.
* **Reviewer action**:
- Trademark registrability check in target jurisdictions (CN, US,
EU at minimum, per DEC-002 target platforms' user base).
- Confirm no conflicting registration in voice-communication
software / mobile-app categories.
- Issue go / no-go ruling. A no-go ruling triggers a rename which
invalidates `v1.0.0-rc.1` and forces a new RC.
### 2. Non-affiliation statement — TeamSpeak
* **DEC-019** accepted the working wording:
> Chanora is independent and is not affiliated with, endorsed by,
> sponsored by, or officially associated with TeamSpeak.
* Engineering: that exact sentence ships in:
- `NOTICE` (top of file).
- `README.md` `## License and trademark` section.
- The in-app About dialog (English: `aboutNonAffiliation` ARB key;
Chinese Simplified: `aboutNonAffiliation` in `app_zh.arb`,
translated by an engineer — translation should be reviewed for
legal precision).
* **Reviewer action**:
- Confirm the English wording is sufficient under target-market
consumer-protection and unfair-competition statutes.
- Confirm the Chinese-Simplified translation does not weaken the
statement.
- Confirm there is no remaining text anywhere in the product that
could imply affiliation (search hints: "TeamSpeak", "official",
"endorsed").
### 3. Trademark usage — "TeamSpeak"
The product documentation and UI strings reference "TeamSpeak" in
several places where we describe interoperability (e.g.
"TeamSpeak-compatible servers"). This is nominative use.
* **Reviewer action**:
- Confirm each occurrence of "TeamSpeak" in user-facing strings,
documentation, and store metadata is permissible nominative
use under target-jurisdiction trademark law.
- Recommend a `™` or `®` symbol convention if required.
### 4. License posture — Chanora's own code
* **DEC-020** accepted dual-license **Apache-2.0 OR MIT**.
* Engineering: the texts ship as `LICENSE-APACHE` and `LICENSE-MIT`
at the repository root; the aggregator `LICENSE` references both.
Cargo-level package manifests carry `license.workspace = true`
pointing to `Apache-2.0 OR MIT` in the workspace `Cargo.toml`.
* **Reviewer action**:
- Confirm the dual-license declaration is consistent with all
contributor agreements (none in place yet — see open items).
- Confirm `LICENSE` file contents satisfy each app store's source-
code-availability and inbound-license requirements.
### 5. Third-party license posture — direct dependencies
* `NOTICE` enumerates the direct dependency list as of v1.0.0-rc.1.
* Each direct dependency is permissively licensed
(`MIT`, `Apache-2.0`, `MIT OR Apache-2.0`, `BSD-3-Clause`).
No GPL / LGPL / AGPL surfaces in the direct set.
* **Reviewer artefacts** checked into the repository:
- `docs/security/license-inventory.md` and
`docs/security/license-inventory.html` — full transitive Rust
inventory generated by `cargo about generate` from
`about.toml`. Covers 364 crates across the workspace.
- `docs/security/flutter-license-inventory.md` — Flutter / Dart
inventory generated by `tools/dump_flutter_licenses.sh`.
Covers 94 packages including the Flutter SDK BSD-3-Clause
text.
- `deny.toml``cargo deny` configuration enforcing the
DEC-020 license posture as a CI guardrail. The `supply-chain`
job in `.github/workflows/ci.yml` runs `cargo deny check` on
every push and PR.
* **Reviewer action**:
- Confirm the `NOTICE` enumeration matches what the build tooling
actually links by spot-checking against the inventories above.
- Confirm each direct dependency's attribution obligations are
satisfied (Apache-2.0 requires a copy of the license text, the
NOTICE entry, and a list of changes in any modified copies).
- Confirm no copyleft transitive dependency creeps in via
`tsclientlib` or `cpal`. The most likely failure mode is a
crypto / DSP subdep with LGPL coverage; `cargo deny` config
should refuse those.
### 6. `tsclientlib` posture specifically
The project pins `tsclientlib` to a specific commit
(`04aa249` on `https://github.com/ReSpeak/tsclientlib`). The crate is
upstream-licensed `MIT OR Apache-2.0`. It implements the
TeamSpeak 3 protocol from publicly observed behaviour, not from
TeamSpeak proprietary sources.
* **Reviewer action**:
- Confirm linking against `tsclientlib` does not by itself create
a derivative-work obligation under TeamSpeak's own licenses or
EULAs.
- Confirm using `tsclientlib` to talk to third-party
TeamSpeak-protocol servers does not create a trademark or
contract-tort exposure.
### 7. Crypto + secure-storage compliance
* `chacha20poly1305` (Apache-2.0 OR MIT) provides envelope
encryption for the identity at rest and bookmark passwords.
* `keyring` (Apache-2.0 OR MIT) hits the platform Secret Service /
Keychain / Credential Manager for the DEK.
* No symmetric or asymmetric primitive other than the above is
introduced by Chanora's own code; `tsclientlib` carries its own
protocol-level crypto.
* **Reviewer action**:
- Confirm export-control posture for the resulting binary
(cryptography category determination, ECCN, any EAR self-
classification needed for store distribution).
- Confirm any privacy-statement updates required by jurisdictions
that treat persistent device identifiers as personal data.
### 8. Data handling — DEC-016 / DEC-017
* **DEC-016** No automatic diagnostic upload. The `export_diagnostics`
bridge function is invoked only on user action and the redacted
output is local-only (Clipboard or share-sheet).
* **DEC-017** Crash reporting disabled. Repository grep for
`sentry|crashlytics|bugsnag` returns zero hits as of v1.0.0-rc.1.
* Engineering: diagnostics redaction is enforced at write-time by
the in-bridge `RedactingLogLayer`; tests
`chanora_diagnostics::tests::*` cover the policy.
* **Reviewer action**:
- Confirm privacy policy text aligns: no telemetry, no automatic
upload, no crash reporting in MVP.
- Confirm app-store privacy-label entries are consistent.
### 9. Store-listing copy
Out of scope for engineering; reviewer drafts and validates per
DEC-002 staged platform list:
- Google Play Store (Android arm64-v8a)
- Apple App Store (iOS, MVP gate)
- Microsoft Store / direct (Windows)
- Mac App Store / direct (macOS)
- Linux (direct distribution; no store)
## Open engineering work blocking sign-off
These are concrete items that engineering must close before the
reviewer's work can complete. They do **not** require legal input
themselves — they are listed here so the reviewer's scope is clear.
| # | Item | Status |
|---|------|--------|
| 1 | `cargo about generate --workspace` output checked into `docs/security/license-inventory.{md,html}` | **Done** (v1.0.0-rc.2 candidate) — generated from `about.toml`. 364 transitive crates enumerated; CI fails on staleness. |
| 2 | Flutter `LicenseRegistry` dump checked into `docs/security/flutter-license-inventory.md` | **Done** (v1.0.0-rc.2 candidate) — generated by `tools/dump_flutter_licenses.sh`; 94 packages enumerated; CI fails on staleness. |
| 3 | `cargo deny check licenses` (with allow-list mirroring DEC-020) | **Done** (v1.0.0-rc.2 candidate) — config at `deny.toml`, CI job `supply-chain` runs `cargo deny check` on every push. |
| 4 | Live iOS and macOS build artefacts | **Open** — DEC-002 staged release allows deferring; today neither has a live build. See `staged-release-plan.md`. |
## Out-of-scope
The following are *not* part of DEC-012 and have their own owners
and decisions:
* Cryptographic primitive selection (`chacha20poly1305`, key sizes,
KDF choice) — Security Architect; closed by DEC-013.2.
* Codec choice (Opus) — Software Architect.
* TLS / connection security — falls inside `tsclientlib`.
-84
View File
@@ -1,84 +0,0 @@
# Documentation Path Migration Map
**Document type:** Configuration / Migration Map
**Version:** 0.9.3
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/path-migration-map.md`
---
## 1. Purpose
This document maps the previous package-style filenames to the new repository documentation paths.
## 2. Migration Map
| Previous package filename | New repo path |
|---|---|
| `CHANORA_SAD_ASPICE_SWE2_Software_Architecture_Description_v0.9.2.md` | `docs/architecture/sad.md` |
| `CHANORA_SDD_ASPICE_SWE3_Software_Detailed_Design_v0.9.2.md` | `docs/architecture/sdd.md` |
| `CHANORA_SYSDES_ASPICE_SYS3_System_Architectural_Design_v0.9.2.md` | `docs/architecture/sysdes.md` |
| `CHANORA_CFG_Baseline_Approval_Record_v0.9.2.md` | `docs/governance/baseline-approval-record.md` |
| `CHANORA_CFG_Baseline_Candidate_Validation_Report_v0.9.2.md` | `docs/governance/baseline-candidate-validation-report.md` |
| `CHANORA_CFG_Decision_Impact_Assessment_v0.9.2.md` | `docs/governance/decision-impact-assessment.md` |
| `CHANORA_CFG_Document_Index_v0.9.2.md` | `docs/governance/document-index.md` |
| `CHANORA_CFG_Document_Naming_Convention_v0.9.2.md` | `docs/governance/document-naming-convention.md` |
| `CHANORA_CFG_Document_Review_Report_v0.9.2.md` | `docs/governance/document-review-report.md` |
| `CHANORA_CFG_Git_Commit_Message_Convention_v0.9.2.md` | `docs/governance/git-commit-message-convention.md` |
| `CHANORA_CFG_Product_Decision_Register_v0.9.2.md` | `docs/governance/product-decision-register.md` |
| `CHANORA_CFG_Traceability_Matrix_v0.9.2.md` | `docs/governance/traceability-matrix.md` |
| `CHANORA_I18N_Localization_Architecture_v0.9.2.md` | `docs/i18n/localization-architecture.md` |
| `CHANORA_LEGAL_Trademark_And_Attribution_Review_v0.9.2.md` | `docs/legal/trademark-and-attribution-review.md` |
| `CHANORA_PRIV_Privacy_Policy_v0.9.2.md` | `docs/privacy/privacy-policy.md` |
| `CHANORA_REFS_ASPICE_SWE2_SWE3_Integration_Note_v0.9.2.md` | `docs/references/aspice-swe2-swe3-integration-note.md` |
| `CHANORA_CFG_External_References_v0.9.2.md` | `docs/references/external-references.md` |
| `CHANORA_REL_Platform_Release_Policy_v0.9.2.md` | `docs/release/platform-release-policy.md` |
| `CHANORA_REL_Release_Readiness_Go_NoGo_Record_v0.9.2.md` | `docs/release/release-readiness-go-nogo-record.md` |
| `CHANORA_SRS_ASPICE_SWE1_Software_Requirements_Specification_v0.9.2.md` | `docs/requirements/srs.md` |
| `CHANORA_SYSRS_System_Requirements_Specification_v0.9.2.md` | `docs/requirements/sysrs.md` |
| `CHANORA_SEC_Dependency_And_Supply_Chain_Report_v0.9.2.md` | `docs/security/dependency-and-supply-chain-report.md` |
| `CHANORA_SEC_Diagnostic_Redaction_Audit_Report_v0.9.2.md` | `docs/security/diagnostic-redaction-audit-report.md` |
| `CHANORA_SEC_Secure_Storage_Audit_Report_v0.9.2.md` | `docs/security/secure-storage-audit-report.md` |
| `CHANORA_SEC_Security_Privacy_Legal_Guideline_v0.9.2.md` | `docs/security/security-privacy-legal-guideline.md` |
| `CHANORA_SEC_Threat_Model_v0.9.2.md` | `docs/security/threat-model.md` |
| `CHANORA_UIUX_Adaptive_Layout_Platform_Guide_v0.9.2.md` | `docs/ui-ux/adaptive-layout-platform-guide.md` |
| `CHANORA_UIUX_Material3_Component_Catalog_v0.9.2.md` | `docs/ui-ux/material3-component-catalog.md` |
| `CHANORA_UIUX_Material3_Design_Tokens_v0.9.2.md` | `docs/ui-ux/material3-design-tokens.md` |
| `CHANORA_UIUX_Material3_Guideline_v0.9.2.md` | `docs/ui-ux/material3-guideline.md` |
| `CHANORA_VER_ASPICE_SWE4_Unit_Verification_Plan_v0.9.2.md` | `docs/verification/swe4-unit-verification-plan.md` |
| `CHANORA_VER_ASPICE_SWE5_Software_Integration_Verification_Plan_v0.9.2.md` | `docs/verification/swe5-software-integration-verification-plan.md` |
| `CHANORA_VER_ASPICE_SWE6_Software_Verification_Plan_v0.9.2.md` | `docs/verification/swe6-software-verification-plan.md` |
| `CHANORA_VER_ASPICE_SYS4_System_Integration_Verification_Plan_v0.9.2.md` | `docs/verification/sys4-system-integration-verification-plan.md` |
| `CHANORA_VER_Master_Plan_v0.9.2.md` | `docs/verification/verification-master-plan.md` |
## 3. Implementation Path Layout (DEC-022)
The canonical implementation directory layout was adopted as DEC-022
(register v0.9.5) and matches the README's sketch + SAD §7.2 module
decomposition. Implementation paths are listed here for traceability
alongside the documentation paths above.
