Commit Graph
18 Commits
Author SHA1 Message Date
makiolajandClaude Opus 5 92483cac4b feat(system): repair running timers and the stopwatch after a reboot
Closes M2's known blind spot. On the first pass of a new boot, every RUNNING
timer has its monotonic anchor rewritten from its wall-clock fallback — one
already past its end becomes EXPIRED, one with no fallback becomes PAUSED at
its banked remaining. The stopwatch keeps no wall-clock fallback at all, so it
is paused at what it had banked rather than being allowed to invent a segment
it never ran.

The gate is persisted, so the repair runs once per boot and survives a process
death in between. ARCHITECTURE §5 booked the stopwatch half of this to M7; it
belongs here with the timer half, and the roadmap is amended to say so.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:53 +02:00
makiolajandClaude Opus 5 57605f22f6 feat(core-time): a persisted boot id, and a zone read afresh each time
M2 left a hole it wrote down: once a new boot's uptime climbs past a stored
elapsed-realtime anchor, the reboot goes unnoticed and a running timer counts
down from an anchor that died with the last boot. Detecting it needs an
identity for the boot, which is what this is — Settings.Global.BOOT_COUNT,
with a derived-instant fallback for the devices that will not give it up.

The fallback is best-effort and is documented as such rather than dressed up.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:53 +02:00
makiolajandClaude Opus 5 0beb1749fc feat(domain): the ring policies and the volume ramp
Both are pure functions so they can be tested without a device. The ramp in
particular: a fade-in is the kind of thing that is easy to get subtly wrong and
impossible to notice until an alarm opens at full volume or never reaches it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:40 +02:00
makiolajandClaude Opus 5 e471c9b750 feat(domain): next-fire resolution, with skip and snooze watermarks
The resolver is pure: it reads an alarm and its ring state and returns what
should happen, and the engine does every write. Two rules keep re-resolution
honest, and both are load-bearing enough to be worth naming.

The grace window lets a fire that arrives a couple of minutes late still count,
so a device powered on at 07:01 rings its 07:00 alarm. The handled-occurrence
watermark suppresses a candidate only when it is both at-or-before the
watermark and at-or-before now — the second conjunct is what stops a user who
set the clock forward, let an alarm fire, then set it back from having every
future occurrence silenced forever.

Skip needs a watermark of its own, because a bare flag eats a second alarm once
the skipped occurrence has passed. On a one-shot alarm, skipping the only
occurrence is dismissing it, so it disables the alarm instead.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:40 +02:00
makiolajandClaude Opus 5 6e40b72c50 feat(domain): DST-correct occurrence generation over a repeat mask
Occurrences are generated by walking local dates forward and mapping each
through ZonedDateTime.of, never by adding 24 hours to an instant. That is the
whole DST story: java.time's default resolver shifts a 02:30 alarm forward to
03:30 on a spring-forward night rather than dropping it, and takes the earlier
of the two 02:30s on a fall-back night rather than ringing twice.

Asserted for Berlin and New York, and across all 128 repeat masks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:40 +02:00
makiolajandClaude Opus 5 f4b7c1a16c feat(data): ring state in a new alarm_states table at schema v2
Snooze, the handled-occurrence watermark and the skip watermark need somewhere
to live that survives a process death. They go in their own table rather than
as columns on alarms: a missing row is the initial record, and the FK cascade
means deleting an alarm cannot leave orphaned ring state behind.

Schema v2 is exported and committed alongside v1, so MIGRATION_1_2 is
reviewable and testable rather than taken on faith.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:04:26 +02:00
makiolajandClaude Opus 5 19b0719066 test(arch): keep Room and query strings inside the data layer
The seam is only worth having if something checks it. This fails the
build if androidx.room, an entity or a query string appears outside
data/, rather than leaving it to review to notice.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:33 +02:00
makiolajandClaude Opus 5 d2ab99867e feat(di): Hilt modules for the database, repositories and clocks
The database and its DAOs, the four repository bindings, and the Android
implementations of the two clocks — so nothing constructs a Room database
or reads a system clock by hand.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:33 +02:00
makiolajandClaude Opus 5 6b7a4d73ed feat(data): Flow-based repositories over the DAOs
The four interfaces the rest of the app will talk to. They speak domain
types and Flows only — no entity and no query string crosses this seam.

Every read-modify-write goes through a DAO transaction rather than a
find-then-update, so the ringing service marking a timer expired cannot
silently lose the minute a user just added. Adding a world clock that is
already there returns the existing row instead of the insert sentinel.

Tested on the JVM against fake DAOs over MutableStateFlow with injected
fake clocks, so repository behaviour needs no device.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:22 +02:00
makiolajandClaude Opus 5 11b220aba0 feat(prefs): clock defaults and the stopwatch run record in DataStore
Alarm and timer defaults, world-clock preferences, and the stopwatch's
running state — the things that are settings rather than rows.

