chore(release): bump to 1.16.0

app 1.15.2 -> 1.16.0, appCode 460 -> 461. That single edit drives Android's
versionName/versionCode, Desktop and CLI packageVersion, quartz's Maven version
and geode's RelayInfo.VERSION; verified by reading the version back out of
:amethyst, :quartz and :geode and from a built APK (versionCode 461,
versionName 1.16.0-DEBUG).

Roughly twenty substantive PRs since v1.15.2, written up in
docs/changelog/v1.16.00.md. The ones a user feels:

- My Fitness: a training dashboard built from both sources Amethyst has --
  Health Connect and the user's own kind 1301 events -- so it works with no
  health permission at all. Workouts gains a "Mine" filter in the top nav, and
  a workout that is already published no longer offers to post itself twice.
- BOLT12 offers move into the profile payment rail, where every other payment
  route already lived, and the zap picker finally shows a bolt for a recipient
  who publishes an offer and no lightning address. A refused offer falls back
  to BOLT11, retried only on codes that mean nothing was attempted.
- Blossom uploads work again. 1.15.0's unpadded base64url token is rejected by
  deployed servers, so about two uploads in three had been failing since then.
- A relay that sends a CLOSE frame is no longer counted as connected for up to
  four minutes with its REQs live, in both the shared and the Android socket.
- Arti 2.3.0 -> 2.6.0 for TROVE-2026-24 and TROVE-2026-27.
- amy ships ~40 MB lighter after the commonsUI split.

Changelog claims were checked against the final state of each series, not the
first commit: the BOLT12 retry set is the narrowed allowlist from the audit
follow-up (a PAYMENT_FAILED can still settle, so retrying it could pay twice),
the relay count comes from the connected flow rather than the removed members
snapshot, and the OkHttp dispatcher resize is absent because it was reverted.

NEEDS A MAINTAINER BEFORE THE TAG: RELEASE_NOTES_ID still points at the v1.15.0
note. RELEASE_OPS repoints it on every x.y.0, which this is, and it has to be
published from Amethyst's own account -- so it is not something this commit
could do.

Also left alone: docs/changelog/translators.json, whose sinceLastTag is seeded
with vitorpamplona credited for all 41 languages and ~50 users with no language
at all, so scripts/translators.sh output is unusable this cycle. The changelog
credits the three translators with real attribution. mstrofnone (the desktop
keychain fixes) has no npub in mappings and is credited by handle.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Vitor Pamplona
2026-09-17 13:33:54 -04:00
co-authored by Claude Opus 5
parent 232c676e79
commit dc866d3568
9 changed files with 144 additions and 23 deletions
+3 -3
View File
@@ -7,7 +7,7 @@ description: Integration guide for using the Quartz Nostr KMP library in externa
Reference for integrating `com.vitorpamplona.quartz:quartz` into external Nostr KMP projects.
**Published artifact**: `com.vitorpamplona.quartz:quartz:1.15.2` (Maven Central)
**Published artifact**: `com.vitorpamplona.quartz:quartz:1.16.0` (Maven Central)
**Targets**: JVM 21+, Android (minSdk 21+), iOS (XCFramework `quartz-kmpKit`)
**License**: MIT
@@ -19,7 +19,7 @@ Reference for integrating `com.vitorpamplona.quartz:quartz` into external Nostr
```toml
[versions]
quartz = "1.15.2"
quartz = "1.16.0"
[libraries]
quartz = { module = "com.vitorpamplona.quartz:quartz", version.ref = "quartz" }
@@ -41,7 +41,7 @@ kotlin {
```kotlin
dependencies {
implementation("com.vitorpamplona.quartz:quartz:1.15.2")
implementation("com.vitorpamplona.quartz:quartz:1.16.0")
}
```
@@ -3,7 +3,7 @@
## Current version
```
com.vitorpamplona.quartz:quartz:1.15.2
com.vitorpamplona.quartz:quartz:1.16.0
```
Check latest: https://central.sonatype.com/artifact/com.vitorpamplona.quartz/quartz
@@ -16,7 +16,7 @@ Check latest: https://central.sonatype.com/artifact/com.vitorpamplona.quartz/qua
