Ghost FTP 0.20.0
Release cycle: 0.20.0 pre-1.0 product release
Cycle date: 30 September 2026
0.20.0 follows canonical 0.19.0. Live publication status is determined by the immutable v0.20.0 GitHub tag/release, not by this document alone.
Changes in this cycle
Durable desktop transfer recovery
- Add a SQLite-backed transfer ledger that persists credential-free queue/history snapshots across process restart and application update.
- Persist only profile identifiers and resolved source/destination paths; passwords, tokens and private-key secrets remain in the existing OS credential store.
- Restore interrupted active rows as explicit recovery/error state instead of falsely presenting them as still transferring.
- Reconnect an interrupted retry through the saved profile when the user explicitly retries.
- Restart the first cross-process retry from byte zero when source identity cannot be proven, preventing old-prefix/new-suffix hybrid corruption.
- Bound terminal transfer history during runtime while preserving all active transfers.
FTP, FTPS and SFTP reliability
- Make FTP and explicit FTPS pause/resume cooperative at bounded transfer chunks.
- Abort active FTP data streams on pause/cancel and on local/network chunk I/O errors, then retire/reconnect the FTP/FTPS control session before subsequent commands so a raced 226/225 ABOR reply sequence cannot poison later transfers.
- Normalize the exact RFC 959 FTP 225 idle reply when SuppaFTP surfaces it while finalizing an already-closed RETR/STOR data stream; all other finalization errors remain fatal.
- Verify resumed upload final size and safely restart from byte zero if the server reports success but persists the wrong number of bytes.
- Extend real FTP and explicit FTPS E2E coverage for pause/resume, cancellation, fresh-session recovery after ABOR/I/O failure and upload/download correctness; separately verify real OpenSSH SFTP non-zero-offset upload/download resume primitives.
Android hardening
- Stage downloads locally and uploads remotely before promotion so incomplete transfers do not replace known-good targets.
- Propagate Activity/disconnect cancellation through upload, download, delete and new-folder operations.
- Close upload document streams at the controller ownership boundary across every early-cancellation path.
- Persist Android document-provider access using lint-safe READ grant modes while retaining persistable picker permissions.
- Fail closed when a previously published stable Android APK cannot be downloaded, signature-verified, package-verified or certificate-compared for signing continuity.
Cross-platform release quality
- Keep Windows console-free helper-process hardening and exact-head Windows tests mandatory.
- Keep Windows portable/NSIS/MSI packaging with installer lifecycle smoke.
- Keep Linux binary/AppImage/DEB/RPM packaging with package lifecycle smoke.
- Keep Android lint, release/preview APK builds, emulator instrumentation, clean install/reinstall and launcher smoke mandatory.
- Keep Quality, real Protocol E2E, Native build, Android and Windows hardening as release blockers for the exact release SHA.
- Bound and retry Ubuntu prerequisite installation in Quality CI so transient APT/network stalls fail deterministically instead of hanging indefinitely.
- Allow the release orchestrator up to 90 minutes for exact-SHA gates to finish, while still failing immediately on a completed non-success result.
Publication requirements
The exact source intended for v0.20.0 must pass all five required exact-head gates: Ghost FTP quality, Ghost FTP protocol E2E, Ghost FTP native build, Ghost FTP Android and Validate Windows hardening.
The canonical release workflow must publish verified Windows portable/NSIS/MSI assets, Linux binary/AppImage/DEB/RPM assets, an Android APK from the exact successful Android gate, source/documentation archives, native-QA evidence and SHA-256 checksums. While version.json remains on the preview channel, the verified non-debuggable com.ghostftp.android.preview APK is allowed when production Android signing secrets are not configured; non-preview channels still require a persistently signed com.ghostftp.android APK. Signed desktop updater assets are included only when the production Tauri signing key is configured.
Stable status
0.20.0 remains part of the pre-1.0 development train. Publication is not the same as a 1.0/FINAL compatibility claim; broader device/server matrices and final product-owner acceptance remain separate.