[4.2.1] - 2026-09-30
Four New Ways to Connect, and a Round of Repairs
A patch release that also brings new places to connect: Twake Drive as a native integration, IBM Cloud Object Storage and Mail.ru Cloud as ready presets, and Proton Drive through the official Proton Drive CLI. AeroAgent reaches 1.5, with provider-native reasoning kept across tool calls and approvals that fail closed. Most of the rest is repair: extraction, trash, keystore backups, sync, the CLI and the cloud providers now do what they say, and several of the fixes came from community reports. A full pre-release review read every change since 4.2.0; the defects it found, among them a Mirror that could delete files it had been told to keep and a keystore import that could drop servers, are all fixed here, each with a test that failed before the fix.
Every change listed here is tracked, with its commit and its discussion, in the release tracker: AeroFTP 4.2.1, known issues, patches and updates.
What changes for you
Most of this release is new places to connect and repair, so the short version below is split by where you meet it: what is new, and what stops going wrong. Everything in this list appears again further down with the detail and the commit.
In the app
- Four new ways to connect: Twake Drive, IBM Cloud Object Storage, Mail.ru Cloud and Proton Drive. Twake Drive (formerly Cozy Cloud, 5 GB free) is a native provider that signs in against your own instance in the browser, with no vendor app. IBM Cloud Object Storage and Mail.ru Cloud join as ready presets with setup pages on the docs site. Proton Drive works through the official Proton Drive CLI: sign in to Proton in the browser and AeroFTP drives it, with a live check that says whether the CLI is installed and signed in.
- A failed extraction no longer empties or shortens files you already had. A wrong 7z password could replace an existing file with an empty one, and a truncated zip, tar or 7z extracted short files silently. Entries are now written aside and moved into place only when complete, and a wrong password is named as such.
- A Mirror keeps what it did not complete, and removing a folder never takes its content along. A file the sync was told to leave alone, or one whose backup copy failed, keeps its folder, and the result says why each folder was kept. Deleting a folder without asking for recursion now refuses one that still holds files, on every backend.
- AeroSync's versioned backup keeps the old copy on remote destinations too. Before a sync overwrites or deletes a file on a remote, the old copy is moved to the backup folder, and a later Mirror can never delete those copies. The Plan also gains exclude patterns for every pair and shows the matching command-line sync for the same run.
- Importing a keystore backup shows, server by server, what would change, and lets you choose. New, removed and changed profiles are listed with their field-level differences (never a secret), and a changed profile can take the backup's version, keep this device's, or be kept as both. A "skip existing" import no longer drops the servers you added after the backup.
- AeroAgent asks for approvals in its own window, and remembers an answer for the rest of the chat. Only that window can grant an approval; allowing a tool for the rest of the chat (off by default, never for delete, trash, shell or extraction) means three folders need one approval instead of three. Stop now also cancels the tools still running, and on a large vault the agent sees every saved server instead of the first fifth.
- SFTP transfers no longer hang when the server goes away. An upload in flight when the server restarted used to never return; every SFTP transfer now ends as a lost connection that the app reconnects on and the command line retries.
- Cloud providers no longer act on an item whose name differs only in case. On Google Drive, uploading
a.txtbesideA.txtoverwroteA.txt; similar traps on Box, kDrive, Drime, Internxt and OneDrive are closed, and a trash purge takes only the item trashed from that folder. - A rename or move never overwrites what already has the destination name. Several providers replaced the existing file silently, or left two files with one name; every provider now refuses a taken name first.
- Upload progress is real on Zoho WorkDrive, Koofr, kDrive, 4shared and FileLu. The bar used to sit still and jump to 100 at the end; it now follows the bytes, reaches 100 only when the server has the file, and WorkDrive accepts uploads over 250 MB through its stream upload server.
- Downloads keep the remote modification time, and WebDAV dates are read. A downloaded file used to get the time of the download, so the next sync saw every one of those files as changed; a second sync after a download is now a no-op.
- AeroSync Compare warns about the files the remote cannot take. With a remote on one side, it lists the files a sync would send that the remote cannot store, each with its reason (too large, name or path over the provider's documented limit), so you can rename or split before starting.
- On Linux the app is harder to lose: no more blank window at a cold start, and a crashed web process reloads by itself. The interface is now served by a new built-in server that answers every connection. In-app updates no longer leave a 70 MB package in
/var/tmp, and the AppImage runs for every user, including sandboxed starts. - Internxt connects again, and implicit FTPS transfers work again. Free Internxt accounts logged in against a host that no longer answers; every implicit FTPS transfer failed in the data handshake. Both are fixed, and a failed Internxt login now says what actually failed.
- Cyber Tools derives Argon2id keys and computes the BLAKE3 keyed and derive-key modes, locally, pinned against the official test vectors, and nothing is stored: the inputs live in the window only.
