Features
- Settings shows the installed version. On Windows and Linux the desktop app showed its version nowhere. Settings now ends with it, and it can be copied into a bug report.
- Group and arrange hosts on the dashboard. With many hosts the dashboard was one long grid in config order. Both apps now group it with
g: each host goes under its first tag, untagged hosts last. In the desktop app, View options also sorts the cards by name or status, sections fold from their header, and a card's handle drags it, or moves it with the arrow keys, into an order of your own that is kept across restarts. - Drag files and folders between the SFTP panes, or onto the remote pane from your file manager. In the desktop app, dragging a row to the other pane uploads or downloads it into the folder row it is dropped on, or else into the folder on show, and dragging a ticked row takes every ticked row along. Files and folders dropped from Explorer, Finder or a Linux file manager onto the remote pane upload to it. Escape cancels a drag.
- Both apps transfer whole folders. Upload and Download in the desktop app, and copy and paste in the terminal app, take a folder with everything in it, merge it into a folder of the same name and replace files that clash, and the desktop app asks first when the folder on show already has those names. Files and folders keep their permission bits, so scripts stay executable, and a copy stays writable for you so the next transfer can replace it; symbolic links and special files are skipped, and the transfer ends by saying how many items were skipped or failed and why the first one was. Cancel in the desktop app's progress strip, closing its tab, or Esc in the terminal app stops a transfer and removes the file it was part way through.
- The file panes show when each file was last changed. The desktop app's panes gain a Modified column, with the full date and time on hover, once the window is wide enough. The terminal app's file manager shows the time at the end of each row when its panel is wide enough.
- Streamer mode shows when it is on and switches from anywhere. In the desktop app it could only be switched in Settings, and nothing on screen said it was on. While it is on, an eye in the status bar says so.
⌘⇧Son macOS orCtrl+Shift+Selsewhere and "Toggle streamer mode" in the command palette switch it from any screen, a terminal included.
Bug Fixes
- Security: a server that offers a host key of another type than the one saved for it is refused. OmnySSH compared the offered key only with saved keys of the same type. A host saved with its Ed25519 key that suddenly offered only an RSA or ECDSA key was therefore taken for a new host: the key was saved and the login went ahead, password included, and the dashboard did this in the background without anyone connecting. Someone intercepting the connection could get past the saved key this way. Like
ssh, OmnySSH now refuses any key that matches none of those saved for the host, whatever its type, and says which type is saved. A server that really dropped the type of key it was saved with needs its old key removed once, assshalso asks. - Security: the terminal app no longer lets server-supplied names control your terminal. A file or process name with escape sequences went to the terminal as is, so anyone who can create a file in a folder you browse could retitle the terminal, recolour text or clear the screen. Control characters in anything the app draws now show as �, tabs as spaces, and a file keeps its exact name for transfers.
- A changed host key names its type and, on Windows, whose list held the old one. OmnySSH 1.1.3 and earlier kept host keys in
%USERPROFILE%\ssh\known_hosts, a list that PuTTY and OpenSSH never read. When a server was reinstalled, or a new one took over its address, OmnySSH refused it while PuTTY and PowerShell'ssshconnected, and nothing said why they disagree. A refusal from that file now says it is the list OmnySSH kept up to 1.1.3. Every refusal also names the type of the key the server offered, ED25519, ECDSA or RSA, and the command that prints that key's fingerprint on the server: a server has one key of each type, and comparing the wrong one shows a mismatch that is not there. - Servers from the RHEL/CentOS 6 era connect. OpenSSH before 5.7 failed with "no common key exchange method". Its only key exchange without SHA-1 is diffie-hellman-group-exchange-sha256, which OmnySSH did not offer. Its only host keys are ssh-rsa and ssh-dss, and it predates the rsa-sha2 signatures, so an RSA key could not log in either. OmnySSH now offers diffie-hellman-group-exchange-sha256 and the ssh-rsa host key after every other method, so a server that supports anything newer negotiates exactly as before. An RSA key signs with SHA-1 only for a server that accepts nothing else: one that lists only ssh-rsa as the signatures it takes, or whose version, OpenSSH before 7.2 or Dropbear before 2020.79, predates that list, as PuTTY and
sshbefore 8.8 sign for it. SHA-1 key exchange, CBC ciphers and DSA keys are still left out. - FreeBSD hosts show CPU, RAM, load average and top processes. A FreeBSD server's card showed only disk and uptime: its
toprejects the options OmnySSH passed, it has neitherfreenor/proc, and itspsread the list of columns as a single column. CPU is now measured from the kernel's tick counters over one second, so each update of a FreeBSD host takes a second longer. RAM is read from the kernel's page counts, with free and inactive memory, the buffer cache and the ZFS ARC above its minimum counted as available, as htop counts them, so a server on ZFS does not look nearly full. The kernel's idle process, whichpscharges with all idle time, is left out of the top processes. Where/proc/loadavgis missing, the load average now comes fromuptime, which also fills it in for macOS hosts in the terminal app's host details. As on any system, an account whose login shell is csh or tcsh still shows no metrics. - Servers that take only NIST key exchange or aes128-gcm connect, such as Cisco RoomOS video devices. A server whose key exchange methods include no curve25519 or Diffie-Hellman group 14/16, or whose only cipher is aes128-gcm, failed with "No common algorithm". OmnySSH now also offers ecdh-sha2-nistp256, -nistp384 and -nistp521 key exchange and the aes128-gcm@openssh.com cipher, which macOS's own
sshtries first. A host whose only host key is ECDSA P-384, as on a RoomOS device set to ECDSA, now connects the first time too; before, that key was only accepted once it was saved inknown_hosts. The new key exchange methods and host key type come after the ones offered before, so a server that already worked keeps its key exchange and host key. This needed a newer release of the SSH library (russh 0.63), and building from source withcargo install omnysshnow needs Rust 1.89 or later. - A server with no algorithm in common says which kind is missing and what it offers. The error read "No common algorithm", and a key exchange mismatch even "Unknown algorithm", without saying whether the key exchange, host key, cipher or MAC was the problem, so there was nothing to go on. It now reads, for example, "no common cipher; the server offers aes128-cbc". Servers that offer only methods OmnySSH leaves out on purpose, such as SHA-1 Diffie-Hellman or CBC ciphers, still do not connect.