```toml
[versions]
quartz = "1.15.2"
quartz = "1.16.0"
[libraries]
quartz = { module = "com.vitorpamplona.quartz:quartz", version.ref = "quartz" }
@@ -55,7 +55,7 @@ kotlin {
```kotlin
// build.gradle.kts (app module)
dependencies {
implementation("com.vitorpamplona.quartz:quartz:1.15.2")
implementation("com.vitorpamplona.quartz:quartz:1.16.0")
}
```
@@ -70,7 +70,7 @@ plugins {
}
dependencies {
implementation("com.vitorpamplona.quartz:quartz:1.15.2")
implementation("com.vitorpamplona.quartz:quartz:1.16.0")
// JNA needed for libsodium (NIP-44) on JVM
implementation("net.java.dev.jna:jna:5.18.1")
}
+4 -4
View File
@@ -534,7 +534,7 @@ reads an optional per-release changelog from
## Bootstrap runbook (one-time)
> **Status as of v1.15.2:** both Homebrew packages are now live upstream — the
> **Status as of v1.16.0:** both Homebrew packages are now live upstream — the
> `amethyst-nostr` cask (`Homebrew/homebrew-cask`, at 1.14.0) and the `amy`
> formula (`Homebrew/homebrew-core`) both answer 200 on `formulae.brew.sh`, so
> `bump-homebrew.yml` finally has something to bump. **Winget is still not
@@ -588,7 +588,7 @@ The token then lives only in that maintainer's shell:
```bash
export HOMEBREW_GITHUB_API_TOKEN=ghp_... # classic PAT, `repo` scope
scripts/bump-homebrew-cask.sh v1.15.2
scripts/bump-homebrew-cask.sh v1.16.0
```
Create one at
@@ -604,7 +604,7 @@ Same split, and it needs **no token at all**. `scripts/bump-winget.sh` drives
runs fine from macOS or Linux:
```bash
scripts/bump-winget.sh v1.15.2
scripts/bump-winget.sh v1.16.0
```
CI (`bump-winget.yml`, `GITHUB_TOKEN` only) does the bookkeeping: downloads the
@@ -690,7 +690,7 @@ Caveats that the maintainer must weigh before submitting:
- **Bundle size.** The bundle used to be ~70 MB because `:commons` leaked
Compose/Skiko jars onto the CLI classpath. Compose UI now lives in
`:commonsUI`, which `:cli` does not depend on: the JVM tarball is ~55 MB
and the jlink image tarball ~80 MB (1.15.2, Linux x64). The release
and the jlink image tarball ~80 MB (1.16.0, Linux x64). The release
workflow caps every amy asset at 120 MB.
After the formula merges, the `livecheck` block lets homebrew-core's BrewTestBot
+5 -5
View File
@@ -328,16 +328,16 @@ repositories {
Add the following line to your `commonMain` dependencies:
```gradle
implementation('com.vitorpamplona.quartz:quartz:1.15.2')
implementation('com.vitorpamplona.quartz:quartz:1.16.0')
```
Variations to each platform are also available:
```gradle
implementation('com.vitorpamplona.quartz:quartz-android:1.15.2')
implementation('com.vitorpamplona.quartz:quartz-jvm:1.15.2')
implementation('com.vitorpamplona.quartz:quartz-iosarm64:1.15.2')
implementation('com.vitorpamplona.quartz:quartz-iossimulatorarm64:1.15.2')
implementation('com.vitorpamplona.quartz:quartz-android:1.16.0')
implementation('com.vitorpamplona.quartz:quartz-jvm:1.16.0')
implementation('com.vitorpamplona.quartz:quartz-iosarm64:1.16.0')
implementation('com.vitorpamplona.quartz:quartz-iossimulatorarm64:1.16.0')
```
Check versions on [MavenCentral](https://central.sonatype.com/search?q=com.vitorpamplona.quartz)
+2 -2
View File
@@ -240,9 +240,9 @@ readable by anyone with push access here), so a maintainer runs the last step:
```bash
# after merging the sync PRs
export HOMEBREW_GITHUB_API_TOKEN=ghp_... # classic PAT, `repo` scope
scripts/bump-homebrew-cask.sh v1.15.2
scripts/bump-homebrew-cask.sh v1.16.0
scripts/bump-winget.sh v1.15.2 # no token — uses your `gh` auth
scripts/bump-winget.sh v1.16.0 # no token — uses your `gh` auth
```
Both scripts re-verify the published artifact's sha256 before submitting, and
+1
View File
@@ -2,6 +2,7 @@
Release notes for Amethyst, one file per version. Files are named with zero-padded version numbers so they sort correctly in any file browser. Use [`TEMPLATE.md`](TEMPLATE.md) as the starting point for the next release.
