A Wi-Fi to cellular switch left the session visibly dropping: the media transport rebound itself within a few seconds, but nothing noticed the blackholed control connection until an unanswered keepalive proved it, and the teardown that followed announced a lost connection and waited another second before dialling again. Watch the system path on iOS and fail the control connection the moment the carrying interface changes, which is the only path change TCP cannot survive. Roaming between access points and a link that is merely unusable for a while keep the same interface and the same source address, so ControlPathWatcher reports neither; an unsatisfied path holds the last signature rather than reporting, so a reconnect is never started into a route that cannot carry it. Tighten the keepalive window on the phone as the backstop for what the monitor cannot see, run the first reconnect attempt immediately, and defer the lost-connection announcement until an attempt has actually failed, so a sub-second handover is silent and only a real outage is announced. A control reconnect still re-authenticates and rejoins: the media keys come from the TLS exporter of the connection that was lost, so seamless handover needs control-plane session resumption rather than a faster reconnect.
Apple clients
VoiceCat.Mac and VoiceCat.iOS are .NET 10 AppKit and UIKit clients over the shared managed
core. The ReplayKit upload extension under native/apple/broadcast remains Swift because it
runs under the extension memory limit and writes the versioned shared audio ring.
Build on macOS with Xcode and the pinned .NET workloads:
./scripts/build-native.ps1
./scripts/build-native-ios.sh
dotnet restore clients/apple/VoiceCat.Apple.slnx
dotnet build clients/apple/VoiceCat.Apple.slnx -c Debug --no-restore
Use publish-macos.sh --dry-run to validate a local ad-hoc macOS bundle. The dry-run build does
not enable hardened runtime because ad-hoc signatures have no Team ID and cannot satisfy macOS
library validation. The script normalizes nested signatures and installs the verified bundle at
both VoiceCat.Mac/bin/Release/net10.0-macos27.0/osx-arm64/VoiceCat.app and
VoiceCat.Mac/bin/Release/distribution/VoiceCat.app. Distribution builds remain hardened and
require VOICECAT_CODESIGN_IDENTITY; optional notarization uses APPLE_ID, APPLE_TEAM_ID, and
APPLE_APP_PASSWORD.
For a physical iOS device, use build-ios-device.sh and deploy-ios-device.sh. The host and
ReplayKit extension require signing profiles with App Group group.me.iamtalon.voicecat.
Hardware validation must cover VoiceOver, background and lock behavior, interruptions, route
changes, Bluetooth, ReplayKit, and iOS 27 ScreenCaptureKit audio.
For iOS voice stability, leave a call joined with the microphone active for at least 30 minutes
and confirm speech stays clear and VC_AUDIO reports no growing feedDrops. While still joined,
toggle Wi-Fi off and on, switch between Wi-Fi and cellular, and confirm the app stays open,
reconnects, and restores the voice session. Repeat with mono, stereo, and voice processing.
The iOS remote-user manual gate must also cover Users → user detail → independent microphone and screen-audio gain/mute controls, microphone receive noise reduction, the no-active-stream state, and Private Chats → conversation → User/audio settings. Repeat the navigation with VoiceOver and disconnect the remote user while its detail and conversation views are open.
App Store builds use the same device builder with --configuration Release. Set
VOICECAT_BUILD_NUMBER, VOICECAT_DISPLAY_VERSION, VOICECAT_DEVELOPMENT_TEAM, the host
VOICECAT_CODESIGN_KEY/VOICECAT_CODESIGN_PROVISION pair, and the extension
VOICECAT_BROADCAST_CODESIGN_KEY/VOICECAT_BROADCAST_CODESIGN_PROVISION pair. The host and
extension profiles must both be App Store Connect profiles and include the shared App Group.
The complete TestFlight workflow is documented in docs/apple-ios-release.md. The shared ring
contract is documented in docs/broadcast-ring-format.md.