Commit Graph
663 Commits
Author SHA1 Message Date
jackandislam 81b5dd15c1 Optimize voice note codec to 16 kHz / 20 kbps for smaller file sizes
- Reduce sample rate from 44.1 kHz to 16 kHz (telephony standard)
- Lower bitrate from 32 kbps to 20 kbps
- Results in ~37% file size reduction (~150 KB/min vs 240 KB/min)
- Increases max voice note length from 4.4 to 7 minutes over 1 MiB BLE limit
- Maintains excellent voice quality using native AAC-LC codec
2025-10-15 00:39:19 +01:00
jackandislam 098f223906 Remove debug print statements from sendMessage 2025-10-15 00:39:19 +01:00
jackandislam d31dd8300f macOS: Focus message input on launch instead of nickname field 2025-10-15 00:39:19 +01:00
jackandislam 85b627945d Complete all translations to 100% and fix auto-extraction
- Mark non-localizable strings with Text(verbatim:) to prevent extraction
- Update UI strings to lowercase per style guide (open, save, close, recording)
- Add complete translations for all 29 languages (194/194 strings at 100%)
- Remove empty/duplicate entries (@, bitchat/, Open, Recording %@)
- Add proper localization comments for all user-facing strings
2025-10-15 00:39:19 +01:00
jackandislam 035ad175a7 Fix infinite render loop and apply all security fixes
CRITICAL BUG FIX - Infinite Render Loop:

Root Cause: Duplicate view identity in ContentView.swift:368
  ForEach(messageItems) { item in  // Already uses item.id via Identifiable
      messageRow(...)
          .id(item.id)  //  REDUNDANT modifier caused identity re-evaluation loop
  }

When @Published properties updated, SwiftUI re-evaluated .id() → appeared as
'new' identity → triggered re-render → infinite loop. Caused UI freezes,
keyboard failures, and 100% CPU usage.

Fix: Remove redundant .id() modifier - ForEach already has stable identity.

PERFORMANCE FIXES:

1. Waveform Cache Deadlock (Waveform.swift)
   - Removed nested queue.async(barrier) on cache hits
   - Was causing task saturation and potential deadlocks

2. Async Send Pattern (ContentView.swift)
   - Clear input immediately, defer actual send to next runloop
   - Prevents blocking current event handler

3. Proper Swift Concurrency (VoiceNoteView.swift)
   - Switch from .onAppear + DispatchQueue to .task
   - Cleaner async/await pattern for loading

4. Remove Redundant objectWillChange (ChatViewModel.swift)
   - @Published already triggers updates automatically
   - Explicit send() was causing double update cycles

SECURITY FIXES (C1-C5, H1-H2):

C1. Path Traversal Protection (BLEService.swift)
    - Unicode normalization, null byte removal
    - Replace ALL path separators, reject dotfiles
    - Validate paths don't escape directory

C2. Integer Overflow (BitchatFilePacket.swift)
    - Use UInt64 for TLV parsing, safe Int conversion

C3. MIME Validation (BLEService.swift)
    - Whitelist: JPEG, PNG, GIF, WebP, M4A, MP3, WAV, OGG, PDF
    - Magic byte validation for all types
    - Lenient on M4A (platform variations)

C4. Compression Bomb (BinaryProtocol.swift)
    - Ratio validation <= 50,000:1
    - Defense-in-depth with 1MB size cap

C5. TOCTOU Race (ChatViewModel.swift)
    - Direct removeItem without fileExists check

H1. File Size Validation (ChatViewModel, ImageUtils)
    - Check attributes BEFORE Data(contentsOf:)
    - Prevents memory exhaustion

H2. Metadata Stripping (ImageUtils.swift)
    - Remove ALL metadata keys from JPEG encoding
    - Only compression quality set
    - Protects GPS/EXIF/device info privacy

RESULT:
 No render loops
 Works with Xcode debugger
 Voice notes display properly
 All security vulnerabilities fixed
 164 tests passing

Production ready.
2025-10-15 00:39:19 +01:00
jackandislam b995a3fe4f Ensure /clear and panic triple-tap delete media files
Fix: /clear command and panicClearAllData() now properly delete media files

1. /clear (triple-tap on chat):
   - Deletes outgoing media (voice notes, images, files)
   - Conservative: only our sent media, preserves received media
   - Runs in background to avoid UI freeze

2. panicClearAllData() (triple-tap on bitchat/ header):
   - Deletes ALL media files (incoming + outgoing)
   - Removes entire files directory and recreates structure
   - Ensures complete data wipe for emergency scenarios

Both operations run async on .utility queue to prevent blocking UI.
2025-10-15 00:39:19 +01:00
jackandislam fb26db3bf0 Make voice note loading completely lazy with deferred initialization
Aggressive performance optimization to prevent UI freezes:

Problem: Even with async loading, creating 10+ VoiceNotePlaybackController
instances simultaneously (when scrolling past multiple voice notes) spawned
20+ concurrent background tasks, potentially starving main thread.

