Commit Graph
100 Commits
Author SHA1 Message Date
EdnunpandClaude Opus 4.8 f0b35b2b8c Tests: remove the opt-in real-service-lifecycle test
Local checkpoint - NOT for public release. Ed will test the real install/service and
the sound by hand, so the elevated (admin-only) install/start/stop/uninstall self-test
isn't worth keeping. Removed it and its IsAdministrator helper. The headless service
tests stay (parity, app-yield, send host, registration args) - those run in the gate and
guard the service against drifting from the main app. Gate 26/26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 22:51:47 +01:00
EdnunpandClaude Opus 4.8 4ee9cf6907 Tests: opt-in real Windows-service lifecycle (install/start/stop/uninstall)
Local checkpoint - NOT for public release.

New self-test "Service real lifecycle" drives the ACTUAL SCM end to end: install ->
report installed -> start -> report running -> stop -> report stopped -> uninstall ->
report gone. Needs admin, so it's OPT-IN via REMSOUND_TEST_SERVICE=1 and skips cleanly
in the normal unprivileged gate. It clears any leftover registration first (DoUninstall
stops a running copy, so a stray from an aborted run can't fail it) and always removes
the service afterwards, even on failure - so it never leaves a service pointing at a
throwaway exe. Run elevated: set REMSOUND_TEST_SERVICE=1 then RemSound.exe --selftest.

The app-yield takeover is already covered headlessly by "Service send host (stream +
yield)"; a full real end-to-end (installed service goes quiet when the app opens) needs
a live peer to observe and stays a manual check. Gate 26 passed, 1 skipped of 27.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 22:41:26 +01:00
EdnunpandClaude Opus 4.8 ce45489b30 Tests: guard the service peer-port default matches the main app
Local checkpoint - NOT for public release. Adds a check that a peer with no explicit
port resolves to RemPacket.DefaultPeerDialPort (not the local audio port), guarding the
third audit divergence. Gate 26/26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 22:33:27 +01:00
EdnunpandClaude Opus 4.8 78a9aa6572 Service: fix divergences from the main app's send path
Local checkpoint - NOT for public release. Audited ServiceSendHost against MainForm's
send path (Ed: make the service reuse the same code, be just as stable). Three real
divergences found and fixed:

1. ENCRYPTION FINGERPRINT (critical): the host set sender.AudioKey but NOT
   sender.AudioFingerprint. The main app (RecomputeAudioCrypto) sets both, and the peer
   verifies the fingerprint before accepting a stream - so the service's encrypted audio
   would have been REJECTED at the far end. Now derives and sets both from the password.
2. OPUS FRAME: the main app applies EffectiveOpusFrameSamples (the "Small" send rate
   halves the Opus frame); the host passed the raw frame, so it would encode differently
   than the main app for the same profile. Now reuses MainForm.EffectiveOpusFrameSamples
   (made internal - same code, not a copy).
3. PEER PORT: send target fell back to the profile's LOCAL AudioPort; the correct default
   is RemPacket.DefaultPeerDialPort (what the main app's manual-peer path uses). Same value
   today but the right constant.

Reviewed and OK: sender defaults to WasapiOnly (no SetAudioMode needed); BuildSendSpecs
matches ApplySendSources for explicit-device profiles; default-device changes are covered
by the device-change watcher; direct-send (no relay/StartReceiving) is the intended v1 scope.

New self-test "Service sender parity" asserts key + fingerprint + effective Opus frame
match the main app. Gate 26/26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 22:13:48 +01:00
EdnunpandClaude Opus 4.8 4fb490b2d5 Service: use the main app's event-driven device watcher, not a poll
Local checkpoint - NOT for public release. Ed: don't add continuous background checks
(they've piled up before) - reuse the disconnect/reconnect mechanism the main app uses.

Replaced the 5s packet-flow health poll with AudioDeviceChangeNotifier - the SAME
event-driven watcher the main window uses. It fires only when a device is added/removed/
changes state or the default changes (nothing polls, nothing accumulates - it's a single
registered COM callback, disposed with the host). While the service intends to send, that
event re-opens capture, covering: the audio stack finishing coming up at boot, a device
plugged/unplugged, and the audio service restarting. Debounced (a hot-plug fires a burst).

Also dropped the per-tick Resume retry: now one start attempt per app-absence, then the
device watcher drives any re-open. The only remaining periodic thing is the tiny 1s
presence-token check for the app-yield (a mutex probe - allocates nothing, accumulates
nothing). Gate 25/25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 22:04:26 +01:00
EdnunpandClaude Opus 4.8 a7742fe2ec Service: self-heal if capture isn't ready (or a device drops) at start
Local checkpoint - NOT for public release. Answers "what if it looks for sound
devices before their services are up?"

Two layers now:
- depend= Audiosrv/AudioEndpointBuilder (prior commit) makes Windows start the service
  only once the audio services are running.
- Self-heal in the run loop: while it should be sending, if no packets have flowed for
  ~5s then no capture is actually running (endpoints not fully ready at boot, a device
  dropped, or the audio service restarted) - it re-opens the capture. And while NOT
  sending it already re-tries every second, so a slow-to-appear audio stack or a device
  that returns later is picked up automatically.

So even if the service races ahead of the endpoints being fully enumerated, it keeps
retrying/re-opening until audio actually flows, rather than sitting silent. Gate 25/25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 21:52:16 +01:00
EdnunpandClaude Opus 4.8 91b3f0c1c1 Service: menu before Options + start-after-audio dependency
Local checkpoint - NOT for public release.

- Service menu now sits before Options in the menu bar (File / Record / Service /
  Options / Help), per Ed.
- The service is registered with depend= Audiosrv/AudioEndpointBuilder, so Windows
  starts it the instant the audio services are ready at boot (before login) - the
  earliest point WASAPI capture can find any audio. It CANNOT start before the audio
  services (there'd be no endpoints to capture, and no sound exists before audio is up),
  so this is the earliest useful start. DoInstall now uses the single BuildCreateArgs
  source of truth.

Gate 25/25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 20:34:34 +01:00
EdnunpandClaude Opus 4.8 004e01306b Service dialog: Connectivity tab now mirrors the main window
Local checkpoint - NOT for public release. Ed: the connectivity box was totally
different from the main window's - I'd rolled a bespoke listbox + textbox + buttons
instead of copying the real tab.

Now built like the main window's Connectivity tab:
- Theme.SectionHeader("Peers") header.
- Peers list is a wired CheckedListBox ("Peers to send to", Alt+C) with the shared
  CheckedListAccessibility so it announces state like every other list; a ticked peer
  is one the service sends to, Delete removes it.
- "Add peer by IP (Alt+A)" button uses the SAME ManualPeerPrompt the main window uses,
  not an inline textbox.
- Set password button kept.

Checked peers persist as SelectedConnectedPeers (the send-to set); every listed peer is
kept as RememberedPeers. Gate 25/25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 20:30:37 +01:00
EdnunpandClaude Opus 4.8 37f28d6c91 Service config dialog: rebuilt to match the main window exactly
Local checkpoint - NOT for public release. Ed flagged the dialog as sloppy - lists
not announcing, wrong tab order, leftover Alt+4/5/6, "Standard/Tight" instead of the
real labels, and not looking like the main window.

- Screen-reader parity: new CheckedListAccessibility.Wire (factored from the main
  window's WireCheckedListAccessibility) drives every checked list - announces
  "checked, <item>. Item N of M. Press Space to toggle." on focus and arrow, plus
  first-letter nav that never toggles. This was the core miss (lists not announcing).
- Layout parity: uses the house FormLayoutRows rows + status labels, QuietTabControl,
  AccessibleCheckBox, MnemonicLabel, and the app icon - so it reads/looks like a real tab.
- Tab order now mirrors the main window: Connectivity, then Audio send, then Audio profile.
- Alt keys renumbered for the dialog (were lifted verbatim from the I/O tab): send tab
  1-5, connectivity 1-2, profile keeps the main window's C/P/D.
- Exact main-window labels copied verbatim: codec ("PCM 48K 24 bit - uncompressed", etc.),
  packet size ("Standard (5 ms PCM, 10/20 ms Opus)" / "Small (2.5 ms ...)"), and the
  lock-to-audio-clock text + accessible description.

Gate 25/25 (dialog passes the accessibility audit: names + unique mnemonics + tab order).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 20:21:48 +01:00
EdnunpandClaude Opus 4.8 9a7bd6c9e8 Release scripts: notes-freshness check + gate the test deploy
Local checkpoint - NOT for public release.

- build-release.ps1: abort if RELEASE_NOTES.md is missing or doesn't mention the tag
  (it leads with "# RemSound <tag>"), so a stale notes file from the previous release
  can't ship with the wrong content via `gh release create --notes-file`.
- deploy-test.ps1: a binary deploy now runs the build-and-test gate (run-tests.ps1)
  first and refuses to deploy a build that didn't pass - so a test build Ed picks up
  has always passed the suite. Sound-only refreshes skip it (no code change). New
  -SkipGate switch overrides when the gate was just run. Verified end-to-end.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 20:06:34 +01:00
EdnunpandClaude Opus 4.8 2a8c608653 Release scripts: bulletproof test-deploy data preservation + tag/version gate
Local checkpoint - NOT for public release.

Two gaps found reviewing the publish/release scripts:

- deploy-test.ps1: the binary sync (publish -> D:\Dropbox\remsound) used /E with no /MIR,
  so it never DELETES user data - but it could OVERWRITE it if publish\ ever accumulated a
  "user settings and logs" folder. Added /XD/'user settings and logs','recordings','logs',
  'profiles','config' + /XF 'global config.json','remsound.config.json' so the binary sync
  is physically incapable of touching Ed's profiles/logs/config in either direction. Test
  deploys keep ALL of his data current, by construction.

- build-release.ps1: never checked the -Tag against the csproj <Version>. A mismatch ships
  RemSound-<tag>.zip containing a different version's binary, which the in-app updater (it
  downloads by tag name) reads as a perpetual "update available". Now aborts up front if
  tag != csproj <Version> - also catches a forgotten version bump.

The intended split was already correct: test deploy keeps everything; build-release
publishes to a fresh folder, strips pdb, and scans staged files AND the zip for any
profiles/logs/config/recordings, aborting if found.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 19:56:34 +01:00
EdnunpandClaude Opus 4.8 a52f08c188 Tests: functional profile round-trip through the real main-window controls
Local checkpoint - NOT for public release.

Toward Ed's "every control and every function tested" goal: a new self-test applies a
profile to the ACTUAL main-window controls (via an internal ApplyThenCaptureForTest seam
on the headless form) and reads it straight back, asserting every persisted value
survived - volume, mute, send/receive toggles, peer-shaping master, send mode, send-all-
applications, and the selected applications. This exercises each control's load AND save
logic, not just that it exists (which the accessibility audit already covers).

The apply path pops the "set a password to stream" dialog when enabling send with no
password (would hang a headless test); the seam sets the existing suppressStreamingPasswordGate
around the apply, same gate the app uses internally.

Gate 25/25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 19:16:08 +01:00
EdnunpandClaude Opus 4.8 499e9644d7 Tests: split-track recording coverage (per-peer + own send)
Local checkpoint - NOT for public release. Closes the second test gap.

- RecordingController gets an internal SettingsSourceForTest seam so a self-test can drive
  a split (multi-track) recording without writing to the real shared settings store.
- New self-test "Recording split tracks": with SplitTracks on + one connected peer, starts
  the real controller, feeds the "your send" track through the tap it wires onto the sender,
  and asserts it wrote a FOLDER of tracks (one per peer plus your own) with content - Ed's
  multi-track feature, now proven on every build.

Gate 24/24. Both previously-deferred test gaps (split-track + main-window tabs) now closed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 19:02:02 +01:00
EdnunpandClaude Opus 4.8 c8fed26115 Tests: headless main-window coverage (all tabs + controls) + fix Alt+L clash
Local checkpoint - NOT for public release. Closes the UI-coverage gap Ed pushed on.

- MainForm gets a `headless` ctor flag (defaults false → real startup path byte-for-byte
  unchanged). When true it builds the WHOLE window — every tab, control and menu — but
  skips the OS touches: global-hotkey registration, the status/device-refresh timers, the
  device-change notifier, and the audio-backend mode switch in ApplyAsioMode. The
  disruptive startup work (Connect + sockets, UPnP, update check) already lives in the
  Shown handler, which never fires when a test constructs the form without showing it — so
  a headless construction is naturally side-effect-free.
- New self-test "Main window coverage": constructs the headless main window and audits the
  lot — accessible names present, Alt mnemonics unique per group, tab order forms no cycle.
  4 tabs, 41 interactive controls.
- It immediately EARNED ITS KEEP: caught a real Alt+L collision — the WASAPI latency and
  ASIO latency labels both claimed Alt+L in the same panel, so in WASAPI+ASIO mode the ASIO
  field was unreachable by its shortcut. Moved ASIO latency to Alt+I; WASAPI keeps Alt+L.

Gate 23/23.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 18:59:09 +01:00
EdnunpandClaude Opus 4.8 fd981211c0 Tests: recording churn + env-gated soak, leak-accurate handle checks
Local checkpoint - NOT for public release.

