Releases: Lord1Egypt/AndroidThothTerm
Release list
ThothTerm Resolute 0.3.2
ThothTerm Resolute 0.3.2
Security and stabilization release for com.thothterm.ubuntu (versionCode 302). Update recommended for every earlier version.
- Renamed: ThothTerm Ubuntu is now ThothTerm Resolute. Same app, package id and data (installs update in place); renamed because Ubuntu is Canonical's trademark. It still runs Ubuntu 26.04 LTS. Not affiliated with or endorsed by Canonical.
- Security: an exported legacy integration accepted untrusted input from other installed apps. It is removed; the app now exports only its launcher, and nothing from outside the app can be typed into a terminal session. Permanent tests check the exported components of every built APK. Versions up to and including 0.3.1 are affected. Details stay in the private advisory for now.
- Setup names both downloads before anything is fetched: the base system, then sudo and package lists from archive.ubuntu.com and security.ubuntu.com.
- A timed-out or interrupted background setup step is really stopped (SIGKILL; Android's
destroyForcibly()only sends SIGTERM, which PRoot survived). - Store icon and per-app store metadata in
term-ubuntu/fastlane; native libraries build byte for byte the same on any machine.
Built from commit 760d54e (JDK 21, Android SDK 36, NDK 23.2.8568313). *-release-unsigned.apk are the R8 release builds for F-Droid/own signing; *-test.apk are the same builds signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt.
Checked: 1275 unit tests, 0 failures; Android lint on the F-Droid release build, 0 errors; release APK checks (identity, 16 KB alignment, ELF, JNI, rootfs, exported components) pass. On a Samsung SM-A165F (Android 16, kernel 6.12.38, isolated test build): no external entry point can start the terminal, an in-place update keeps /home, and a hung optional-setup step times out, leaves no process behind and can be retried from the menu. Not tested: kernel 4.14 devices (PRoot child tracking, see 0.3.1), other ABIs.
ThothTerm Trixie 0.2.2
ThothTerm Trixie 0.2.2
Patch release for com.thothterm.debian (versionCode 202). Debian GNU/Linux 13 (trixie) environment; rootfs unchanged.
- A timed-out or interrupted background setup step is really stopped (SIGKILL instead of Android's SIGTERM-only
destroyForcibly()). - Native libraries build byte for byte the same on any machine; store icon in
garden-debian/fastlane. - Security check: the exported-component vector reported against ThothTerm Ubuntu and the regular Terminal is not present in Trixie (0.2.1 and 0.2.2): the merged manifest exports only the launcher activity (plus androidx's profile-installer receiver, which requires
android.permission.DUMP). This is now pinned by tests on every build.
Built from commit 760d54e (JDK 21, Android SDK 36, NDK 23.2.8568313). *-release-unsigned.apk are the R8 release builds; *-test.apk are the same builds signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt.
Checked: 1275 unit tests, 0 failures; lint on the F-Droid release build, 0 errors; release APK checks pass. No device run of this build in this round beyond the shared setup/timeout code, which was exercised on Resolute.
ThothTerm Terminal Emulator 1.4.1
ThothTerm Terminal Emulator 1.4.1
Security patch on top of 1.4.0 (terminal-v1.4.0). Update recommended; 1.4.0 and earlier are affected.
- Text that another installed app supplied through the share target or the "Term here" / window-opening integration could be typed into a terminal session as a command. Nothing from outside the app is typed any more: the directory is passed as a structural working-directory value.
- Add-on applications are trusted only when signed with the terminal's own certificate, not by package name.
- The local socket server refuses a connection from another app and keeps serving.
- Permanent regression tests pin the exported components and the integration surface (
docs/security/THORNS.md).
Features, permissions, package id (com.thothterm) and data are unchanged from 1.4.0. Details of the report stay in the private advisory for now.
Built from commit 760d54e. *-release-unsigned.apk are the R8 release builds; *-test.apk are signed with the public Android debug key for testing only. No AAB is attached to this release. Hashes: terminal-v1.4.1-SHA256SUMS.txt.
Checked: 1275 unit tests, 0 failures; release APK checks pass. lintFullRelease reports one error, GestureBackNavigation in Term.java, which is unchanged from 1.4.0.
ThothTerm Rolling 0.1.1
ThothTerm Rolling 0.1.1
Patch release for com.thothterm.arch (versionCode 101).
