Files
echolot/docs/build-status.md
T
mrambossekandClaude Opus 5 6ddf013dfe License the project; add root README, website, and parked release CI
- Code: GPL-3.0-or-later (LICENSE, SPDX headers on all .kt/.aidl).
  Specs in docs/: CC-BY-4.0 (docs/LICENSE). Rationale in build-status.md;
  server decided GPL (not AGPL).
- Root README for the public repo.
- web/: Cloudflare Worker site for echo-lot.app. /apk resolves the newest
  APK from the Gitea latest-release API at request time (edge-cached 5 min),
  so tagging a release is the only publish step. /fdroid, /source, and a
  manual DOWNLOAD_URL fallback are wrangler vars.
- .gitea/workflows/release.yml: tag-driven (v*) signed semver APK builds for
  the future production app in echolot-app/. Parked; the prober is
  deliberately not CI-built.
- Fix UserService.kt: drop the explicit secondary constructor that
  conflicted with the implicit primary (never compiled before — first
  local build caught it). Prober now builds: :app:assembleDebug OK.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 09:15:35 +02:00

2.9 KiB

Echolot — build status & next steps

Last updated: 2026-07-29.

Decided

  • Name Echolot; domain echo-lot.app; scheme echolot://; namespace app.echo_lot.* (hyphen→underscore; appIds/packages can't contain hyphens). Prober appId app.echo_lot.prober.
  • Stack: native Kotlin + Jetpack Compose, no Flutter.
  • Tiers: app (no root), shizuku in v1 (wireless-ADB pairing), root future.
  • License (decided 2026-07-30): all code GPL-3.0-or-later; the specs in docs/ CC-BY-4.0. Rationale: the moat is the no-root platform research, which is trivially liftable into a proprietary repackage — copyleft is the only option that prevents that, and the F-Droid / network-engineer audience reads GPL as a trust signal rather than friction. The specs go permissive on purpose: a wire protocol only becomes a standard if anyone can implement it. Not AGPL for the server — the ASP loophole it closes is speculative here, while blanket corporate AGPL bans would hit exactly the enterprise network teams most likely to self-host. Sole copyright holder, so relicensing the server to AGPL later stays possible. Open: substitute a real legal copyright holder for "Echolot contributors" in the SPDX headers.

Specs (in docs/, alongside this file)

  • feature-catalog-and-feasibility.md, measurement-schema.md, probe-protocol.md. Considered draft-complete and reviewed by the user.

Capability prober — DELIVERED (as zip, 2026-07-29)

Full Kotlin/Compose project scaffolded: app.echo_lot.prober, minSdk 26 / target+compile 35, AGP 8.7.3, Kotlin 2.0.21, Compose BOM 2024.10, Shizuku api+provider 13.1.5, kotlinx-serialization. Probes implemented: link.snapshot, icmp.ping4/6 (unprivileged ICMP datagram), sockopt.matrix (TTL/TOS/RECVERR/MTU_DISCOVER), trace.errqueue_reachable, multinetwork.request_and_bind, local.mdns_discover, peer.ble_advertise, shizuku.command_battery (ip neigh / ip -6 route / ip addr / ip monitor / dumpsys network_stack DHCP+IpClient / dumpsys wifi). JSON export via share intent; results carry verdict + raw evidence.

Could NOT be compiled in the cloud sandbox: dl.google.com (Google Maven) and services.gradle.org are proxy-blocked, and no device is reachable for on-device runs. Build + iterate locally (Android Studio / Claude Code). Wrapper is pinned to Gradle 8.14.3.

Next steps

  1. Build locally, run on several physical devices (varied Android versions/vendors), collect the JSON reports — especially the real per-device Shizuku dump formats.
  2. If trace.errqueue_reachable = PARTIAL, add a C-over-JNI errqueue shim (recvmsg+cmsg parse) as a :native module and a real traceroute.udp4 probe.
  3. Start the Go server skeleton (enrollment + profile + sessions + UDP echo with observation blocks + canary-DNS reference records) per probe-protocol.md.
  4. Fold confirmed capabilities into the production core-probe / core-shizuku modules.