- New "Recording churn / soak": rapidly start/feed/stop/dispose recordings across all
  four formats, asserting handles stay bounded - catches recorder/encoder lifecycle
  leaks a single recording wouldn't.
- Both the recording churn and the lifecycle churn now honour REMSOUND_TEST_SOAK=<seconds>:
  unset, one quick round in the gate; set, they hammer until the deadline for a real
  minutes-long soak. Verified at 8s: 312 lifecycle transitions + 16 record cycles.
- Handle checks now force GC + finalizers to settle before measuring, so the reading
  reflects genuine leaks, not collection lag under fast churn (which would false-fail a
  long soak). Post-settle the churn shows NEGATIVE handle growth - no leaks.

Gate 22/22.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 16:09:04 +01:00
EdnunpandClaude Opus 4.8 47e4159cf9 Tests: broaden dialog accessibility audit + tab-order cycle check
Local checkpoint - NOT for public release.

- The accessibility audit now covers 8 dialogs (was 3): Recording settings,
  Preferences, Service profile, About, Add EQ band, Rename peer, Keyboard shortcut
  import, Profile selection. Each is constructed and checked for accessible names on
  every control + unique Alt mnemonics per group.
- Added a tab-order sanity check to the audit: the GetNextControl walk must terminate
  (no cycle) for every audited form - guards a keyboard/screen-reader user from a Tab
  trap, and the wrapper-TabIndex trap we've hit before.

Deferred (documented): auditing the MAIN WINDOW's tabs needs a headless construction
seam - MainForm's ctor opens audio backends, registers global hotkeys, binds sockets
and shows a tray icon, interleaved through the ctor. A `headless` flag that skips those
is safe in principle (real path unchanged) but invasive on the critical startup path
and best added with Ed able to test it. The dialog surface (most of the app's controls)
is now covered. Gate 21/21.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 16:03:24 +01:00
EdnunpandClaude Opus 4.8 b258bec9a2 Tests: recording engine coverage (all formats + source gate + mono)
Local checkpoint - NOT for public release. First test-suite increment.

New self-test "Recording engine" drives the real AudioRecorder headless by feeding
its audio-thread taps a synthetic tone, then asserting the output files:
- every format written with real content: WAV / MP3 (LAME) / OGG-Opus (Concentus) /
  FLAC (FLAKE), native encoders and all.
- source gate: a SentOnly recorder fed only received audio stays (near) empty.
- mono downmix produces a valid smaller WAV.

This is the recording pain Ed flagged - now proven on every build instead of by ear.

Follow-up: split-track (per-peer) recording is orchestrated by RecordingController,
which reads settings from the shared store; testing it without mutating real config
needs a settings-injection seam. Deferred, noted.

Gate 21/21.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 15:58:46 +01:00
EdnunpandClaude Opus 4.8 6e84f491e8 Service: manual section + menu-list sweep
Local checkpoint - NOT for public release.

- New manual section "24. The lock-screen service (send only)": what it is, the
  send-only/WASAPI-only limits, the yield-to-the-app behaviour, the Service menu
  (configure/install/start/stop), and the good-to-know notes (direct peers, firewall,
  updates picked up on next restart, install both ends for two-way).
- Swept the two stale "Menus (File, Record, Options, Help)" references to include
  Service; added a Service-menu pointer at the end of the Menus section.
- Updater needs NO change: UpdateApplier renames the old exe aside (survives the
  running service's lock) then copies the new one in, so the service keeps running the
  previous version until its next restart and never blocks a swap. Documented.

MANUAL.md regenerates from readme.html at release time (sync-manual.py), so untouched.
Gate 20/20.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 15:53:54 +01:00
EdnunpandClaude Opus 4.8 f4551517e5 Service: config dialog + Service menu
Local checkpoint - NOT for public release.

- ServiceProfileDialog: modal 3-tab editor (Audio send / Audio profile / Connectivity)
  reusing the house controls, with a Save and Close / Cancel / Additional options
  button row. Send-only: send-mode chooser + WASAPI outputs/apps + inputs (no "Send
  my audio" toggle, no receive, no ASIO); codec/rate/lock-to-clock; peers add/remove +
  a Set password button. Additional options sub-dialog = play connect/disconnect sound
  + enable service logging. Edits a Profile clone; returns it on OK.
- Service menu in MainForm: status line + Configure / Install / Uninstall / Start / Stop,
  items enabled per live state on drop-down. Install/uninstall confirm then elevate.
  Configure saves the reserved service profile, points AppConfig at it, stores the
  machine-wide logging choice, and restarts a running service to pick up edits.
- ProfileStore.ReservedServiceProfileTitle ("RemSound service"): the service profile
  lives with normal profiles (so the service Loads it) but ListProfileTitles hides it
  from every picker. ServiceControl reuses that single constant.
- Self-test: the service dialog is now in the accessibility audit (constructs cleanly,
  unique mnemonics, all controls named). Gate 20/20.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 15:27:37 +01:00
EdnunpandClaude Opus 4.8 5dbbe4dd71 Service: --run-service host + registration CLI (install/uninstall/start/stop)
Local checkpoint - NOT for public release.

- RemSoundService (ServiceBase): hosts ServiceSendHost.RunLoop on a worker thread,
  OnStop cancels + joins. Added System.ServiceProcess.ServiceController package.
- ServiceControl: install (sc.exe create, auto-start, careful binPath quoting) /
  uninstall (stop + delete) / start / stop / status. Status query is unprivileged
  (menu can poll it); the mutating verbs self-elevate via ShellExecute runas.
- Program.cs: early guards for --run-service (blocks in the SCM dispatcher) and the
  one-shot elevated verbs, before the single-instance lock (the service is a
  separate role and must never take the interactive lock).
- Self-test "Service registration args" verifies the sc create binPath quoting
  survives a spaced exe path. Gate 20/20.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 15:19:01 +01:00
EdnunpandClaude Opus 4.8 e648bee531 Lock-screen service: spike + headless send host + app-yield coordination
Local checkpoint - NOT for public release. First increment of the send-only
Windows service feature (design in memory/project_remsound_service).

THE SPIKE PASSED: the send engine runs fully headless (no window, no message
pump) and streams, proven by a real self-test — the one genuine unknown that
gated the whole feature. Also proves the app-yield model end to end.

What's in this increment (all headless, all tested, 19/19 gate):
- AppConfig: ServiceProfileName + ServiceLoggingEnabled (machine-wide).
- InteractivePresence (Core): the cross-session app-yield token. App holds a
  Global\ mutex for its lifetime; the service checks it and yields while an
  interactive app is present, resuming when it closes OR crashes (OS frees the
  mutex). Name-parameterised internal seams for isolated testing.
- ServiceSendHost (App): loads a send-only profile and streams it to its peers,
  WASAPI-only, no ASIO/receive. ApplyProfile/Suspend/Resume + a RunLoop that
  drives them from the presence token with a settle delay. v1 sends to direct
  peer addresses (LAN/port-forwarded); NAT/relay discovery stays the app's job.
- Program.cs: the interactive app now acquires the presence token at startup so
  a future service yields to it.
- Tests: "Service app-yield token" (held=present, released=absent) and "Service
  send host (headless stream + yield)" — streams a captured device to a local
  receiver over loopback, verifies start/suspend/resume, then drives the full
  RunLoop against the token (held=suspended, released=resumes-and-flows).

Still to come (later increments): the --run-service entry + Windows-service
registration, the Service menu, the 3-tab config dialog, updater integration,
docs. None user-facing yet, so nothing deployed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 14:59:31 +01:00
EdnunpandClaude Opus 4.8 8f61eb800d Add lifecycle-churn soak test for runtime transitions
Local checkpoint - NOT for public release.

Ed's ask: the ASIO-toggle crash was a lifecycle-transition bug, and those take an
age to test by hand but regress easily. Automate tearing features down and adding
them back in every combination.

New self-test "Lifecycle churn" drives a REAL sender+receiver pair over loopback
through a matrix of runtime transitions and asserts no crash + bounded handles:
- audio mode changes
- send sources: empty / device loopback / process-loopback (own pid) / both,
  reconfigured repeatedly so the process-loopback capture is torn down and rebuilt
  many times (the mechanism that hard-crashed)
- receive outputs on/off
- per-peer pan + parametric EQ: none / volume-only / full pan+EQ chain
- codec (PCM/Opus) and tight-latency toggles
- a rapid WASAPI-only reconfigure loop (no mode changes, never abuses hardware)

Any unsafe teardown crashes the test process and fails the gate; it also checks
handle growth stays bounded across the churn (caught nothing leaking: +25).

Real ASIO hardware cycling is OPT-IN via REMSOUND_TEST_ASIO ("1" = first installed
driver, or a driver name) so routine builds never open - and possibly hang or lock -
a real interface. When set it adds a GENTLE ASIO on/off loop (4 toggles, 600ms settle
- some drivers stall for seconds on a quick close+reopen) with a process-loopback
source live across the toggle, i.e. the exact Ed repro. Verified on the Audient:
52 transitions, no crash.

Gate: 17/17 (default, WASAPI-only path).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 11:31:50 +01:00
EdnunpandClaude Opus 4.8 ffeba4ad2b Fix hard crash when toggling ASIO while sending a specific app
Local checkpoint - NOT for public release.

Repro (Ed): in applications send mode with an app being captured, turning the
ASIO driver off hard-crashed the process. No log and no crash-report file were
written - and MixingEngine.DisposeEntry swallows managed exceptions - which points
to a native access violation, not a managed throw.

Cause: the ASIO toggle rebuilds the capture backend (ApplyAsioMode -> ApplyAudioRuntime
-> ApplySendSources), which disposes the live ProcessLoopbackCapture. The old design
released the WASAPI COM objects from the disposing thread while the capture thread
could still be inside a native GetBuffer call - a classic use-after-free / AV.

Fix: the capture thread now owns the ENTIRE COM lifecycle. It activates, runs, and
releases every COM object itself, in its finally, only after the loop has exited.
StopRecording/Dispose merely signal and join (2s) - they never touch the COM objects.
If the thread ever wedges in a native call we leak it rather than free from outside
(a rare bounded leak beats a hard crash). The thread is also explicitly MTA, and
activation moved onto it, so the async-activation callback can't stall the UI thread.
bufferReady is volatile and only disposed once the thread has genuinely exited.

Also: ApplyAsioMode force-sets the WASAPI send-list visibility for the new mode, which
resurrected the loopback-outputs list in applications mode; re-assert ApplySendModeVisibility
at the end so the correct list stays shown after an ASIO toggle.

New self-test "Per-application capture lifecycle" runs real start/stop/dispose cycles
of the native capture against our own process on hardware - a bad teardown would AV
and fail the gate. Gate: 16/16.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 11:23:18 +01:00
EdnunpandClaude Opus 4.8 f8a42f2806 Per-app send: UI on the Input/Output tab, saved per profile
Local checkpoint - NOT for public release. Builds on the engine core commit.

Ed's revisions to the plan: the send-mode chooser lives on the Input/Output tab
(not Preferences), right after "Send my audio", and the setting saves per profile.

Input/Output tab:
- New "How to send WASAPI audio" listbox (Alt+6) after the send checkbox, with
  two rows: send whole sound devices (classic) or send specific applications.
  Switching it swaps the tab live between the loopback-outputs list and the app
  section. Hidden entirely on Windows too old for process loopback (mode pinned
  to devices), so nothing changes for Win7.
- Applications section: "Send all applications" master checkbox (Alt+7, ticked by
  default = whole system audio, same as today) and an "Applications to send"
  checked list (Alt+8) shown only when the master is unticked.
- All house controls (AccessibleCheckBox, MnemonicLabel, WireCheckedListAccessibility),
  accessible names + Alt-shortcut suffixes, tab order slotted in.

Behaviour:
- App list reconciles on a 3s timer while visible: apps appear/disappear as they
  open and close, ticks preserved by process NAME, and a ticked app that closes
  stays in the list marked "(not running)" and resumes when it reappears.
- ApplySendSources: devices mode unchanged; applications mode sends either the
  default-render loopback (send all) or one process-loopback spec per running
  process of each ticked app. WASAPI mics and ASIO run alongside in both modes.
- Process-loopback sources are excluded from the single-source push-mode fast
  path (it opens an MMDevice; a "proc:<pid>" id has none) - they go via MixingEngine.
- "Is anything being sent" status/tray gates account for applications mode.

Persistence moved from AppConfig to Profile: WasapiSendMode / SendAllApplications /
SelectedSendApplications. Profile round-trip self-test extended. Gate: 15/15.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 10:53:58 +01:00
EdnunpandClaude Opus 4.8 8a7c4ddf2b Multi-output fan-out, offline-marker fix, #19, and per-app send engine core
Local checkpoint - NOT for public release.

Fan-out (every received stream to every selected output, no added latency):
- SessionPlayout mirror replicas fed the same decoded bytes; delicate ReadFloats untouched.
- PlayoutEngine reconciles replicas per active output lane; per-route tuner
  aggregation keeps lanes from disturbing each other. Recording dispatch gated
  to the recording route only.
- PeerDspChain.Clone() gives each output lane independent biquad state.
- ReceiverSelfChecks.FanOutToBothOutputs proves both lanes get audio (self-test).