- A timed-out or interrupted background setup step is really stopped (SIGKILL instead of Android's SIGTERM-only
destroyForcibly()). - Reproducible build: native output no longer depends on the checkout path or machine (
-ffile-prefix-map,--build-id=none, PRootGIT=false). The F-Droid buildserver job and a host build produced a byte-identical unsigned APK (seedocs/RELEASE_SIGNING.md). - Store icon in
garden-arch/fastlane. - Security check: the exported-component vector reported against ThothTerm Ubuntu and the regular Terminal is not present in Rolling: only the launcher activity is exported.
No upstream release signature yet: *-release-unsigned.apk are unsigned R8 builds; *-test.apk are signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt. Built from commit 760d54e (JDK 21, Android SDK 36, NDK 23.2.8568313).
Checked: 1275 unit tests, 0 failures; lint on the F-Droid release build, 0 errors; release APK checks pass. No device run of this build in this round.
ThothTerm Ubuntu 0.3.1
ThothTerm Ubuntu 0.3.1
Patch release over 0.3.0 (com.thothterm.ubuntu, versionCode 301). No rootfs change.
- The terminal opens as soon as Ubuntu is extracted and configured; installing sudo runs afterwards in the background (single run at a time, never on the main thread, retry from the menu). Fixes the report of a setup screen stuck on "Extracting Ubuntu… 100%" while sudo was being installed (fdroiddata !49556).
- PRoot: a new process whose pid the kernel does not report at fork time is now found from /proc, or the window stops with an error, instead of hanging (patch 0007). Reproduced and tested on a desktop kernel only; not verified on kernel 4.14.
- PRoot: fchmodat2 translated (0006) and the guest owner kept on link2symlink hard links (0008).
- A damaged installation is never erased; reinstalling system files keeps /home. Safer extraction of the system image.
Built from commit 54a965f (JDK 17, Android SDK 36, NDK 23.2.8568313). *-release-unsigned.apk are the R8 release builds for F-Droid/own signing; *-test.apk are the same builds signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt.
Tested on a Samsung SM-A165F (Android 16, kernel 6.12, isolated test builds): first run (download/extract/terminal ready, background setup), HOME preservation through damage/repair/interrupted reinstall, LAN Mode, package manager gates, extractor gate with the app's own extractor on the pinned archive, and the host security suites. Not tested: Android devices with a 4.14 kernel (see the PRoot child-tracking note), other ABIs. Release notes list only what was run; details in docs/garden/closure/CLOSURE_REPORT.md.
ThothTerm Trixie 0.2.1
ThothTerm Trixie 0.2.1
Patch release over 0.2.0 (com.thothterm.debian, versionCode 201). No rootfs change (still Debian GNU/Linux 13 (trixie) environment f6520ff1c6ee).
- The terminal opens as soon as Debian is extracted and configured; installing sudo runs afterwards in the background (single run at a time, never on the main thread, retry from the menu).
- PRoot: a new process whose pid the kernel does not report at fork time is now found from /proc, or the window stops with an error, instead of hanging (patch 0007). Reproduced and tested on a desktop kernel only; not verified on kernel 4.14.
- PRoot: fchmodat2 translated (0006) and the guest owner kept on link2symlink hard links (0008).
- A damaged installation is never erased; reinstalling system files keeps /home. Safer extraction of the system image.
Built from commit 54a965f (JDK 17, Android SDK 36, NDK 23.2.8568313). *-release-unsigned.apk are the R8 release builds for F-Droid/own signing; *-test.apk are the same builds signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt.
Tested on a Samsung SM-A165F (Android 16, kernel 6.12, isolated test builds): first run (download/extract/terminal ready, background setup), HOME preservation through damage/repair/interrupted reinstall, LAN Mode, package manager gates, extractor gate with the app's own extractor on the pinned archive, and the host security suites. Not tested: Android devices with a 4.14 kernel (see the PRoot child-tracking note), other ABIs. Release notes list only what was run; details in docs/garden/closure/CLOSURE_REPORT.md.
ThothTerm Rolling 0.1.0 — first release
ThothTerm Rolling 0.1.0 — first release
Arch Linux ARM AArch64 environment under PRoot (com.thothterm.arch, versionCode 100, LAN Mode port 7683). The Full APK embeds the pinned rootfs; the F-Droid build downloads arch-rootfs-aarch64-03a4c669ed6f after consent and verifies size and SHA-256. pacman with signatures required (only DisableSandboxFilesystem, as the phone kernel has no Landlock), a per-install keyring created in the background after the terminal opens, sudo, uploads into a terminal's directory, LAN Mode (off by default, plain HTTP — trusted networks only). Not affiliated with or endorsed by Arch Linux or Arch Linux ARM.