In the CLI and for automation
- Ctrl-C now stops a transfer and reports it as interrupted. A single-file
get,putorpgetused to run to its end or hang; every transfer stops in every phase and exits 130 with"status": "interrupted"instead of a misleading success or a retryable failure. - One-way sync reaches parity with the app.
sync --update,--conflict-mode,--modify-windowand--checksumbring the Backup and Update rules to the command line, one modification-time rule applies on every backend, andsync --deleteremoves the directories it emptied on every backend. - Deletes got safer edges.
rmwithout-rrefuses a folder that still holds files (exit 9), a percentage--max-deleterounds down so a cap under 100% can never empty a side, andrm --dry-runon a non-empty directory exits 9 like the real run. sync --immutablecan no longer drop a transfer silently. A same-size destination counts as skipped, one of another size (usually the partial a cut left behind) is refused instead of overwritten, and batch uploads on providers without a transfer pool sign in once per worker instead of once per file, which removes the login rate limits that cut large uploads.- One exclude rule in the app and the CLI. A bare name such as
node_modulesnow excludes the whole directory, matching is case-insensitive, and an invalid pattern is a usage error (exit 5) instead of being dropped without a word. Patterns match more than before, never less, so exclude lists written for the old reading deserve a review. - The rclone bridge reads and writes keys the way rclone does. S3, Azure, Swift and B2 keys import exactly as written (a small share used to be stored corrupted, so a profile imported from rclone that fails to sign in should be imported again), Internxt exports to rclone, Drime, Cloudinary and ImageKit round-trip both ways, and secrets stay out of the JSON report.
- AeroAgent 1.5 keeps reasoning state across tool calls and fails closed. Modern providers keep their native reasoning between steps, a changed provider or model cannot replay another turn,
--auto-approve highstops short of delete and shell, andagent --provider anthropicreaches the right endpoint again. - Recursive downloads honour the multi-thread settings.
get -r, globgetandsyncdownloads now follow--multi-thread-streamsand--multi-thread-cutoffinstead of always using the measured default, and print the policy they use.
Added
- AeroAgent 1.5: modern provider contracts and native tool continuations. Reasoning models keep their provider-native state across tool calls (OpenAI Responses, Anthropic content blocks, compatible Chat), with scope checks so a changed provider, model or endpoint cannot replay another turn. NVIDIA and Alibaba Model Studio capabilities are discovered exactly and public OpenRouter metadata enriches its models; custom providers can be added more than once and named. The Send button becomes Stop during generation. Each turn starts with four core tools and loads more through a local tool search that never grants approval.
aeroftp-cli agent --provider anthropicreaches the right endpoint again, Ctrl-C exits 130 with the partial answer, and provider errors reach the user bounded and with keys removed (#948). - One modification-time rule for sync, and CLI one-way sync at parity with the GUI. Two times within 2 s are the same instant, the window follows the precision each backend keeps (size only where a backend has no comparable time, stated), one date parser replaces thirteen, and a pair with the same date is never decided by its size. CLI one-way sync gains the GUI's Backup and Update rules:
--update,--conflict-mode source|skip,--modify-window,--checksumagainst server checksums, and safe removal of directories emptied by--delete; every pair left open is reported. AeroCloud waits for a file to be quiet before sending it and reports one that keeps changing instead of marking it synced (#949). - Proton Drive, through the official Proton Drive CLI. Sign in to Proton in the browser and AeroFTP drives the CLI. The form has the MEGA and Filen two-column layout, a mode strip that already names the official API for when Proton opens one, and a live check that says whether the CLI is installed and signed in. The executable never comes from a profile, and trash purges refuse ambiguous names (@Markoise, #573).
- AeroAgent approvals open in a dedicated AeroFTP window instead of the system message box. Only that window can grant an approval, and it holds its own minimal capability. A tool can be allowed for the rest of the chat (unticked by default, never for delete, trash, shell or extraction), so three folders need one approval instead of three, and batch approvals in expert mode no longer ask twice.
- AeroSync names direction and mode with the same words everywhere. The Plan tab and template previews read "Local → Remote · Mirror" instead of
local_to_remote, with headers and translated preset names (@EhudKirsh, #347). - FlatPark, the independent community Flatpak repository, is notified as soon as a release is published, and is listed as a Linux install method; the README's AUR commands are corrected.