Offline-marker pile-up fix:
- ResolvePeerDisplayName strips the " (offline)" marker before reuse, so a ghost
  peer no longer compounds the suffix hundreds of times in the status line.

Issue #19 (Use-Windows-default follower in the loopback send list):
- DefaultLoopbackSendFollower resolves to the current default render device's
  loopback spec, re-applied when the default changes.

Per-application send engine core (issue #20) - WASAPI-only, Win10 19041+ gated:
- CaptureKind.ProcessLoopback + ProcessLoopbackId ("proc:<pid>").
- AudioAppEnumerator: snapshots apps with audio sessions, tracked by process
  name, releasing every session object each pass so nothing piles up.
- ProcessLoopbackCapture: IWaveIn over the process-loopback activation API
  (hand-rolled COM interop; NAudio has no binding). Fixed 48k/float/stereo.
- CaptureSource IWaveIn overload; MixingEngine opens "proc:<pid>" sources with
  no MMDevice and no render keepalive. ASIO path untouched.
- Self-test enumerated real apps on hardware; support gate verified.

UI (Preferences device/app mode + app checklist), ApplySendSources app specs,
and the reconcile timer are still to come. Gate: 15/15.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 05:58:33 +01:00
EdnunpandClaude Opus 4.8 2fb9274a95 v5.2: stability and polish — deep-audit bug fixes + install-flow fixes
Verified findings from a multi-dimension code audit, plus the two install-flow bugs:
- Fix Opus encoder use-after-free on a codec/rate change while streaming (guard swap vs encode).
- Fix "both" single-file recording dropping audio + drifting (drain both directions in lockstep).
- Fix broken clip counter, UPnP teardown on exit, auto-update-restart foreground grant, and a
  malformed-Opus-format packet orphaning a playout session forever.
- Post-install relaunch now respects start-minimised; uninstall is path-aware so it won't clear a
  different copy's run-at-startup.
- Perf/hygiene: cache AppConfig off UI hot paths, fold per-peer EQ+gain into one pass, deterministic
  disposal (tray menu, timers, COM shortcut, Process handles, process meter), ring-buffer overflow
  guard, receiver session-lock fix, remote-control allow-list moved onto the UI thread.
- Remove dead code (two IsAsioBackend, SessionPlayout.Reset, IsSameEndpoint, RemSoundUpdater
  IDisposable); several stale-doc fixes.

Deferred (not in this release): drift-estimator tweak, peer-discovery pruning, uninstall retry-loop,
encryption nonce. Wire format unchanged (interops v3.3-v5.1). Version -> 5.2.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-09 20:54:53 +01:00
EdnunpandClaude Opus 4.8 7038fef67c v5.1: install RemSound as a proper Windows app, plus smaller sounds
New Options -> Install / Uninstall RemSound on this PC: a per-user self-installer
(%LOCALAPPDATA%\Programs\RemSound, no admin) with optional desktop + Start-menu
shortcuts, login auto-start (reuses StartupAutoStart), Windows Installed-apps
registration, and copy-across of profiles+config, recordings and logs. Install
state is decided by a marker file, not a folder-path guess; the post-install
relaunch hands over foreground via AllowSetForegroundWindow so the installed copy
comes to the front; uninstall uses a batch remover (no PowerShell) and confirms
with two independent tick-boxes. All new dialogs use the house accessible controls
(AccessibleCheckBox, Theme.Heading).

Also: iOS (TestFlight) companion link alongside Android in README + manual;
slimmed-down default cue WAVs; About/RELEASE_NOTES/manual updated; version -> 5.1.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-09 15:45:21 +01:00
EdnunpandClaude Opus 4.8 a92928d357 Docs: add the iOS (TestFlight beta) companion app alongside the Android one
Jonathan Schuster's iOS client (iPhone/iPad) is in TestFlight beta — linked in the GitHub README and
the bundled manual next to the existing Android app, framed the same way (separate community project,
speaks the same protocol, not maintained by us).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-09 11:18:02 +01:00
EdnunpandClaude Opus 4.8 849a0b4c73 v5 manual: deep audit sweep, About-box changelog, version bump
Full manual audit before release: fixed the General→Appearance toggle location (3 places), the
Connectivity section-6 tab order (Add-by-IP after Remembered), a new Appearance subsection (theme /
tab order / list toggles) resolving the #appearance links, standardised the recording-source names
and default, added the split-recording friendly-name precedence, the two recording tickboxes to the
Options-menu summary, Alt-keys on the pan/EQ table, Alt+L and Alt+O,N to the shortcut tables, fixed
the glossary (hotkeys not per-profile; remote-control cross-ref) and the section-4 tab-count wording.
About-box v5.0 changelog and version 5.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 18:22:59 +01:00
EdnunpandClaude Opus 4.8 aeca24ae17 v5 pre-release: multi-track drift fix, more self-tests, logging, CLI, version bump
Multi-track recording drift fix (Ed's question — can the separate tracks drift over an hour?):
 * Root: FlushPeerTracks skipped a peer that produced no samples in a render block, so a peer that
   went quiet long enough for its session to be pruned (>4 s idle) would have its track fall behind
   and desync. Now every peer track is padded to a full render block each cycle (silence when the
   peer produced nothing), so all peer tracks stay sample-locked to the single render clock — they
   can't drift apart however long the recording runs, and all end the same length. Same padding for
   the single-file bypass path. OnRecordBlockComplete now carries the block's float count.
   (The peer tracks are already resampled to the render clock per peer, so this makes peer-to-peer
   sync exact; your own "me" track is capture-clocked — same soundcard for capture+playback = same
   clock = no drift, different interfaces can drift slightly.)

 * Self-test: two new steps — "Per-peer shaping DSP" (PeerDspChain unity/master-off/volume/parametric
   + ParametricToPeaking) and "v5 settings and shaping round-trip" (AppConfig defaults, NamedPeers,
   MainTabOrder, parametric PeerShaping, recording default = Both).
 * Logging (gated by the logging checkbox): master shaping switch, EQ-mode change, parametric band
   add/delete, peer rename/clear/delete, and the applied Appearance settings after Preferences close.
 * CLI: --list-profiles and --list-named-peers (read-only), in --help.
 * Version bumped to 5.0; About-box changelog, RELEASE_NOTES.md and README updated for v5.

Build clean; --selftest passes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 18:19:01 +01:00
EdnunpandClaude Opus 4.8 fcc3cdc793 Ctrl+1..9 to jump to a tab by its current position (main window + Preferences)
Ctrl and a number selects the Nth tab as it currently appears — positions are live, so they follow
the user's tab reordering and the pan/EQ tab's show/hide. Handled in ProcessCmdKey on both the main
window and the Preferences dialog; focuses the tab strip afterwards so NVDA reads the new tab (like
Ctrl+Tab). Matches Andre's readout app. Manual updated.

Build clean; --selftest passes; deployed to both test folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 14:31:22 +01:00
EdnunpandClaude Opus 4.8 597b002f01 Clearer wording for the tab-order list: "Tab order, press the move up and move down buttons to reorder"
Renamed from "Main tab order" and reworded the accessible name so NVDA reads a clear instruction
instead of the confusing "main tab order, then move up / move down".

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 13:31:47 +01:00
EdnunpandClaude Opus 4.8 78684f29f1 New Preferences "Appearance" tab: theme + show-pan/EQ moved in, tab reordering, peer-list toggles
Adds an Appearance tab (after General) and moves the colour theme and "show volume/pan/EQ tab" into
it, per Ed. New on that tab:
 * Main tab order — a list of the four main-window tabs (all shown, even when the pan/EQ tab is
   hidden) with Move up / Move down buttons to reorder them. Saved to AppConfig.MainTabOrder and
   applied by the new ApplyMainTabLayout (rebuilds the tab strip in order, dropping pan/EQ when off,
   preserving selection). Replaces RefreshPanEqTabVisibility.
 * Enable discovered / remembered peers lists on the Connectivity tab (AppConfig.ShowDiscoveredPeers
   / ShowRememberedPeers, both default on). RefreshConnectivityListVisibility hides the row's label
   and its list wrapper when off. Row labels are now captured for this.

All apply when Preferences closes. Manual updated. Build clean; --selftest passes; deployed to both
test folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 12:56:06 +01:00
EdnunpandClaude Opus 4.8 9c8e50667b Actually fix Connectivity tab order — set TabIndex on the list WRAPPERS, not the lists
Root cause of the repeated failures: each list is wrapped in a FlowLayoutPanel by AddCheckedListRow,
so setting the list's own TabIndex only ordered it inside its (single-child) wrapper and did nothing
to the tab traversal — the wrappers stayed at TabIndex 0 and sorted by add-order. Now the WRAPPERS
(list.Parent) carry the TabIndex, alongside the directly-added controls, giving:
connected, details, rename, discovered, remembered, add-by-IP, lock, status.

Set authoritatively in BuildConnectivityTab; removed the ineffective Connectivity block from
SetTabOrder. Verified against a faithful WinForms mock (GetNextControl walk) before shipping.

Build clean; --selftest passes; deployed. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 12:04:57 +01:00
EdnunpandClaude Opus 4.8 9d54d4c9e9 Connectivity tab order: Add-by-IP after the lists (per Ed's revised order)
Order is now connected, details, rename, discovered, remembered, add-by-IP, lock, status — in both
SetTabOrder (authoritative) and the visual layout. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 11:57:03 +01:00
EdnunpandClaude Opus 4.8 5e974f7064 Fix Connectivity tab order (SetTabOrder was overriding layout) and announce parametric gain
* Connectivity tab order: the real driver was SetTabOrder(), whose explicit TabIndex forced
   Add-peer-by-IP and Status to the end while the newer Peer details / Rename / Lock controls
   defaulted to 0 — so reordering the layout did nothing. SetTabOrder now lists every focusable
   control in the intended order: connected, details, rename, add-by-IP, discovered, remembered,
   lock, status.
 * Parametric bands Left/Right gain nudge now speaks: the new gain is announced via a UIA
   notification (NVDA reads it natively — not an extra speech layer), since a plain listbox item
   won't announce a value change on its own. The Bands list's accessible name now also hints that
   left/right adjust the gain, so it's discoverable.

Build clean; --selftest passes; deployed to both test folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 11:49:04 +01:00
EdnunpandClaude Opus 4.8 e35f2f318a Testing-feedback fixes: tab order, label wording, parametric editing, recording default
* Connectivity tab order: Add peer by IP now sits right after Rename peer (before the Discovered
   list), grouped with the connected-peer actions, per Ed's requested order. Dropped the second
   section header (only the lock toggle was under it).
 * Audio I/O labels: "Set volume for all received audio" → "Master volume for received audio" (the
   code never got this rename, only the manual had). Device lists now say "audio": "...for received
   audio" and "WASAPI/ASIO audio inputs/outputs to send". Labels + AccessibleNames updated together.
 * Add EQ band dialog: the spin/edit boxes now select-all on focus, so a typed value REPLACES what's
   there instead of being inserted next to it and reverting (typing 2.5 over 4.0 now works).
 * Parametric bands list: Left/Right arrow nudge the selected band's gain by half a dB, live —
   up/down still move between bands. NVDA re-reads the band's new dB.
 * Recording settings: source list reordered to Both (top, now the default) / Received / Sent;
   display order decoupled from the RecordingSource enum. Default RecordingSettings.Source = Both.
 * Preferences: Colour theme is now first in the General tab order.

Manual updated. Build clean; --selftest passes; deployed to both test folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 11:36:02 +01:00
EdnunpandClaude Opus 4.8 90a1ab3257 Visual polish pass: modern font, light/dark theme, app icon, accent, health cue
A do-no-harm cosmetic pass — all changes are colours/fonts/spacing/icons only; no control types or
accessibility wiring changed, so NVDA behaviour is unchanged. Held for next release.

 * Segoe UI 9pt app-wide (ApplicationDefaultFont) — was the legacy default font.
 * Follow the Windows light/dark theme via Application.SetColorMode, driven by a new AppConfig.ThemeMode
   ("system"/"light"/"dark", default system) read at startup in Program.Main (guarded — a failure just
   leaves the classic theme). New Preferences → General → "Colour theme (Alt+T)" picker; takes effect
   next launch.
 * Custom app icon (equalizer-bars motif): multi-size remsound.ico, embedded + set as ApplicationIcon,
   on the main window and the tray icon (dialogs are FixedDialog, no title-bar icon).
 * New Theme helper (accent colour, section-header + dialog-heading label factories, health colours)
   and StatusDot (a small NVDA-invisible colour dot).
 * Connectivity tab grouped under "Peers" and "Connect manually, and locking" section headers.
 * Connection-health colour dot in the status footer (green streaming / amber idle / grey off); the
   health text is unchanged.
 * Bold headings on the Rename peer, Add EQ band and Manage named peers dialogs.
 * EQ curve: soft translucent fill under the response line.

Audio I/O tab left un-restructured on purpose (its conditional ASIO rows make a blind layout change too
risky); its existing labels already read clearly. Manual updated. Build clean; --selftest passes;
deployed to both test folders.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 08:47:26 +01:00
EdnunpandClaude Opus 4.8 3c449d78b3 Named-peers registry + Options → Manage named peers dialog
Turns the flat friendly-name map into a proper machine-wide book (AppConfig.NamedPeers), and adds a
management dialog. Held for next release.