| Logical role | Repo path | Authority |
|---|---|---|
| Flutter application | `apps/chanora_flutter/` | SAD §7.1, DEC-022 |
| Rust orchestration / top-level API | `core/chanora_core/` | SAD §7.2 |
| Protocol adapter (tsclientlib isolation) | `crates/chanora_protocol/` | SAD §7.2, SAD-067, SysDes-011/029 |
| State synchronisation | `crates/chanora_state/` | SAD §7.2 |
| Audio subsystem | `crates/chanora_audio/` | SAD §7.2, DEC-011, DEC-011.1 |
| Storage (non-secret DB + platform secure store) | `crates/chanora_storage/` | SAD §7.2, SAD-067, DEC-013, DEC-013.1, DEC-013.2 |
| Diagnostics (logs, redaction, export) | `crates/chanora_diagnostics/` | SAD §7.2, DEC-016, DEC-017 |
| Typed Flutter/Rust bridge | `crates/chanora_bridge/` | SAD §7.2, DEC-014, SDD-079, SAD-068 |
The Cargo workspace is declared at the repository root (`Cargo.toml`).
The Flutter application is **not** a Cargo workspace member; it is
owned by Flutter / Gradle / Xcode tooling and listed under the
workspace's `exclude` array along with the `poc/` spike directories.
## 4. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Initial migration map from package filenames to repo docs paths. |
| 0.9.3 | 2026-05-14 | Added §3 Implementation Path Layout recording the DEC-022 directory adoption (apps/, core/, crates/) as the workspace was first scaffolded on `product/scaffold-v0`. |
-158
View File
@@ -1,158 +0,0 @@
# PoC Results Summary
**Document type:** Governance / PoC Results Summary
**Version:** 0.6.0
**Status:** Draft
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/poc-results-summary.md`
---
## 1. Purpose
This document is the single top-level entry point summarising the
outcome of the technical proof-of-concept (PoC) phase defined by
[`docs/architecture/proof-of-concept-plan.md`](../architecture/proof-of-concept-plan.md).
It exists so that reviewers (security, audit, baseline-approval) can
read one page and follow pointers to evidence, rather than having to
crawl seven `VERIFICATION.md` files under `poc/`.
This summary records facts as of **2026-05-13**.
## 2. Status table
| Spike | PoC plan exit criterion | Status | Evidence |
|---|---|---|---|
| `flutter_rust_bridge_hello` | Flutter can call Rust and receive event stream data | **PASS** | `poc/flutter_rust_bridge_hello/VERIFICATION.md` |
| `tsclientlib-connect-spike` | Rust can connect to a compatible server/test double | **PASS** | `poc/tsclientlib-connect-spike/VERIFICATION.md` |
| `secure-storage-spike` | Secret write/read/delete works through platform secure storage | **PASS (Linux only)** | `poc/secure-storage-spike/VERIFICATION.md` |
| `sqlite-storage-spike` | Schema, migration, and repository pattern are demonstrated | **PASS** | `poc/sqlite-storage-spike/VERIFICATION.md` |
| `diagnostics-redaction-spike` | Password and identity-secret samples are redacted (REDACT-TC-001..010 covered) | **PASS** | `poc/diagnostics-redaction-spike/VERIFICATION.md` |
| `audio-capture-playback-spike` (desktop half) + `audio-capture-playback-android-spike` (mobile half) | Capture/playback works on at least one desktop **and** one mobile target | **PASS** — desktop on Linux + PipeWire; mobile on a physical Motorola Moto G Stylus 5G running Android 14 arm64-v8a. iOS remains explicitly deferred per DEC-011.1. | `poc/audio-capture-playback-spike/VERIFICATION.md`, `poc/audio-capture-playback-android-spike/VERIFICATION.md` |
Aggregate test count across the PoCs: **44 tests + 1 live-server CLI
run + 1 desktop-audio CLI round-trip + 1 Android playback + 1 Android
capture (real-device, with WAV file inspection)**, all passing in the
recorded runs. **All six PoC plan entries now PASS.**
## 3. Toolchain exercised
| Tool | Version |
|---|---|
| Rust toolchain | stable 1.95.0 (59807616e 2026-04-14) |
| Rust Android targets | aarch64-linux-android, armv7-linux-androideabi, x86_64-linux-android, i686-linux-android |
| Flutter SDK | 3.41.9 stable (Dart 3.11.5) |
| `flutter_rust_bridge` (Rust + Dart) and codegen | 2.12.0 |
| `tsclientlib` | git `04aa2491` (no published crates.io release) |
| `cpal` | 0.16 |
| `rusqlite` | 0.32 (bundled) |
| `keyring` | 3.6.3 (sync-secret-service + linux-native) |
| `linux-keyutils` | 0.2.5 |
| `regex` / `serde` / `serde_json` | 1 |
| Android SDK | platform 34, build-tools 34.0.0 |
| Android NDK | r26.3.11579264 |
| `cargo-ndk` | 4.1.2 |
| AGP / Gradle / Kotlin | 8.5.2 / 8.7 / 1.9.24 |
| `jni`, `ndk-context`, `android_logger` | 0.21, 0.1.1, 0.14 |
| Host OS for verification | Linux (Arch, kernel 7.0.5-arch1-1, x86_64) |
| Host audio server | PipeWire 1.6.4 (via pcm_pipewire ALSA plugin) |
| Host Secret Service backend | gnome-keyring (default collection observed locked; kernel keyutils backend used for hermetic tests) |
| Android test device | Motorola Moto G Stylus 5G (2023), Android 14 (SDK 34), arm64-v8a |
## 4. Owner-confirmed decisions
Recorded in [`docs/governance/product-decision-register.md`](product-decision-register.md) at version **0.9.5**:
### From the PoC phase (decisions surfaced by the spikes)
| Decision | Status | Closed by |
|---|---|---|
| **DEC-014** typed bridge | Accepted (`flutter_rust_bridge` 2.x pinned) | `flutter_rust_bridge_hello` |
| **DEC-013.1** SQLite crate | Accepted (`rusqlite` bundled) | `sqlite-storage-spike` |
| **DEC-013.2** Linux secure-storage backend policy | Accepted (Secret Service preferred, keyutils fallback) | `secure-storage-spike` |
| **DEC-011.1** audio crate | Accepted (desktop: `cpal`; Android: `cpal`-on-Oboe) / Deferred (iOS) | `audio-capture-playback-spike` (desktop) + `audio-capture-playback-android-spike` (mobile) |
| **DEC-022** canonical implementation directory layout | Accepted (README sketch — `apps/chanora_flutter/`, `core/chanora_core/`, `crates/chanora_*`) | Owner ruling on 2026-05-13 |
| **DEC-020** license | Accepted (Apache-2.0 OR MIT dual-license) | Owner ruling on 2026-05-14; license texts added as `LICENSE-APACHE` and `LICENSE-MIT`. |
### From the 2026-05-14 owner-confirmation pass (all 17 previously-Proposed)
| Decision | Status | Notes |
|---|---|---|
| DEC-001 Release type sequence | Accepted | Alpha → Beta → Public. |
| DEC-002 MVP platform scope | Accepted | All five platforms; staged release allowed. |
| DEC-003 Minimum iOS | Accepted | iOS 13. |
| **DEC-004 Minimum Android** | **Accepted — MODIFIED** | **API 28** (raised from the recommendation of API 24). Affects the Android spike's `minSdk = 24`; product `apps/chanora_flutter` must move it to 28. |
| DEC-005 Android target SDK | Accepted | Google Play-required API on upload date. |
| DEC-006 Connections in MVP | Accepted | Single connection. |
| DEC-007 AEC | Accepted | Enabled by default where supported. |
| DEC-008 AGC | Accepted | Enabled by default + toggle. |
| DEC-009 Noise suppression | Accepted | Enabled by default + toggle. |
| DEC-010 High-pass filter | Accepted | Enabled by default. |
| DEC-011 Audio path | Accepted | Platform-native first. |
| DEC-012 Legal review gate | Accepted (as a release gate) | The legal review work itself is still to be performed. |
| DEC-013 Local DB | Accepted | SQLite or equivalent. |
| **DEC-015 Product language for MVP** | **Accepted — MODIFIED** | **English + Chinese (Simplified)** at MVP (expanded from the recommendation of English-only). Affects translation pipeline and design-system text length budgets. |
| DEC-016 Diagnostics upload | Accepted | User-initiated local export only. |
| DEC-017 Crash reporting | Accepted | Disabled for MVP. |
| DEC-018 Product name | Accepted | Chanora. |
| DEC-019 Non-affiliation statement | Accepted (drafted wording) | Final legal sign-off still required under DEC-012. |
| DEC-021 Apple App Store SDK gate | Accepted | Xcode 26+ / iOS 26 SDK+ on or after 2026-04-28. |
### Still open
(none — DEC-020 closed on 2026-05-14; see register v0.9.6.)
