github bren-wp/Ghost-FTP v0.95.0
Ghost FTP 0.95.0

2 hours ago

Ghost FTP 0.95.0 — Premium Android visual evidence and screen acceptance

Development candidate. Previous publicly verified release: v0.94.0. This page documents source changes and proposed acceptance, not a published release or a claim of pixel-identical UI.

Why visual evidence needs a separate debug workflow

Ghost FTP intentionally sets FLAG_SECURE on Android windows. As a result, normal adb screencap and Android system screenshots can show black or protected pixels. A passed emulator test or black PNG is not evidence that the 480 × 960 premium reference has been implemented.

The 0.95.0 candidate adds a test-only process that renders the actual empty Activity view tree into private PNGs. No production screenshot policy is disabled; no debug code is added to the shipped MainActivity or to release packages.

Current implementation

  • PremiumVisualReferenceTest.kt navigates the existing real Android UI to Files, Sites, Transfers, Sync, Cloud, Settings and About and captures their authentic empty-state views at the reference 480-pixel width.
  • Captures fail closed if an editable field holds a value outside a tiny allowlist of original product defaults. The QA environment must be an empty session; never record actual hostnames, user credentials, signed cloud URLs or file names.
  • An additional instrumentation case checks 480dp screen width, 64dp docked navigation rail and 58dp full-width brand bar from the actual laid-out view dimensions.
  • run-instrumentation-smoke.sh configures the CI emulator to 480x960 at 160dpi, runs normal click-through tests, then reruns only the capture case on the installed debug package.
  • The CI artifact GhostFTP-Android-Premium-Visual-QA-480x960 contains seven actual PNG renders, the instrumentation report and SHA256SUMS.txt. It is kept out of the packaged Android APK/AAB source and release assets.
  • The canonical 75-screen source references remain visual_acceptance: pending. The seven empty workspaces provide six matching screen names out of 16 Android references, plus Cloud (which has no supplied reference). The other ten reference screens are connect, new-folder, rename, delete, upload, download, host-key, activity, disconnected and transfer-detail. Not even these seven are accepted until actual screenshots have been visually inspected against the supplied concept PNGs.

Security and privacy conditions

  • FLAG_SECURE remains enforced in normal debug and release Activity windows; test rendering operates only within the instrumentation process.
  • Never insert fictitious remote connections, file lists, transfer histories, progress percentages or user profiles just to imitate a mockup.
  • If non-default user-provided input exists in the test process, abort screenshot generation.
  • The artifact is a CI review deliverable. It cannot prove the user's actual device, manufacturer skin or third-party cloud service will look identical.

Acceptance gates

  1. All six GitHub PR workflows must succeed for the final exact feature-branch SHA.
  2. Android production contract, Kotlin compilation, lint and unit tests must pass.
  3. Android emulator click-by-click tests, new layout geometry assertions and seven debug-only captures must pass at the 480dp reference viewport.
  4. Verify each PNG is nonempty and width 480 pixels; publish deterministic hashes and preserve the capture test log.
  5. Compare approved reference screens/android/{files,sites,transfers,sync,settings,about}.png and the approved cloud reference only if one exists. The supplied 16-screen Android set has no cloud screen; cloud evidence is an additional real workspace, not a fabricated reference match.
  6. Keep Windows/Linux 30/29 reference screen parity and macOS platform-specific QA open until real screenshots and their functional controls are separately verified.
  7. Merge/release only through the canonical existing QA and release workflow; never reuse or rewrite published v0.94.0 assets.

See premium brand implementation, 75-screen mapping and Android QA.

Additional 0.95.0 progress on existing Issues

  • #131: Real responsive React/Tauri Files hero, non-secret inline quick connection handed off to secure editor, and backend-backed active transfers strip. Exact-head desktop QA/screenshots and 30+29 visual review still required; not declared complete.
  • #127: Optional S3 x-amz-checksum-sha256 verification now rejects a bad object before copying it to the Android SAF destination. Unit tests cover matching, missing, malformed and mismatching headers. This does not make arbitrary SAF writes atomic or verify absent provider hashes.
  • #126: Android transport-bound DNS policy from 0.94.0 remains, but macOS peer routing and adversarial public provider/DNS lab verification remain pending. Do not claim resolved.
  • #128: Mobile/macOS account OAuth/paginated vendor browsing, secure token storage and provider E2E are not yet implemented; signed one-object links must not be presented as OAuth integration.

All six CI runs must succeed for the final SHA; no 0.95.0 release or 1:1 parity is claimed from source alone.

Additional 0.95.0 security and real visual QA changes

  • macOS: Streaming S3 x-amz-checksum-sha256 verification before replacing a downloaded local file; strictly ASCII/unambiguous cloud hostname validation, disabled URLSession proxy discovery, and new Swift tests. Not a fix for the lack of macOS transport-bound public peer validation (#126).
  • Linux: New isolated Xvfb native-window capture at 1290×852 using the actual built Tauri executable and a clean HOME. QA artifact GhostFTP-Linux-x86_64-Preview-QA holds a real screenshot, checksum and execution log if the new CI gate passes. Never call this a visual reference match without inspecting the PNG.
  • Windows: Genuine 0.95.0 QA evidence from GitHub native run 38092179580, compared against six corresponding user-provided reference screens; current findings are recorded at desktop visual audit. UI matches reference semantics better for Files, but all 30 Windows/29 Linux acceptance fields remain pending.
  • Android: Corrected binary PNG signature parsing in the 480px debug-only evidence test. Runtime FLAG_SECURE is not disabled. Android emulator screenshot artifact is still subject to real exact-SHA CI acceptance.
  • Android/macOS vendor OAuth (#128), Android provider-atomic SAF recovery (#127), macOS transport-bound network destination (#126), and complete 75-screen pixel/interaction review (#131) remain outstanding.

Don't miss a new Ghost-FTP release

NewReleases is sending notifications on new releases.