 * New NamedPeer record (machine name, friendly name, last address, last-seen UTC). AppConfig gains
   NamedPeers; the legacy PeerFriendlyNames map is migrated into it once on load, then no longer
   written. The book stays machine-wide and profile-independent (it always was — this just enriches it).
 * Only deliberately-renamed peers are recorded (per Ed) so the list can't balloon. A named peer's
   last address / last-seen are updated in memory each tick while connected; persisted on address
   change and on app close (timestamp-only changes don't thrash the disk).
 * Options → Manage named peers (Alt+O, N): lists each named peer as "friendly — machine — last seen
   date, address"; Rename (Alt+R / F2 / double-click) reuses RenamePeerDialog; Delete (Alt+D / Del)
   forgets the name. Edits refresh the connected/discovered lists, the volume/pan/EQ list and details
   box live.
 * ApplyFriendlyName now records machine name + last address alongside the name.

Manual updated (readme.html + MANUAL.md). Build clean; --selftest passes; deployed to both test folders.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 08:20:31 +01:00
EdnunpandClaude Opus 4.8 289bb2b15c F2 renames the highlighted connected peer (Windows Explorer idiom); manual note
Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 08:08:47 +01:00
EdnunpandClaude Opus 4.8 f35f6c3c28 Peer rename + details box on Connectivity tab; Add band dialog fixes
Add band dialog (from testing feedback):
 * Tab order is now Start, End, Gain, OK, Cancel (OK was after Cancel).
 * Gain box takes decimals like 1.5 (half-dB steps); parametric list shows one decimal.
 * The two frequency boxes start empty — nothing prepopulated to mislead; both required on OK.

New Connectivity-tab feature (held for next release):
 * Rename peer (Alt+M) opens a dialog to give a peer a friendly name, with a Clear custom name
   button. Names are keyed by the peer's MACHINE NAME (stable across restarts, IP changes and
   networks), stored machine-wide in AppConfig.PeerFriendlyNames, and resolved everywhere a peer
   shows: both peer lists (via PeerListItem.DisplayNameProvider), the volume/pan/EQ list, the
   status line and split-recording filenames. Manual-by-IP peers with no announced name fall back
   to keying by address.
 * Peer details (Alt+E): a read-only box for the highlighted connected peer showing name, machine
   name, IP, connected-for, link health + ping, what they're sending, and whether they're
   receiving our audio. "Sending: 2 devices on ASIO at 48 kHz, Opus" is derived from the live
   receive streams — each stream is one device and its lane gives WASAPI vs ASIO — so NO protocol
   change and no new privacy exposure. AudioReceiver.ActiveFormatsFromAddress added for this.

Manual updated (readme.html + MANUAL.md). Build clean; --selftest passes; deployed to both test
folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 23:56:42 +01:00
EdnunpandClaude Opus 4.8 033edd776f Volume/pan/EQ tab overhaul: one master switch, peer checklist, 16-band parametric EQ
Reworks the per-peer shaping tab (held for next release):

 * Renamed the tab to "Volume, pan and EQ for peers"; the Preferences toggle now defaults ON.
 * Collapsed the two master switches (Enable EQ / Enable pan) into ONE: "Enable volume, pan and
   EQ for all peers" (Alt+E). Volume now obeys it too. PeerDspChain.Build takes a single enabled
   flag; Profile.EnableAllPeerShaping replaces the two bools (old ones kept for load-migration).
 * Peer picker is now a CheckedListBox: ticking a peer shapes them (per-peer bypass via new
   PeerShaping.Enabled, default true); the focused row is the one the controls edit. Effective
   shaping = master switch AND that peer's tick. Letter-nav suppressed so keys never toggle a tick.
 * Three EQ modes, renamed: "3 band simple EQ", "12 band advanced graphic EQ", and the new
   "16 band parametric EQ" (PeerEqMode.Parametric16Band).
 * Parametric EQ: up to 16 user bands, each a boost/cut across a start->end range (PeerShaping
   .ParametricBands; ParametricToPeaking maps range -> peaking centre+Q, shared by DSP and curve).
   Add band dialog (spin-or-type, numeric-only, live preview, OK/Escape); Bands list sorted
   bass->treble reading "X Hz to Y Hz, plus/minus N dB"; Delete key / Delete button, multi-select.
   Set peer EQ to default clears the parametric list too.
 * dB now spoken as words ("plus 3 dB" / "minus 6 dB" / "flat") on the graphic sliders and the
   parametric list, since NVDA users typically have punctuation off and never hear a "+".
 * New unbound machine-wide global shortcut "Toggle volume, pan and EQ for all peers" (not stored
   in any profile) via the hotkey controller + settings store.
 * Renamed the Inputs/outputs "Set volume for all received audio" to "Master receive volume".
 * Added EqCurveControl: a purely-visual EQ response graph (not focusable, invisible to NVDA).
 * Full manual sweep (readme.html + regenerated MANUAL.md).

Build clean; --selftest passes. Deployed to both test folders. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 23:21:18 +01:00
EdnunpandClaude Opus 4.8 eaae76d015 Manual: document Pan and EQ, multi-track/raw recording, new naming, and the tab
Full sweep of readme.html (regenerated MANUAL.md) for the held batch:
 * New section 9 "Pan and EQ tab" — per-peer volume/pan/EQ, the two master switches, the peer
   picker, 3-band and 12-band (31/63/80/125/250/500 Hz, 1/2/4/6/8/16 kHz) EQ, reset button,
   real-time, saved per profile; shown via the "Show the Pan and EQ tab" Preferences checkbox.
   Sections 9-24 renumbered to 10-25; TOC entry added.
 * Recording section: the two new tickboxes (split into per-peer tracks; bypass pan/EQ for raw),
   and the new date-folder / "<time> RemSound recording <machine>" / multi-track-folder naming.
 * Section 4 tab list, keyboard-shortcuts (Pan and EQ tab: Alt+E/P/U/L/N/Q/M), and a Preferences
   mention. Replaced a stale old-format recording-filename example.

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:43:23 +01:00
EdnunpandClaude Opus 4.8 57847ff358 Pan/EQ: label the advanced mode "12 band"; single recordings include the machine name
Two of Ed's test findings: the EQ mode picker still said "10 band advanced EQ" (it's 12 now);
and a single-file recording's name now carries the recorder's machine name too —
"<HH-mm-ss> RemSound recording <machine>.<ext>" — matching the split tracks. Held for release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:36:17 +01:00
EdnunpandClaude Opus 4.8 c138fdf39c Pan/EQ: 12-band advanced EQ — swap 3 kHz for 80 Hz
Ed's tweak: drop 3 kHz, add 80 Hz in the low end (between 63 and 125). Still 12 bands, so no
array-length change. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:21:39 +01:00
EdnunpandClaude Opus 4.8 bbfa76945a Recording settings: open focused on the first checkbox, not the option columns
The dialog set sourceList.TabIndex=0, so it grabbed initial focus and the user landed partway
down, past the two new toggles. Put the toggles first in tab order (and ordered the containers,
so the top row precedes the grid), and force focus to the split-tracks checkbox on show.

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:20:31 +01:00
EdnunpandClaude Opus 4.8 d0d14ab95c Pan/EQ: 12-band advanced EQ (add 3 kHz and 6 kHz)
Ed wanted a band between 4 and 8 kHz. Advanced EQ goes from 10 to 12 bands: added 6 kHz (4-8
gap) and 3 kHz (2-4 gap) for even resolution through the presence region. PeerShaping
.AdvancedBandsDb default is now 12; MainForm.NormalizeBands grows an older 10-length array on
load so nothing breaks. (Feature unreleased, so no shipped settings to migrate.) Held for
next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:16:21 +01:00
EdnunpandClaude Opus 4.8 fc4ad3bb92 Recording fixes: date folders on top, and multi-track honours the Source setting
Two issues Ed found testing:
 * The default recordings path was recordings\<machine>\, so date folders nested under a
   machine-name folder. Dropped the per-machine subfolder — recordings now nest by date at the
   top (recordings\<yyyy-MM-dd>\...); the machine name still appears in split-track file names.
 * Multi-track always created the "me" (sent) track regardless of the Source setting, so a
   receive-only recording wrongly produced a track of your own machine. Multi-track now follows
   Source like single-file does: peer (received) tracks unless "sent only", and your own (sent)
   track only when Source is "both" or "sent only".

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 20:10:39 +01:00
EdnunpandClaude Opus 4.8 6b1e65f418 Pan/EQ: add a per-peer volume slider (before pan)
Ed's request — an individual level fader per peer, sitting just before the pan control on the
Pan and EQ tab. New PeerShaping.Volume (0..1, default 1.0 = 100% = transparent), always applied
(no master switch — unity does nothing). It folds into PeerDspChain's L/R gain alongside pan
(gainL = panL*vol, gainR = panR*vol), so it's another per-sample multiply, zero added latency,
and multiplies with the global volume (per-peer fader -> mix -> master). Slider is 0-100%,
saved per profile, announces "Volume: N percent". Shaped recording captures it; raw (bypass)
recording doesn't. Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:45:52 +01:00
EdnunpandClaude Opus 4.8 efa9435da7 Recording: sum each peer's streams per track (record how it sounds)
Follow-up to the multi-track feature (Ed): the split path wrote each per-peer tap straight to
that peer's file, so a peer sending on more than one lane stacked their streams sequentially
instead of summing. Playback and the single-file path already sum; now the per-peer path does
too. Each PeerTrack accumulates that peer's block(s) per render and flushes the sum once on the
block boundary (OnRecordBlockComplete = FlushPeerTracks). "Sum to listen, sum to record."

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:39:09 +01:00
EdnunpandClaude Opus 4.8 de55230048 Multi-track + shaped/raw recording (per-peer split tracks) — held for next release
Recording Settings gains two per-profile toggles (Ed's request):
 * "Split recording into separate tracks" — each recording becomes a folder with one file per
   connected peer (their received audio only) plus one for your own send.
 * "Bypass pan and EQ when recording" — record the RAW audio (before pan/EQ) instead of the
   shaped audio you hear; applies to single and split.

Engine: a per-peer record tap in SessionPlayout hands each peer's block to the recorder RAW
(before pan/EQ) or SHAPED (after) per the bypass flag; PlayoutEngine propagates the tap to all
sessions (+ inherits on reconnect) and fires OnRecordBlockComplete each render; AudioReceiver
exposes SetPeerRecordTap / OnRecordBlockComplete. AudioRecorder now accepts an explicit path and
exposes ExtensionFor. RecordingController composes one AudioRecorder per track: multi-track =
a recorder per connected peer + a "me" recorder; single-track shaped = the existing mixed tap;
single-track raw (bypass) = sum each peer's raw block per render, flushed on the block boundary.

Naming (Ed's scheme, sortable): <recordings>/<yyyy-MM-dd>/ then, single-track, "<HH-mm-ss>
RemSound recording.<ext>"; multi-track, a folder "<HH-mm-ss> RemSound recording multi track/"
containing "<machine name> <HH-mm-ss>.<ext>" per peer (name or IP) and for your own send.

Known edge (noted): a peer using sender-side BothIndependent (two lanes) records both lanes to
one file in a split recording; single-track bypass sums per render in the Mixed path. Off by
default (both toggles unticked = today's behaviour). Builds clean; pending Ed's hands-on test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:05:00 +01:00
EdnunpandClaude Opus 4.8 703e6a022d Fix #18: accept audio from all of a multi-homed sender's source IPs
A sender reachable at more than one IP at once (e.g. LAN + Tailscale/VPN) picks its own
egress interface per packet, so its audio can arrive from a different IP than the single
address we discovered/dialled and allow-listed. The receiver then silently dropped every
Format/Audio packet (packetsRejectedNotAllowed climbing) while heartbeats — which skip the
allow-list — kept the peer showing connected: connected but silent. (Reported by
Jonathans859 building the RemSoundApple client; receiver-side, affects any multi-homed
sender incl. Windows<->Windows over a VPN.)

Discovery now remembers ALL source IPs per peer InstanceId (PeerDiscoveryService
.addressesById, expired on the same 8 s window; GetKnownAddresses). PushAllowedReceiveSenders
unions each selected peer's endpoint address with every address that peer has announced from,
so audio from any of the peer's interfaces is accepted. The SEND targets are unchanged
(still single-address) — only the accept-list widens, and only to other addresses the SAME
peer (by InstanceId) announced from, so it can't accept an unrelated machine.

Held for next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-04 14:26:42 +01:00
EdnunpandClaude Opus 4.8 1c1bf5a5cb Per-peer pan + EQ ("Pan and EQ" tab) — off by default, held for next release
New feature (Ed's jam-mixing request): pan and EQ each peer's signal independently.

Engine (zero added latency — per-sample, applied to each peer's isolated block just
before the mix): PeerDspChain (balance pan + RBJ biquad EQ) built on the UI thread and
swapped onto SessionPlayout via a volatile reference; PlayoutEngine remembers it per
address so a reconnecting peer keeps its shaping; AudioReceiver.SetPeerDsp facade.

Model: per-profile PeerShaping dict (keyed by peer address) + EnablePan/EnableEqForPeers
master switches; machine-wide AppConfig.ShowPanEqTab. Fixed band layouts in PeerEqBands
(3-band tone control: bass/mids/treble shelves+bell; 10-band ISO graphic EQ), +/-12 dB.

