The seam is only worth having if something checks it. This fails the
build if androidx.room, an entity or a query string appears outside
data/, rather than leaving it to review to notice.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The database and its DAOs, the four repository bindings, and the Android
implementations of the two clocks — so nothing constructs a Room database
or reads a system clock by hand.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The four interfaces the rest of the app will talk to. They speak domain
types and Flows only — no entity and no query string crosses this seam.
Every read-modify-write goes through a DAO transaction rather than a
find-then-update, so the ringing service marking a timer expired cannot
silently lose the minute a user just added. Adding a world clock that is
already there returns the existing row instead of the insert sentinel.
Tested on the JVM against fake DAOs over MutableStateFlow with injected
fake clocks, so repository behaviour needs no device.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Alarm and timer defaults, world-clock preferences, and the stopwatch's
running state — the things that are settings rather than rows.
The run record is read and written as a whole in one DataStore
transaction, so a reader never sees a half-applied record and a process
killed mid-write cannot persist one.
Values are clamped on read: a preferences file someone has edited by hand
degrades to the default instead of propagating nonsense upwards.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The translation either way, including the repeat mask's bit order and the
nullable per-alarm overrides that mean "inherit the app default" rather
than a concrete value.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
alarms, timers, world_clocks and stopwatch_laps, with the schema exported
to app/schemas and committed so migrations can be tested from v1 onwards.
The DAOs return Flows for reads and keep every multi-step write inside a
@Transaction, so a read-modify-write cannot lose a concurrent one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The aggregates Clockula stores — alarms, timers, world clocks and the
stopwatch run — as ordinary Kotlin, with no Room or Android type anywhere
near them.
Time is taken as a parameter, never read ambiently: WallClock and
ElapsedRealtimeClock are separate types so a call site has to name which
one it means. A running timer resolves against the monotonic clock and
keeps a wall-clock value only as a post-reboot fallback; the stopwatch
gets no wall-clock value at all.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The theme now reads the persisted preference instead of the device night flag
alone. The system bar styles are resolved from the same value and re-applied
when it changes, so a light theme forced under a dark system no longer draws
white status bar icons onto a light background.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
SettingsPrefs exposes the appearance slice; DataModule builds the DataStore on
the kit's @IoDispatcher. The store is created with a corruption handler that
replaces an unreadable file with empty preferences, so a truncated
clockula_prefs.preferences_pb cannot leave the app crashing on every launch
with no recovery short of clearing app data.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The README leads with the thing that is actually different about this app
rather than burying it: Calendula and Agendula front standards someone else
maintains, and Clockula cannot, because there is no open provider behind a
clock. Saying so plainly is better than implying a thesis the app does not
meet — and the three things that replace it (the AlarmClock contract, IANA
zones, an exportable format) are real commitments, not consolation.
CONTRIBUTING's scope section now names the trade this project will not make:
nothing ships that buys a feature by making an alarm less certain to ring.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
Both siblings' pipelines are near-identical; the real difference between them
is which forge is canonical. This is Agendula's spine — it pushes the tag to
Codeberg itself and flags pre-1.0 releases as pre-releases — with Calendula's
`play` job grafted on unchanged.
Taking Agendula's spine means there is no Gitea-canonical phase to migrate out
of later, which is the one thing Agendula had to unwind.
The Codeberg publish step stays NOT continue-on-error, inherited that way
deliberately: in Agendula it reported green through five consecutive releases
while never once publishing, which is how a crash-fix release reached F-Droid
but not the users who needed it. Comments that recount that history now name
Agendula, so an inherited scar isn't misread as ours.
The `play` job runs last and isolated, and skips cleanly until
PLAY_SERVICE_ACCOUNT_JSON exists — so it stays dormant through the whole
pre-1.0 run, which is the correct behaviour anyway.
Templates, the contributing guide and verify-release.sh are rewritten for this
app's domain rather than renamed: the architectural rule here is that Room
types stay in the data layer, and the on-device release check is an alarm that
survives a lock screen and a reboot, not a task list that loads.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
Clockula's seed is #6B7A5C, the third step of the family's colour cycle.
Calendula's slate (#5C6B7A) and Agendula's mauve (#7A5C6B) are the same three
bytes rotated — and that byte rotation is exactly a 120° hue rotation, so the
three seeds sit at 210°, 330° and 90° with identical saturation and lightness.
The fallback schemes are therefore not eyeballed: they are Agendula's
hand-picked scheme with its hue rotated the same 120°, which keeps the three
apps structurally one palette turned rather than three colours picked. The
cycle closes at three.
The launcher icon keeps the family's Calendula bloom badge path-for-path and
swaps the task card for a clock dial, drawn as a 308° arc so the badge
overhangs into a gap rather than colliding with the stroke — the same device
Agendula uses to open its card's corner.
MainActivity is M0 scaffolding: theme plus the crash surface, with a
placeholder where the four-tab shell and the live pill land in M4. The theme
follows stored preferences from M2, once there are any.
The manifest declares no permissions yet, deliberately. Clockula's permission
set belongs to the alarm engine and is declared in M3 alongside the receivers
and the ringing service that need it, so the manifest never claims a
capability the code cannot honour.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
Copied from Agendula, which is the family's current template: AGP 9.x
conventions, the shared version catalog, and the F-Droid reproducibility
invariants that are load-bearing rather than cosmetic — no foojay toolchain
resolver anywhere, vcsInfo off on release, dependenciesInfo out of the APK.
floret-kit comes in as a git submodule wired up as a Gradle composite build,
so the kit is built from source and pinned by commit, exactly as its
ARCHITECTURE.md prescribes.
Two deliberate divergences from Agendula's catalog:
- Room replaces Glance. Clockula owns its storage (docs/PLAN.md §0) and ships
no widget in v1 (§1, decision 2). The schema is exported to a committed
directory, because a migration is only reviewable against a recorded
previous version.
- :provider and core-reminders are dropped. There is no vendored task
provider here, and Agendula's reminder lead-time model is not the shape
Clockula's scheduling takes.
Version starts at 0.1.0 / 100.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
Third floret after Calendula and Agendula: a Material 3 Expressive clock app
(alarms, timers, stopwatch, world clock).
The family thesis doesn't survive contact with a clock — there is no open
provider behind one — so PLAN opens by saying so plainly and relocates the
open-standards commitment to the three places it can actually live: the full
android.provider.AlarmClock intent contract, IANA tzdata, and a documented
JSON backup format.
Locked: four surfaces and no extras in v1, Room + DataStore + JSON export,
maximum alarm reliability including a self-check diagnostics screen, seed
#6B7A5C (completing the family's Calendula→Agendula colour rotation), four
tabs plus a live running-state pill, Codeberg-canonical from commit one, and
floret-kit from day one with core-prefs + core-di extracted up front.
ROADMAP carries M0–M11 as an ordered work queue with per-milestone done
criteria, written to be executed one milestone per loop iteration.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy