Releases: Harzva/mobilecode
Release list
MobileCode v0.1.78
MobileCode v0.1.78
Release type: local-model linkage and Android background-safety pre-release patch.
Scope
- Parse MobileCore's public
background_restrictedhealth state, retain active-model metadata for diagnosis, and remove a restricted runtime from eligible local routes. - Reject local inference with a typed
background_restrictederror before sending prompts or attachments, while showing a user-controlled Android Battery-settings recovery instruction. - Keep a restricted but loaded model visible in the coherent MobileCore runtime snapshot instead of misclassifying the control plane as inconsistent.
- Activate the pinned Omni runtime for a selected local image or audio task only when both artifacts are verified, then re-check the live capability before sending media bytes.
- Project post-switch memory from the coherent runtime snapshot, count only bounded matching active-runtime memory as reclaimable, retain 10% headroom, and reduce context under pressure.
- Revalidate the active runtime immediately before model load so a concurrent model, backend, capability, quantization, or background-state change fails without sending the lifecycle request.
- Preserve the v0.1.77 public-build credential policy: no provider keys, relay bearer tokens, or OAuth client secrets are compiled into distributed Android/iOS binaries.
Acceptance gates
- Focused MobileCore provider and adaptive-policy tests cover restricted probing, zero-payload inference rejection, coherent restricted snapshots, and verified Omni activation.
- The full Flutter test suite and targeted analyzer complete without fatal diagnostics.
- The final client regression passes 582 Flutter tests; the Android 16 ARM64 emulator passes 30/30 offline cross-app tasks with the rebuilt v0.1.78 APK.
- The exact upload-signed
0.1.78+68APK passes version, certificate, credential-pattern, install, cold-launch, and fatal-log checks. - With MobileCode foregrounded, MobileCore
0.1.4-rc6retains a real local model for 40 authenticated health polls and one controlled inference without FGS timeout, freeze, ANR, OOM, or SIGABRT.
Published verification
- Final tag-triggered Android workflow 31134596808 passed from merge commit
4275c76, including the public-credential policy, source analysis, stable signing, release build, version check, workflow artifact, and GitHub Release upload. - The final published
mobilecode-v0.1.78.apkis 33,073,027 bytes with SHA-2565123f48f93161838b166259061857b058ab63429051544e4ac0234088a886073; the downloaded workflow artifact exactly matches the GitHub Release digest. - APK Signature Scheme v2 verifies with certificate subject
CN=MobileCode, OU=MobileCode, O=Harzva, L=Shanghai, ST=Shanghai, C=CNand certificate SHA-25635a6eee3e2d81d4c6b5d426984d1b04d7d5ffc3eae7707c6225f5decd80fa2da. - Post-download AOT scanning found zero recognizable GitHub-token, provider-key, bearer-token, JWT, or concrete private-host-path values.
- A clean Android 16 ARM64 emulator install reported
0.1.78+68; the final asset then cold-launched in 479 ms with controlled permissions, renderedv0.1.78andTuiMa 就绪, and produced no fatal exception, ANR, OOM, or SIGABRT marker. MobileCore remained a foreground protocol-v2 service with the real local Qwen2.5 model ready. - iOS Simulator workflow 31135405199 rebuilt the generated iOS project, verified
0.1.78+68plus top-level microphone and speech-recognition usage descriptions, built the simulator app, installed it, kept the same process alive through the smoke interval, rejected known privacy/crash signatures, and retained the screenshot and Runner log as private workflow artifacts. - Unsigned iOS archive workflow 31135408249 built and packaged the
0.1.78+68device.xcarchivesuccessfully. Both iOS runs usedupload_to_release=false; simulator and unsigned-archive evidence do not replace signed physical-iPhone acceptance.
Remaining gates
Emulator evidence does not satisfy physical Android thermal/background recovery, controlled-account login, verified Qwen2.5-Omni audio, or iOS background inference acceptance. MobileCore remains inference-only; MobileCode continues to own Phone Use, transaction risk, one-shot approvals, credentials, cloud consent, and ActionEvidence.