UI: a "Pan and EQ" tab (before Audio profile, shown only when ShowPanEqTab is on) with
the two enables, a connected-peer picker, a pan slider (balance, keeps stereo), a
"reset EQ" button (clears both modes' bands, leaves pan), a 3/10-band mode picker and its
band sliders — all TrackBars (arrow + page-up/down), updating in real time and saved per
profile. Sliders set a friendly AccessibleName on change (pan centre/left/right %, band
dB). "Show the Pan and EQ tab" checkbox added to Preferences > General.

Everything is off by default (tab hidden, both enables off), so this is dormant for all
users until switched on. Builds clean. Pending Ed's hands-on testing before release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-04 13:54:30 +01:00
EdnunpandClaude Opus 4.8 d7f6d9fd9d Release v4.9: lock a profile to fixed peer addresses (#17)
Ships the per-profile "Lock to these exact peer addresses, no matter what" toggle.
Version 4.9; About changelog + RELEASE_NOTES added.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 17:04:22 +01:00
EdnunpandClaude Opus 4.8 c7d422e3ba Add per-profile "Lock to exact peer addresses" setting (#17, held for next release)
Feature request from the same singer: a way to pin a profile to exact peer addresses
so RemSound never matches the other computer by its advertised name and never switches
to a different address it discovers — for a machine reachable at two addresses at once
(VPN + LAN), they want only the one they chose, and would rather the connection die than
wander. The logical end of the v4.7/v4.8 direction.

New per-profile Profile.LockPeerAddresses (default false), round-tripped through
RemSoundSettingsStore (ApplyProfile/CopyTo + Load/SaveLockPeerAddresses), mirroring the
PriorityMode pattern. New AccessibleCheckBox on the Connectivity tab ("Lock to these exact
peer addresses, no matter what — never follow names or switch", Alt+L), saved with the
profile, marks the profile dirty on change. When set, RefreshKnownPeers early-returns
before the discovered-peer merge and the address-follow, so the profile's peers stay
exactly as set (the allow-list is still pushed). Off = unchanged behaviour.

Manual: rewrote the "Connecting to one specific IP" section (which over-promised that
add-by-IP "can never drift" — the merge/follow could) into an unambiguous "Locking a
profile to one exact address" section, plus a Connectivity-tab control-table row.

Held for the next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 15:31:50 +01:00
EdnunpandClaude Opus 4.8 0df2a576fc Release v4.8: fix rare crash from endpoint thrash on a dual-address peer (#16)
The same singer hit a rare crash: their transmitter (COMP3) was reachable at two
addresses at once — the VPN address 10.8.0.1 they chose and that machine's wireless
192.168.3.245 — and the discovery-driven endpoint-follow ping-ponged the connection
between the two (the log shows four moves in 58 ms) right where the process died with
no shutdown line, no managed exception, no dialog: a hard crash from the receiver
audio-session teardown/rebuild churn the thrash caused.

Fix: the follow loop now never moves off an endpoint that's still answering heartbeats,
only follows once the current one has been unreachable for a sustained grace period
(6 s), only to an address that is itself answering, and never more than once per cooldown
(15 s) — so it can't thrash, and a peer reached on a working address stays put (honours
the singer's "just stay on 10.8.0.1"). New endpointUnreachableSinceUtc + lastEndpointMoveUtc
state; genuine DHCP/network moves are still followed a few seconds later.

Also: a global crash handler (Program.WriteCrashReport on AppDomain.UnhandledException +
TaskScheduler.UnobservedTaskException) writes a crash-*.txt into the logs folder, so a
future "RemSound just vanished" report leaves a stack behind. Removed a stale doc comment
left over from the v4.7 adoption removal. Manual gains a "RemSound closed unexpectedly"
troubleshooting entry. Version 4.8; About + RELEASE_NOTES updated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 22:57:49 +01:00
EdnunpandClaude Opus 4.8 64d5cb5a86 Release v4.7: keep trying your configured peer after a reboot (#15)
Removes the heartbeat "adopt a live address" feature (added v1.6). On a LAN with
more than one RemSound machine it could latch a receiver onto an unrelated sender
that happened to be pinging the audio port — then never recover to the real peer,
needing a manual restart (the singer's #15, with log). The feature guessed peer
identity from an untracked ping source with no way to verify it was the same peer;
on the stable VPN/LAN addresses RemSound is actually used with, it only ever caused
harm, since same-address reconnect already works via the continuous heartbeat.
Removed TryAdoptLiveHeartbeatAddress + IsPrivateLanAddress (MainForm) and
GetUntrackedPingSources + recentPingSources (HeartbeatService); the identity-safe
discovery-based following (by verified peer ID) stays. Manual troubleshooting entry
rewritten to match.

Also bundles the held changes since v4.6: status reads line-by-line with GB totals
and double-press-to-copy, CPU/memory in the status, the Install Scripts folder, and
the what's-new-after-failed-update fix. Version 4.7; About + RELEASE_NOTES updated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 22:41:43 +01:00
EdnunpandClaude Opus 4.8 843be9b7fb Speak-status: drop the double-press-copy Preferences toggle
Andre confirmed (via NVDA speech history) that holding the speak-status hotkey
doesn't repeat or spam — so the defensive toggle that let users disable the
double-press-to-copy was needless configurability. Removed the Preferences
checkbox and the DoublePressStatusToCopy setting; double-press-to-copy (Andre's
own idea) stays, now simply always on. There was never any debounce/anti-spam
code to remove — the only timing is the 600 ms double-tap detection window, which
is the feature itself. Manual updated to drop the toggle line.

Held for the next release (the toggle never shipped).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 18:55:03 +01:00
EdnunpandClaude Opus 4.8 6c36369806 Docs: correct RemSound's origin story (true remote-audio-monitoring use)
The manual intro and the repo README both carried an invented origin (a guitarist
and singer playing together, "built by a sound designer"). RemSound was actually
built to hear the audio from a powerful computer while working remotely from a
lighter one — other programs can move audio between PCs, but none did it quite the
way Ed wanted. Reworded the manual opening (readme.html) and the README audience
and "Who made this" lines to tell one true, consistent story in Ed's voice. The
music-together and podcast uses stay as the genuine secondary use cases they are.

readme.html ships to users on the next release; README/MANUAL update on push.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 16:04:31 +01:00
EdnunpandClaude Opus 4.8 771a358a87 Status box: show RemSound's own CPU and memory usage (held for next release)
New last status line "CPU usage 2% and memory 184 MB" — CPU as a share of the whole machine
(Task Manager style: process CPU-time delta / wall-clock / logical-core count), memory as the
working set via the same MB-to-GB formatter the totals use. Sampled on the existing once-a-second
status tick with a cached Process handle. Shows on screen and reads/copies with the rest of the
status (Ed's idea).

Held for the next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 15:22:40 +01:00
EdnunpandClaude Opus 4.8 be32a060e7 Add "double-press to copy status" toggle + document the spoken-status changes (held for next release)
Preferences General-tab checkbox "Double-press the speak-status hotkey to copy the status to the
clipboard" (Alt+C), machine-wide (AppConfig.DoublePressStatusToCopy), on by default. When off, a
double press just reads the status again. SpeakStatusLine reads the flag only when the timing already
qualifies, so a normal single press never touches the config. Manual's speak-status section now
covers the line-by-line read, GB totals, and the double-press copy + its toggle.

Held for the next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 14:47:02 +01:00
EdnunpandClaude Opus 4.8 0fe9637356 Status speech: read line-by-line, MB->GB on totals, double-press to copy (held for next release)
Andre's feedback on the spoken status (the issue #13 feature):
- Speak the status one line at a time instead of collapsing the lines into a run-on sentence —
  this also removes the doubled "." the collapse produced (each line already ended in a period).
- Totals switch to GB once they reach a gigabyte ("4.5 GB" vs "4558.2 MB"), via a FormatDataSize
  helper used by the readout itself so the on-screen and spoken figures stay consistent.
- A quick DOUBLE press of the speak-status hotkey copies the status to the clipboard (with a
  "copied" announcement) so it can be shared with others.

Held for the next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 14:31:03 +01:00
EdnunpandClaude Opus 4.8 f9b3ed9e67 Add Install Scripts (winget .NET 10 install) for the no-runtime case (held for next release)
RemSound is a .NET 10 app, so it can't install its own runtime — it can't start without it. A
plain .cmd/.ps1 (which run on what's already in Windows) sidesteps that: double-click
"Install Scripts\Install .NET for RemSound.cmd" and it winget-installs the .NET 10 Desktop Runtime
(Microsoft.DotNet.DesktopRuntime.10), falling back to opening Microsoft's download page if winget
is absent. Modelled on Andre Louis's accessible-sensor-readout Install_Scripts (his install .NET
Framework 4.8 because SR is Framework; ours installs the .NET 10 Desktop Runtime RemSound needs).

Bundled into the build + release zip via csproj Content + EnsureInstallScriptsPublished target.
Manual Quick-start note points users here if RemSound won't start. Held for the next release.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 14:24:20 +01:00
EdnunpandClaude Opus 4.8 e710834458 Fix what's-new re-appearing after a failed update (held for next release)
Replace the running-version-vs-saved-version trigger for the "what's new" popup with a
one-shot marker the updater writes ONLY on a successful update (UpdateApplier success
path). A failed/rolled-back update never writes it (and clears any stale one), so it can
no longer re-trigger what's-new — the old best-effort flag save could lose a race during
the update churn and leave the version mismatched, which was the bug.

New WhatsNewMarker seam (Write/Exists/Consume) + a SelfTest case for the consume-once
contract. MaybeShowWhatsNewAfterUpdate now shows iff the marker is present, then deletes
it; still records LastWhatsNewVersion for the import-offer's upgrade detection.

Not released yet — bundling with the connection-retry (#15) work in the next release.
No version bump, no manual change (internal fix).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 17:16:54 +01:00
EdnunpandClaude Opus 4.8 36431d6d39 Release v4.6: follow the Windows default audio device (output + input)
- New "Use Windows default audio device, follows Windows changes" entry at the top of the
  received-output and send-input WASAPI lists. Resolves the current Windows default live,
  re-routes automatically when the default device changes, works alongside specific devices,
  and persists across launches (a follower can't go stale). Optional "untick the others?"
  prompt with a remembered "don't ask again", reset via a new Options item "Reset the default
  audio device prompt".
- Manual updated for the feature, plus a sweep that corrected the now-stale Options-menu
  section (retired Startup-behaviour item, four->five Preferences tabs, missing entries).
  About changelog and RELEASE_NOTES updated; version 4.6.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 11:41:58 +01:00
EdnunpandClaude Opus 4.8 962f35ab80 Release v4.5: import shortcuts on pre-4.4 upgrade + clearer shortcuts dialog
- Pre-v4.4 upgraders are offered a one-time dialog to copy their keyboard shortcuts
  from one of their profiles (still readable in the profile files) instead of being
  reset. Users who already went through v4.4's reset are deliberately NOT re-offered
  (gated on KeyboardShortcutsGlobalNoticeShown). New KeyboardShortcutImportDialog +
  AppConfig.KeyboardShortcutsImportOffered + MainFormHotkeyController.ReloadAndReRegisterAll.
- Keyboard shortcuts dialog: new "Clear this shortcut" button; Delete inside the
  capture box leaves a shortcut unassigned.
- Relabelled the three RemSound-app remote rows to "Send remote RemSound volume/..."
  to distinguish them from the Windows-global ones.
- Manual (readme.html + MANUAL.md), About changelog, RELEASE_NOTES updated; version 4.5.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 06:36:00 +01:00
EdnunpandClaude Opus 4.8 8a1bc0c813 Release v4.4: keyboard shortcuts are now machine-wide, not per-profile
Fixes issue #14: shortcuts were stored on each Profile, so one set on profile A
didn't apply on profile B and seemed to vanish on switch. They now live in
AppConfig (one set shared by every profile). RemSoundSettingsStore's Load*/Save*
hotkey methods re-point to AppConfig (callers unchanged); the per-profile cache
fields, profile load/save plumbing, and the HotkeySetting helper class are removed.
Profile's HotkeyRecord fields stay only for back-compat deserialization.

On upgrade, shortcuts reset to defaults (there's no single correct set to carry over
since profiles could hold different/partial sets). A one-time startup notice tells
upgraders to re-set them; fresh installs are silently marked done (nothing to reset).

