Ghost FTP 0.30.7
Release date: 5 October 2026
Ghost FTP 0.30.7 follows the published 0.30.6 release with deeper Windows/Linux production hardening, transfer race protection, Sync & Backup reliability, Android localization completion and additional credential-surface safeguards.
Windows and Linux transfer reliability
- Batch upload/download conflict handling now reserves each destination name immediately after a successful enqueue, preventing two same-name source items in one batch from racing toward the same target.
- Transfer Center serializes pause, resume, cancel, retry and priority operations per transfer, while queue-wide pause/resume is independently locked.
- Busy transfer actions are disabled and exposed through
aria-busy, preventing duplicate rapid clicks from sending conflicting backend mutations. - Existing transfer persistence, staged overwrite protection, rollback behavior and real FTP/FTPS/SFTP protocol paths remain unchanged and release-gated.
Sync & Backup correctness and Linux parity
- Sync pair creation no longer closes as if it succeeded when the backend write fails.
- Sync enable/disable, manual sync and removal failures now propagate back to the active UI action so the interface cannot report false success.
- Folder-picker and Sync operation failures use the normal redacted error path.
- Local and remote folder hints are platform-neutral instead of presenting Windows-only example paths on Linux.
- Linux parity checks now protect the shared Sync UX and portable desktop asset bootstrap.
Desktop production and security hardening
- Quick Connection clears password and private-key passphrase state before a successful or user-requested close.
- Quick Connection and Site Manager no longer emit raw connection failure objects to the WebView debug console after the connection store has already surfaced a redacted structured error.
- Connection-dialog close behavior has an explicit accessible label and production copy no longer depends on sample/demo host text.
- Desktop postinstall no longer synthesizes placeholder application icons. Required Ghost FTP brand assets are validated and the build fails closed if they are missing or malformed.
- The Tauri frontend bootstrap is a neutral Ghost FTP document used only for codegen before the real Vite production build replaces it.
Android UI, localization and credential handling
- Android navigation, workspace, session and static product surfaces use localized resource strings across the supported locale set.
- CI enforces duplicate-free Android string resources and canonical locale key parity so missing translations cannot silently ship.
- Compact navigation, session labels, workspace actions and About/Settings surfaces keep the responsive phone/tablet behavior introduced in the 0.30.6 cycle.
- The session password field remains excluded from Activity saved state and is additionally excluded from Android Autofill services.
- Existing cleartext-traffic prohibition, plain-FTP risk disclosure, FTPS hostname validation and strict SFTP host-key verification remain enforced.
Quality and release safety
- Production contracts now reject reintroduction of raw Quick Connection/Site Manager diagnostics, generated fallback branding, Windows-only Sync hints and unserialized Transfer Center actions.
- Ghost FTP quality, real FTP/FTPS/SFTP E2E, Windows/Linux native build, Android and Windows hardening remain mandatory exact-head release gates.
- Canonical 0.30.7 publication requires the exact verified
mainSHA and the already-published v0.30.6 release. - Windows Portable/Setup/MSI, Linux binary/AppImage/DEB/RPM, Android packages, source archives, QA evidence and SHA-256 checksums are produced by the canonical release workflow.
Release validation
The exact release source must pass:
- Ghost FTP quality
- Ghost FTP protocol E2E
- Ghost FTP native build for Windows and Linux
- Ghost FTP Android
- Validate Windows hardening
The canonical release workflow may publish v0.30.7 only from the exact verified main SHA and only after v0.30.6 is present.