Rolling pacman gate on the phone: 89 PASS, 0 FAIL (upgrades, interrupted-transaction recovery, a stale image upgraded to current). Known: 5 package files with non-root groups report a group mismatch in pacman -Qkk, and symlink times from the app's extractor differ from the package's in -Qkk until a package is reinstalled.
Built from commit 54a965f (JDK 17, Android SDK 36, NDK 23.2.8568313). *-release-unsigned.apk are the R8 release builds for F-Droid/own signing; *-test.apk are the same builds signed with the public Android debug key for testing only. Hashes: SHA256SUMS.txt.
Tested on a Samsung SM-A165F (Android 16, kernel 6.12, isolated test builds): first run (download/extract/terminal ready, background setup), HOME preservation through damage/repair/interrupted reinstall, LAN Mode, package manager gates, extractor gate with the app's own extractor on the pinned archive, and the host security suites. Not tested: Android devices with a 4.14 kernel (see the PRoot child-tracking note), other ABIs. Release notes list only what was run; details in docs/garden/closure/CLOSURE_REPORT.md.
ThothTerm Ubuntu 0.3.0 — Garden File Bridge Golden Baseline
ThothTerm Ubuntu 0.3.0 — Garden File Bridge Golden Baseline
Feature release on top of 0.2.1 (com.thothterm.ubuntu, versionCode 300). This is the new Ubuntu Garden Golden baseline. Everything in 0.2.1 is kept: Ubuntu 26.04 environment, sudo and apt, the hard-link fix, window hang-up and nohup, LAN Mode on 7681, Arabic in the browser, the manual Keep screen awake. No rootfs change.
New: Garden File Bridge
- Upload files and Upload folder — from the phone's overflow menu (Android's document picker; no storage permission) and, with LAN Mode on, from the paired browser's header — copy into the current working directory of that terminal session: wherever its shell has
cd'd to, a different directory for each phone window and each browser tab. The target is read on the phone from the session itself (the PTY's foreground process's working directory in/proc, made visible under PRoot by the new PRoot patch 0005). Nothing is typed into the shell or read from the screen, and a browser can never choose the directory. - Before anything is sent, the dialog shows Upload to: …. A
cdduring the transfer does not move it. Progress (bytes, percent) and Cancel. - Never overwrites. An existing
notes.txtstays; the upload becomesnotes (1).txt. A folder is never merged:projectbecomesproject (1). - Never partial. Files are streamed (never held in memory) into a hidden staging directory and moved into place only when complete. Cancel, errors, a full device, a dropped connection, sign-out, LAN Mode off and Exit remove unfinished work; if the app is killed mid-upload it is removed at the next start.
- Folder uploads keep the hierarchy, Unicode names (Arabic, CJK, accents), hidden files and — from the phone — empty folders. Browsers do not send empty folders, so none arrive from a browser.
- Names are checked like any untrusted input (
.., absolute paths, separators, encoded traversal, NUL and control characters, over-long names); existing symlinks in the directory are never followed. Uploaded files get the permissions acpin that shell would give them and are never executed, sourced, made executable or unpacked. - The browser header is now Upload files | Upload folder | Sign out. The header Copy button is gone; mouse selection, Ctrl+Shift+C and the browser clipboard (logical Arabic included) are unchanged.
New: Keep screen awake while charging
- Settings → Keep screen awake while charging (on by default): while the phone is on AC, USB, wireless or dock power and the terminal is in front, the display stays on. With another app in front, or unplugged, it sleeps at the normal timeout.
- It is the window's
FLAG_KEEP_SCREEN_ON, computed as manual OR (setting AND charging). No wake lock, no permission, no battery-optimization exemption, and the system screen timeout is never changed. While only charging keeps the screen on, the menu says Screen awake while charging and opens the setting; the manual Keep screen awake / Allow screen to sleep action is unchanged.
Security
Browser file uploads are local-network only and require the existing authenticated LAN session (PIN pairing, 256-bit bearer token, exact Host and Origin; a terminal and an upload are usable only by the browser that owns them; no second password, nothing in URLs). LAN traffic, including uploaded file contents, is plain HTTP and is NOT encrypted. Use LAN Mode only on trusted networks. The phone's LAN Mode screen and the browser page say so.