Manual, About changelog and RELEASE_NOTES updated; csproj <Version> 4.4.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 23:11:53 +01:00
EdnunpandClaude Opus 4.8 32be3426e7 Release v4.3.1: quieter default update sound
Both update cue variants ("update 1.wav" / "update 2.wav") replaced with a
gentler mix that signals an incoming update without interrupting work mid-flow.
About-box note added (tidied wording); csproj <Version> bumped to 4.3.1. No code
changes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 14:46:46 +01:00
EdnunpandClaude Opus 4.8 fd5c31740a Release v4.3: speak status line (Tolk) + Logging tab with housekeeping
- New screen-reader hotkey "Speak the RemSound status information" (issue #13):
  reads the status line aloud through the active screen reader via Tolk, fires from
  anywhere (system-wide), unset by default. Built behind an IScreenReaderOutput seam
  so a future build can swap Tolk for Prism on Windows 10+ without touching callers.
  Tolk DLLs vendored under tolk/ and shipped next to the exe.
- New Logging tab in Preferences: Enable logs + Write logs now moved there, plus
  opt-in startup "warn if logs folder exceeds N MB" and "delete logs older than N days",
  and a "Delete all logs" button (Yes/No confirm). New LogMaintenance helper + AppConfig
  settings drive it.
- Manual (readme.html + regenerated MANUAL.md), About changelog and RELEASE_NOTES
  updated in plain English; csproj <Version> bumped to 4.3.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 13:09:06 +01:00
EdnunpandClaude Opus 4.8 034a7de632 Release v4.2: fix connect-freeze (#10) and new-profile minimize (#12); smoother WASAPI timing
- Connect no longer freezes: PushDiscoveryUnicastHints resolved remembered
  hostnames with synchronous Dns.GetHostAddresses on the UI thread, blocking the
  whole window for the DNS timeout on an unresolvable name. A screen-reader user
  experiences that as the entire machine locking up. Resolution now runs off the
  UI thread. Same class of bug as the v3.0.1 UPnP-on-the-UI-thread hang. (#10)

- New profile / profile switch no longer hides the window: OnShown ORed the
  global StartMinimised into every instance, so creating a new profile while
  Start minimised was on dropped the window to the tray and looked like a crash.
  StartMinimised now applies only to a genuine cold launch; relaunches honour the
  explicit per-instance flag. (#12)

- Smoother WASAPI audio: the receive producer loop and sender mix loop pace
  themselves with WaitHandle.WaitOne, bound by the system timer (~15.6ms default).
  Without a fine timer the 10ms feed slips to ~16-31ms and delivers audio in
  chunky bursts (the desktop-render chunkiness behind Andre's dropouts/lag). New
  SystemTimerResolution holds a 1ms timer whenever a stream is live, independent
  of the opt-in Priority mode.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 09:21:04 +01:00
EdnunpandClaude Opus 4.8 5abbeefe29 v4.1: two screen-reader fixes — silent start-in-tray, announce on restore
- Starting straight into the tray (StartMinimised / --minimized) no longer plays the "minimise"
  cue; only a genuine user minimise does (the startup path passes playCue:false)
- Restoring the window from the tray now lands focus on a real named control on the active tab so
  NVDA announces it, instead of resting on the role-less QuietTabControl and surfacing silently
- Shared the focus-a-leaf-for-announcement helper between the main window and Preferences

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 15:59:59 +01:00
EdnunpandClaude Opus 4.8 a408d2b56e v4.0: full audio-cue system, cause-aware auto-tune, four-tab Preferences, install-side default sounds
Audio cues
- Cues for send/receive on-off, minimise/restore, checkbox tick/untick, and tab switch
- Soft keyboard clicks while typing, with a distinct passkey sound on password fields
- Per-cue "Choose sound" variant picker; "(none)" silences a cue; front-most missing-sound warning
- Send/receive cues take priority over the generic checkbox sound; programmatic ticks stay silent

Preferences
- Redesigned into four tabs (General, Audio cues, Startup behaviour, Update settings)
- Startup behaviour moved in from the Options menu
- NVDA now announces the dialog on open (focus a real named control, not the quiet tab control)

Auto-tune
- Cause-aware: tells device render-callback stalls (more buffer can't fix) apart from genuine
  network/buffer starvation, so it no longer pins latency high on chunky onboard cards
- Lowering the target eases the buffer down (glide) instead of trimming it, so no clicks while tuning

Sounds layout
- Shipped defaults moved out of the per-user folder into an install-side "default sounds" folder,
  so updates can refresh them; user customs are Browse-picked file paths and are left untouched
- Startup migration removes both legacy sound folders; verified from oldest (v1.0-v3.3) and v3.4 layouts

Quiet automated launches
- New --silent launch flag mutes all cue sounds and suppresses the startup dialogs (migration notice,
  update check, Realtek/mic/missing-sound warnings) so test launches never disturb the user
- run-tests / build-release / SelfTest repointed to the new "default sounds" layout

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 11:57:19 +01:00
EdnunpandClaude Opus 4.8 0b7ad49021 Fix: passkey sound now layers in on password fields
RemSound's password boxes are deliberately NOT PasswordChar-masked (a screen-reader user can't see
a mask), so the key-click hook's "is this a password field?" check (UseSystemPasswordChar /
PasswordChar) was always false and the distinct passkey.wav never played. Password fields now mark
themselves with Tag = KeyClickService.PasswordFieldTag, and the hook checks that (keeping the
masking-flag check as a fallback). Tagged both password fields - ProfilePasswordDialog (which all
password entry routes through, including the send/receive streaming gate) and
ProfilePasswordManagerDialog. So a key click + passkey now layer together on every password keystroke.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 07:23:54 +01:00
EdnunpandClaude Opus 4.8 56417eb7c3 Cues: send/receive checkboxes' own cue sounds take priority over the generic checkbox sound
The Send/receive checkboxes have dedicated cue sounds (send/receive turned on/off) AND would
otherwise also fire the generic checkbox tick/untick. AccessibleCheckBox gains a SuppressCheckSound
gate; the send/receive checkboxes set it so that when their dedicated cue is on, only that cue
plays. When the dedicated cue is "(none)", the gate returns false and the generic checkbox sound
plays as normal - so the checkbox sound never overrides the purpose-built send/receive sounds.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 06:53:36 +01:00
EdnunpandClaude Opus 4.8 2eaf7da184 Manual: document the Preferences tabs, the cue "(none)" model, and the missing-file warning
Audio cues section rewritten for the redesign: the cue list is a plain list you arrow through to
hear each cue, the "Choose sound" list's "(none)" entry turns a cue off (no more tickboxes), and
a new note covers the front-most "couldn't find the sound file" warning + auto-disable. Startup
behaviour section and the Menus -> Preferences entry updated for the four-tab Preferences dialog
(General / Audio cues / Startup behaviour / Update settings) and the retired Options-menu item.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 06:47:57 +01:00
EdnunpandClaude Opus 4.8 e8dcf724d8 Cues: front-most "missing sound file" warning + auto-disable
When a cue is switched on but its sound file can't be found (the player resolved to null - e.g.
a custom WAV was deleted, or a chosen sound is gone), RemSound now turns that cue off and tells
the user, front-most even when minimised (RestoreFromTray first), once per cue per session:
"RemSound was unable to find the <cue> sound file used when <event> happens. RemSound has set
this particular audio cue to not play for now, until a new sound file is specified."

CheckForMissingEnabledCues runs on first show (Shown) and after every cue reload (so it catches
a just-deleted custom WAV when the user closes Preferences). Per-profile cues are turned off via
the settings store, machine-wide cues via AppConfig.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 06:43:48 +01:00
EdnunpandClaude Opus 4.8 75e7432fcb Preferences: four accessible tabs (General / Audio cues / Startup behaviour / Update settings)
The Preferences dialog is now a QuietTabControl with four tabs (same accessible tab approach as
the main window; Ctrl+Tab / arrows switch tabs):

- General: profiles-folder browse, accept-remote-volume, UPnP, enable logs / write logs now.
- Audio cues: the redesigned cue UI (plain cue list + "(none)" sound option) + keyboard clicks.
- Startup behaviour: Start minimised / Start with Windows / Start with a specific profile -
  moved here from the standalone Options-menu dialog, wiring and persistence unchanged (AppConfig
  + the Windows auto-start registry entry).
- Update settings: startup-check, frequency, check-now, silent-install, show-what's-new.

Removed the Options-menu "Startup behaviour" item and deleted the now-unused
StartupBehaviourDialog.cs (and dropped it from the self-test's accessibility audit). The audit
still passes on the tabbed dialog with no mnemonic clashes (Alt-letters are isolated per tab).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 06:39:57 +01:00
EdnunpandClaude Opus 4.8 0bd3ef0018 Audio cues: redesign the cue UI - plain cue list + a "(none)" sound option replaces the tickboxes
The per-cue enable tickboxes are gone. The cue list is now a plain list of names; arrowing it
previews that cue's current sound (custom or chosen default). The sound list below gains a
"(none)" entry at the top: picking it turns the cue off (reusing each cue's existing on/off
storage - per-profile cues persist off-ness in the profile, machine-wide cues in global
settings), and picking a numbered variant turns the cue on and records that sound. All cues
default on, on the first variant; "(none)" is never the default.

Part of the larger Preferences overhaul; the 4-tab restructure, the Startup-behaviour/Update
moves, and the missing-file error are the remaining steps.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 00:50:45 +01:00
EdnunpandClaude Opus 4.8 aed555cc2e Reset-ASIO button + checkbox tick/untick sounds (parts 1-2 of the cue/preferences overhaul)
Part 1 - "Uncheck all inputs and outputs" button now also resets the ASIO driver to "(none)":
renamed to say so, and UncheckAllDevices sets asioDriverBox to row 0 for a full clean
WASAPI-only, nothing-selected state.

Part 2 - checkbox tick/untick sounds: every checkbox toggle anywhere in RemSound now plays a
short cue (check.wav on tick, uncheck.wav on untick) - instant feedback on which way a box
went, especially in the inputs/outputs lists. New CheckSoundService + two machine-wide cues
(CheckboxOn/Off) with the usual numbered-variant + Preferences treatment. Hooked from
AccessibleCheckBox.OnCheckedChanged and the device lists' WireCheckedListAccessibility, both
gated on the control being Focused so a genuine user toggle clicks but bulk programmatic
(un)checking (profile load, "uncheck all") stays silent. Reloaded at startup and on cue change.

Tests + manual updated; .sfk byproducts cleared.

Remaining for the overhaul (next): tabbed Preferences (General / Audio cues / Startup behaviour /
Update settings), the cue-list redesign with a "none" option replacing per-cue checkboxes, moving
Startup behaviour out of the Options menu, and a front-most "missing sound file" error.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 00:42:41 +01:00
EdnunpandClaude Opus 4.8 8763470037 Audio cues: add send/receive on-off and minimise/restore cues (2 sounds each), drop .sfk byproducts
Six new machine-wide cues, each with the same numbered-variant + Preferences treatment as
the others (enable tickbox, Choose default sound picker, Play/Browse):

- Send turned on / off, Receive turned on / off: fire from OnStreamingCheckboxChanged, so
  they sound whether the user clicked the in-window tickbox or pressed the mute shortcut
  (the hotkey flips .Checked, which routes through the same handler). Suppressed during
  profile load by the existing password-gate guard, so loading a profile doesn't blast them.
- Minimise (hide) / Restore (show): fire from the tray controller's Minimize()/Restore() on a
  genuine visibility transition (guarded against no-op / startup-minimise).

Enable flags + custom-WAV overrides for these six live machine-wide in AppConfig
(EnableSendOnCue.., MachineCueCustomPaths) - they're app-level feedback, not per-profile
audio - so no Profile/settings-cache plumbing. TryLoadCueSound now also honours the
machine-wide custom path. PreferencesDialog gains a MachineRow helper + the six rows.

Sounds: shipped via the existing sounds\*.wav wildcard. Fixed an obvious typo in the
supplied files ("rcieve off 1.wav" -> "recieve off 1.wav") so receive-off has both variants.
Renamed the old single-name cue WAVs to Ed's numbered-variant set; added key/passkey and the
new cue sounds.

build-release.ps1: new step deletes the SoundForge .sfk peak-file byproducts from sounds\
before packaging (they never shipped - build is *.wav only - this just keeps the tree tidy).

Tests + manual updated for the six new cues.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 00:18:09 +01:00
EdnunpandClaude Opus 4.8 e526014e6a Audio cues: per-cue default-sound picker, keyboard-click typing feedback, passkey on password fields
Cue sounds now ship as numbered variants ("connect 1.wav", "connect 2.wav", ...); the
count is never hard-coded so more can be added with no code change.

- CueSounds.cs: discovers a cue's "<base> <n>.wav" variants (case-insensitive) and
  resolves the active default: per-profile custom WAV > machine-wide chosen variant >
  first variant > silent. Wired into MainForm.TryLoadCueSound, the startup cue in
  Program.cs, and PreferencesDialog.ResolveCueFilePath.
- AppConfig: DefaultCueSounds (machine-wide cueId -> chosen filename) and
  EnableKeyboardClicks (on by default).
- Preferences: a "Choose default sound" listbox under the cue checklist - it lists the
  selected cue's variants, arrowing it previews each sound and makes it that cue's
  default. Plus a "Play keyboard clicks when typing into any edit field" checkbox.
- KeyClickService.cs: an app-wide WM_CHAR message filter + a low-latency NAudio mixer.
  Typing into any edit field plays a random key click (key 1..N.wav); password fields
  also play passkey.wav at the same instant. On/off live from the Preferences toggle.
  Inert if the sounds are missing or the device won't open; never consumes the keystroke.
- csproj: ship every sounds\*.wav via a wildcard (variants, key clicks, passkey, future
  additions) instead of stale per-file canonical names.
- Tests: resource checks (self-test + run-tests.ps1) now verify each cue has >=1 variant
  and that key 1.wav / passkey.wav are present. Accessibility audit still green with the
  new Preferences controls (Alt+D, Alt+K - no mnemonic clashes).
- Manual: variant picker, keyboard clicks, and the new sound-file naming documented.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 00:06:07 +01:00
EdnunpandClaude Opus 4.8 ad66fe5364 Test suite: richer diagnostics, headless accessibility audit, perf/leak sanity
Andre's three "bigger ideas" from RemSound-smoke-test-agent-brief.md:

- Richer diagnostics: --diagnostics now includes a live localhost audio self-check
  (PCM + Opus, with packet/underrun/drop/buffer/latency counters), the most recent
  session snapshot parsed from the log (codec, send/receive state, buffer, drops,
  heartbeat), and a recent-warnings/errors digest from the log. BuildDiagnosticsReport
  gained a runLiveAudioProbe flag so the self-test's privacy check stays fast.

