Ghost FTP v0.92.2 — macOS Keychain write and site-edit integrity
This patch is based on the independently verified public v0.92.1 release. The current document describes the candidate source; a public v0.92.2 release exists only once the canonical exact-SHA release workflow completes.
Fixed
-
Password updates use
SecItemUpdateon the existing Keychain item rather than deleting the previous password before attempting an insertion. -
For a missing Keychain item, the app inserts one. If another writer created it in the interim, the app retries the in-place update. Failed operations return an error and do not perform a destructive delete.
-
A failed Keychain password write no longer lets the connection editor save changed site data while reporting a credential error.
-
A failed Keychain password removal no longer silently deletes a corresponding saved site in either the connection editor or the Sites workspace. The existing site remains and the user receives an error.
-
FTP/FTPS cooperative upload pause/cancel treats an out-of-order, already-idle
225ABOR reply during the post-abort SIZE check as unverified remote size. The resumable offset falls back to zero rather than assuming bytes have been committed or failing on a stale control reply. The owning session must reconnect after interruption.
Regression coverage
Six Swift XCTest cases inject Security framework status codes for successful updates, rejected updates, insertion, concurrent duplicate insertion, rejected insertion, and rejected retry. These tests do not read or alter real personal Keychain entries.
Verification boundaries
Do not classify this candidate as released until all six current-commit PR checks, all six merged-main checks and canonical package/checksum release gates pass. A successful compiler/test run alone is insufficient. Windows and Linux packaging, Android stable-signing continuity, macOS notarization, unsupported macOS FTPS/SFTP transfers, and installed-device 75-screen/pixel parity retain their established limitations. Existing tags, especially v0.92.1, must never be moved.