New app: SysReadout Launcher

SysReadout Launcher is a minimal home screen whose background can be a live, terminal-style system monitor: status rows (CPU, memory, battery, network, sensors…), an event stream and optional deeper tables through Shizuku, usage access, notification access or a local DNS-only VPN. With the log switched off it is a plain, quiet list of apps. GPL-3.0-only, Kotlin + Jetpack Compose.

Checklist

Policy

  • The app complies with the inclusion criteria.
  • The original app author has been notified (and does not oppose the inclusion). If you are not the author, please paste the link of the reply from the author.
  • The upstream app source code repo contains the app metadata in a Fastlane or Triple-T folder structure. The summary and description must be included and images, icon, and changelog should also be provided for better user experience. The en-US locale must be included.

Docs

Merge Request Setup

Metadata

  • Metadata must be put in metadata/<applicationId>.yml.
  • Metadata must be a valid YAML file.
  • Metadata must use LF as line ending.
  • Don't add summary/description/changelog/images or anything that should be provided in upstream repo. Please check the Changes tab to make sure there is no other unrelated files added in the MR.
  • Releases are tagged and auto update is enabled unless there is a special reason.
  • There is an issue tracker and contact info of the author so that we can report bugs and contact the author.
  • An AuthorName must be added. It doesn't need to be the real name.
  • External repos are added as git submodules instead of srclibs. You can update git submodules without opening an MR in this repo and the submodule is covered by our scanner. (none are used)
  • Enable Reproducible Builds. We'll use your signature for improved security/reliability, also allowing users to switch between different channels. Do note that if you don't enable reproducible build then the apk will be signed with our key so you can't enable it later. If you can't enable this, please add the reasons here.
  • Setup abi split if the APK is large and the splitted ones can be much smaller. (not needed: the only native code is about 40 KB of AndroidX libraries, so per-ABI APKs would be no smaller)
  • Only the latest versions should be kept in the metadata before it's merged. If you update the metadata, please replace the old versions with the new ones.
  • Don't add any disabled versions in the metadata.
  • The commit field should be the full hash. Please don't use tag or branch in commit.

Pipeline

  • All pipelines should pass.
  • All warnings and errors in the Reports tab should be fixed or explained.
  • F-Droid CI runners are under GitLab's FOSS program, so there's no need for you to pay for any CI time. If Gitlab starts asking for phone numbers or credit cards don't submit anything, just leave a note in the MR so we know we need to trigger the CI.

Notes for reviewers

Reproducible build. Binaries points at the APK attached to each version tag by the upstream CI; AllowedAPKSigningKeys is its certificate (also the key registered for com.sysreadout.app in Android developer verification). Checked again for v0.2.4 (built with R8, names not obfuscated):

  • the upstream CI build (JDK 17) and a local build (JDK 21) of 5b8cfb5198cedde98669a68d8ef70fd74193f9e6 are byte-identical, and two clean checkouts in different directories build identically;
  • a build of that commit without the keystore gives app-release-unsigned.apk, and apksigcopier compare --unsigned against the released APK passes;
  • the APK signing block holds only the v2 signature and padding (no dependency-info block); VCS info is disabled so the APK doesn't depend on how the source was checked out.

Permissions and anti-features. No ads, analytics, tracking or accounts; no Google libraries (AndroidX, Jetpack Compose, Haze and the Shizuku API only). Everything beyond the basic rows is optional and asked for when the user switches it on:

  • QUERY_ALL_PACKAGES: real app names for processes, connections and traffic in the monitor.
  • INTERNET: only the optional DNS monitor, a local VpnService that routes nothing but DNS and relays apps' own lookups to the network's own DNS servers (no public fallback resolver). Since 0.2.3 the app also leaves out EmojiCompat, so Google Play services no longer downloads an emoji font for it on first start.
  • Reverse DNS (with Shizuku only): the connections table shows server names from reverse DNS (PTR) lookups of the remote addresses, sent to the network's own resolver. They run in the Shizuku helper process (shell user), not under the app's INTERNET permission. They are on by default once Shizuku is connected, and can be switched off under settings › log › hostnames (reverse dns). Names the DNS monitor already saw are used instead of a lookup.
  • An accessibility service used only to lock the screen on double-tap (canRetrieveWindowContent="false", no event types).
  • A notification listener for the optional notification log (kept in memory only).
  • Shizuku (app Apache-2.0, API library MIT) is optional and off by default; with it the app reads top, /proc/net and a few dumpsys outputs.

I don't think any anti-feature applies; happy to add one if you see it differently.

Edited by Andris Sni

Merge request reports

Loading
Loading