- [v1.16.0 — My Fitness, BOLT12 Payments, and a Leaner Core](v1.16.00.md)
- [v1.15.2 — Media Previews, Nested Replies, and Health Connect](v1.15.02.md)
- [v1.15.1 — Release Build Fix](v1.15.01.md)
- [v1.15.0 — Marmot Updates, a Advanced Search Box, and Books, DVM Updates](v1.15.00.md)
+120
View File
@@ -0,0 +1,120 @@
# v1.16.0: My Fitness, BOLT12 Payments, and a Leaner Core
Highlights:
- Adds **My Fitness**, a dashboard over everything you have trained.
- Moves **BOLT12 offers** into the profile payment rail, and zaps over BOLT11
when a wallet refuses one.
- Opens the **zapped note** from wallet history.
- Fixes **Blossom uploads**, broken on most servers since 1.15.0.
- Takes **~40 MB off every `amy` distribution**.
- Stops counting a relay that hung up as connected.
- Updates **Arti to 2.6.0** for two medium-severity fixes.
## New Features
### My Fitness
- Adds a training dashboard, reached from the drawer or a pinned bottom-bar slot.
- Builds it from both sources: Health Connect, and the kind 1301 workouts you
published. Neither is required.
- Summarises four weeks: this week against last, weekly averages, a breakdown by
activity, best efforts, active days and a day streak.
- Shows distance, calories, steps, climb and heart rate only when a workout
carries them.
- Offers to share a workout only when it is not already published.
- Prefers the Health Connect copy when the same effort appears in both sources —
it carries the heart rate, steps and climb the published event drops.
- Filters the Workouts feed by **Mine** from the top nav.
- Reads workouts in the POWR dialect, which carry `start`/`end` and no `duration`.
### Payments
- Renders each BOLT12 offer as a chip in the profile payment rail. Offers were
already payable, but only through a small button in the profile header.
- Removes both header wallet buttons. The rail lists everything they reached.
- Shows the zap bolt to recipients who publish an offer and no lightning address.
The send path already paid them; the picker just never offered it.
- Falls back to a BOLT11 zap when a wallet refuses an offer and the recipient also
publishes a lightning address.
- Retries only refusals that mean nothing was attempted. A `PAYMENT_FAILED` can
still settle later, so retrying it could pay twice.
- Reports a timeout when a wallet never answers, instead of hanging the zap.
- Opens the zapped note when you tap a zap in wallet history.
## Performance
- Stops emptying the media connection pool on every client rebuild. Both HTTP
clients share one pool, so the proxy check misread every rebuild as a route
change.
- Drops pooled connections once per real Tor route change instead.
- Stops `debugState()` walking the whole cache on every backgrounding. Its nine
scans were built eagerly and then discarded unread.
- Signs one Blossom read-auth token per server, not one per racing caller.
## Improvements and Bug fixes
- Sends the Blossom authorization token as standard padded Base64 again. Deployed
servers reject 1.15.0's unpadded base64url, so roughly two uploads in three
failed.
- Points the Sovbit default Blossom server at `files.sovbit.host`.
- Answers a relay's WebSocket CLOSE frame, in both the shared and the Android
socket. Without it a closed socket looked connected for up to four minutes,
silently discarding everything sent.
- Counts connected relays from the pool's connected flow, which the pool now
clears itself whenever it drops a relay.
- Renders a GIF with no `imeta` as a loading placeholder. It used to collapse the
whole note to a gap in the feed until the fetch finished.
- Drains the event-sync outbox before closing the client. Events from the final
page were reported Done and never delivered.
- Fixes 34 bugs found auditing `commons` and `commonsUI`. Among them: AES-GCM
initialised with a spec every JDK rejects; an `Onion-Location` header from any
host re-pointing Tor traffic for 24 hours; a bundled insert wedged after one
exception; a URL validator backtracking exponentially per keystroke.