- IBM Cloud Object Storage and Mail.ru Cloud, as ready presets. IBM Cloud Object Storage is an S3 preset with HMAC credentials, bucket Fetch and the 22 locations IBM documents (13 regional, 3 cross-region, 6 single data center), listed as a 12-month trial; Mail.ru Cloud is a WebDAV preset on
webdav.cloud.mail.ruwith 8 GB free, which needs an app password because Mail.ru has refused the mailbox password since 2022; both have setup pages on the docs site. An S3 profile whose endpoint is only in its host, as Cyberduck and restic imports and AeroCloud connections have it, now keeps that endpoint instead of the preset's template host and signs with the region the endpoint names, in the app, the CLI and the MCP server, and an importedcustom-s3profile with a self-hosted endpoint keeps path-style addressing. On every provider form the setup steps and the Wrappers/Overlays section start collapsed, and the overlay section opens when editing a profile that has an overlay bound (#923). - Twake Drive, as a native provider. Twake Drive (Linagora Twake Workplace, formerly Cozy Cloud, 5 GB free) works in the app, the CLI, the MCP server and AeroCloud, and signs in against your own instance with no vendor app: AeroFTP registers an OAuth client there, opens the authorization page in the system browser, and deletes that client again if the sign-in fails or is cancelled. Listings are paginated, uploads stream with real progress and are checked against the server's MD5, a delete goes to the trash, and rename, move, server-side copy, quota and MD5 checksums are supported; a transfer of many files runs on 4 workers (260 small files in 46 s instead of 621 s). Trash listing and restore and share links are not there yet, and AeroFTP never revokes an OAuth client on its own: older clients stay under Twake Settings, Connected devices, until removed there (#937).
- Cyber Tools derives Argon2id keys and computes the BLAKE3 keyed and derive-key modes. In Hash Forge, BLAKE3 gains a keyed mode (a 32-byte key in hex, with a Random button) and a derive-key mode (a context string), on text and on files, with the same output as
b3sum --keyedandb3sum --derive-key; Argon2id (RFC 9106) takes the password from the text box and a salt in hex or UTF-8 (a random 16-byte salt is prefilled), with memory up to 2 GiB, iterations, parallelism and output length, and returns the hex tag and a PHC string ($argon2id$v=19$m=...) that theargon2CLI and libsodium accept. Argon2id runs when you press Derive, one derivation at a time, and nothing is stored: the inputs live in the window only. Both are pinned against the official BLAKE3 test vectors and the phc-winner-argon2 reference vector (@EhudKirsh, #347, #929). - Importing a keystore backup shows, per server profile, what would change and lets you choose. A Review changes step lists new, removed and changed profiles; a changed one can take the backup's version, keep this device's, or keep both as a copy with its own credentials. Differences are named field by field, never showing a secret, and a profile that changed after the preview is never decided blind. If applying the choices fails, the server list and its credentials go back to how they were before the import (@EhudKirsh, #736).
- AeroSync Compare warns about files the remote cannot take. With a remote on one side, a red section lists the files a sync toward the remote would send and the remote cannot store, each with its reason: larger than the provider accepts, a name over its limit, or a whole path over its limit, counted with the remote folder included. The files stay in the run: the list says what to rename or split before starting it. The limits come only from each provider's own documentation (the highest plan where the limit depends on the plan, Amazon S3 only on AWS endpoints), and providers with no documented limit or with limits their operator sets (OpenStack Swift, self-hosted GitLab) show nothing (@EhudKirsh, #347, #932).
- AeroRsync is checked against rsync itself in CI. 35 frozen captures of the rsync 3.2.7 wire protocol, together with the instruments that record them, now run on every change, so a regression in AeroFTP's own rsync engine is caught before it ships (#930).
Fixed
- Cloud providers no longer act on an item whose name differs only in case. On Box, Google Drive, kDrive, Drime, Internxt and OneDrive a folder cached under one capitalization could keep a stale id after a rename, move or delete, and some lookups ignored case, so an upload, delete or replace could land on a different, live item (on Google Drive, uploading
a.txtbesideA.txtoverwroteA.txt). Cached ids are now forgotten under every capitalization, destructive steps resolve the exact name, a permanent delete from the trash takes only the item trashed from that folder, and a Drime upload no longer trashes a same-named folder. Also fixed: renaming or moving a folder on Box always failed (#976). - Ctrl-C stops a single-file transfer. Ctrl-C during
aeroftp-cli get,putorpgetraised a flag the single-file path never read, so the transfer ran to its end or hung on a server that stopped answering. It now stops in every phase, closes the connection and exits 130, and--retriesandbatchstop with it. Download temporaries are locked by their writer, so a resume or a second download can no longer publish a half-written file (where locks are unavailable, as on Windows, NFS and SMB, an interrupted part is discarded as before); a plain in-place download starts from zero; and--limit-ratenow holds onpgetandget --segments(#951). - 7z compression with a very large dictionary keeps working. sevenz-rust2 0.23 refuses an LZMA2 dictionary above 1073741823 bytes; a larger request (
compress --dictionary, or the same GUI option) is now clamped to that size instead of failing (#975). - Storage reads can be cancelled, and the Filen WebDAV quota no longer hangs. A used-storage scan against Filen WebDAV waited on a listing the server never answered and blocked Disconnect; storage reads (used-storage scan, quota, folder size) are now cancellable, connect and disconnect cancel them, and an unanswered full-tree listing falls back to a folder-by-folder walk after 30 s. A long transfer no longer turns Properties or the quota into a timeout, and a finished scan survives an ordinary quota refresh. OneDrive mkdir refreshes its parent instead of trusting a cached folder that may be gone, and the Dropbox trash retries throttled requests (@EhudKirsh, #957, #958, #397, #960).