DEC-012 legal/trademark/licensing review remains a release-gating
*work* item but is not an open decision.
## 5. Audit-report coverage
| Audit ID | Verified by | Audit-report row updated? |
|---|---|---|
| SS-AUD-001 (identity secret absent from local DB) | `secure-storage-spike` | Yes — `docs/security/secure-storage-audit-report.md` §4 v0.9.3 |
| SS-AUD-002 (server password absent from local DB) | `secure-storage-spike` | Yes |
| SS-AUD-003 (no secrets in logs) | `secure-storage-spike` + cross-ref `diagnostics-redaction-spike` | Yes |
| SS-AUD-004 (no secrets in diagnostic export) | `diagnostics-redaction-spike` REDACT-TC-008 | Yes |
| SS-AUD-005 (safe error on backend failure) | `secure-storage-spike` (test + live CLI fallback) | Yes |
| SS-AUD-006 (delete removes entry) | `secure-storage-spike` | Yes |
| SS-AUD-007 (per-platform documentation) | Linux only — partial | Yes (status: Partial) |
| SS-AUD-008 (migration path safety) | Pending (depends on product `chanora_storage`) | Yes (status: Pending) |
| SS-TC-001 (Windows) | Not run | Status: Deferred |
| SS-TC-002 (macOS) | Not run | Status: Deferred |
| SS-TC-003 (Linux) | `secure-storage-spike` | **PoC Pass** |
| SS-TC-004 (Android) | Not run | Status: Deferred |
| SS-TC-005 (iOS) | Not run | Status: Deferred |
| REDACT-TC-001..010 | `diagnostics-redaction-spike` (12/12) | Yes — `docs/security/diagnostic-redaction-audit-report.md` §4 v0.9.3 |
| Export bundle policy §5 (all rows) | `diagnostics-redaction-spike` | Yes — §5 v0.9.3 |
## 6. Open risks and gaps
| ID | Risk | Owner | Recommended close path |
|---|---|---|---|
| RISK-PoC-001 | iOS audio (AVAudioEngine via cpal or a per-platform iOS adapter) is not verified. The desktop and Android halves of the PoC plan's audio criterion are met; iOS is explicitly deferred per DEC-011.1. | Audio Owner + iOS Owner | iOS spike on macOS + Xcode hardware; or accept the risk and discover it during product integration (not recommended). |
| RISK-PoC-002 | Windows / macOS / iOS / Android secure-storage adapters not implemented. SS-TC-001/002/004/005 unverified. | Platform Owners | Per-platform adapter spike or first-implementation-in-`chanora_storage` with the audit checks re-run on each target. |
| RISK-PoC-003 | ~~License (DEC-020) deferred. Blocks public/store release.~~ **CLOSED 2026-05-14.** DEC-020 Accepted as Apache-2.0 OR MIT dual-license; texts present in repository root. Release-gating legal review under DEC-012 remains pending as a separate *work* item, but no longer a license-choice blocker. | Product Owner + Legal | Closed. |
| RISK-PoC-004 | ~~DEC-001..012, 015..019, 021 still in Proposed status.~~ **CLOSED 2026-05-14.** All 17 decisions were owner-reviewed; statuses recorded in the register at v0.9.5. | Product Owner | Closed. |
| RISK-PoC-005 | Production code does not exist yet. README's "Implementation status: Not production-ready" remains accurate. | Software Architect | **Further progress 2026-05-14.** Internal Alpha (`v0.1.0-alpha.1`, 3bb038c) wired the connect/snapshot/disconnect cycle. **Internal Beta (`v0.2.0-beta.1`) reached the same day** with voice in/out: `chanora_audio` promoted from scaffold; PTT, Opus encode, decode + jitter buffer + mix all wired through to Flutter. README's status line remains accurate (not production-ready) but is now genuinely close to dogfoodable. |
| RISK-PoC-006 | **DEC-004 Android minimum was raised to API 28 from the spike's `minSdk = 24`.** The Android spike still builds and runs; product code in `apps/chanora_flutter` must move `minSdk` to 28 and may simplify its AAudio fallback logic accordingly. | Android Owner | Set `minSdk = 28` when the Android target is added to `apps/chanora_flutter`. |
| RISK-PoC-007 | **DEC-015 expanded the MVP language scope from English-only to English + Chinese (Simplified).** Adds zh-Hans translation, font, and design-system text-length-budget work to MVP. | Product Owner + i18n Owner | Land en + zh-Hans message catalogues in `chanora_flutter/lib/i18n/` at scaffolding time; verify Material 3 design tokens accommodate CJK text metrics. |
## 7. Non-promotion reminder
Per `proof-of-concept-plan.md` §4: **a PoC is not product code unless
explicitly promoted.** Nothing under `poc/` should be imported by
the future `apps/chanora_flutter` or `crates/chanora_*` trees
without an explicit promotion record per spike.
## 8. Change History
| Version | Date | Description |
|---|---|---|
| 0.1.0 | 2026-05-14 | Initial PoC results summary. Records the outcome of the first PoC batch (5 PASS, 1 PARTIAL), the toolchain versions exercised, the owner-confirmed decisions, audit-report coverage, and the open risks. |
| 0.2.0 | 2026-05-14 | Audio PoC promoted from PARTIAL to PASS after the Android spike verified the mobile half on a physical Motorola Moto G Stylus 5G running Android 14 arm64-v8a. All six PoC plan entries now PASS. RISK-PoC-001 narrowed from "mobile audio" to "iOS audio only". Android toolchain (NDK r26.3, cargo-ndk, AGP/Gradle/Kotlin, jni/ndk-context/android_logger) added to the toolchain table. |
| 0.3.0 | 2026-05-14 | Recorded the owner-confirmation pass on the 17 remaining Proposed decisions (register at v0.9.5). RISK-PoC-004 closed. Added RISK-PoC-006 (Android `minSdk` 24 → 28) and RISK-PoC-007 (MVP language expanded to English + Chinese Simplified) for the two decisions that diverged from the original recommendations. DEC-020 license remains the sole open release-gating decision. |
| 0.4.0 | 2026-05-14 | DEC-020 license closed as Apache-2.0 OR MIT dual-license (register v0.9.6). RISK-PoC-003 closed. No remaining open decisions; the only release-gating activity outstanding is the DEC-012 legal review *work*, which is sign-off rather than an architectural choice. |
| 0.5.0 | 2026-05-14 | Internal Alpha build reached. `poc/tsclientlib-connect-spike` promoted into `crates/chanora_protocol`; `core/chanora_core::ChanoraSession` wires the typed protocol API; `crates/chanora_bridge` exposes the FRB 2.12.0 boundary; `apps/chanora_flutter` runs the connect → snapshot → disconnect cycle end-to-end against `cn.teamspeak.app`. Verified by `apps/chanora_flutter/test/alpha_e2e_test.dart` + `core/chanora_core/tests/alpha_smoke.rs`. Tag: `v0.1.0-alpha.1` (commit 3bb038c). RISK-PoC-005 partially closed. |
| 0.6.0 | 2026-05-14 | **Internal Beta build reached** (same day as Alpha). `poc/audio-capture-playback-spike` promoted into `crates/chanora_audio`: cpal capture/playback + `audiopus` Opus encode + `tsclientlib::audio::AudioHandler` decode/jitter/mix. `chanora_protocol` extended with voice-out mpsc and voice-in mpsc; `chanora_core` adds `start_audio` / `set_ptt` / `audio_stats`. `chanora_bridge` adds matching DTOs (`BridgeAudioStats`). Flutter UI gains "Start audio" + hold-to-talk PTT + live frame counters. Verified end-to-end on `cn.teamspeak.app` by `apps/chanora_flutter/test/beta_e2e_test.dart`. Tag: `v0.2.0-beta.1`. Capture runs gracefully in playback-only mode on hosts with no usable microphone. |
@@ -1,362 +0,0 @@
# CHANORA_CFG_Product_Decision_Register_v0.9.7.0.0
**Document type:** Configuration / Product Decision Register
**Version:** 0.9.8
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/product-decision-register.md` ---
## 1. Purpose
This document records key product, architecture, release, legal, and engineering decisions that affect Chanora scope, testing, architecture, app store eligibility, and release readiness.
A decision marked **Proposed / Owner Confirmation Required** is a recommended decision that should be confirmed by the owner before Final / Approved Baseline.