MobileCode v0.1.77
MobileCode v0.1.77
Release type: security hardening pre-release patch.
Scope
- Remove raw managed-provider API keys, DeepSeek keys, relay bearer tokens, and OAuth client secrets from every public Android and iOS build workflow.
- Allow only non-secret public configuration in distributed binaries: managed relay URL, OAuth client ID, and OAuth redirect URI.
- Enable managed MiMo/DeepSeek presets in public builds only when a relay URL is configured; otherwise users provide their own key through MobileCode's secure-storage flow.
- Add a fail-closed repository policy check to every public build job so a later workflow edit cannot silently restore forbidden credential inputs.
- Preserve the MobileCore v2 handshake, model controls, adaptive local routing, attachment capability gates, cancellation, and redacted ActionEvidence behavior from v0.1.76.
- Keep MobileCore as the local inference engine and MobileCode as the orchestration, Phone Use, approval, and evidence authority.
Acceptance gates
- Policy unit tests reject forbidden secret references and runtime-key Dart definitions while allowing release-signing secrets and public configuration.
- All public release workflows pass the credential policy and YAML parsing checks.
- A clean
pureReleaseAPK reports0.1.77+67, contains no recognizable managed-provider credential values, and verifies with the MobileCode release certificate before publication. - The exact published APK installs and cold-launches on the Android emulator. A controlled MobileCore local request remains a separate open gate until MobileCore preserves foreground-service state across notification updates.
- Emulator evidence does not satisfy physical-device thermal, background-recovery, controlled-account, or verified Omni audio gates.
Published verification
- Android workflow 31128587598 passed the credential policy, source analysis, release signing, APK build, version check, artifact upload, and Release upload from merge commit
d031692. - The downloaded
mobilecode-v0.1.77.apkis 33,046,287 bytes with SHA-256f008ede0e0305c835c3bf45bcc56f22c4fc911d0ae10b513f298d1bdfb0a1c1d; that matches the GitHub asset digest and reports0.1.77+67. - APK Signature Scheme v2 verifies with certificate subject
CN=MobileCode, OU=MobileCode, O=Harzva, L=Shanghai, ST=Shanghai, C=CNand certificate SHA-25635a6eee3e2d81d4c6b5d426984d1b04d7d5ffc3eae7707c6225f5decd80fa2da. - Post-download AOT scanning found zero recognizable provider-key, GitHub-token, bearer-token, JWT, or private-host-path patterns. The workflow log also contained zero forbidden runtime-credential variable names.
- After a clean install, Android reported version code 67 and version name 0.1.77; the UI rendered
v0.1.77, the process stayed alive, and logcat contained no fatal exception, ANR, OOM, or SIGABRT marker. - MobileCore
0.1.4-rc4still passed its v2 health and model-load controls while foregrounded. When MobileCode became active, Android reported MobileCore's service asisForeground=falseand froze its process despite the visible notification, so the exact published APK's local-chat pairing is deliberately not claimed yet.
MobileCode v0.1.76 (official APK withdrawn)
MobileCode v0.1.76
Release type: pre-release patch.
Distribution notice (2026-08-07): the official
mobilecode-v0.1.76.apk
asset was withdrawn after post-build review found that the old public build
workflow supplied runtime service credentials as Dart compile definitions.
The remaining explicitly named debug-signed APK is QA-only. No credential
value is recorded here; affected provider credentials should be rotated at
their providers. Use v0.1.77 or later for public distribution.
Scope
- Require a
mobilecore.localv2 protocol handshake before MobileCore model control or inference. - Fail closed with
protocol_missing,protocol_invalid,protocol_unsupported, orservice_mismatchinstead of sending control requests to an incompatible loopback service. - Confirm the requested model remains active before every local inference request.