- Archive extraction no longer reports success with empty or truncated files. With a wrong 7z password, about one extraction in 256 succeeded and replaced the file at the destination with 0 bytes; a truncated zip, tar or 7z extracted short files silently. An entry that ends before its declared size is now refused and leaves an existing file untouched. Also: gz, bz2 and xz files made of several members (pbzip2, bgzip) extract every member, a failed RAR entry no longer deletes the file already at its path, the archive browser extracts any file of a solid 7z, a tar entry sized by a PAX record keeps its size, a full or read-only destination is no longer reported as a wrong password, and a compressed-overlay object whose payload disagrees with its header fails instead of downloading the wrong length (#966).
- SFTP transfers no longer hang when the server goes away. An upload in flight when the server restarted or the connection dropped never returned (CLI and GUI), and a download ended as "cancelled by user". Every SFTP request and transfer now ends as soon as the connection is known to be gone, reported as a lost connection that the CLI retries and the GUI reconnects on; a listing or search cut that way is no longer a partial result, and a resume that cannot look at the remote no longer truncates the file (#963).
- CLI batches sign in once per worker, not once per file.
put -r,get -r,put/getwith a glob andsyncon providers without a transfer pool (Internxt, MEGA, Filen, Jottacloud and others) and every--immutableor--no-clobberupload opened a connection per file, which hit login rate limits (Internxt: 429 after 11 files). They now keep one connection per worker. Under--immutablea remote file of another size, most often the partial a cut left, is refused instead of skipped, the batches honour--no-clobber, and an existence check that lost the connection never leads to an overwrite (#956). rmwithout-rnever erases a folder that still holds files. On the backends whose folder delete takes the content along, a non-recursive delete (CLI, TUI, MCPremote_delete, AeroAgent, the GUI) now lists first and refuses a non-empty folder (CLI exit 9, FTP 550, ENOTEMPTY on the mount); a listing that fails removes nothing. The served FTP DELE and SFTP REMOVE delete files only, and the served WebDAV root can no longer be deleted or moved (#964).- Remote edits keep the file mode and refuse symbolic links. CLI
edit, MCP and the GUI AeroAgentremote_editpublish through a temporary and a replace, stay refused by default where the server cannot replace in one step (an explicit opt-in works where the replace sets the old file aside), keep the file mode where the server reports one, and refuse a link, naming the file it points to (#964). - Azure, Swift, Jottacloud, Drime, Zoho WorkDrive and the rclone bridge. Azure removes a folder's directory blob with the folder, only if it is still the one its check saw, and reports hierarchical-namespace folders as folders; a Swift recursive delete goes through every page; Jottacloud and Drime times are in UTC; WorkDrive refuses a second folder of one name; a crypt profile that starts in a subfolder exports to rclone and imports back to the right folder (#964).
- Implicit FTPS transfers work again, and FTP moves to suppaftp 12.1.0. Every transfer over implicit FTPS failed in the data handshake against vsftpd (4.2.0 too): AeroFTP now asks for protected data connections after login. A file the server refuses after the data (
451,452,552) is reported as refused instead of being sent a second time, a range the server cuts short is an error instead of a shorter read, an upload whose local file cannot be read aborts the transfer, and on Windows a download no longer waits on a control connection with nothing to say or runs on a deadline meant for a server that already answered. The FTP library moves from suppaftp 10.0.2 to 12.1.0, whose control replies are capped at 256 KiB (#950). - The Flatpak config import says what it actually did. Accepting the offer to import an existing configuration into the Flatpak install always said the configuration was imported, even after an error or when nothing was copied. It now shows the result: files imported (with the restart button), nothing copied, or the error, and says whether the saved servers and vault came with it or stayed behind because this install already has its own vault. The offer appears only when there is something to copy, and
aeroftp-cli flatpak-importreports the same. A keystore backup import whose app preferences failed to restore now says so (#961). - rclone crypt remotes open with the right key, and AeroFTP no longer guesses how a crypt secret was entered. A crypt remote imported from rclone.conf whose salt rclone generated opened with the wrong key (names read as noise, new files written under a key rclone cannot open). Under the password and the salt there is now a choice, "Typed" or "Pasted from rclone.conf"; a value that could mean two things is refused with a message that says how to answer instead of being used, an empty or empty-revealing password never gives rclone's all-zero key, and a warning appears when no name in the encrypted folder decrypts.
