Skip to content

wisp 0.0.3

Choose a tag to compare

@vcealicu vcealicu released this 03 Oct 08:06
· 18 commits to main since this release

LocalGhost wisp 0.0.3

The third cut of wisp. 3 October 2026.

Still a wisp: the name is the release line, the number is the cut. Everything in
0.0.1's notes still holds (what LocalGhost is, what is in it, how it works, how a box
and a phone are installed), and 0.0.2's say what the second cut changed. This page is
what changed since.

What changed since 0.0.2

The weather moved to the box

Until now a weather question that named no place sent the phone's position, rounded to two
decimals, to Open-Meteo. That was the one position that ever left either device, and it is gone.
The box pulls the forecast of the world's three thousand larger places once a day (GeoNames
populated places of a hundred thousand or more, from the geo set it already holds), the same list
whoever and wherever the person is, a hundred places a request, and keeps four days for each in
weather_places. The chat answers "what's the weather like" from that table for the phone's own
fix (which already travels to the box, and nowhere else) or the trail's newest point, and "weather
in Faro" for the place named, through the box's GeoNames when the place itself is not among the
three thousand (the nearest pulled place within 120 km answers, and says how far away it is). The
phone has no weather tool any more: the box's plan says it has the weather, and the phone's own
judgement says the same when the plan is late, so a weather question naming no place never
reaches the web. A named place may still be searched for; the name says nothing about where the
phone is.

ghost-cli ghost.tallyd weather shows the table and the forecast where the trail says the phone
is, weather place=Faro or weather lat= lon= a place, weather fetch=1 pulls now. Box Status
has a Weather section (places, the pull's age, the batches that came). The first pull comes a
minute or two after ghost.tallyd starts, then once a day; on a box without the geo set there is
nothing to pull and the chat says so rather than guess.

"What leaves the box" in the README is shorter for it: never a position, from either device.

What the release holds

One GitHub release, v0.0.3:

  • server/: the server set, built reproducibly from the tag: the bundle
    (localghost-server-0.0.3-linux-amd64.tar.gz), RELEASE.txt, these notes as NOTES.md,
    NOTICE.txt, TERMS-MIT.txt.
  • app/: localghost-app-0.0.3.apk, built on the release machine from the tag and signed with
    the app's keystore (the same key as before, so it installs over 0.0.1 and 0.0.2), its GPG
    signature by the site key, and APP.txt (its hash, commit, version and signing certificate).
  • source/: localghost-0.0.3-source.tar.gz, the whole tree at the tag.
  • SHA256SUMS over all of it, signed by the site key (SHA256SUMS.asc; the key is at
    https://www.localghost.ai/.well-known/pgp-key.asc, fingerprint DCE9 A3D1 4EB4 6197 1DD5 F393
    706E 4194 F08A 09A0). The signatures themselves are not in the sums.

The server set is the same bytes any machine gets from tools/cut_release.sh 0.0.3 at the tag.
The APK is not yet byte-reproducible (a gradle build differs from run to run), so the one in the
release is the one to verify: its signature, its certificate in APP.txt, and VERIFY BUILD in
the app, which shows the commit it was built from.

Installing 0.0.3

A box on 0.0.1 or 0.0.2 takes 0.0.3 from the phone: SETTINGS › SERVER shows "wisp 0.0.3 is out"
once the mirror carries it; DEPLOY downloads the set, the box checks the manifest's signature and
every hash, restarts onto the new build and opens a trial, and rolls back by itself if the first
unlock fails or a critical daemon keeps falling over. The weather_places table is added at the
first start (adding converges; nothing is dropped), and the first pull follows within minutes.

The phone installs localghost-app-0.0.3.apk over the earlier app (same signing key, the
enrolment kept). An older app against a 0.0.3 box still works; it just keeps asking Open-Meteo
itself for a weather question until it is updated. A fresh box or phone is installed as 0.0.1's
notes say.

Known gaps at 0.0.3

  • The box CA key stays on the OS disk, by choice: a phone can be enrolled and refused while the
    vault is locked.
  • Device certificates last ten years; shorter ones renewed by the phone are next.
  • Releases are signed by the site key alone; an offline release key is planned.
  • The APK is not byte-reproducible; the server set is.
  • The weather is a chat answer; a card on HOME and the lock screen is next.
  • Mail, the Mist (peer-to-peer backup) and the decoy volume are not built.