## 2. Decision Status Legend
| Status | Meaning |
|---|---|
| Proposed / Owner Confirmation Required | Recommended decision; owner must confirm before Final. |
| Accepted | Confirmed and part of baseline. |
| Deferred | Not decided for this release; must not block scope if explicitly deferred. |
| Rejected | Not selected. |
## 3. Key Blocking Decisions
| Decision ID | Decision | Recommended decision | Status | Owner | Why it matters |
|---|---|---|---|---|---|
| DEC-001 | Release type | Internal Alpha first, then External Beta, then MVP Public / Store Release | Accepted | Product Owner | Controls release gate, verification bar, legal/privacy requirements, and platform scope. |
| DEC-002 | MVP platform scope | MVP target remains Windows, macOS, Linux, Android, and iOS; first release may be staged by channel/platform | Accepted | Product Owner + Engineering Owner | Controls verification matrix, build artifacts, store readiness, and support load. |
| DEC-003 | Minimum iOS version | iOS 13 minimum for Flutter support baseline; test latest iOS release separately | Accepted | Product Owner + iOS Owner | Controls iOS compatibility, test devices, and app store eligibility. |
| DEC-004 | Minimum Android version | **Android API 28 (Android 9.0)** minimum, raised from the original recommendation of API 24 by explicit owner ruling on 2026-05-14. Rationale: simplifies the audio path (AAudio is unconditionally available from API 26+ and stable from API 28), narrows the TLS / privacy / scoped-storage compatibility surface, and matches typical 2026 Android baselines. The cpal-on-Oboe Android spike was built with `minSdk = 24` and `cargo-ndk -P 26`; product code in `apps/chanora_flutter` must move `minSdk` to 28 and may simplify the AAudio-vs-OpenSL-ES fallback logic accordingly. | Accepted | Product Owner + Android Owner | Controls Android device support, runtime permissions, and Play Store eligibility. |
| DEC-005 | Android target SDK | Target the Google Play-required API level on the upload date; current release gate uses API 35+ unless newer Google policy applies | Accepted | Android Owner + Release Manager | Required for new apps and updates submitted to Google Play after the current policy date. |
| DEC-006 | Multiple server connections in MVP | Not in MVP; support one active server connection per client instance | Accepted | Product Owner + Software Architect | Reduces state synchronization, audio routing, UI complexity, and verification scope. |
| DEC-007 | AEC default state | Enabled by default on platforms/audio backends where supported and stable | Accepted | Audio Owner + Product Owner | Affects echo quality, CPU usage, platform behavior, and user experience. |
| DEC-008 | AGC default state | Enabled by default, with user setting to disable | Accepted | Audio Owner + Product Owner | Affects perceived loudness consistency and may affect advanced user preference. |
| DEC-009 | Noise suppression default state | Enabled by default, with user setting to disable | Accepted | Audio Owner + Product Owner | Improves typical voice quality but may affect voice naturalness and CPU usage. |
| DEC-010 | High-pass filter default state | Enabled by default | Accepted | Audio Owner | Removes low-frequency rumble and usually improves speech capture. |
| DEC-011 | Audio processing implementation path | Use platform-native audio processing first where available; use Rust/WebRTC-style processing as controlled fallback or later architecture option | Accepted | Software Architect + Audio Owner | Controls architecture, latency, CPU use, platform compatibility, and testing. |
| DEC-011.1 | Audio crate choice | `cpal` for desktop (empirically verified on Linux/PipeWire by `poc/audio-capture-playback-spike` on 2026-05-13) and for Android (cpal-on-Oboe, empirically verified on a Motorola Moto G Stylus 5G (2023) running Android 14 arm64-v8a by `poc/audio-capture-playback-android-spike` on 2026-05-13); iOS crate TBD pending an iOS spike that requires macOS + Xcode hardware | Accepted (desktop + Android) / Deferred (iOS) | Software Architect + Audio Owner | Pins the desktop and Android audio dependencies; iOS remains an open risk surface. |
| DEC-012 | Official SDK / trademark / licensing review | Public/store release is blocked until legal confirms TeamSpeak non-affiliation wording, trademark usage, OSS licenses, and `tsclientlib` license posture | Accepted (as a release gate) | Legal / Compliance + Product Owner | Public release risk and store metadata risk. Owner accepted the gate on 2026-05-14; the legal review itself is still to be performed and remains a public-release blocker. |
| DEC-013 | Local database choice | Use SQLite or equivalent embedded local database for non-secret local state; secrets remain in platform secure storage | Accepted | Software Architect + Storage Owner | Controls storage schema, migrations, backup/delete policy, and portability. |
| DEC-013.1 | SQLite crate | `rusqlite` with the `bundled` feature (SQLite statically linked into the binary; no system libsqlite3 dependency); verified by `poc/sqlite-storage-spike` on 2026-05-13 | Accepted | Software Architect + Storage Owner | Pins the embedded-DB dependency; locks reproducibility. |
| DEC-013.2 | Linux secure-storage backend policy | Prefer Secret Service (libsecret / gnome-keyring / kwallet / KeePassXC) on Linux; if the default collection is locked or D-Bus is unavailable, fall back to kernel keyutils with a clear user notice. Both backends are "equivalent" per SysRS-053 / SysRS-162; verified by `poc/secure-storage-spike` on 2026-05-13 | Accepted | Software Architect + Storage Owner + Security Reviewer | Closes the SysRS-162 ambiguity surfaced by the secure-storage PoC. |
| DEC-014 | Bridge choice | Use a stable typed Flutter/Rust bridge with generated or schema-controlled DTOs; **`flutter_rust_bridge` 2.x pinned** (empirically verified at 2.12.0 by `poc/flutter_rust_bridge_hello` on 2026-05-13) | Accepted | Software Architect | Controls API stability, maintainability, async event flow, and long-term code generation. |
| DEC-015 | Product language for MVP | **English + Chinese (Simplified) for MVP**, raised from the original recommendation of English-only by explicit owner ruling on 2026-05-14. Rationale: the demonstrated test-server population (verified live against `cn.teamspeak.app`) and broader TS3 audience include substantial Chinese-speaking users; shipping zh-Hans alongside en at MVP avoids a launch-window UX gap. Architecture remains i18n-ready so additional languages can be added later mechanically. Server-provided content is preserved verbatim and never translated (ADR-008 UTF-8 boundary, DEC-015 server-content rule retained). | Accepted | Product Owner | Controls localization scope and release schedule. |
| DEC-016 | Diagnostics upload policy | No automatic upload for MVP; user-initiated local diagnostic export only | Accepted | Product Owner + Legal + Security | Controls privacy policy, support workflow, and security review scope. |
| DEC-017 | Crash reporting | Disabled for MVP unless explicit opt-in provider and privacy policy are approved | Accepted | Product Owner + Legal + Security | Avoids privacy/legal complexity before public release. |
| DEC-018 | Public product name | Chanora | Accepted | Product Owner | Branding and legal identity. Trademark / registrability check remains under DEC-012 legal review before public release. |
| DEC-019 | Public non-affiliation statement | Use legal-approved wording; drafted text accepted as working copy: "Chanora is independent and is not affiliated with, endorsed by, sponsored by, or officially associated with TeamSpeak." Subject to final legal review under DEC-012 before public release. | Accepted (drafted wording) | Legal / Compliance | Required for public release and store metadata. |
| DEC-021 | Apple App Store submission SDK | Use Xcode 26 or later and the iOS 26 / iPadOS 26 SDK or later for App Store submission on or after 2026-04-28, unless Apple publishes a newer applicable requirement before upload | Accepted | iOS Owner + Release Manager | Controls App Store Connect upload eligibility and release pipeline. |
| DEC-020 | License model | **Dual-licensed under Apache-2.0 OR MIT (recipient's choice)**, the standard Rust-ecosystem permissive license model. Accepted on 2026-05-14. Compatible with every direct dependency in the PoC tree (`tsclientlib` MIT-OR-Apache-2.0, `flutter_rust_bridge` MIT, `cpal` Apache-2.0, `rusqlite` MIT, `keyring` MIT-OR-Apache-2.0, etc.) and with the Flutter framework's BSD-3-Clause. The license texts ship as `LICENSE-APACHE` and `LICENSE-MIT` at the repository root; an aggregator `LICENSE` points to both. `NOTICE` enumerates current direct-dependency attributions. The full OSS legal review (transitive deps, license obligations, OSS notices) remains under DEC-012 and is still required before public release. | Accepted | Product Owner + Legal | Business and OSS compliance decision. No longer a public-release blocker by itself; legal review under DEC-012 is the remaining gate. |
| DEC-022 | Canonical implementation directory layout | Accept the README's sketch as canonical: `apps/chanora_flutter/`, `core/chanora_core/`, `crates/chanora_protocol/`, `crates/chanora_audio/`, `crates/chanora_state/`, `crates/chanora_storage/`, `crates/chanora_diagnostics/`, `crates/chanora_bridge/`. Matches SAD §7.2 module decomposition | Accepted | Software Architect | Unblocks product-crate scaffolding; was not formalised by any prior doc. |
| DEC-023 | Windows desktop Global PTT priority | **P0 in MVP.** Resolves PTT-OPEN-001 from `gen2/chanora-desktop-ptt-review-summary-v0.9.2.md`. The Windows backend ladder (Raw Input → low-level keyboard hook → Focused fallback) is mandatory for the first public release; release notes shall not claim Global PTT support on Windows until live measurement confirms a Global level from a non-fallback rung. | Accepted | Product Owner + Windows Platform Owner | Sets the MVP commitment level for the most common desktop platform. |
| DEC-024 | macOS desktop Global PTT priority | **P0 in MVP, with explicit permission UX flow.** Resolves PTT-OPEN-002. The macOS backend shall request the Input Monitoring / Accessibility permission, accept user denial gracefully (continue at `L0Focused` without functional regression), and upgrade to Global asynchronously when the user grants the permission. | Accepted | Product Owner + macOS Platform Owner | Forces the permission UX to ship with the rest of the macOS audio path rather than as a follow-up. |
| DEC-025 | Officially-tested Linux environment for first public release | **GNOME on Wayland (only).** Resolves PTT-OPEN-003. The Linux backend shall use the freedesktop `org.freedesktop.portal.GlobalShortcuts` interface on GNOME-on-Wayland and fall back to Focused PTT on every other Linux environment (X11, sway, KDE, untested compositors). Release notes shall not claim Global PTT support outside the tested compositor. | Accepted | Product Owner + Linux Platform Owner | Bounds the verification matrix; honest claim on Linux. |
| DEC-026 | Mouse side-button support in first desktop PTT release | **Supported on Windows and macOS; Linux follows whatever the GlobalShortcuts portal exposes.** Resolves PTT-OPEN-004. The Raw Input backend (Windows) and the Event Tap backend (macOS) shall accept Mouse4 / Mouse5 bindings; the Linux portal binding accepts whatever the session exposes and the release notes shall not over-claim. | Accepted | Product Owner + UX Owner | Common dedicated PTT input class; shipping in MVP avoids a follow-up. |
| DEC-027 | PTT diagnostics privacy posture | **Capability and availability state only — no raw key codes ever leave the device.** Resolves PTT-OPEN-005. The diagnostic export shall name only `PttCapabilityLevel`, `backend_id`, `bound_input_class`, and `fallback_exercised`; the user's actual key value (scan code, virtual key, keysym) shall never be logged, persisted, or exported. `PttSanitizer` enforces this at write time. | Accepted | Security Reviewer + Privacy Reviewer | Closes a clear privacy risk that the gen2 review flagged; aligns with DEC-016. |
| DEC-028 | Missed-key-up watchdog requirement | **P0.** Resolves PTT-OPEN-006. The audio engine shall include a missed-key-up watchdog that clears `transmit_active` after a configured ceiling (default 30 s) when no key-up event arrives. The watchdog is a P0 release-gate item rather than an implementation-level concern because the failure mode (stuck transmission after the user has released the binding) is user-visible and reputation-relevant. | Accepted | Audio Owner + Software Architect | Prevents stuck-PTT bug class regardless of platform-input quirks. |
| DEC-029 | Flutter global-hotkey packages rejected for PTT | **Use the native Rust `DesktopPttBackend` trait + per-OS implementations (already specified in SDD-083 / SDD-084 / SDD-085); do not adopt `hotkey_manager`, `super_hot_key`, or any equivalent pub.dev package for PTT.** Rationale: those packages wrap the OS `RegisterHotKey` / `RegisterEventHotKey` semantics — they consume the key (suppressing it from other applications), they do not deliver a key-up event, and they do not support mouse side-buttons. PTT requires the opposite primitive (observe, do not consume, deliver both up and down). | Accepted | Software Architect + Audio Owner | Locks the v1 PTT capture path to the native backend; removes ambiguity for future maintainers tempted to "simplify" via a Flutter package. |
| DEC-030 | Voice activity detection deferred to P1 | **`TransmitMode::VoiceActivity` ships as a reserved enum variant with no v1 implementation.** The settings UI shows it as a disabled "coming soon" option. The actual implementation choice is deferred to a future baseline. Rationale: three viable backends were compared (RMS energy threshold — trivial but quality-poor; WebRTC VAD via the `webrtc-vad` crate — frozen-but-stable C++ BSD-3 dep, ~200 KB binary, industry baseline; Silero VAD via ONNX Runtime — best quality but ~816 MB binary uplift per platform plus an ONNX-runtime dependency surface). The v1 dependency-surface budget does not have room for the trade-off review required to pick correctly. Choosing too early risks either user-visible quality regression (RMS) or a forced ONNX adoption (Silero) before there is a comparable need for ML inference elsewhere (noise suppression, AEC). | Accepted | Audio Owner + Product Owner | Locks v1 to PTT + Continuous; preserves the enum surface so a P1 increment is non-breaking. |
| DEC-031 | Missed-key-up watchdog disabled on P0; redesign deferred to P1 | **The `MissedKeyUpWatchdog` is constructed and unit-tested but is NOT spawned by `ChanoraSession::start_audio` in the P0 baseline.** Supersedes DEC-028 for the v1 ship. Rationale: the original 30 s ceiling cut real users off mid-sentence when speaking through PTT for longer than the timeout — Mumble and TeamSpeak do not ship a comparable watchdog, so the protection is stricter than industry baseline while imposing a real UX cost. The watchdog's purpose (catching OS-level key-up loss when the app loses focus / is minimised / hits App Nap) remains valid; the fixed-timeout shape is the wrong implementation. P1 will reintroduce a redesigned variant using one of: (a) raised ceiling (~5 min, owner-tunable) only, (b) active OS-level key-state polling via `GetAsyncKeyState` / `CGEventSourceKeyState` / `XQueryKeymap` so we detect the actual OS desync directly, (c) audio-activity (RMS-silence) fallback once the level meter lands, or (d) a combination. The Rust unit tests for `MissedKeyUpWatchdog::spawn_on_signal` remain in `crates/chanora_audio/src/ptt.rs` so the P1 re-enable is non-breaking. | Accepted | Audio Owner + Product Owner | Eliminates a P0-class UX regression (long PTT speech cut off at 30 s) while preserving the implementation surface for P1. |
## 4. Accepted MVP Defaults
The "Recommended" defaults below have all been confirmed by the owner;
two were modified from the original recommendation (marked **MODIFIED**).