- Headless accessibility audit: new --selftest step constructs the dialogs that can be
  built without hardware (Startup behaviour, Recording settings, Preferences) and checks
  every actionable control announces a name and that Alt-key mnemonics are unique within
  a container. MainForm is out of scope (its constructor opens audio/hotkeys/sockets).
  Dialogs that won't construct are skipped, not failed. Currently audits 3, no violations.

- Perf/leak sanity: new --perftest command runs several audio-loopback cycles and reports
  whether handle/memory/thread counts stay bounded (handles ratcheting up cycle-on-cycle is
  the leak fingerprint, given RemSound's handle-leak history). Lenient thresholds; logs the
  numbers for build-to-build comparison. Wired into run-tests.ps1.

- Shared AudioLoopback helper (used by the self-test, diagnostics and perf test) so all
  three exercise the identical real capture/encode/network/decode path on test port 47929.

- csproj: the four previously-unconditional cue Content items are now Exists-guarded like
  the rest, so a mid-edit sounds\ folder doesn't break the dev build; the gate still
  enforces the required cues before release.

Help + manual updated (--perftest, --smoke-test, --config-dir, richer --selftest).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 23:45:08 +01:00
EdnunpandClaude Opus 4.8 832ed40bf7 Test suite: add --config-dir isolation, --smoke-test alias, and a cold-start/close gate step
Adopted from Andre's RemSound-smoke-test-agent-brief.md - the gaps our pack didn't
already cover:

- --config-dir <folder>: redirect ALL user state (config, profiles, logs, cue
  sounds) to an explicit folder for this process only, applied at the very start of
  Program.Main before the layout migration runs. Lets a test exercise a real build
  without touching the user's live settings (the brief's safety rule 1). Works with
  every command. AppConfig gains SetUserDataDirectoryOverride / an override on
  UserDataDirectory; CommandLine.TryGetConfigDir parses it early.
- --smoke-test / --smoketest: alias for --selftest, matching the brief's vocabulary.
- run-tests.ps1: a cold-start + clean-close smoke (brief baseline steps 3-4) -
  launches the GUI minimized against an isolated --config-dir, confirms it stays up,
  that it used the isolated folder (real settings untouched), and that --close shuts
  it down with no orphan process. SKIPs cleanly if a RemSound instance is already
  running (machine-wide single-instance lock).

Manual + --help updated for both switches.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 23:12:22 +01:00
EdnunpandClaude Opus 4.8 141c5e8ce1 Add build-and-test suite (in-app self-test + publish gate); fix release-zip missing sounds
The test suite, modelled on Andre's Sensor Readout (an in-app self-test + a build
script), runnable as one step before every publish.

Part 1 - in-app multi-step self-test (SelfTest.cs), run by --selftest:
  audio round-trip (PCM + Opus over localhost, dedicated test port so it never
  clashes with a running instance), encryption right/wrong-password + fingerprint,
  packet framing + malformed rejection, client<->server wire-format compatibility,
  settings save/reload, profile save/reload (temp folder), diagnostics-report
  privacy (never leaks a password), and bundled-resources present. Each step is
  timed and reported PASS/FAIL/SKIP; exit 0 only if nothing failed. Replaces the
  old single-shot --selftest. RunDiagnostics refactored to expose
  BuildDiagnosticsReport(AppConfig) for the privacy step.

Part 2 - run-tests.ps1: builds, then checks the package (sounds, readme, native
  opus, framework-dependent, dll version == csproj), the About-box changelog, the
  client/server wire contract (relay magic/version/port still match RemPacket),
  the CLI surface, and runs --selftest. build-release.ps1 now runs this gate first
  and aborts the release if it fails.

Bug caught + fixed: the published release zip carried ZERO cue sounds (startup
  sound + connect/disconnect/etc.) - MSBuild's incremental Content-copy marker
  skipped sounds\ on a fresh publish. Added an AfterTargets=Publish copy in the
  csproj that lands every cue WAV in the published sounds\ folder regardless of
  the marker. Verified: a staging publish now contains all 9 cue WAVs.

Manual/help: --selftest description updated (readme.html + MANUAL.md).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 23:01:40 +01:00
EdnunpandClaude Opus 4.8 05b218825d Release v3.9: silent-mic fix, buffer drain, idle-send guard, start-up sound, command-line
- Receiver: a plain (Mixed) stream now renders on an active lane when the
  receiver is in two-lane (ASIO) mode, instead of being decoded into a ring
  nothing reads. Fixes one-way silence ("my mic works for me but not for them").
- Receiver: drift resampler gains a buffer-depth correction term so a bloated
  standing buffer eases back to the latency target over a long session.
- App: don't send audio until a peer is genuinely reachable (issue #8); status
  no longer shows phantom send traffic with nobody connected.
- App: start-up cue sound (machine-wide toggle + custom path in Preferences).
- App: command-line options (CommandLine.cs) -- --devices, --selftest,
  --diagnostics, --log, --close, --profile, --connect, --minimized, --version,
  --help. New "Command-line options" manual section (readme.html + MANUAL.md).
- Version 3.9; About-dialog and RELEASE_NOTES updated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 19:57:36 +01:00
EdnunpandClaude Opus 4.8 84c4a47411 v3.9.1: plain/WASAPI streams now play on an ASIO-mode receiver (silent-mic fix)
Receiver: a Mixed (plain) session is rendered on an active lane in BothIndependent mode instead of being skipped, so a WASAPI-only sender is no longer silent to a receiver that has an ASIO driver selected. Also port the per-session buffer depth-drain (stops the receive jitter buffer bloating).

Sender: add sndAudFr meter (audio frames actually sent) to localise capture vs send.

App: startup sound cue (machine-wide, Preferences); stop sending audio when no peer is reachable (issue #8). Version 3.9.1.

Server (relay): fix updater version-compare for multi-dot tags, guard the main loop against crashes, reject spoofed BYE from a mismatched endpoint.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 19:00:33 +01:00
EdnunpandClaude Opus 4.8 04b17ff1ab Release v3.8: New profile (blank template renamed), password-mismatch warning stays up, IP-pinning docs
New profile: a File-menu item + Ctrl+N that loads a fresh blank template as a
new unsaved session via a LoadBlankTemplateNext handoff to Program.cs's relaunch
loop — reachable even when "start with a specific profile" boots past the picker
(issue #6). Offers to save the current profile first if dirty; deliberately
silent (no profile-switch cue).

Renamed the user-facing "blank template" to "New profile": the picker's synthetic
entry (now a distinct marker TYPE, collision-safe against a real profile named
"New profile"), the window title ("RemSound — New profile"), and the manual.

Fixed the password-mismatch warning flashing away: it's raised from the 1 Hz
statusTimer, which kept firing into the modal loop and rebuilt the peer lists
(SyncAllPeerLists) under the dialog, knocking it out of the foreground. Now the
tick is frozen while it's up, it's routed through ForegroundDialog, and a
re-entry guard ensures one warning that stays put. Audited: it was the only
popup raised from a recurring timer.

Docs: manual section "Connecting to one specific IP address (and only that one)"
explaining by-name vs by-fixed-IP and that a profile saves the exact address
(issue #7 — functionality already existed); About box + RELEASE_NOTES for v3.8;
MANUAL.md regenerated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-11 21:38:38 +01:00
EdnunpandClaude Fable 5 9e247112cb Release v3.7: device-change smoothing, auto-tune spike rejection, wider mic detector, forensic logging
Coalesce capture-engine rebuilds (CompositeCaptureBackend): a swap-triggering
source change now arms a 250ms debounce timer and re-arms on each further
change, so a flap or quick reconfiguration produces ONE rebuild to the final
state instead of a burst (Andre's 16:40 four-rebuilds-in-33s crackle). In-place
updates still apply immediately; a pending rebuild whose target flaps back is
cancelled.

Auto-tune (TickRoute) now keys off the SECOND-highest arrival-gap/render-gap
second in the lookback window instead of the single worst, so a lone ~1s
OS/driver stall no longer balloons the buffer to the 200ms cap (the 16:51
trim burst); sustained jitter still reacts at full speed. Logs both gap-max
(true peak) and gap-used (value acted on).

Mic-privacy detector widened: also catches a per-app Deny aimed at this exe
under ConsentStore\microphone\NonPackaged\<exe>, the HKLM NonPackaged gate,
and the Group-Policy/MDM force-deny (AppPrivacy LetAppsAccessMicrophone=2) —
the block shapes that silence WASAPI capture while ASIO sails past, and that
the old three-value check missed.

Forensic instrumentation so the next log proves what happened: capPeak=
(loudest pre-encode sample, per lane, on the diag line), mic-privacy verdict
logged at startup, ui: capture tick/untick events, and device-event: lines for
Windows endpoint changes.

Docs: mic-privacy + auto-tune sections updated in readme.html, MANUAL.md
regenerated, About-box changelog and RELEASE_NOTES for v3.7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 22:44:55 +01:00
EdnunpandClaude Opus 4.8 55bdcde0af Release v3.6: rebuild the self-updater (in-app, rollback-safe); warnings to front
Replace the generated cmd.exe + robocopy update helper — which silently
failed on some machines — with an in-app C# installer:
  * Stage the new version to a per-user temp folder off the install and run
    the new RemSound.exe from there, so nothing in the install is locked by
    the updater itself.
  * Wait for the old process to fully exit (real WaitForExit), then
    back-up-and-swap files in C# with retry + rename-aside; roll the install
    back to the previous version on any failure, so a failed update can never
    leave a half-installed RemSound.
  * Log every step to updater.log; clean up old stages and legacy batch
    artefacts on launch. Removed the old BuildInstallScript batch generator.

Route the "RemSound is already running" dialog and its follow-up message
through ForegroundDialog so they surface in front from a background-relaunched
copy, matching the earlier post-update fix.

Docs: rewrite the readme update sections for the new mechanism, regenerate
MANUAL.md, refresh the About-box changelog and RELEASE_NOTES.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 13:37:19 +01:00
EdnunpandClaude Opus 4.8 4dbe9a47a0 Release v3.5: USB-card recovery, per-card adaptive buffer, one user folder, audit fixes
- Recover an unplugged/replugged output sound card automatically (issue #5):
  detect the dead WASAPI device and remember the receive-output selection so it
  re-ticks and re-opens when the card returns.
- Adaptive per-card WASAPI buffer target sized to each card's pull chunk, held
  stable so it never flits about under CPU/network load.
- Consolidate all per-user data (config, profiles, logs, sounds) into one
  "user settings and logs" folder; migrate every older layout; exclude it from
  the updater so custom cue sounds now survive updates.
- Mic-privacy detector: warn once when a Windows-blocked mic is switched on, or a
  profile loads with one already on.
- All warning/notice dialogs now come to the foreground even when minimised.
- Apply volume + mute on profile load (were saved but not restored).
- Crash-safe (atomic) profile/config saves.
- Fix two resource leaks (push-mode capture MMDevice; UPnP DeviceFound handler).
- Remove dead code (baseline-diff machinery, dead ASIO probes, no-op stubs).
- Docs: readme.html, MANUAL.md, About-box changelog and release notes for v3.5.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 11:34:17 +01:00
EdnunpandClaude Opus 4.8 946e6f4be4 v3.4 refinements: WASAPI drift correction, startup-dialog sequencing, quick-switch polish, docs
Builds on the v3.4 freeze (dd70613) with the fixes and tuning from live testing,
plus the v3.4 documentation pass.

Audio (receiver):
- Per-device WASAPI drift correction in MultiOutputPlayout. A pull-side resampler
  (mirroring SessionPlayout's proven corrector) holds each output device's buffer at
  a fixed low depth, cancelling the slow clock drift that made WASAPI peers "lag
  apart" over long sessions. Feed-forward clock-ratio measurement plus a gentle
  depth-restoring term; the first measurement window is discarded because WASAPI
  start-up priming poisons it. ASIO already self-corrected; this brings WASAPI level.
- Output device buffer requested at 5 ms (WASAPI clamps it up to the device's minimum
  period, ~10 ms) instead of 15 ms, since the corrector keeps it fed — a free saving.

UI / accessibility (MainForm, Program):
- Startup notices (what's-new About box, Realtek warning) now run one at a time via a
  single sequence instead of separate BeginInvokes, so they no longer stack into
  nested modals that couldn't be closed. The loading splash is skipped for a
  tray-bound quick switch.
- Quick profile switch keeps RemSound in the tray if it was there, and plays the
  switch cue immediately on click.
- Profile-switch cue now plays on click for every switch path (recent menu, quick
  switch, File > Open) and no longer on a fresh start into the first profile. It was
  also previously dead on the rebuilt form (pendingProfile was nulled first).
- Realtek ASIO toggle's accessible name now reads "Enable"/"Disable" to match the
  visible text, instead of "Toggle" (screen reader read the wrong word).