Solution - Ultra-lazy loading:
1. VoiceNotePlaybackController.init() now does ZERO work
   - No duration loading
   - No player creation
   - Instant initialization

2. Duration loaded on-demand via public loadDuration() method
   - Called from VoiceNoteView.onAppear after 150ms delay
   - Reduced priority: .utility instead of .userInitiated
   - Guard prevents duplicate loading

3. Waveform loading also deferred 150ms
   - Gives UI time to settle after message appears
   - Prevents task storms when multiple voice notes appear

This spreads the work over time instead of all at once.
2025-10-15 00:39:19 +01:00
jackandislam de4bf0a471 Cache geohash identity in ChatViewModel to prevent crypto during rendering
Additional optimization for location channels (voice notes are mesh-only,
but this helps with text message rendering in geohash channels):

- Add cachedGeohashIdentity to avoid deriveIdentity calls during rendering
- Check cache before falling back to crypto derivation
- Reduces main thread crypto work in location channels
2025-10-15 00:39:19 +01:00
jackandislam f493b50163 Cache Nostr identity derivation to prevent crypto during view rendering
Critical performance fix:

Problem: formatMessageHeader() called deriveIdentity(forGeohash:) during
every SwiftUI render for every media message. Each call performed:
- Keychain I/O (getOrCreateDeviceSeed)
- HMAC-SHA256 computation
- Up to 10 secp256k1 key validations (elliptic curve crypto)

With multiple media messages, this resulted in 100s of milliseconds of
blocking crypto on main thread per render cycle.

Solution: Add thread-safe cache for derived identities
- Check cache before expensive crypto operations
- NSLock protects concurrent access
- Identity is deterministic per geohash, so caching is safe

This eliminates crypto from the hot rendering path.
2025-10-15 00:39:19 +01:00
jackandislam 4aa12c08e7 Eliminate disk I/O from SwiftUI view rendering path
Critical performance fix for UI freezes when receiving media:

Problem: mediaAttachment(for:) was called during every SwiftUI render,
performing synchronous disk I/O on main thread:
- FileManager.fileExists() called 2-6x per message (checking subdirs)
- applicationFilesDirectory() creating directories on every call
- With multiple media messages, this meant 20-100+ disk ops per render

Solution:
1. Remove fileExists checks - construct URLs directly
   - Files are validated during playback/display (fail gracefully if missing)
   - Sender determines subdirectory (outgoing vs incoming)

2. Cache applicationFilesDirectory() result
   - Static cache prevents repeated FileManager.url() calls
   - Directory created only once

3. Remove redundant playback.replaceURL() in VoiceNoteView.onAppear
   - Controller already initialized with correct URL

This eliminates ALL disk I/O from the view rendering hot path.
2025-10-15 00:39:19 +01:00
jackandislam c2a0c86542 Fix memory leaks and post-playback freeze
Fixes:
1. Post-playback freeze: audioPlayerDidFinishPlaying now dispatches to main
   thread before updating @Published properties (Swift concurrency violation)

2. Unbounded waveform cache: Implement LRU eviction with 20-entry limit
   - Track last access time for each cached waveform
   - Evict oldest entry when cache is full
   - Prevents unlimited memory growth as voice notes accumulate

3. Audio buffer memory leaks: Wrap computeWaveform in autoreleasepool
   - AVAudioPCMBuffer allocations are autoreleased
   - Pool ensures buffers are freed promptly

4. Image processing memory: Add autoreleasepool around compression loops
   - Each jpegData() call creates temporary objects
   - Inner pool per iteration prevents memory spikes during quality search

Memory should now remain stable during extended use.
2025-10-15 00:39:19 +01:00
jackandislam 073e22e126 Fix UI freeze when receiving voice notes
Problem: AVAudioPlayer initialization in VoiceNotePlaybackController.init()
was running synchronously on main thread during view creation, blocking
UI for 50-200ms per voice note.

