Ghost FTP v0.92.1 — macOS Keychain identity isolation on backup restore
This patch follows the verified, publicly published v0.92.0 release.
Fixed
- A saved macOS site's Keychain password is identified by its profile UUID.
- Previously an imported JSON backup could reuse that UUID while replacing the
server, protocol, port or username. A subsequent connection could then reuse
the original Keychain credential against the imported destination. - Restores now reject these identity conflicts before changing saved sites.
Keychain passwords are never accessed or changed during backup restore. - Metadata-only backup edits for an unchanged connection identity continue to
merge as before. - The Sync & Backup workspace displays a clear reason for a blocked restore.
Regression coverage
Swift XCTest exercises each connection-identity field, preservation of saved
profiles after rejected imports, atomic rejection when one entry conflicts, and
successful same-identity metadata updates.
Verification boundaries
This patch does not certify the entire cross-platform feature matrix, all 75
concept-reference screens, macOS FTPS/SFTP transfers, Android production-key
continuity or Apple Developer ID notarization. Existing release tags stay
immutable. A public v0.92.1 requires all exact-SHA PR and merged-main CI gates
plus the official package/checksum verification workflow.