| Area | Accepted MVP default |
|---|---|
| Release sequence | Internal Alpha → External Beta → MVP Public |
| MVP platforms | Windows, macOS, Linux, Android, iOS (staged release allowed) |
| Active connections | One active server connection |
| UI design system | Material 3 + Chanora Design System |
| Product language | **MODIFIED** — English + Chinese (Simplified) at MVP; i18n-ready architecture |
| Server content | Preserve and display Unicode; do not translate |
| Diagnostics | Local, user-initiated export only |
| Telemetry | None |
| Crash reporting | None unless later approved |
| Secret storage | Platform secure storage |
| Non-secret local storage | SQLite (`rusqlite` bundled) |
| Audio processing | Platform-native first; fallback strategy documented |
| AEC | Enabled by default where supported |
| AGC | Enabled by default (user-toggleable) |
| Noise suppression | Enabled by default (user-toggleable) |
| High-pass filter | Enabled by default |
| Android minimum | **MODIFIED** — API 28 (Android 9.0), raised from the original recommendation of API 24 |
| Android target | API 35 or newer per current Google Play policy on upload date |
| iOS minimum | iOS 13 |
| Apple App Store SDK gate | Xcode 26+ / iOS 26 SDK+ for uploads on or after 2026-04-28 |
| Audio crate | `cpal` (desktop, Android); iOS deferred |
| Bridge | Stable typed Flutter/Rust bridge; `flutter_rust_bridge` 2.x pinned |
| Implementation directory layout | `apps/chanora_flutter/`, `core/chanora_core/`, `crates/chanora_*` |
| License | **Dual-licensed under Apache-2.0 OR MIT**, recipient's choice (DEC-020) |
## 5. Decision Impact Matrix
| Decision | Affects SysRS | Affects SysDes | Affects SRS | Affects SAD | Affects SDD | Affects Verification | Affects Release |
|---|---|---|---|---|---|---|---|
| Minimum iOS / Android versions | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Android target SDK | No | No | Yes | No | No | Yes | Yes |
| Multiple active connections | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| AEC/AGC/NS/HPF defaults | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Audio implementation path | No if behavior unchanged | Yes | Possibly | Yes | Yes | Yes | Yes |
| SDK/trademark/legal review | Yes | No | No | No | No | Yes | Yes |
| SQLite/equivalent choice | Possibly | Yes | Yes | Yes | Yes | Yes | Yes |
| Bridge choice | No if API behavior unchanged | Yes | Possibly | Yes | Yes | Yes | Yes |
| Apple App Store SDK gate | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Diagnostics upload policy | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Crash reporting | Yes if included | Yes if included | Yes if included | Yes if included | Yes if included | Yes | Yes |
| Flutter hotkey packages rejected for PTT (DEC-029) | No | Yes | Yes | Yes | Yes | Yes | No |
| VAD deferred to P1 (DEC-030) | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
## 6. Decisions That Must Be Confirmed By You
All decisions in the register have been addressed by the owner. The
remaining release-gating *work* (not decisions) is the legal review
itself under DEC-012, which must complete before any public/store
release but is not an open decision:
| Priority | Item | Status |
|---|---|---|
| P0 | DEC-012 legal/trademark/licensing review — perform the actual review work (non-affiliation wording final sign-off, trademark registrability check, transitive-dependency OSS obligations, `tsclientlib` license posture confirmation). | Pending; gate Accepted. |
## 7. Open Decision Log
| Decision ID | Owner | Decision | Status | Date | Notes |
|---|---|---|---|---|---|
| DEC-001 | Product Owner | Release type sequence | Accepted | 2026-05-14 | Internal Alpha → External Beta → MVP Public. |
| DEC-002 | Product Owner / Engineering | MVP platform strategy | Accepted | 2026-05-14 | All five platforms as target; staged release allowed. |
| DEC-003 | Product Owner / iOS Owner | Minimum iOS version | Accepted | 2026-05-14 | iOS 13. |
| DEC-004 | Product Owner / Android Owner | Minimum Android version | Accepted | 2026-05-14 | **API 28** (modified from the recommendation of API 24). |
| DEC-005 | Android Owner / Release Manager | Android target SDK | Accepted | 2026-05-14 | Google Play-required API on upload date (currently API 35+). |
| DEC-006 | Product Owner / Software Architect | Multiple server connections in MVP | Accepted | 2026-05-14 | Single connection in MVP. |
| DEC-007 | Audio Owner / Product Owner | AEC default | Accepted | 2026-05-14 | Enabled by default where supported. |
| DEC-008 | Audio Owner / Product Owner | AGC default | Accepted | 2026-05-14 | Enabled by default with user toggle. |
| DEC-009 | Audio Owner / Product Owner | Noise suppression default | Accepted | 2026-05-14 | Enabled by default with user toggle. |
| DEC-010 | Audio Owner | High-pass filter default | Accepted | 2026-05-14 | Enabled by default. |
| DEC-011 | Software Architect / Audio Owner | Audio processing path | Accepted | 2026-05-14 | Platform-native first; Rust/WebRTC-style fallback. |
| DEC-011.1 | Software Architect / Audio Owner | Audio crate (desktop / mobile) | Accepted (desktop: `cpal`; Android: `cpal`-on-Oboe) / Deferred (iOS) | 2026-05-13 | Closed by `poc/audio-capture-playback-spike` (desktop) and `poc/audio-capture-playback-android-spike` (Android). iOS crate TBD pending iOS spike. |
| DEC-012 | Legal / Compliance | SDK/trademark/licensing review | Accepted as a release gate | 2026-05-14 | Required before public/store release; legal review work still to be performed. |
| DEC-013 | Software Architect / Storage Owner | Local database | Accepted | 2026-05-14 | SQLite or equivalent for non-secret state. |
| DEC-013.1 | Software Architect / Storage Owner | SQLite crate | Accepted (`rusqlite` bundled) | 2026-05-13 | Closed by `poc/sqlite-storage-spike` 11/11. |
| DEC-013.2 | Software Architect / Storage Owner / Security Reviewer | Linux secure-storage backend policy | Accepted (Secret Service preferred, keyutils fallback) | 2026-05-13 | Closed by `poc/secure-storage-spike` 6/6. Resolves SysRS-053 / SysRS-162 ambiguity. |
| DEC-014 | Software Architect | Bridge choice | Accepted (`flutter_rust_bridge` 2.x pinned) | 2026-05-13 | Closed by `poc/flutter_rust_bridge_hello` 3/3. |
| DEC-015 | Product Owner | Product language for MVP | Accepted | 2026-05-14 | **English + Chinese (Simplified)** (modified from the recommendation of English-only). |
| DEC-016 | Product Owner / Legal / Security | Diagnostics upload policy | Accepted | 2026-05-14 | User-initiated local export only; no automatic upload. |
| DEC-017 | Product Owner / Legal / Security | Crash reporting | Accepted | 2026-05-14 | Disabled for MVP. |
| DEC-018 | Product Owner | Public product name | Accepted | 2026-05-14 | Chanora. Trademark check still required under DEC-012. |
| DEC-019 | Legal / Compliance | Public non-affiliation statement | Accepted (drafted wording) | 2026-05-14 | Final legal sign-off still required under DEC-012. |
| DEC-020 | Product Owner / Legal | License model | Accepted (Apache-2.0 OR MIT dual-license) | 2026-05-14 | Compatible with every direct dependency; texts ship as LICENSE-APACHE / LICENSE-MIT. Full OSS legal review remains under DEC-012. |
| DEC-021 | iOS Owner / Release Manager | Apple App Store SDK gate | Accepted | 2026-05-14 | Xcode 26+ / iOS 26 SDK+ on or after 2026-04-28. |
| DEC-022 | Software Architect | Canonical implementation directory layout | Accepted (README sketch) | 2026-05-13 | Closes the absence flagged during PoC review. |
| DEC-023 | Product Owner / Windows Platform Owner | Windows desktop Global PTT priority | Accepted (P0 / MVP) | 2026-05-15 | Resolves PTT-OPEN-001 from the gen2 desktop-PTT review. |
| DEC-024 | Product Owner / macOS Platform Owner | macOS desktop Global PTT priority | Accepted (P0 / MVP, permission-UX required) | 2026-05-15 | Resolves PTT-OPEN-002. |
| DEC-025 | Product Owner / Linux Platform Owner | Officially-tested Linux environment | Accepted (GNOME on Wayland only) | 2026-05-15 | Resolves PTT-OPEN-003. |
| DEC-026 | Product Owner / UX Owner | Mouse side-button support | Accepted (Windows + macOS; Linux portal-dependent) | 2026-05-15 | Resolves PTT-OPEN-004. |
| DEC-027 | Security / Privacy Reviewer | PTT diagnostics privacy posture | Accepted (capability + availability only, no key codes) | 2026-05-15 | Resolves PTT-OPEN-005. |
| DEC-028 | Audio Owner / Software Architect | Missed-key-up watchdog | Accepted (P0) | 2026-05-15 | Resolves PTT-OPEN-006. |
| DEC-029 | Software Architect / Audio Owner | Flutter global-hotkey packages rejected for PTT | Accepted | 2026-05-15 | Native `DesktopPttBackend` is the v1 PTT capture path; pub.dev hotkey packages consume the key, drop key-up events, and skip mouse side-buttons. |
| DEC-030 | Audio Owner / Product Owner | Voice activity detection deferred to P1 | Accepted (deferred to P1) | 2026-05-15 | `TransmitMode::VoiceActivity` reserved on the enum surface; UI shows "coming soon"; backend choice (RMS / WebRTC / Silero) deferred for dependency-surface review. |
| DEC-031 | Audio Owner / Product Owner | Missed-key-up watchdog disabled on P0; redesign deferred to P1 | Accepted (supersedes DEC-028 for P0) | 2026-05-16 | Watchdog implementation + tests retained; not spawned by `ChanoraSession::start_audio` in v1. P1 chooses between raised ceiling / OS key-state polling / RMS-silence fallback. |
## 8. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Updated decision register with proposed decisions for mobile minimum versions, audio defaults, audio implementation path, legal review, local database, bridge choice, diagnostics policy, and MVP release scope. |
## Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ for App Store Connect upload on or after 2026-04-28, platform baselines and decision traceability propagated across the document set. |
## Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
## Baseline Candidate 0.9.3 Update
| Version | Date | Description |
|---|---|---|