aeroftp-cli import rclone --applynow stores crypt secrets in the vault and binds the overlay;crypt set-form,--password-formand--salt-formrecord the form from the CLI (#955). - Recovering files written with the wrong rclone crypt key. Files uploaded through a crypt remote whose salt rclone generated, imported or typed into an overlay made before this version, are encrypted with your password and rclone's default salt: an rclone crypt remote with the same password and no password2 reads them, copy them out and upload them again. Files written up to 4.2.0 under a typed password that AeroFTP read as a much shorter one:
rclone reveal <the password as typed>prints the password actually used (map+and/to-and_and drop=first) (#955). - The AppImage runs for every user. A launcher file inside the AppImage was executable by root only, so a sandboxed start that keeps the image's ownership (firejail, the AppImageHub test) failed with "Permission denied"; a normal launch was not affected. The build now sets every executable to 755 and data to 644, and fails if that ever regresses (#962).
- Internxt connects again. Every login ended with a 504 after about a minute and a message blaming the credentials: the login fallback that free accounts need went to a legacy Internxt host that no longer answers. It now goes to Internxt's gateway, as the official clients do. A failed login says what failed (wrong credentials, a plan restriction, a rate limit with its wait, a server error), and folders are listed with Internxt's paginated routes so large folders are read to the end (#953).
- The startup log no longer reports a config migration on every launch. Release builds logged "Migrated legacy AeroFTP app config" at each start although the one-time merge of the legacy config folder had run long before; it is now logged only when files were actually copied, with their count (#959).
- A rename or move no longer overwrites what already has the destination name. On pCloud, on MEGA through MEGAcmd and on devices mounted through MTP (all in v4.2.0 too), on most Unix FTP servers and on Azure, S3, B2, Swift, OpenDrive, Cloudinary and ImageKit it replaced the file there, and on Google Drive, FileLu and MEGA it left two files with one name. Every provider now checks the destination first and refuses a taken name (CLI exit 9, also where the server's own refusal used to come back as a generic error), and a rename onto its own path does nothing. (#944)
- A move that reports success has moved the item. Filen across folders, Cloudinary on dynamic-folder accounts, OneDrive after a
cd, MEGA for an item without a key and ImageKit folder moves said Ok and left the item where it was, and B2 and S3 hid a failed delete of the original. A move plus a rename (Drime, Zoho WorkDrive, Internxt, Proton Drive, 4shared, Filen, MEGA, FileLu, ImageKit) never passes through a taken name, and one that fails halfway is undone or says where the item is. (#944) - Replacing a file works or refuses before it writes:
aeroftp-cli edit, the AeroAgent and MCP edit tool, and a WebDAV client saving a document throughaeroftp-cli serve webdav. It overwrites in one step where the service can (Google Drive keeps it as a new revision), sets the old file aside and deletes it last on MEGA, Filen, FileLu, Dropbox, Koofr, Drime and kDrive, never puts a file in place of a folder, and says so when the old copy could not be deleted. Where no one-step replace exists,editrefuses before uploading anything. (#944) - On Google Drive and Zoho WorkDrive
/xmeans the root again after acd, OneDrive moves and copies after acdland where asked, and a folder that was renamed or deleted is no longer reached through its old path on seven providers. (#944) - Cloudinary acts on the asset you name.
rmof an image no longer deletes a video that shares its public id, a path two assets share is refused instead of guessed, a renamed asset no longer answers to its old name, and a replace never overwrites an asset of another type or format. An upload and a private asset that share a public id are told apart when one is deleted. (#944) aeroftp-cli serve webdavhonoursOverwriteon a MOVE, so a client that saves through a temporary file works, with 412, 409 and 403 where RFC 4918 prescribes them, and it decodes a path once;serve ftpandserve sftpno longer percent-decode raw paths (deletinga%41.txtreachedaA.txt);rmand a served DELETE remove a folder only when the path is one. (#944)- Smaller fixes found on the way: OneDrive's
catof a missing file no longer prints Graph's error as the content, WebDAV renames work on rclone-based servers (Depth: infinity), and resumed Azure downloads with a shared key are no longer refused with 403. A Swift rename of a missing source is reported as not found instead of a server error, and the versioned sync backup now works on Filen. (#944) aeroftp-cli export rcloneexports Internxt profiles, and the rclone import says why it skips a remote. An Internxt profile becomes an rcloneinternxtremote (email and obscured password; rclone derives the rest onrclone config reconnect); the import refuses a password rclone itself could not reveal instead of storing garbage, never repeats a secret in a skip reason, keeps crypt passwords, the crypt salt and the Filen API key out of--json, and sanitizes the report against terminal control sequences. Some Internxt plans do not allow rclone access.- rclone import reads plain keys as rclone writes them, and Drime, Cloudinary and ImageKit export to and import from rclone.conf. S3, Azure Blob, Swift and B2 keys (and the new providers' secrets) are imported exactly as written: they used to go through the reveal codec, and a small share (0.4% of B2 application keys, 2.2% of Cloudinary secrets) was stored corrupted, so a profile imported from rclone that fails to sign in should be imported again. Every rclone password field is revealed the way rclone does, a value rclone could not have used is left out and named in the report, and a crypt remote with an unreadable password or salt is not imported. Files written by older AeroFTP versions still import with the right keys. FileLu and Proton Drive stay out of the export, and the CLI and the GUI now say why (#954).