- Uses `https` in preview data and image-URL placeholders.
## Desktop
- Stops a silent account wipe on macOS. One Deny on the Keychain prompt rotated
the encryption key and orphaned every saved account.
- Consolidates the keychain into a single `vault-v1` item, so a cold boot prompts
once.
- Allows first-launch key bootstrap on Linux and Windows.
## Cli
- Ships ~40 MB lighter, now that `amy` no longer drags Compose UI and Skiko behind
`commons`.
- Fails fast when a buzz-agent wrapper cannot be made executable.
## Quartz
- Answers a duplicate `EVENT` with `OK true`, per NIP-01, and a superseded
replaceable the same way. Clients used to get raw SQLite text they could not
classify, and retried forever.
- Gives each socket adapter its own session, removing the pool's locking and
identity checks.
## Build & Documentation
- Updates Arti 2.3.0 → 2.6.0, the JNI crate to 0.22, the NDK to r30 and Rust to
1.98.1. Picks up TROVE-2026-24 and TROVE-2026-27, both reachable in normal use.
- Splits Compose UI out of `commons` into a new `commonsUI` module. 236 files
moved and no consumer import changed.
- Bumps LightCompressor-enhanced to 2.2.3.
- Drops the unused Guardian Project Maven repository.
- Runs relay-backed tests against geode instead of external relays.
- Clears the compiler, Android Lint and Gradle 10 deprecation warnings.
- Bumps `appCode` to 461.
## Contributors
- @npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z
- @npub1e2yuky03caw4ke3zy68lg0fz3r4gkt94hx4fjmlelacyljgyk79svn3eef
- mstrofnone
## Translations
- Polish by @npub16gjyljum0ksrrm28zzvejydgxwfm7xse98zwc4hlgq8epxeuggushqwyrm
- Hindi by @npub1ww6huwu3xye6r05n3qkjeq62wds5pq0jswhl7uc59lchc0n0ns4sdtw5e6
- Hungarian by @npub1dnvslq0vvrs8d603suykc4harv94yglcxwna9sl2xu8grt2afm3qgfh0tp
+3 -3
View File
@@ -32,7 +32,7 @@ docker run -d --name geode -p 7447:7447 \
```
with `in_memory = false` and `file = "/var/lib/geode/events.db"` in your
`geode.toml`. Pin a version (`:1.15.2`) instead of `:latest` for reproducible
`geode.toml`. Pin a version (`:1.16.0`) instead of `:latest` for reproducible
deploys. To build the image yourself, from the repo root:
```bash
@@ -47,7 +47,7 @@ it — a minimal JRE is bundled, so no system Java is required. It installs to
`/opt/geode/` with the launcher at `/opt/geode/bin/geode`.
```bash
sudo dpkg -i geode-1.15.2-linux-x64.deb # or: sudo rpm -i geode-1.15.2-linux-x64.rpm
sudo dpkg -i geode-1.16.0-linux-x64.deb # or: sudo rpm -i geode-1.16.0-linux-x64.rpm
```
To run it as a managed service, wire up the shipped systemd unit
@@ -69,7 +69,7 @@ formula: [`packaging/homebrew/geode-relay.rb`](packaging/homebrew/geode-relay.rb
Download `geode-<version>-<os>-<arch>.tar.gz`, unpack, and run:
```bash
tar xzf geode-1.15.2-linux-x64.tar.gz
tar xzf geode-1.16.0-linux-x64.tar.gz
./geode/bin/geode --config geode/share/geode/config.example.toml
```
+2 -2
View File
@@ -2,8 +2,8 @@
# Amethyst app version — single source of truth consumed by both Android (amethyst/)
# and Desktop (desktopApp/). `appCode` is the Android versionCode: a monotonic
# integer that must increment on every release, even when `app` is unchanged.
app = "1.15.2"
appCode = "460"
app = "1.16.0"
appCode = "461"
accompanistAdaptive = "0.37.3"
# Pinned: 0.3.0 turns CacheMap.entries/keys/values into DeprecationLevel.ERROR (and
# throws UnsupportedOperationException at runtime), which breaks quartz's appleMain