github bren-wp/Ghost-FTP v0.94.0
Ghost FTP 0.94.0

latest release: v0.95.0
4 hours ago

Ghost FTP 0.94.0 — Android cloud network and transfer safety

Source candidate only. The previously published release is 0.93.0. This document does not claim that 0.94.0 has been released, installed on a physical device, or tested against live cloud accounts. The source SHA and six passing workflows are mandatory before any merge.

Android — transport security

  • Replace disconnected InetAddress.getAllByName preflight + HttpsURLConnection with a direct-only, cancellable OkHttp client.
  • PublicCloudDns blocks the actual HTTP transport's DNS result when any IP is local, private, shared/CGNAT, link-local, documentation/reserved IPv4 or non-global IPv6. Mixed safe/unsafe DNS answers fail closed.
  • Disable network proxies, redirects (including HTTPS redirects) and automatic replay retries. Preserve the platform's standard TLS certificate chain and hostname validation; never trust-all.
  • Stream 1 GiB-bounded signed PUT/GET objects and reject compressed/unexpected content encoding. Presigned links remain transient bearer secrets and never appear in logs.

Android — lifecycle and SAF recovery

  • Add a Cancel cloud transfer UI action that cancels the active OkHttp Call and interrupts the worker.
  • Guard against stale callbacks after Activity destruction and remove pending signed links after empty picker results.
  • On failed/canceled download, attempt to delete the newly created SAF destination. If deletion fails or is not supported, tell the user the incomplete file may remain.
  • Distinguish failed upload (remote state must be checked before retry) from failed download (possible incomplete local destination).

Unit tests

  • Add CloudNetworkSafetyTest.kt for address allowlisting, IPv4 CGNAT/private/metadata ranges, IPv6 global vs local, mixed-answer rejection, provider-host restrictions, proxy/redirect/retry configuration and cancellation.
  • Preserve SignedCloudLinkTest.kt for provider-specific signature query validation.

Packaging

Android continues shipping separately labeled unsigned release APK/AAB and installable signed Preview APK. New production signing identity, actual Google Play delivery and account OAuth are not part of this release.

Boundaries and remaining acceptance

  • Issue #126: macOS still needs transport-bound DNS/peer routing, and Android needs adversarial device DNS rebinding/VPN/IDNA/provider tests. The new OkHttp resolver is source-level protection, not a penetration test.
  • Issue #127: Android SAF deletion is best effort; real document providers can reject deletion or commit partially. File-integrity validation and reliable failure recovery need device E2E.
  • Issue #128: No Android/macOS account-level Google Drive OAuth, bucket browsing or cloud directory synchronization was added.
  • A URL's signature query shape is not proof of provider authenticity. Actual cloud services validate request signature, HTTP method and signed headers.
  • Validate real AWS S3/R2/GCS/Azure GET/PUT, expired or wrong signatures, cancellation during streaming, 401/403/429/5xx, DNS rebinding, SAF provider permission errors, Unicode and 1 GiB limits before production promotion.

Review provider support, threat model, cloud QA, and production readiness.

Release controls

Merge only after the six exact-SHA PR gates succeed. Verify the same gates again on the resulting main SHA, allow the official ghostftp-release.yml workflow alone to publish and verify all package hashes. Never retarget v0.93.0 or another public tag.

Don't miss a new Ghost-FTP release

NewReleases is sending notifications on new releases.