- A failed extraction no longer empties a file you already had. Every extractor wrote the destination before decoding, so a wrong 7z password truncated a same-named file to zero bytes. Entries are now written aside and renamed in only when complete, with permissions kept, and a wrong 7z password is named as such.
- Move to Trash no longer silently becomes something else. On a drive without a usable trash it used to copy the whole item into the home folder, and the Duplicate Finder turned it into a permanent delete: AeroFTP now asks first, and Escape no longer leaves a confirmation pending.
- A keystore export and import restore My Servers as it was. A profile deleted before the export no longer comes back, because the vault's legacy profile list now follows the active partition instead of staying frozen since the partition migration (@EhudKirsh, #736).
- A file larger than the destination accepts (HTTP 413, a plan cap) is its own kind, "File too large": reported once, never retried, and it no longer stops the rest of the batch (@EhudKirsh, #347).
- The AeroSync Sync tab (local to local only) is no longer offered with a remote connected, where Start would have copied into a local folder named after the remote path (@EhudKirsh, #347).
- AeroCompress stores already-compressed formats without a wasted zstd pass (media, archives, AeroFTP containers), and refuses an upload whose source changed length mid-read instead of sending a corrupted object (@EhudKirsh, #407).
- AeroAgent sees every saved server. On a large vault the list went through an 8 KB cap and the model saw only the first fifth. Profiles now fit on one line each, the tool can search by name, and any cut result says it is incomplete.
- AeroAgent opens alone from the status bar and starts on a new chat at launch; earlier conversations stay in the history.
- OpenRouter's "Test connection" checks the key itself (
/key) instead of the public model list, so an invalid key no longer passes the test and fails at the first message; pasted keys are trimmed. - Proton Drive refuses writes in its root, which only lists the account sections, with a clear message, counts only your own storage and says which folders it could not read. kDrive's root refusal reads as a permission error and is no longer retried, and transfers that failed for good stay out of the restored queue.
- Recursive
get, globgetandsyncdownloads honour--multi-thread-streams,--multi-thread-cutoffand the SFTP presets instead of always using the measured default, and print the effective policy. The cutoff floor is per provider again (WebDAV and Koofr no longer get a 1 MiB minimum they never had), and an invalid value is rejected with a clear error instead of silently becoming 250M. - Every copy button uses the native clipboard, with the web API as fallback, and shows "copied" only when the copy happened.
- On Linux the main window reloads by itself when its WebKit web process crashes, instead of staying grey until AeroFTP is restarted from the tray.
- On Linux the main window no longer stays blank at a cold start. The interface is served to the window by a new built-in server instead of tiny_http, which could leave a request unanswered: the start-up check that missed 5 cold starts in 24 now misses none. The server also answers only this app's address, refuses other methods and paths outside the interface, sends each file with nosniff and same-origin headers, and holds one shared copy of every file instead of one per connection.
- The AeroAgent approval window and the extraction window no longer show the main menu bar, also after the menu is rebuilt.
- Linux in-app updates no longer leave a copy of the package (about 70 MB, owned by root) in
/var/tmp, and copies left there by earlier versions are removed on the next .deb or .rpm install. - Zoho WorkDrive uploads files over 250 MB. Every upload went to Zoho's single-request endpoint, which accepts up to 250 MB, so a 287 MB file sent through AeroSync failed with
413 Payload Too Large. Files above 250 MB now go through Zoho's documented stream upload server, up to 50 GB depending on the edition, and a success reply that does not list the file is reported as a failure. The UK data centre, for which Zoho documents no upload server, keeps the single request and its 413 (@EhudKirsh, #347, #933). - Non-ASCII text no longer crashes a log preview or a masked credential. Provider response previews in the logs and the credential masks in the TUI, Koofr and Jottacloud cut text at a fixed byte count, which panics when a multibyte character straddles the cut: a file name in a response could fail the upload or listing being logged, and an e-mail such as
aaé@example.comcrashed the screen showing it. Those previews and masks, the speed-test report's URL column, the Filen response preview and the B2 value redaction now cut on a character boundary (#934). - Downloads keep the remote modification time, and WebDAV dates are read. A file downloaded from the command line (
get,get -r,getwith a glob,pget,sync) got the time of the download, and no WebDAV download kept its date in the app or the CLI, because the RFC 2822 dates WebDAV reports (Thu, 24 Sep 2026 19:41:46 GMT) were not read; the next sync then saw every one of those files as changed. The remote time now reaches the local file on every download path, and the CLI sync and the mount read RFC 2822 too (the sync planned every WebDAV file again on every run, and the mount showed every WebDAV file as modified now). A second bidirectional sync after a download is a no-op, verified on Mail.ru Cloud and Twake Drive (#936). - Native delta sync works against rsync 3.1 servers, and older servers fall back to plain SFTP. AeroFTP's own rsync engine never worked against the rsync 3.1.x that Ubuntu 20.04, Debian 10, RHEL 8 and many NAS ship: each file paid a failed SSH session and then went through the plain transfer without saying so. The session start now follows the peer (algorithm lists only when negotiated), the file list and compression use the encodings rsync 3.1 expects, and the integrity check uses MD5 where the protocol wants it; a transfer is never committed without a resolved checksum. A server below protocol 31 (rsync 3.0.x and older, as on RHEL 7) is refused before any byte is sent and the file goes through plain SFTP (protocols 27 to 29 used to stop the transfer), and the refusal is remembered for 30 minutes so a sync opens one refused session per server. Measured against rsync 3.1.3: delta download 435 times and delta upload 201 times faster than a full transfer (#935).