Solution:
- Remove eager preparePlayer() call from init
- Load duration asynchronously on background queue
- Player is only prepared when playback is actually requested via ensurePlayerReady()

This prevents UI freezes when voice notes appear in the chat.
2025-10-15 00:39:19 +01:00
jackandislam 6533293f75 Fix critical issues from PR #681 review
Critical fixes:
- BinaryProtocol: Return nil for unknown versions (prevents buffer underflows)
- Add BinaryProtocol.Offsets struct to centralize magic numbers
- Replace magic offset calculations with named constants

Security/Privacy:
- FileAttachmentView: Use url.lastPathComponent instead of url.path
  (prevents exposing full system paths)

Documentation:
- Fix compression algorithm documentation (zlib, not LZ4)

All tests passing.
2025-10-15 00:39:19 +01:00
jackandislam 757acef8d1 Fix binary protocol test fixtures 2025-10-15 00:39:18 +01:00
jackandislam db52c9463b Reset BLE assembler on stalled fragment trains 2025-10-15 00:37:41 +01:00
jackandislam b179d99cf8 Drop attachment ceilings to 1 MiB and bump release version 2025-10-15 00:37:41 +01:00
jackandislam 73d0867c18 Guard peer map reads on BLE message path 2025-10-15 00:37:41 +01:00
jackandislam 97f822b88d Restore BLE broadcasts when notify buffer is saturated 2025-10-15 00:37:41 +01:00
jackandislam 3f91d6510b Fix cleanupLocalFile lookup 2025-10-15 00:37:41 +01:00
jackandislam 2bb55cbe1a Resolve image/voice path handling 2025-10-15 00:37:41 +01:00
jackandislam 7fb93eb522 Hide absolute paths in media messages 2025-10-15 00:37:41 +01:00
jackandislam cb8b34f8ea Stub file transfer methods in mock 2025-10-15 00:37:41 +01:00
jackandislam b872113a4b Stub file transfer methods in mock 2025-10-15 00:37:41 +01:00
jackandislam de3795289d Use unique transfer identifiers 2025-10-15 00:37:41 +01:00
jackandislam bd37cc69a0 Preserve packet version when signing 2025-10-15 00:37:41 +01:00
jackandislam 788e21c4ea Fix CFMutableData handling 2025-10-15 00:37:40 +01:00
jackandislam c179e34c43 Target image byte size across platforms 2025-10-15 00:37:40 +01:00
jackandislam aa8b257e68 Normalize mac JPEG color space 2025-10-15 00:37:40 +01:00
jackandislam 7b4aeb506e Strip metadata in mac image encoding 2025-10-15 00:37:40 +01:00
jackandislam 5d5ed94952 Revert unsupported JPEG option 2025-10-15 00:37:40 +01:00
jackandislam 4945688eca Align mac image JPEG encoding 2025-10-15 00:37:40 +01:00
jackandislam 22bd975059 Allow user-selected write access 2025-10-15 00:37:40 +01:00
jackandislam d28b58ecb2 Fix image attachment detection 2025-10-15 00:37:40 +01:00
jackandislam e17163b3da Use save panel for mac image export 2025-10-15 00:37:40 +01:00
jackandislam 9346e62971 Keep processed images for outgoing messages 2025-10-15 00:37:40 +01:00
jackandislam a89fd153ee Lowercase image preview buttons 2025-10-15 00:37:40 +01:00
jackandislam 25bc737919 Reblur images via swipe 2025-10-15 00:37:40 +01:00
jackandislam 8218c12f69 Allow long-press reblur on images 2025-10-15 00:37:40 +01:00
jackandislam 60c2263a46 Use Photos picker on mac 2025-10-15 00:37:40 +01:00
jackandislam e2fcb44982 Restore mac photo picker access 2025-10-15 00:37:40 +01:00
jackandislam ebbb7b356f Display recording milliseconds 2025-10-15 00:37:40 +01:00
jackandislam 2d0f55ae84 Harden attachment transfer bookkeeping 2025-10-15 00:37:40 +01:00
jackandislam 51e8e4e51a Describe microphone usage 2025-10-15 00:37:40 +01:00
jackandislam fb251a3fa8 Permit mac media library access 2025-10-15 00:37:40 +01:00
jackandislam 4052ba581a Allow mac microphone access 2025-10-15 00:37:40 +01:00
jackandislam 235fefe4ab Enable mac attachment importers 2025-10-15 00:37:40 +01:00
jackandislam 8389961269 Fix compressed BLE file transfers 2025-10-15 00:37:40 +01:00
jackandislam a244c4084f Stop dropping partial BLE frames while assembling notifications 2025-10-15 00:37:40 +01:00
jackandislam ed320fb0ad Log incomplete BLE frames for debugging 2025-10-15 00:37:40 +01:00
jackandislam 2bdc1535c7 Add detailed logging for BLE fragment assembly 2025-10-15 00:37:40 +01:00