| 0.9.3 | 2026-05-14 | Recorded owner-confirmed decisions surfaced during the initial PoC phase: DEC-014 Accepted (`flutter_rust_bridge` 2.x pinned); added DEC-011.1 Accepted for desktop (`cpal`) / Deferred for mobile; added DEC-013.1 Accepted (`rusqlite` bundled); added DEC-013.2 Accepted (Linux Secret Service preferred with keyutils fallback); added DEC-022 Accepted (canonical implementation directory layout per README sketch and SAD §7.2); DEC-020 explicitly Deferred and remains a public-release blocker. Evidence pointers: `poc/flutter_rust_bridge_hello/VERIFICATION.md`, `poc/secure-storage-spike/VERIFICATION.md`, `poc/sqlite-storage-spike/VERIFICATION.md`, `poc/audio-capture-playback-spike/VERIFICATION.md`. |
## Baseline Candidate 0.9.4 Update
| Version | Date | Description |
|---|---|---|
| 0.9.4 | 2026-05-14 | Promoted DEC-011.1 mobile half from Deferred to Accepted (Android), keeping iOS Deferred. Evidence: `poc/audio-capture-playback-android-spike/VERIFICATION.md` records empirical playback (22,050 frames at 44.1 kHz mono out of the device speaker) and capture (42,624 frames written to a valid 85,292-byte RIFF/WAVE mono 16-bit PCM file) on a physical Motorola Moto G Stylus 5G (2023) running Android 14 arm64-v8a, verifying the full Rust → cpal → Oboe → AAudio → Android audio HAL path. |
## Baseline Candidate 0.9.5 Update
| Version | Date | Description |
|---|---|---|
| 0.9.5 | 2026-05-14 | Owner confirmation pass on all previously-Proposed decisions. Accepted: DEC-001, DEC-002, DEC-003, DEC-005, DEC-006, DEC-007, DEC-008, DEC-009, DEC-010, DEC-011, DEC-012 (as a release gate), DEC-013, DEC-015, DEC-016, DEC-017, DEC-018, DEC-019 (drafted wording), DEC-021. Two decisions modified from their original recommendations: **DEC-004 Android minimum** raised from API 24 to **API 28** (simpler audio path, narrower compatibility surface); **DEC-015 product language** expanded from English-only to **English + Chinese (Simplified)** for MVP (reflects the demonstrated TS3-compatible-server audience). DEC-020 license model remains Open / Deferred — the only public-release blocker outstanding. §4 renamed from "Recommended MVP Defaults" to "Accepted MVP Defaults" with MODIFIED rows annotated. §6 collapsed to the single remaining DEC-020 item. §7 dated and statused. |
## Baseline Candidate 0.9.6 Update
| Version | Date | Description |
|---|---|---|
| 0.9.6 | 2026-05-14 | DEC-020 license model closed: **Apache-2.0 OR MIT** dual-license (standard Rust-ecosystem permissive model). The license is compatible with every direct dependency in the PoC tree (tsclientlib, flutter_rust_bridge, cpal, rusqlite, keyring, hound, etc.) and with the Flutter framework's BSD-3-Clause. License texts added as `LICENSE-APACHE` and `LICENSE-MIT` at the repository root; the existing `LICENSE` file now aggregates both with the dual-license declaration and the standard Apache-2.0 inbound-contribution clause. `NOTICE` populated with current direct-dependency attributions. README §License rewritten. §4 updated. §6 collapsed: there is no longer any open decision — DEC-012 legal review remains a pending *work* item, not a pending decision. With this change, every previously-Proposed or Open decision in the register has been resolved; the only outstanding release-gating activity is the DEC-012 legal review itself (which is sign-off work, not an architectural choice). |
## Baseline Candidate 0.9.7 Update
| Version | Date | Description |
|---|---|---|
| 0.9.7 | 2026-05-14 | DEC-001 release-sequence progress recorded: Internal Alpha (`v0.1.0-alpha.1`, commit 3bb038c) completed on 2026-05-14; **Internal Beta first build (`v0.2.0-beta.1`)** reached the same day. Beta milestone adds voice in/out: `crates/chanora_audio` promoted from scaffold to a cpal-based capture + playback engine with `audiopus` Opus encoding and tsclientlib `AudioHandler` for decode + jitter buffer + mix; `crates/chanora_protocol` extended to forward inbound voice packets and accept outbound `OutPacket`s via mpsc channels; `core/chanora_core::ChanoraSession` exposes `start_audio`, `set_ptt`, and `audio_stats`; `crates/chanora_bridge` adds matching DTOs; the Flutter UI gains a "Start audio" action and a hold-to-talk PTT button with live frame counters. Verified end-to-end against `cn.teamspeak.app`; capture runs in graceful playback-only mode on hosts with no usable microphone (e.g. the PipeWire `auto_null` source on the verification host). No decision rows change; this entry documents progress against DEC-001 only. |
| 0.9.8 | 2026-05-15 | DEC-001 release-sequence progress recorded for the polished Internal Beta and the External Beta milestones, plus the first MVP-public release candidate. **`v0.3.0-beta.1`** ("Internal Beta polish") added the supervisor + reconnect-with-watchdog path (A.6), OS-connectivity-aware backoff (A.6.1), persistent identity at rest as a plain 0600 file (A.2), the redacted in-memory log sink + user-initiated diagnostic export per DEC-016 (A.3), the `SnapshotChanged` lifecycle event for UI auto-refresh (A.4), and the `mobile_voice_preset` config-surface plumb-through (A.5). **`v0.4.0-beta.2`** ("External Beta") added the server-password input, channel join via tap, self mute (input + output), master output gain, SQLite-backed bookmark list, ChaCha20-Poly1305 encryption of the identity at rest with the DEK in a separate `identity.dek` file, Android `AudioManager.setMode(MODE_IN_COMMUNICATION)` routing engagement via JNI, and the `.github/workflows/ci.yml` pipeline. **`v1.0.0-rc.1`** ("MVP Public release candidate") closes the v0.4 DEK-on-disk weakness on every keyring-reachable platform: `chanora_storage::IdentityFileStore` now stores the DEK in the OS keyring (Linux Secret Service via D-Bus / macOS Keychain / Windows Credential Manager / iOS Keychain via the `keyring` crate) and migrates pre-existing file-fallback installs into the keyring opportunistically; bookmark server passwords are ChaCha20-Poly1305-encrypted under the same per-install DEK and the legacy plain `password TEXT` column is upgraded into a new `password_blob BLOB` column on the next `update()`; `SessionEvent::SnapshotChanged` now fires on any tree mutation (the in-channel-move blind spot from A.4 is closed); the in-app About dialog surfaces DEC-018 / DEC-019 / DEC-020. New `docs/governance/legal-review-readiness.md` carries the DEC-012 handoff package (trademark check, non-affiliation wording, third-party license posture, `cargo about` deliverables, `cargo deny` lifelines); new `docs/governance/staged-release-plan.md` enumerates the DEC-002 platform staging (Linux + Android sideload GA on DEC-012 sign-off; Windows, macOS, iOS gate on per-platform signed-build availability). No decision rows change; DEC-012 remains the sole outstanding release gate. |
| 0.9.9 | 2026-05-15 | Recorded six new accepted decisions DEC-023 through DEC-028 closing the gen2 desktop-PTT review's open questions PTT-OPEN-001 through PTT-OPEN-006: Windows Global PTT is P0/MVP (DEC-023), macOS Global PTT is P0/MVP with permission UX (DEC-024), the officially-tested Linux environment is GNOME-on-Wayland only (DEC-025), mouse side buttons are supported on Windows + macOS and Linux follows the portal (DEC-026), PTT diagnostics carry capability/availability only with no raw key codes (DEC-027), and the missed-key-up watchdog is a P0 release-gate requirement (DEC-028). No prior decision rows are mutated. |
| 0.9.10 | 2026-05-15 | Code-side promotion: the Linux GNOME-Wayland backend (DEC-025) is now a live `org.freedesktop.portal.GlobalShortcuts` session — `CreateSession` + `BindShortcuts` + `Activated` / `Deactivated` signal subscription scoped to the session handle, owned by a dedicated tokio task per backend instance. The Flutter "Configure" button on Linux portal delegates to the portal's own system dialog (Q3a) rather than the in-app `_PttBindingCaptureDialog`. Descriptor transitions broadcast via a `watch::Sender` consumed by `chanora_core::ChanoraSession::start_audio` and forwarded to `SessionEvent::PttCapability`. Cancellation / failure path downgrades to `L0Focused` and re-emits. No decision rows mutate. |
| 0.9.11 | 2026-05-15 | Added DEC-029 and DEC-030 covering the v1 audio + PTT lifecycle redesign. DEC-029 rejects Flutter global-hotkey packages (`hotkey_manager`, `super_hot_key`, equivalents) for PTT — they consume the key, do not deliver key-up, and do not support mouse side-buttons; the native Rust `DesktopPttBackend` already specified in SDD-083 / SDD-084 / SDD-085 is the v1 capture path. DEC-030 defers Voice Activity Detection to P1: `TransmitMode::VoiceActivity` ships as a reserved enum variant with no v1 implementation pending a backend trade-off review (RMS vs WebRTC VAD vs Silero VAD differ by ~816 MB and an ONNX-runtime dependency surface). No prior decision rows mutate; §5 impact matrix and §7 open-decision log gain matching rows. |
| 0.9.12 | 2026-05-16 | Added DEC-031: missed-key-up watchdog is disabled on P0 (supersedes DEC-028 for the v1 ship). The 30 s default ceiling spec'd in DEC-028 was cutting real PTT users off mid-sentence whenever a single utterance crossed the timeout; the watchdog's intent (catching OS-level key-up loss) remains valid, but the fixed-timeout implementation is the wrong shape. The `MissedKeyUpWatchdog` Rust type and its unit tests remain in `crates/chanora_audio/src/ptt.rs`; only the `ChanoraSession::start_audio` spawn is removed. P1 will choose between a raised ceiling, OS key-state polling (`GetAsyncKeyState` / `CGEventSourceKeyState` / `XQueryKeymap`), an RMS-silence fallback paired with the audio level meter, or a combination. DEC-028 stays in the register as historical context. |
## Baseline Candidate 0.9.8 Update — DEC-032
### DEC-032 — Temporary reduction of Android `abiFilters` to `arm64-v8a` only during P0 smoke-test cycle
| Field | Value |
|---|---|
| Decision ID | DEC-032 |
| Title | Temporary reduction of Android `abiFilters` to `arm64-v8a` only during P0 smoke-test cycle. |
| Status | **Resolved (canonical three-ABI set restored)** |
| Owner | Build/Toolchain |
| Restore-by | P0 release gate (must be restored before any P0 release upload). |
| Date recorded | 2026-05-18 |
| Date resolved | 2026-05-18 |
| Supersedes | None (temporary deviation from SDD-073 item 4 and SDD-118 item 3; does NOT supersede them). |