- AeroSync's versioned backup keeps the old copy, on remote destinations too. The switch ignored its folder field and kept copies only of local files, and on a remote destination nothing was kept: now, before a sync overwrites or deletes a destination file, the old copy is moved with its
.aerocorrectsidecar to<backup folder>/<date and time of the run>/<path>, never overwritten (name.1.extfor a second copy in one run), the Plan says before the run how the server moves files and keeps Execute off where it cannot, and the backup folder and the folders a nested one sits in are never compared, so a later Mirror cannot delete old copies. The Plan gains exclude patterns for every pair, shared with the Local mirror tab and the templates, and shows theaeroftp-cli synccommand for the same run or the reason there is none. Plan and Compare are translated in all 47 locales, the Sync tab is now "Local mirror", a template with several path pairs gets a clear message instead of one that read as a contradiction, speed modes no longer show stream and compression controls that no run used, and an FTP existence check switches to binary mode first, since a vsftpd server read an existing file as absent (@EhudKirsh, #347, #941). - FTP checksums work on servers that implement
HASH. On those servers the Checksum tab in Properties failed for every algorithm: AeroFTP never selected the algorithm withOPTS HASH, and it read the reply with the status code still attached, so even the digest of the algorithm the server had selected was lost. The requested algorithm (MD5, SHA-1, SHA-256, SHA-512 or CRC32, among those the server lists inFEAT) is now selected withOPTS HASHand its digest read past the reply code, and the legacyXMD5,XSHA1andXCRCverbs no longer show the code as part of the digest, accept a250reply (ProFTPD mod_digest, Serv-U) and are each sent for their own algorithm instead ofXMD5for all. A backend's own digest row in the Checksum tab (CRC32, QuickXor, Dropbox, Koofr, Git SHA-1, Adler-32) now has a Calculate button when the backend lists it, and a sync asks an FTP server for SHA-256 only, the one digest its comparison reads (#947). - Upload progress follows the bytes on Zoho WorkDrive, Koofr, kDrive, 4shared and FileLu. The bar stood still for the whole upload and jumped to 100 at the end; it now moves as each chunk goes out, after the bandwidth limit has paced it, and reaches 100 only once the server has acknowledged the file, so a failed upload never shows a completed one. A streamed upload is no longer retried as an empty request, which a server could store and acknowledge as complete after a passing 503; FileLu keeps its retries by sending the whole file again, and the bar never moves back when an attempt is retried. pCloud uploads above 4 MiB still show no progress until they end, as in 4.2.0 (@EhudKirsh, #347, #943).
- FileZilla imports keep
&in site names, users, folders and plain-text passwords. A site stored insitemanager.xmlasR&Dcame in as "R D", a plain-text passwordp&ssas "p ss" (a wrong password, with no warning) and a folderA&Bas "A", a name in CDATA was dropped, and a file written by AeroFTP's own FileZilla export did not import back unchanged. Each value is now read whole and an unknown reference stays as written, as FileZilla reads it, so an AeroFTP export imports back identical (#945). - A keystore import with "Skip existing" keeps the servers added after the backup. Without opening Review changes, an import of a backup that carried the account partition replaced My Servers with the backup's list; it now applies the review's defaults (new profiles added, changed and removed ones left as they are). The preview says when the list will be replaced because the backup's partition cannot be read on this device, a background connection no longer makes your review choices stale, and an rclone export without credentials no longer carries a crypt password, crypt salt or Filen API key left in a profile's options (#980).