Docs (plain English):
- RELEASE_NOTES.md: v3.4 entry.
- About dialog: v3.4 "what's new".
- readme.html (the canonical bundled manual): quick switch, the hotkey read-outs, the
  new profile-menu-open cue, Realtek auto-detect/disable, and the config-folder path.
- MANUAL.md regenerated from readme.html via sync-manual.py so the two stay in sync.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 15:31:32 +01:00
EdnunpandClaude Opus 4.8 dd70613017 v3.4: handle-leak fix, Realtek ASIO block, device notifications, quick profile switch, hotkey announcements
Freezes the v3.4 feature set (everything since the v3.3 public release):

- Fix the receiver handle leak: the 3-second device-refresh timer reopened the
  configured ASIO driver every tick, and Realtek's ASIO driver leaks Event+Mutant
  handles on every open. Cache the ASIO probe per driver so it is opened once.
- Realtek ASIO block: detect a Realtek ASIO driver, offer once to disable it, and
  never touch it again if disabled; Options-menu toggle to reverse. Global config.
- Device hot-plug is event-driven (AudioDeviceChangeNotifier) instead of a 3s poll;
  debounced refresh, falls back to polling if registration fails.
- Quick profile switch: new global hotkey opens an NVDA-friendly popup of all
  profiles (current marked); Enter/click switches; plays a new "profile menu open"
  cue with Preferences mute + custom-sound.
- Announce assigned global hotkeys on the controls/menu items they drive (NVDA reads
  "press X anywhere"). File > Open already had Ctrl+O.
- Held-back changes folded in: config-folder migration, codec-column fix, Tailscale
  endpoint network-prune, empty-password guard, and the handle-leak diagnostics
  (ProcessSelfMeter, HandleTypeProbe).

Version bumped to 3.4.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 09:12:11 +01:00
EdnunpandClaude Opus 4.8 fc451ba3e3 Add Android receiver link to README front page
Points users to Aryan Choudhary's community Android receiver (RemSoundAndroid) Releases page for the signed APK. Third-party companion app, TalkBack-tuned, not maintained here.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 05:08:50 +01:00
EdnunpandClaude Opus 4.8 959720f54d Release v3.3: end-to-end encrypted audio, plus cue and reliability fixes
Headline: all audio is now encrypted (AES-256-GCM), keyed by a per-profile
password. Mandatory — v3.3 only interoperates with v3.3+.

Encryption
- RemSoundCrypto (Core): PBKDF2 key derivation, AES-GCM encrypt/decrypt
  (low-alloc, into-span), password fingerprint, light on-disk obfuscation.
- Wire: SenderLane encrypts the audio payload (PCM split across parts when the
  +28 overhead crosses MTU); AudioReceiver/StreamSession decrypt via a shared
  single-thread AudioDecryptor. Fingerprint piggybacks on the Format packet
  (offset 36, backward-compatible) so a peer can detect a password mismatch.
- Profile.Password (scrambled), carried through BuildCurrentProfile; MainForm
  derives + pushes the key/fingerprint to sender + receiver (RecomputeAudioCrypto).
- UX: ask-for-password on profile create; File -> Change this profile's password
  (ProfilePasswordDialog); Options -> Profile passwords (manager); a gate that
  prompts before streaming without a password; and a clear "passwords don't
  match" / "peer needs to update" message driven by the fingerprint.

Cue fixes
- CuePlayer (NAudio) replaces System.Media.SoundPlayer, which silently failed
  on the 96 kHz/24-bit cue WAVs (and any custom file) — cues now play reliably,
  resampled to 48 kHz/16-bit. Also fixes the Preferences preview button.
- Connect/disconnect cues now audio-gated with hysteresis: connected when audio
  flows OR heartbeat healthy; lost only when audio stops AND heartbeat
  unreachable. Kills false disconnects and the receive-only "no cues" case.
- Honest cue logging (played / muted / not loaded).

Smaller
- Endpoint stickiness: keep the audio target pinned to the heartbeat-proven
  address instead of chasing a multi-homed peer's other (unreachable) address.
- "Online/offline" label now audio+heartbeat aware, not discovery-only.
- "Show what's new after each update" preference (on by default).

Docs: About v3.3 block, RELEASE_NOTES, README (encryption as a headline),
manual section 12 "Passwords and encryption" (+ renumber), MANUAL.md regenerated.
Version 3.2.0 -> 3.3.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 23:57:32 +01:00
EdnunpandClaude Opus 4.8 cdcac859c4 Release v3.2: update sound cue + single-instance bring-to-front fix
- New "Update sound" cue (CueId.Update / update.wav). Plays just before an
  update starts installing, on every path (manual, background-silent,
  startup-silent), so a silent background update gives an audible heads-up
  before RemSound closes to restart. Per-profile mute + custom-sound override
  in Preferences, same infrastructure as the other cues:
    * Profile.EnableUpdateCue + RemSoundSettingsStore Load/Save + round-trip
    * MainForm updateSound field, TryLoadCueSound, play in InstallUpdateAsync
      gated by LoadEnableUpdateCue
    * PreferencesDialog "Update sound" CueRow + ResolveCueFilePath mapping
    * update.wav shipped in sounds\ via csproj Content
- Single-instance "switch to the running copy" now actually brings the window
  to the front. The second copy grants the running copy foreground rights via
  AllowSetForegroundWindow before signalling, and lingers briefly so it can
  raise itself before we exit — without this, Windows' foreground lock left
  the running window only flashing in the taskbar (Ed's report).
- Docs: About box v3.2 block, RELEASE_NOTES.md, manual cue section (now seven
  cues, with the update cue described), MANUAL.md regenerated.
- Version bumped 3.1.3 -> 3.2.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-31 17:58:25 +01:00
EdnunpandClaude Opus 4.8 9ab0a1a20a Bump to v3.1.3: single-instance lock + update/read-only reliability fixes
Fixes the chained-fault runaway Andre hit after an update (multiple copies
stacking, audio climbing to deafening, terminal kill to recover).

- Single-instance lock (SingleInstanceCoordinator + SingleInstanceDialog,
  wired in Program.Main). A named mutex makes two copies impossible. A second
  launch offers: switch to the running copy (default; surfaces it from the
  tray via a named activation event), or force the running copy closed and
  start fresh (Process.Kill, retried elevated if the target is elevated).
  This is the structural fix that makes the stacking runaway impossible.
- Prompt-free update exit. InstallUpdateAsync sets updatingInProgress before
  Application.Exit(); the close path's skipPrompt now honours it, so no
  unsaved-changes dialog (whose default button is Cancel) can abort the
  update's restart.
- Read-only persistence fix. BuildCurrentProfile now carries
  currentProfileReadOnly into the saved snapshot. Previously a deliberate
  save of a locked profile wrote ReadOnly=false, silently unlocking it on
  disk — which re-armed the save prompt that then blocked the update.
- In-process double-install guard. updateInstallStarted stops the ~4 s
  startup check and the background poll both staging an install + helper.
- Docs: About box, RELEASE_NOTES.md, readme.html + MANUAL.md ("Only one copy
  of RemSound runs at a time").

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-31 17:33:11 +01:00
EdnunpandClaude Opus 4.8 baf50baf73 Bump to v3.1.2: tray icon re-stamps on state change, recording shows as a flag
- Tray icon now re-registers itself (hide+re-show) whenever the meaningful
  state changes — peer connect/drop, send/receive toggle, recording
  start/stop — so the name a screen reader announces stays in step with
  the live state. Fixes the persistent "no peers" then "1 peer" double
  announcement that the old "show window then minimise again" trick used
  to clear by hand. Same root cause as the v3.1.1 stuck-tooltip fix, just
  exposed when the state changes a moment after the icon appears.
- Recording shows as a plain "recording" flag in the tray rather than a
  live timer. A ticking timer would have either flickered the icon once a
  second or left a screen reader announcing a stale time next to the live
  one. Removed the now-dead FormatRecordingElapsed helper.
- Bundles the earlier Win7 updater fix (6cbde0d): a failed secure
  connection is no longer mislabelled as "you're up to date".
- About box, RELEASE_NOTES.md, readme.html and MANUAL.md updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-30 23:34:44 +01:00
EdnunpandClaude Opus 4.7 6cbde0da12 Updater: distinguish 'no newer version' from 'check failed' on all three paths
Tech Singer's Windows 7 log from 2026-05-28 had this pattern:

  updater: GET https://api.github.com/repos/...
  updater: check failed: HttpRequestException: The SSL connection could not be established
  ...
  updater: startup check — up to date (v3.0.1)

i.e. the SSL handshake to GitHub failed (Win7's TLS stack missing
KB3140245 / KB4474419) but the updater logged 'up to date' and the
user-facing message in CheckForUpdatesManually said the same. So a
user with a broken update check has no way to distinguish that from
genuinely having the latest version.

Fix:
  * CheckForUpdateAsync now returns a discriminated UpdateCheckResult
    (UpdateAvailable / UpToDate / UpdateCheckFailed) instead of the
    old UpdateInfo?. Each return-null site is replaced with the
    appropriate concrete type.
  * The catch-all 'try { ... } catch (Exception ex) { return null; }'
    becomes 'return new UpdateCheckFailed(ClassifyFailure(ex), ...)'.
    ClassifyFailure walks the exception chain and maps to a coarse
    FailureKind enum: SecureConnection (TLS/auth), Timeout, HttpError,
    NetworkUnreachable. SecureConnection is broken out separately so
    the manual-check UI can point Win7 users at the specific Microsoft
    KBs that fix the issue.
  * MainForm.CheckForUpdatesManually pattern-matches on the result:
    UpToDate -> existing 'you're running the latest' message;
    UpdateAvailable -> existing install confirmation;
    UpdateCheckFailed -> NEW dialog (ShowUpdateCheckFailedDialog)
    whose wording is tailored to the FailureKind. The
    SecureConnection branch explicitly names KB3140245 and KB4474419
    and offers the manual zip-install URL as a fallback. All branches
    keep the technical detail out of the dialog and route it to the
    log instead.
  * Background and startup polls stay silent on UpToDate and
    UpdateCheckFailed (no point nagging the user about something
    they can't act on from a timer tick), but the startup-poll log
    now records the failure kind and detail instead of mislabelling
    the outcome as 'up to date'.

No version bump - this rides along with the next feature release
(planned v3.2 with the Reaper ReaStream integration). The bug is
silent on the affected users today, and shipping a v3.1.2 just for
the error-message improvement would mean another update cycle for
everyone for marginal benefit.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-28 19:42:26 +01:00
EdnunpandClaude Opus 4.7 aa099eb555 Bump to v3.1.1: tray tooltip 'starting up' could get stuck after first launch
Bug: if v3.1 installed via auto-update on a profile with StartMinimised
on, the tray icon's hover tooltip got stuck at the initial "RemSound -
starting up" string. The snapshot tick was running and SetTooltip was
being called every second with the live state, but Windows shell kept
showing the original cached text on hover. The fix-by-workaround was a
hide-then-re-show cycle which forced the shell to rebuild the icon
registration with the latest NotifyIcon.Text.

Root cause: NotifyIcon.Text values set BEFORE the icon's first
NIM_ADD (i.e. while Visible=false) become the shell's "initial"
tooltip when the icon eventually appears. Subsequent NIM_MODIFY calls
from text changes DO propagate, but the shell tends to keep showing
the original text on hover - presumably a tooltip-cache eviction
quirk. In the resume-after-update-with-StartMinimised flow, the
window briefly shows then BeginInvokes a Minimize that flips
Visible=true before the snapshot timer has had a chance to fire, so
the shell registers with the stale "starting up" string.

Fix: drop the hard-coded "starting up" initial text from the
controller ctor entirely. The controller now takes a Func<string>
buildTooltip callback from MainForm and calls it in Minimize() right
before flipping Visible=true, so the shell's NIM_ADD sees current
live state instead of a stale string. The 1 Hz snapshot tick keeps
working for ongoing live updates while the icon is visible.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-28 14:43:06 +01:00
EdnunpandClaude Opus 4.7 752c12b579 build-release.ps1: more robust Python detection
Two Windows-specific gotchas the previous code didn't handle:

1) The 'python' / 'python3' commands on most Windows installs are
   Microsoft Store execution aliases. They appear on PATH, accept
   any invocation, exit with code 9009, and print a "go install
   from the Store" message instead of running the script.

2) The 'py' launcher accepts --version and returns the right thing
   (it knows about registered Pythons via the registry), but on
   some setups it refuses to run scripts and falls through to the
   Store alias too. Seen here: 'py --version' prints 3.11.9 but
   'py sync-manual.py' prints the Store message and exits 9009.

The new approach runs an actual sentinel script via -c with each
candidate and only accepts the candidate when stdout matches the
expected string. User-local install paths come first because they
skip the Store-alias issue entirely. Falls through to 'py' and the
PATH commands as backstops.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-28 14:28:04 +01:00