**Resolution (2026-05-18).** All four exit criteria below are met.
The propagation gap (criterion 1) is closed by a workspace
`[patch.crates-io]` stanza pinning the `cmake` crate to a fork
carrying cmake-rs PR #257
(<https://github.com/rust-lang/cmake-rs/pull/257>), which forwards the
`ANDROID_ABI` and `ANDROID_PLATFORM` environment variables (set per-
invocation by `cargo-ndk` 4.x and reinforced by the SDD-118 item 5
cleanEnv map) to the child `cmake` invocation as `-D` variables. The
fork is pinned by exact commit SHA
(`bdad5edc569d82151922c5c6c4685b1563f12aa1` on `pr2502/cmake-rs`,
branch `android-build`) for reproducibility — see the
`[patch.crates-io]` block in the workspace root `Cargo.toml`. Per-ABI
`cargo ndk --platform 28 -t <abi> build -p chanora_bridge` now passes
cleanly for all three ABIs (criterion 2). `abiFilters` in
`apps/chanora_flutter/android/app/build.gradle.kts` is restored to
`{arm64-v8a, armeabi-v7a, x86_64}` and the `TODO(x86_64/armv7
follow-up)` comment removed (criterion 3). The SDD-118 item 10
release-inspection assertion exercises every staged `.so` (including
`libc++_shared.so` per SDD-118 item 6 extended) for all three ABIs
again — no code change required, that assertion is driven by the
restored `abiFilters` set (criterion 4). Upstream tracking: re-
evaluate the `[patch.crates-io]` override once PR #257 merges and a
fresh `cmake` crates.io release lands; at that point the patch
should be removed in favour of a plain dep bump.
**Context.** SDD-073 item 4 and SDD-118 item 3 mandate the canonical
three-ABI set `{arm64-v8a, armeabi-v7a, x86_64}` for the Android AAB.
`apps/chanora_flutter/android/app/build.gradle.kts:72-79` currently has
`abiFilters` reduced to `arm64-v8a` only with a `TODO(x86_64/armv7
follow-up)` comment explaining the reduction.
**Cause.** The `audiopus_sys` + `cmake-rs` + NDK toolchain-file
interaction does not propagate `ANDROID_ABI` as a CMake variable when
invoked via the Gradle Exec task chain. `armeabi-v7a` and `x86_64`
builds fail because the inner CMake configure step does not see the
correct `-DANDROID_ABI=<abi>` argument. `arm64-v8a` (the smoke-test
emulator target) builds cleanly because it happens to be the default
that `cmake-rs` emits when no `ANDROID_ABI` is propagated.
**Scope.** Smoke-test build only. The P0 release **must** restore the
full three-ABI set before any release upload. Internal Beta / RC
builds for the smoke-test emulator path may continue using the
reduced set while the cmake-rs propagation fix is in flight.
**Exit criteria (all four must be met to close DEC-032).**
1. `audiopus_sys` / `cmake-rs` `ANDROID_ABI` propagation gap resolved
(research + builder-dispatch fix; root-cause whether upstream
`cmake-rs` patch, a builder-side env override, or a Gradle-Exec
level argument injection is the correct fix).
2. All three ABIs (`arm64-v8a`, `armeabi-v7a`, `x86_64`) compile
cleanly in CI for `chanora_bridge` cdylib.
3. The `abiFilters` declaration in
`apps/chanora_flutter/android/app/build.gradle.kts` is restored to
the canonical three-ABI set, and the `TODO(x86_64/armv7
follow-up)` comment removed.
4. The SDD-118 item 10 release-inspection assertion confirms that all
three `libchanora_bridge.so` files **and** all three
`libc++_shared.so` co-staged files (per SDD-118 item 6 extended,
absorbed into the traceability matrix v0.9.9 addendum) are present
in any release AAB.
**Impact assessment.**
- `arm64-v8a` installs work on all 64-bit modern Android devices,
including the smoke-test emulator and every device meeting the
DEC-004 API 28 minimum on 64-bit hardware.
- `armeabi-v7a` (32-bit ARM Android, ~1% of the 2026 active install
base for app-stores that still permit 32-bit) installations are
**blocked** until restoration. Affected users see Play Store
filtering and cannot install the AAB.
- `x86_64` (some Android emulators outside the smoke-test loop, rare
Chromebook deployments, some VMs) installations are **blocked**
until restoration.
- **P0 release-gate cannot pass** until the three-ABI set is
restored: release-inspection assertion (SDD-118 item 10) would
fail, and the canonical SDD-073 item 4 / SDD-118 item 3 contract
would be violated.
- No SDD edit is required: the deviation is governance-layer only
and the SDD canonical intent is unchanged.
**Cross-references.**
- SDD-073 item 4 (canonical Android ABI set).
- SDD-118 item 3 (Gradle automation enforcing the three-ABI set);
also item 6 (extended) for `libc++_shared.so` co-staging and item
10 for the release-inspection assertion that any future restoration
must satisfy.
- `apps/chanora_flutter/android/app/build.gradle.kts:72-79`
(in-source TODO comment marking the deviation site).
- Audit task `ses_1c7645e36ffeY007MaYPep4wqs` (auditor New-D — origin
of this DEC entry).
- Traceability matrix v0.9.9 §D (governance cross-reference).
- DEC-031 (separate temporary deviation, for `MissedKeyUpWatchdog`
P0 disable) — listed only as precedent for the
"Active (temporary deviation)" status pattern; no direct technical
overlap.
**§3 row (for canonical table consistency).**
| Decision ID | Decision | Recommended decision | Status | Owner | Why it matters |
|---|---|---|---|---|---|
| DEC-032 | Android `abiFilters` set during P0 smoke-test cycle | Canonical three-ABI set `{arm64-v8a, armeabi-v7a, x86_64}` (per SDD-073 item 4 / SDD-118 item 3) restored 2026-05-18 after the `audiopus_sys` + `cmake-rs` + NDK toolchain-file `ANDROID_ABI` propagation gap was closed via a workspace `[patch.crates-io]` override pinning `cmake` to a fork carrying cmake-rs PR #257 | **Resolved** | Build/Toolchain | Multi-ABI install support restored; P0 release-gate ABI blocker cleared. Re-evaluate the `[patch.crates-io]` override once cmake-rs PR #257 merges and a fresh release lands. |
**§5 row (impact matrix).**
| Decision | Affects SysRS | Affects SysDes | Affects SRS | Affects SAD | Affects SDD | Affects Verification | Affects Release |
|---|---|---|---|---|---|---|---|
| `abiFilters` temporary reduction (DEC-032) | No | No | No | No | No (canonical intent unchanged; SDD-073 item 4 / SDD-118 item 3 stand) | Yes (release-inspection assertion path) | Yes (release-gate blocker until restored) |
**§7 row (open decision log).**
| Decision ID | Owner | Decision | Status | Date | Notes |
|---|---|---|---|---|---|
| DEC-032 | Build/Toolchain | Temporary reduction of Android `abiFilters` to `arm64-v8a` only during P0 smoke-test cycle | Resolved (2026-05-18) | 2026-05-18 | Canonical three-ABI set restored 2026-05-18. Root cause (`audiopus_sys` + `cmake-rs` + NDK toolchain-file `ANDROID_ABI` propagation gap) closed by a workspace `[patch.crates-io]` override pinning the `cmake` crate to fork `pr2502/cmake-rs` @ `bdad5edc569d82151922c5c6c4685b1563f12aa1` carrying cmake-rs PR #257 (forwards `ANDROID_ABI` / `ANDROID_PLATFORM` env vars as `-D` variables to the child cmake). All four exit criteria met. Follow-up: drop the `[patch.crates-io]` override once PR #257 merges and a fresh `cmake` release lands. SDD-073 item 4 / SDD-118 item 3 unchanged. |
### Change history
| Version | Date | Description |
|---|---|---|
| 0.9.8 | 2026-05-18 | Added DEC-032: temporary reduction of Android `abiFilters` to `arm64-v8a` only during the P0 smoke-test cycle. Status: Active (temporary deviation) from SDD-073 item 4 / SDD-118 item 3, which both remain unchanged. Restore-by gate: any P0 release upload must restore the canonical three-ABI set `{arm64-v8a, armeabi-v7a, x86_64}` and satisfy the SDD-118 item 10 release-inspection assertion (including the `libc++_shared.so` co-staging per SDD-118 item 6 extended). Root cause: `audiopus_sys` + `cmake-rs` + NDK toolchain-file `ANDROID_ABI` propagation gap. Owner: Build/Toolchain. Cross-references: SDD-073 item 4, SDD-118 item 3 (+ item 6 extended, item 10), `apps/chanora_flutter/android/app/build.gradle.kts:72-79` (in-source TODO), audit task ses_1c7645e36ffeY007MaYPep4wqs, traceability matrix v0.9.9 addendum §D. No prior decision row mutates. |
| 0.9.8.1 | 2026-05-18 | DEC-032 **Resolved**: canonical three-ABI set `{arm64-v8a, armeabi-v7a, x86_64}` restored in `apps/chanora_flutter/android/app/build.gradle.kts`. Root cause closed by a workspace `[patch.crates-io]` stanza in the repo-root `Cargo.toml` pinning the `cmake` crate to fork `pr2502/cmake-rs` @ commit `bdad5edc569d82151922c5c6c4685b1563f12aa1` (branch `android-build`), which carries cmake-rs PR #257 forwarding the `ANDROID_ABI` and `ANDROID_PLATFORM` environment variables (set per invocation by `cargo-ndk` 4.x and reinforced by the SDD-118 item 5 cleanEnv map) to the child `cmake` invocation as `-D` variables. Verification (host: Linux): `cargo ndk --platform 28 -t arm64-v8a build -p chanora_bridge`, `... -t armeabi-v7a ...`, and `... -t x86_64 ...` all pass cleanly. `cargo check --workspace --all-targets` passes on the host target. SDD-073 item 4 / SDD-118 item 3 unchanged (canonical intent was always the three-ABI set). Follow-up: re-evaluate the `[patch.crates-io]` override once cmake-rs PR #257 merges and a fresh `cmake` release lands; at that point switch to a plain dep bump and remove the override. No prior decision row mutates. |