- Give local inference at least three minutes and convert transport timeouts to a typed, redacted
inference_timeoutfailure. - On timeout or explicit Agent pause, call MobileCore's authenticated inference-cancel endpoint so native decoding does not continue after the client stops waiting.
- Use the last measured local decode rate to cap the next response budget on very slow or constrained runtimes.
- Surface MobileCore's
runtime_busyresult when another request owns the shared llama context. - Preserve the v0.1.75 one-task cloud approval boundary: declining cloud inference stays local or fails closed, and does not grant Phone Use, login, payment, or ordering authority.
- Keep prompts, media, credentials, and generated content out of protocol and cancellation evidence.
Acceptance gates
- MobileCore
0.1.4-rc4publishes the exact protocol name, major/minor, and supported client-major range from/health. - Client tests prove incompatible protocols cannot reach model-control or chat endpoints.
- A clean Android
pureReleaseAPK reports0.1.76 (66)and pairs with MobileCore0.1.4-rc4on the emulator. - The paired emulator completes one real local text request; its measured latency is emulator evidence only.
- Release assets identify signing status. Emulator pairing does not satisfy physical-device thermal, low-memory, background-recovery, controlled-account, or 30-task gates.
Published verification
- Android workflow 31128209900 completed source analysis, release signing, APK build, version consistency, artifact upload, and GitHub Release upload from merge commit
0860190. - A fresh download of
mobilecode-v0.1.76.apkis 33,053,383 bytes with SHA-25652c53c26d51d6335588a443fd3f84f9a36ed9ac093de79a4238a23b2ff3ead31and reports0.1.76+66. - The official APK verifies with APK Signature Scheme v2 and the MobileCode release certificate (
CN=MobileCode, O=Harzva), not the Android Debug certificate. - After removing the differently signed QA build, the official APK installed on an Android 16 ARM64 emulator, cold-launched through the microphone permission sheet, resumed
MainActivity, and completed a real TuiMa Local request with the exact answerOKwithout a crash, ANR, OOM, or SIGABRT marker. - The separate
mobilecode-v0.1.76-debug-signed-qa.apkremains explicitly labeled QA evidence and has SHA-2564c0592cf7e0c1fd45145e3eaced74f405c5fe6fa96f72e7dcbd83a9657a8da11.
MobileCode v0.1.75
MobileCode v0.1.75
Release type: pre-release patch.
Scope
- Require a one-task approval before a long-context or Agent task opens a cloud inference request.
- Route a declined request to MobileCore, or cancel it when the local runtime is unavailable; never silently fall back to cloud.
- Keep Phone Use, login, payment, and ordering outside the cloud-inference approval scope.
- Store only a safe approval identifier, decision, provider preset, scope, and redacted routing state in ActionEvidence.
Acceptance gates
- Flutter tests and release-version consistency checks pass for
0.1.75+65. - A clean Android
pureReleaseAPK reports version0.1.75 (65)and cold-launches without crash, ANR, or OOM. - The real Android emulator UI displays the approval card before provider access, and decline stays local without cloud fallback.
- Release assets must identify their signing status; a debug-signed QA artifact must not be presented as a production-signed APK.
Published verification
- Android workflow 31127234312 completed all release, version-check, artifact, and upload steps successfully from the tagged merge commit.
- The published
mobilecode-v0.1.75.apkis 33,047,539 bytes with SHA-25666e7a26bb7efa4b3c6f959b3e8063fb05a25f91e5b13463211c80c60da5272e2; a fresh GitHub download reports0.1.75+65. - The official APK verifies with APK Signature Scheme v2 and the MobileCode release certificate (
CN=MobileCode, O=Harzva), not the Android Debug certificate. - The downloaded official APK installed on an Android 16 ARM64 emulator. Its first cold launch reached the system microphone-consent sheet in 1.254 seconds; dismissing the sheet restored
MainActivity, kept the app process alive, and produced no crash, ANR, or OOM signal. - The separate asset named
mobilecode-v0.1.75-debug-signed-qa.apkremains explicitly labeled as QA evidence and has SHA-256ca6d6908b3c4d315a76adf5d974c4e923df2a3acd9d43d6566a2fad074a0511d.
