Repository navigation
v1.4.1
MESH v1.4.1 — delivery, identity, and a real release APK
This build is app-release.apk (versionCode 27), not a debug APK. Installs from v1.3.6–v1.4.0 can update in place. Studio debug builds still need an uninstall first.
What users should notice
- Messages typed with nobody nearby stay waiting for a nearby phone instead of flipping to failed.
- A checkmark means the other phone acknowledged the message, not that a neighbor merely forwarded it.
- If a known contact advertises a different signing key, the chat shows a fingerprint warning and ignores the new key.
- Nearby empty states distinguish Bluetooth off, missing permission, and still searching.
- The Mesh notification has Stop nearby chat.
Under the hood
- Pending messages are kept until an authenticated ACK or 24 hours, not deleted after the first hop.
- Direct ACKs can use the incoming Bluetooth link (two-phone chat).
- Packets are authenticated before they occupy the duplicate cache.
- New installs keep the signing key in Android Keystore; existing installs keep their current identity files.
- The upload keystore is no longer tracked in git. Git history still contains it — treat that certificate as compromised, and put signing secrets in GitHub Actions if you want CI to build future releases.
Chat payloads are still signed plaintext, not end-to-end encrypted. Relays and radios in range can read message bodies.
Checks
./gradlew testDebugUnitTest assembleDebugpassed on the developer machine.- This APK is a non-debuggable release build, signed with the existing Mesh upload certificate.
- Two- and three-phone radio tests were not run for this tag. See
docs/HARDWARE_TEST.md.