@@ -1,77 +0,0 @@
# Repo Documentation Format Validation Report
**Document type:** Configuration / Validation Report
**Version:** 0.9.3
**Status:** Baseline Candidate
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/repo-format-validation-report.md`
---
## 1. Package
```text
chanora-docs-repo-format-v0.9.3
```
## 2. File Count
| Type | Count |
|---|---:|
| Markdown files under docs/ | 38 (added `docs/architecture/desktop-ptt-architecture.md`) |
| README files | 1 |
## 3. Naming Check
| Check | Result |
|---|---:|
| Old `CHANORA_*_v*.md` filename references outside migration map | 0 |
| Old `CHANORA_*_v*.zip` package references outside migration map | 0 |
| CJK characters in en-only doc set | 0 |
## 4. Defined ID Counts
| ID family | Defined IDs |
|---|---:|
| SysRS | 302 |
| SysDes | 148 |
| SRS | 203 |
| SAD | 80 |
| SDD | 93 |
## 5. Undefined Reference Check
| ID family | Undefined references |
|---|---:|
| SysRS | 0 |
| SysDes | 0 |
| SRS | 0 |
| SAD | 0 |
| SDD | 0 |
## 6. Direct-Layer Rule Check
| Rule | Result |
|---|---:|
| SRS direct SysRS references | 0 |
| SAD direct SysRS references | 0 |
| SAD direct SysDes references | 0 |
| SDD direct SysRS references | 0 |
| SDD direct SysDes references | 0 |
| SDD direct SRS references | 0 |
## 7. Old Reference Details
| Type | Values |
|---|---|
| Old markdown filename references outside migration map | None |
| Old ZIP filename references outside migration map | None |
## 8. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Validated repository-format documentation package and internal filename reference updates. |
| 0.9.3 | 2026-05-15 | Re-validated repository-format after desktop PTT update: added `docs/architecture/desktop-ptt-architecture.md`; ID totals advance to 302 / 148 / 203 / 79 / 92; naming, undefined-reference, and direct-layer-rule counts remain at zero. |
| 0.9.4 | 2026-05-15 | P0 audit follow-up: ID totals advance to 302 / 148 / 203 / 80 / 93 after adding `SAD-080` (sources SRS-200) and `SDD-093` (sources SAD-080). Direct-layer-rule and undefined-reference counts remain zero. |
@@ -1,72 +0,0 @@
# Repository Bootstrap Plan
**Document type:** Governance / Repository Bootstrap Plan
**Version:** 0.1.0
**Status:** Draft
**Language:** English
**Product:** Chanora
**Repo path:** `docs/governance/repository-bootstrap-plan.md`
---
## 1. Purpose
This document defines the files and directories that should exist before product implementation begins.
## 2. Bootstrap Scope
This bootstrap package intentionally excludes CI workflow files.
The goal is to establish:
- repository metadata;
- contributor guidance;
- security policy;
- changelog;
- license placeholder;
- notice placeholder;
- editor and ignore rules;
- local command placeholders;
- documentation validation script;
- future scaffold plan.
## 3. Required Root Files
| File | Purpose |
|---|---|
| `README.md` | App/project overview |
| `CONTRIBUTING.md` | Contribution rules |
| `SECURITY.md` | Security reporting and security gates |
| `CHANGELOG.md` | Release/change history |
| `LICENSE` | License placeholder until final license decision |
| `NOTICE` | Non-affiliation and attribution placeholder |
| `.editorconfig` | Editor formatting baseline |
| `.gitignore` | Ignore rules |
| `.env.example` | Safe local environment template |
| `justfile` | Local command entrypoint |
## 4. Required Tooling Files
| File | Purpose |
|---|---|
| `tools/validate_docs.py` | Local documentation and traceability validation |
## 5. Future Work
CI workflow files should be added later after this bootstrap is committed and the repo structure is accepted.
Recommended later CI files:
```text
.github/workflows/docs.yml
.github/workflows/repo-health.yml
.github/workflows/flutter.yml
.github/workflows/rust.yml
.github/workflows/security.yml
```
## 6. Change History
| Version | Date | Description |
|---|---|---|
| 0.1.0 | 2026-05-14 | Initial repository bootstrap plan excluding CI. |
-111
View File
@@ -1,111 +0,0 @@
# Staged MVP release plan — DEC-002 channels
| Version | Date | Status |
|---|---|---|
| 0.1.0 | 2026-05-15 | Initial draft alongside v1.0.0-rc.1 |
## Purpose
DEC-002 in `product-decision-register.md` accepts a five-platform
MVP target (Windows, macOS, Linux, Android, iOS) and explicitly
permits a **staged release** in which not all platforms ship on the
same day. This document records the staging plan for the MVP public
release.
## Channel definitions
* **GA — Linux desktop**: x86_64 GNU/Linux. Direct distribution
via the GitHub Releases page (release tarball + AppImage when
the bundle is added). No app store.
* **GA — Android**: arm64-v8a APK. Direct distribution from the
Releases page during early MVP. Play Store submission deferred
until DEC-012 legal sign-off includes Play-specific consumer-
protection review (`docs/governance/legal-review-readiness.md`
§9). Other Android ABIs (armeabi-v7a, x86_64) are deferred to
v1.1.
* **Beta — Windows**: x86_64 MSI / portable zip. The build steps
are documented in `docs/release/windows-build.md`; a live
artefact has not yet been produced because the development
toolchain ran on Linux. Public bits land once a Windows builder
produces a signed artefact.
* **Beta — macOS**: Apple Silicon (`aarch64-apple-darwin`) + Intel
(`x86_64-apple-darwin`) universal `.app`. Same gating as Windows:
build documentation only at v1.0.0-rc.1; an Apple-side builder
must produce a notarised artefact.
* **Beta — iOS**: arm64 IPA. Same gating; in addition the
`mobile_voice_preset` AAudio engagement on Android is documented
as a routing hint, and the iOS equivalent
(`AVAudioSession.Mode.voiceChat`) is not yet wired.
## Promotion schedule
Each row triggers when the listed prerequisite is satisfied. There
is no calendar.
| Order | Channel | Prerequisite |
|---|---|---|
| 1 | Linux GA | DEC-012 legal sign-off; `v1.0.0` tag cut from `v1.0.0-rc.N` after all RC reviews close. |
| 2 | Android GA (sideload) | Same prerequisite; APK signed with the project key; Releases page updated. |
| 3 | Android Play Store | DEC-012 §9 Play-listing review complete; signing key migrated to Play App Signing if not already there. |
| 4 | Windows Beta | Live x86_64 Windows builder produces a signed MSI; smoke test on a Windows 11 host that the build host can verify. |
| 5 | macOS Beta | Live `aarch64-apple-darwin` build with code-signing certificate and notarisation; smoke test. |
| 6 | iOS Beta | TestFlight build cycle; per-device entitlement review; mic permission flow validated. |
| 7 | Windows / macOS / iOS GA | Each platform promoted from Beta after its first round of public-Beta feedback is triaged. |
## Per-platform readiness as of v1.0.0-rc.1
### Linux x86_64
* Cargo build: green (`cargo check --workspace`, `cargo test
--workspace` with `CHANORA_DISABLE_KEYRING=1`).
* Flutter build: `flutter build linux --release` documented; live
bundle exists at `apps/chanora_flutter/build/linux/x64/`.
* Audio: cpal-on-PipeWire / ALSA verified through Beta lifecycle.
* Secure storage: Secret Service via D-Bus when a session is
available; file-fallback when not.
* Status: **GA-ready** pending DEC-012.
### Android arm64-v8a
* Cargo + cargo-ndk build: green; the APK pipeline produced
`app-release.apk` for v0.4.0-beta.2.
* Audio: cpal-on-AAudio with `AudioManager.MODE_IN_COMMUNICATION`
engaged via JNI on engine start.
* Secure storage: keyring crate falls back to file on Android in
v1.0.0-rc.1 (no Android Keystore wiring yet). The identity and
bookmark passwords remain ChaCha20-Poly1305-encrypted under the
file-DEK in this configuration.
* Status: **GA-ready for sideload** pending DEC-012; Play Store
promotion is a separate gate.
### Windows / macOS / iOS
* Build docs exist (`docs/release/windows-build.md`,
`docs/release/ios-build.md`); macOS does not have a dedicated
doc yet because the build is a straightforward
`flutter build macos` once Apple-side signing is configured.
* Status: **Beta-track**. The RC tag still ships for these
platforms in source form (anyone with the appropriate toolchain
can build), but no signed binary is included.
## Rollback policy
Each platform's Releases-page artefact carries the exact `v1.0.0-rc.N`
or `v1.0.0` tag. If a critical regression surfaces in a channel:
1. Mark the affected Releases asset "deprecated — do not download" in
the GitHub UI within 24h.
2. Cut a `v1.0.x` patch from the `release-1.0` branch (created
when `v1.0.0` is tagged).
3. Re-promote per the schedule above; no platform fast-tracks the
schedule, no platform skips a channel.
## Out-of-scope for MVP
* iOS hardware AEC engagement (`AVAudioSession.Mode.voiceChat`).
* Android `setInputPreset(VOICE_COMMUNICATION)` (RISK-AUDIO-MOBILE-001).
* Android Keystore-backed DEK (the file-fallback path is exercised in
the current build).
* Multi-server connection (DEC-006: explicitly out of MVP).
* Crash reporting (DEC-017: explicitly disabled).
* Automatic diagnostic upload (DEC-016: user-initiated only).
File diff suppressed because it is too large Load Diff