Physical-device background recovery, low-memory/thermal behavior, controlled login, the full 30-task Android/iOS acceptance matrix, and verified Omni image/audio quality remain separate gates.
MobileCode v0.1.74
MobileCode v0.1.74
Release type: pre-release patch.
Scope
- Harden the MobileCoreClient v2 control plane with atomic runtime snapshots, exact active-model checks, public model/projector identifiers, and explicit load, switch, unload, preflight, recommendation, and metrics handling.
- Route offline and privacy-sensitive tasks before cloud transport, and honor memory/thermal pressure when choosing or switching local models.
- Keep MobileCore responsible only for local inference. MobileCode continues to own orchestration, Phone Use, approvals, device actions, and ActionEvidence.
Acceptance gates
- Flutter tests and release-version consistency checks pass for
0.1.74+64. - A clean Android
pureReleaseAPK reports version0.1.74 (64)and cold-launches without crash, ANR, or OOM. - Dual-app emulator evidence confirms exact model discovery/switching and coherent health/preflight/metrics state.
- Release assets must identify their signing status; a debug-signed QA artifact must not be presented as a production-signed APK.
Physical-device background recovery, low-memory/thermal behavior, controlled login, and the full 30-task Android/iOS acceptance matrix remain separate gates.
MobileCode v0.1.73
MobileCode v0.1.73
Release type: pre-release patch.
Scope
- Keep the MobileCode-to-MobileCore local model discovery, capability, load/unload, model switching, and image-input integration from v0.1.71/v0.1.72.
- Write microphone and speech-recognition usage descriptions into the root dictionary of regenerated iOS
Info.plistfiles. - Verify iOS bundle version and required privacy keys before simulator installation.
- Reject TCC privacy-description crashes and other known fatal launch signatures before publishing iOS simulator assets.
Why this patch exists
The v0.1.72 Android APK passed signed release and emulator smoke verification. Post-build inspection found that the regenerated iOS project placed speech permission descriptions in a nested URL dictionary, causing the simulator app to terminate during launch. The old smoke grep did not recognize that TCC message. The affected iOS simulator evidence was removed from the v0.1.72 release; its verified Android APK remains available.
Acceptance gates
- Python regression tests cover top-level plist insertion, idempotence, nested-key rejection, and TCC crash-log rejection.
- Flutter tests and release-version consistency checks pass for
0.1.73+63. - The iOS Simulator build exposes both required privacy descriptions at the top level, remains running after the smoke interval, and produces an in-app screenshot and clean log.
- The Android release APK reports
0.1.73 (63), verifies with the stable MobileCode signing certificate, and clean-launches on the release emulator.
Exact workflow links, artifact hashes, and simulator evidence are added after the release jobs complete.
MobileCode v0.1.72
MobileCode v0.1.72
This patch preserves the MobileCore local multimodal integration delivered in v0.1.71 and closes a version-consistency defect found during installed-release QA.
Highlights
- Use one in-app version definition for the home screen, release link, and update service.
- Align package metadata, GitHub Pages update feed, release links, and Android asset naming on
0.1.72+62. - Reject release APKs whose manifest version and embedded Flutter AOT release label do not match, preventing stale incremental-build payloads from being published.
- Preserve model discovery, modality reporting, projector pairing, local model switching, and local image request support from v0.1.71.
Verification
- The complete Flutter suite passed 544 tests in the merge-commit Runtime CI run.
- The signed Android workflow passed build, version consistency, artifact, and GitHub Release upload from merge commit
81e8d7d. - The downloaded APK SHA-256 is
acdada50092e7aa2e9727ee8a45e9c20f4c977b4be6e7c21f0ce48e1be955101; the GitHub Release digest matched. - The APK reports
0.1.72 (62), verifies with the MobileCode release certificate, and clean-launched with thev0.1.72home label on the dedicated Android 16 ARM64 emulator. - The post-launch scan found no MobileCode crash, ANR, or OOM signature.