- FTPS no longer sends a refused file twice, OneDrive deletes the live file behind a stale id, and trash purges refuse an ambiguous name. A file an FTPS server refuses after the data (552, for example over quota) is sent once and the refusal reported. A redial returns to the working directory, a case-insensitive server that lists with LIST alone refuses a rename onto a taken name of another case, a name taken on RNTO reads as already existing, and a dotfile a bare LIST hides is deleted as a file. On OneDrive a delete behind a stale cached id deletes the live file, and a permanent delete takes only the trashed item of its own folder. Box, kDrive, Internxt, Google Drive and OneDrive read the whole trash and refuse to purge when several trashed items share the name. Twake upload progress rises once across retries, and a Proton share password starting with a dash is passed as one token (#981).
- A Mirror keeps what it did not complete, and removing a folder never takes its content along. A destination folder is removed only once empty: a file whose versioned-backup move failed, or a file the compare excluded such as
.env, keeps its folder, and the result lists each folder kept with the reason. Exported sync scripts (.aeroftp-script,.sh,.ps1) carry the compare's default exclusions and the backup folder, and the Plan offers the matchingaeroftp-cli syncline. Removing a folder without asking for recursion now refuses one that holds anything on every backend (native guards on Box, pCloud, OneDrive and the object stores, a listing check elsewhere);aeroftp-cli rmdirexits 9 on a full folder, FTP and SFTP included, andsync --deleteremoves the directories it emptied on every backend and fails when a removal is refused for another reason (#979). - Archives extract entries with names near the file-system limit again. An entry whose name was longer than about 232 bytes stopped the whole extraction, because the temporary file added 23 bytes to it; the temporary now has a short fixed name and is renamed into place only on success, and a 7z entry that cannot be found is an error rather than an empty file. The Flatpak host-config import brings the three vault files in only together and says how many files it had copied when it stops part way. A download temporary too long for the file system is reported plainly, trash handling cannot overflow on an escaped mount path and deletes permanently only on the explicit choice, each Quick Connect method opens its own docs page, and the IBM COS locations match IBM's documented endpoints (#987).
- AeroAgent approvals fail closed, and Stop reaches the tools still running. "Allow for the rest of the chat" is refused for every high-danger tool and any tool the app does not know, and the approval window is never skipped for delete, trash, shell, extraction, a mutating server command or a sync start. Stop cancels the follow-up request of a multi-step answer and the tools still running for that turn. A tool call with empty arguments is accepted, a remote edit on the legacy FTP session is published by replacement, and the approval window can be dragged on Linux (#982).
- The CLI reports Ctrl-C as interrupted, never drops an immutable transfer silently, and rounds delete caps down. Interrupting
sync, a recursivegetorput, or a glob transfer exits 130 with"status": "interrupted"instead of 0 or the retryable 4.sync --immutablerefuses a destination of another size and counts one of the same size as skipped. A percentage--max-deleterounds down, so a cap under 100% never empties a side.rm --dry-runon a non-empty directory exits 9 like the real run,--auto-approve highstops short of delete and shell, and the agent trims an API key read from the vault or the environment (#993).
Changed
- One exclude rule for every sync, in the app and the CLI. AeroSync (Compare, Plan and local mirror), AeroCloud and
aeroftp-cli sync/sync --watch/sync-doctor/reconcilenow read exclude patterns with the same matcher, which excludes everything either former reading excluded. For the CLI this means: a bare name such asnode_modulesnow excludes the whole directory, not only files with that exact name; matching is case-insensitive; a pattern with a/also matches that run of folders anywhere in the tree (build/outputexcludesa/build/output/x.o) and a leading/anchors it at the sync root; and an invalid pattern is a usage error (exit code 5) instead of being dropped without a word. For the app: globs outside the*.extform (~*,src*,cache/**,*.{jpg,png}) now match, and an invalid pattern is reported instead of matching nothing..aeroignorekeeps its own rules, including!re-includes. Exclude patterns now match more than before, never less, so review exclude lists that relied on the old, narrower reading: files they did not match before may now stay out of the sync (#939). - Dependency updates:
clap4.6.7 andclap_complete4.6.11 (zsh completion escaping),quick-xml0.42 (the WebDAV, S3, Azure Blob, AWS STS, Jottacloud and FileZilla import parsers migrated; an S3 key containing a carriage return now survives tagging and DeleteObjects requests, #945),rand0.10.3,tauri-plugin-log2.9.2,tauri-plugin-single-instance2.4.5; development only,vitest5.0.1,autoprefixer10.6.1 andcodecov-action7.1.1. Alsohyper-util0.1.21,sevenz-rust20.23.0 (PPMd archives from 7-Zip accepted),thiserror2.0.21,monaco-editor0.57.0,@tauri-apps/plugin-log2.9.2,react-window2.3.3,react-virtuoso4.18.15 andvite8.3.1 (#975).
Contributors
Thanks to the people who shaped this release:
Downloads:
- Windows:
.msiinstaller,.exe, or.zipportable (no installation required) - macOS:
.dmgdisk image - Linux:
.deb,.rpm,.snap, or.AppImage