Ghost FTP 0.30.9
Release date: 6 October 2026
Ghost FTP 0.30.9 continues the post-0.30.8 cross-platform hardening cycle with real macOS FTP session progress, live connection-health checks and stricter input/data-channel safety.
Main changes
- Hardens connection host input across desktop, Android and macOS so URLs, credentials, paths, embedded ports, whitespace and control characters cannot be accepted as transport host values.
- Extends the dedicated macOS SwiftUI Preview from TCP reachability to a real plain-FTP control session with 220 greeting validation, USER/PASS authentication, TYPE I, PWD, CWD, NOOP and QUIT.
- Adds real macOS FTP directory browsing through EPSV + MLSD, including typed directory entries, size/modify metadata and SwiftUI listing refresh after connect/CWD.
- Bounds macOS FTP listing payloads to 8 MiB so a hostile or broken server cannot grow the listing buffer without limit.
- Adds live Windows/Linux FTP/FTPS health checks using protocol NOOP and SFTP health checks that require an actual SFTP channel.
- Tracks desktop session health as unknown/checking/healthy/unhealthy, including saved, Quick Connect and refocused sessions.
- Adds authenticated Android FTP/explicit-FTPS NOOP and SFTP PWD health probes while retaining TLS endpoint checking, strict SSH host-key verification and password-memory protections.
- Keeps FTPS/SFTP, upload/download and Developer ID/notarization work on macOS explicitly gated instead of presenting unfinished capabilities as complete.
Verification
Publication is allowed only from the exact release source SHA after all required gates succeed:
- Ghost FTP quality
- Ghost FTP protocol E2E
- Ghost FTP native build
- Ghost FTP Android
- Validate Windows hardening
- Ghost FTP macOS
The canonical native build must also pass Windows installer lifecycle smoke, portable/native launch QA, Linux package lifecycle checks and artifact verification before release publication.
Platform status
- Windows/Linux: production desktop packages and portable Windows executable remain canonical release deliverables.
- Android: verified unsigned production APK plus separately installable Preview APK.
- macOS: ad-hoc-signed development Preview only; not Developer ID signed/notarized and not labeled production-ready.
Previous canonical release: 0.30.8.
Canonical metadata
- Product version: 0.30.9
- Build: 2026.10.06.1
- Android versionCode: 300901
- Channel: stable
- Source of truth: root
version.json
The release workflow must publish the tag and every normalized package from the exact merge SHA that passed all six gates. A version tag is never retargeted to newer source.