The run record is read and written as a whole in one DataStore
transaction, so a reader never sees a half-applied record and a process
killed mid-write cannot persist one.

Values are clamped on read: a preferences file someone has edited by hand
degrades to the default instead of propagating nonsense upwards.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:22 +02:00
makiolajandClaude Opus 5 1d85faa54e feat(data): entity and domain mappers
The translation either way, including the repeat mask's bit order and the
nullable per-alarm overrides that mean "inherit the app default" rather
than a concrete value.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:11 +02:00
makiolajandClaude Opus 5 778d08af24 feat(data): the Room database, its four tables and their DAOs
alarms, timers, world_clocks and stopwatch_laps, with the schema exported
to app/schemas and committed so migrations can be tested from v1 onwards.

The DAOs return Flows for reads and keep every multi-step write inside a
@Transaction, so a read-modify-write cannot lose a concurrent one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:11 +02:00
makiolajandClaude Opus 5 a2beae94ec feat(domain): plain-Kotlin models and the two clocks
The aggregates Clockula stores — alarms, timers, world clocks and the
stopwatch run — as ordinary Kotlin, with no Room or Android type anywhere
near them.

Time is taken as a parameter, never read ambiently: WallClock and
ElapsedRealtimeClock are separate types so a call site has to name which
one it means. A running timer resolves against the monotonic clock and
keeps a wall-clock value only as a post-reboot fallback; the stopwatch
gets no wall-clock value at all.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 13:52:02 +02:00
makiolajandClaude Opus 5 52f3296dc7 feat(theme): follow the stored theme mode and dynamic colour
The theme now reads the persisted preference instead of the device night flag
alone. The system bar styles are resolved from the same value and re-applied
when it changes, so a light theme forced under a dark system no longer draws
white status bar icons onto a light background.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 12:47:26 +02:00
makiolajandClaude Opus 5 fc615e4622 feat(prefs): app preferences over the kit's PrefStore
SettingsPrefs exposes the appearance slice; DataModule builds the DataStore on
the kit's @IoDispatcher. The store is created with a corruption handler that
replaces an unreadable file with empty preferences, so a truncated
clockula_prefs.preferences_pb cannot leave the app crashing on every launch
with no recovery short of clearing app data.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 12:47:26 +02:00
makiolajandClaude Opus 5 2f2a2c529d build: depend on the kit's core-prefs and core-di
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 12:47:20 +02:00
Jean-Luc MakiolaandClaude Opus 5 5ddec0f248 feat: theme, app entry points, and the sage identity
Clockula's seed is #6B7A5C, the third step of the family's colour cycle.

Calendula's slate (#5C6B7A) and Agendula's mauve (#7A5C6B) are the same three
bytes rotated — and that byte rotation is exactly a 120° hue rotation, so the
three seeds sit at 210°, 330° and 90° with identical saturation and lightness.
The fallback schemes are therefore not eyeballed: they are Agendula's
hand-picked scheme with its hue rotated the same 120°, which keeps the three
apps structurally one palette turned rather than three colours picked. The
cycle closes at three.

The launcher icon keeps the family's Calendula bloom badge path-for-path and
swaps the task card for a clock dial, drawn as a 308° arc so the badge
overhangs into a gap rather than colliding with the stroke — the same device
Agendula uses to open its card's corner.

MainActivity is M0 scaffolding: theme plus the crash surface, with a
placeholder where the four-tab shell and the live pill land in M4. The theme
follows stored preferences from M2, once there are any.

The manifest declares no permissions yet, deliberately. Clockula's permission
set belongs to the alarm engine and is declared in M3 alongside the receivers
and the ringing service that need it, so the manifest never claims a
capability the code cannot honour.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
2026-09-11 11:46:54 +02:00
Jean-Luc MakiolaandClaude Opus 5 9fb02d5083 build: scaffold the Gradle project and draw floret-kit from source
Copied from Agendula, which is the family's current template: AGP 9.x
conventions, the shared version catalog, and the F-Droid reproducibility
invariants that are load-bearing rather than cosmetic — no foojay toolchain
resolver anywhere, vcsInfo off on release, dependenciesInfo out of the APK.

floret-kit comes in as a git submodule wired up as a Gradle composite build,
so the kit is built from source and pinned by commit, exactly as its
ARCHITECTURE.md prescribes.

Two deliberate divergences from Agendula's catalog:

- Room replaces Glance. Clockula owns its storage (docs/PLAN.md §0) and ships
  no widget in v1 (§1, decision 2). The schema is exported to a committed
  directory, because a migration is only reviewable against a recorded
  previous version.
- :provider and core-reminders are dropped. There is no vendored task
  provider here, and Agendula's reminder lead-time model is not the shape
  Clockula's scheduling takes.

Version starts at 0.1.0 / 100.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L94fydiJC37LtxVusNQBDy
2026-09-11 11:46:42 +02:00