- macOS: a host on your local network that fails with "No route to host" says macOS may be blocking it. macOS keeps an app away from devices on the local network until you allow it, and a blocked connection fails at once with "No route to host (os error 65)", while the router usually stays reachable because it is also your DNS server, so it looked like a fault on that one machine. The error now adds that macOS may be blocking the app and where to allow it: System Settings, Privacy & Security, Local Network, then reopen the app. The desktop app also now carries the explanation macOS shows when it asks for that permission. The terminal app needs the permission for the terminal it runs in; Apple's Terminal has it already.
- A terminal the server closes right after login stays open and shows why. A Synology NAS gives a shell only to administrators: any other account logs in, gets DSM's "Permission denied, please try again." and the session ends.
sshshows that message, but OmnySSH closed the tab the moment the session ended, so the terminal seemed to vanish right after the password while file sessions to the same NAS worked. In both apps, a terminal tab that showed anything now stays open when the remote side ends its session, including afterexitor a dropped connection, with "[Connection closed. Press Enter to close this tab.]" under the last output. Enter or Esc closes it, and it takes no other input. A terminal that fails before showing anything still closes, with the reason in the status bar. The desktop app could also drop the last lines a session printed just before it ended; they now always arrive. - Settings keeps its bottom margin when scrolled to the end. The last section sat flush against the bottom of the window.
- A snippet with the same tag twice no longer empties the Snippets screen. Tags typed as
db, dbin a snippet form, or written so intosnippets.toml, left the desktop app's Snippets screen blank, so the snippet could not even be opened to fix it. The Run dialog broke the same way when two hosts share a name, as twoHostblocks with one name in~/.ssh/configgive. It now lists that name once, for the host a run goes to. The host picker and the command palette listed such a name twice, and either row opened the first host; they now list it once too. - Sizes in the terminal app's file manager stay in their column next to wide file names. A name with Chinese, Japanese or Korean characters or emoji, which take two cells each, pushed its size past the panel's edge, so a 14-byte file read
1. Names are now padded and cut by the cells they take. - Closing the host picker with Esc gives the keyboard back to the terminal. In the desktop app, clicking SFTP or Terminal in the sidebar over an open terminal and then pressing Esc left the keyboard on the sidebar, so typing reached nothing until you clicked in the terminal. The command palette's sidebar button had the same problem, and so did clicking the terminal's own tab. A terminal that finishes connecting while the palette is open, or comes into view just as a passphrase prompt opens, no longer takes the keyboard from it.
- Pasting a folder in the terminal app copies it instead of leaving an empty file. The file manager handed a folder to the transfer as if it were a file, so the paste failed after creating an empty file of that name on the other side.
- A paste or delete of more than 64 items in the terminal app handles them all. They went to the SFTP queue at once, and whatever did not fit in its 64 places was dropped without a word while the app kept waiting for it. They now go one at a time.
- The terminal app no longer crashes when a file grows while it is copied. A log still being written to could end up larger than when its transfer started, which took the progress bar past 100% and brought the app down.
- Key setup no longer reports success while the server still takes passwords. Turning password login off needs sudo without a password prompt. Without it, as for an account whose sudo asks for a password, key setup stopped once the new key worked, yet the desktop app said "Key authentication configured", the card showed a key badge and the key button was gone, so there was no way to try again. The terminal app went further: it marked the host key-only and deleted the saved password. Both apps now say that key login works and password login is still on, and keep the saved password. The desktop app's card shows a "Password on" badge that runs the setup again, for when sudo allows it, and a shield for a host that takes keys only. After a full setup it also says that the server's SSH settings were changed, where their backup is, and that the saved password was removed.
- The desktop app asks before setting up a key. One click on the key icon generated a key, added it to the server and could turn password login off for every account on it. A dialog now says what will happen and names the key file, and nothing starts until you confirm. Cancel is focused, and Esc or a click outside cancels.
- Key setup that fails after turning password login off says so. When the last check failed, the desktop app said "Password authentication was not changed", although password login had been turned off, and even when turning it back on failed and left the server reachable only through the hosting provider's console. It now says when password login was turned back on, and when it may still be off, now or after the SSH service restarts: then it keeps the new key for the host, says how to check the server's setting and restore its backup, and offers a terminal to do it.
- The desktop app asks before quitting while anything is still open. Closing the window,
⌘Q, the tray's Quit, and⌘Won macOS ended every terminal, transfer, tunnel and snippet run without a word. Closing or quitting now asks first and names what will be closed, with a "Don't ask again" box; Settings → Window turns the question back on. On macOS⌘Wcloses the active tab and⌘⇧Wthe window. Quitting from the Dock or by logging out still does not ask. - Streamer mode hides addresses in error messages and the host form too. The cards showed made-up addresses, but the status bar printed real ones, for example for a changed host key or a tunnel that could not open, and so did the file panes, snippet results and key setup. Errors now show the same made-up addresses as the cards, and the host form hides its addresses until you click Reveal.