Evidence boundary
The emulator verifies packaging and the MobileCode/MobileCore integration contract. Physical Android/iOS background, thermal, battery, and Qwen2.5-Omni image/audio quality gates remain open.
MobileCode v0.1.71
MobileCode v0.1.71
This candidate completes the MobileCode side of MobileCore's generic local-vision pair contract while preserving the existing orchestration and Phone Use boundary.
Highlights
- Parse model-level modality capabilities and projector metadata from MobileCore without receiving local paths.
- Mark installed models with an image capability before selection, then continue to use active
/healthas the truth for enabling attachment input. - Keep loading and switching based on public model IDs; MobileCore owns compatible projector pairing and validation.
- Add a strict dual-app QA option that fails model-switch acceptance when no second model is present.
- Preserve local-only attachment handling and redacted inference ActionEvidence.
Verification
- The complete MobileCode Flutter suite passed 543 tests; focused client coverage includes projector metadata and image-capability parsing.
- MobileCore Android unit/build gates and targeted API instrumentation passed.
- The emulator dual-app lane passed 30 offline real-GGUF requests and a Qwen2.5-to-Qwen3 switch.
- A real Qwen3.5 main GGUF/mmproj pair completed a local image request through the unified OpenAI-compatible API with no crash, ANR, or OOM.
Evidence boundary
The real image chain is execution evidence, not an accuracy claim: the controlled image was classified incorrectly. Physical Android acceptance, verified Qwen2.5-Omni audio/image acceptance, physical thermal/background behavior, and a labeled vision-quality benchmark remain open gates. See the detailed report.
MobileCode v0.1.70
MobileCode v0.1.70
This release connects MobileCode to MobileCore as a dynamic, capability-aware local inference engine while preserving the product boundary: MobileCode remains responsible for orchestration, Phone Use, approvals, transaction safety, and evidence.
Highlights
- Discover the active MobileCore model, backend, runtime revision, quantization, capabilities, resource preflight, recommendations, and performance metrics.
- Load, unload, and switch installed models using public model IDs; local model paths are not exposed to MobileCode.
- Show local image/audio entry points only when the active runtime advertises those inputs.
- Keep attachment bytes local and ephemeral; local-only media never falls back to a cloud provider.
- Adapt local routing under privacy, offline, memory, thermal, battery, media, and complex-task conditions.
- Record local inference in ActionEvidence without prompts, media, credentials, cookies, tokens, or raw payloads.
- Add a repeatable same-device MobileCode ↔ MobileCore Android QA lane.
Verification
- 90 focused Flutter routing, provider, adaptive-policy, and evidence tests passed.
- MobileCode
pureDebugand Android test APKs built successfully. - MobileCore unit and targeted Android API instrumentation tests passed.
- 30 real offline cross-app tasks passed on Android emulator: 15 buffered and 15 SSE.
- Model unload/reload, background continuity, low-memory notification, and process restart recovery passed.
Evidence Boundary
This release does not claim physical-device acceptance, verified Omni image/audio inference, real cross-model switching, or physical thermal performance. The acceptance host had one Android emulator, one installed text model, and no physical Android device. See the detailed report.
MobileCode v0.1.69
MobileCode v0.1.69 Phone Use controlled-evaluation candidate.
Highlights:
- Controlled 30-task Phone Use evaluation contract and verifier.
- Semantic snapshots and short-lived element references.
- ActionEvidence integration and safer approval evidence.
- Android emulator action probe and hardened release smoke gate.
Validation:
- Android emulator smoke passed before merge.
- Mobile Runtime CI passed.
- Local release manifest: versionName 0.1.69, versionCode 59.
Boundary: this is a prerelease evaluation candidate. It does not claim validated real-device autonomous ordering or real financial transaction capability.