Skip to content

v1.4.1

Choose a tag to compare

@Devil1716 Devil1716 released this 10 Sep 17:46
· 5 commits to main since this release

MESH v1.4.1 — delivery, identity, and a real release APK

This build is app-release.apk (versionCode 27), not a debug APK. Installs from v1.3.6–v1.4.0 can update in place. Studio debug builds still need an uninstall first.

What users should notice

  • Messages typed with nobody nearby stay waiting for a nearby phone instead of flipping to failed.
  • A checkmark means the other phone acknowledged the message, not that a neighbor merely forwarded it.
  • If a known contact advertises a different signing key, the chat shows a fingerprint warning and ignores the new key.
  • Nearby empty states distinguish Bluetooth off, missing permission, and still searching.
  • The Mesh notification has Stop nearby chat.

Under the hood

  • Pending messages are kept until an authenticated ACK or 24 hours, not deleted after the first hop.
  • Direct ACKs can use the incoming Bluetooth link (two-phone chat).
  • Packets are authenticated before they occupy the duplicate cache.
  • New installs keep the signing key in Android Keystore; existing installs keep their current identity files.
  • The upload keystore is no longer tracked in git. Git history still contains it — treat that certificate as compromised, and put signing secrets in GitHub Actions if you want CI to build future releases.

Chat payloads are still signed plaintext, not end-to-end encrypted. Relays and radios in range can read message bodies.

Checks

  • ./gradlew testDebugUnitTest assembleDebug passed on the developer machine.
  • This APK is a non-debuggable release build, signed with the existing Mesh upload certificate.
  • Two- and three-phone radio tests were not run for this tag. See docs/HARDWARE_TEST.md.