Validation (Samsung SM-A165F, Android 16, the minified release build from a fresh clone)
- Browser uploads (Chromium, LAN 7681): two tabs
cd'd to~/upload-test/aand~/upload-test/beach received only their own files, SHA-256 equal; folderproject/withsrc/,docs/,.hiddenand Arabic names arrived whole, hashes equal; a second copy becameproject (1); a 150 MB file in ~7 s, SHA-256 equal, app memory flat; cancel at 25 % and LAN Mode off mid-transfer left no file and no staging; 15/15, 4/4 and the LAN-off check pass. - Forged requests 38/38: missing, wrong and expired (earlier LAN run) credentials, wrong/missing Origin, wrong Host, unknown terminal, another browser's terminal and upload, a browser-sent target ignored, 19 forged paths (
../, absolute,%2e%2e, double-encoded, backslashes,C:, NUL, 300-byte names…), and a folder named after a plantedevil -> /etcsymlink becameevil (1)with nothing written to/etc. The existing LAN negative suite 13/13. - Phone uploads: two windows in
AandB; each upload landed in the window in front; files, folder (incl. empty folder,.hidden, Arabic), SHA-256 equal; no staging left. - Charging, 15 s timeout: on the charger the display stayed on 48 s with the terminal in front (window flag + WindowManager hold, no partial wake lock); behind another app and unplugged it slept at ~14 s; returning while charging kept it on. Device tests
KeepScreenAwakeTest+UploadFsDeviceTest19/19. - Regression: guest suite 12/12 on the new PRoot (sudo,
dpkg --audit,apt-get update, coreutils, hard links, DNS, TLS,cd-heavy work); browser suite (pairing, real PTY, sudo, Arabic logical UTF-8 and RTL, Ctrl+Shift+C copy, paste, resize, Ctrl-C, scrollback, reconnect, separate PTYs, sign-out) 35/35 — three of its items re-checked by hand after a script timing race; phone smoke 12/12 (PTY, Ctrl-C, zoom, windows, busy close withnohup, notification, Exit with nothing left, relaunch). App data preserved acrossadb install -r. - Build: 235 unit tests per flavour; PRoot host tests incl. 11 new working-directory cases (all fail without patch 0005); R8 with the same two JNI keep rules, 7/7 natives (new
renameNoReplace); all 64-bit ELFs 16 KB aligned;zipalign -c -P 16; F-Droidfdroid build --test --refresh-scanner --on-server com.thothterm.ubuntu:300succeeds.
Assets
*-release-unsigned.apk are unsigned. *-test.apk are the same release builds signed with the Android debug key, for testing only. full embeds the Ubuntu userland; fdroid downloads it after consent. SHA-256 values are in SHA256SUMS.txt.
ThothTerm Ubuntu 0.2.1 — Garden Golden Baseline
ThothTerm Ubuntu 0.2.1 — Garden Golden Baseline
A narrow bug-fix release on top of 0.2.0 (com.thothterm.ubuntu, versionCode 201). This is the new Ubuntu Garden Golden patch baseline; every 0.2.0 feature is unchanged: LAN Mode, PRoot patches 0001–0004 (including the /proc/self/exe hard-link fix), window hang-up and nohup, and the in-place sudo repair.
Fixed
- Keep screen awake now correctly prevents Android's display timeout while the terminal is in the foreground. It uses Android's foreground display flag (
FLAG_KEEP_SCREEN_ON) and no longer depends on a CPU WakeLock or a battery-optimization exemption; it no longer sends you to battery settings. Normal screen sleep resumes when you choose Allow screen to sleep or when the app is not in the foreground.
The choice lasts while the terminal is open, including rotation and screen recreation; Exit or a fresh launch starts with it off. Keep Wi-Fi on is unchanged.
Validation
- Samsung SM-A165F, Android 16, minified release build, 15 s screen timeout: display stayed on 45 s with the option on and the terminal in front; slept at the timeout with it off or in the background; WindowManager's screen hold attributed to
com.thothterm.ubuntuwhile on; no partial wake lock; no battery prompt.KeepScreenAwakeTest7/7 on the device; 164 unit tests per flavour. - Regression: Ubuntu 26.04.1 rootfs intact across
adb install -r, sudo,apt-get update,dpkg --auditclean, DNS and TLS, uutilslswith/proc/self/exenaming the hard link, PTY, Ctrl-C, multiple windows, busy-window close withnohup, notification, Exit; LAN Mode on 7681 with the browser suite 35/35 (pairing, real PTY, sudo, Arabic in logical UTF-8 and RTL rendering, copy/paste, resize, reconnect, separate PTYs, sign-out). - R8: two JNI keep rules, 6/6 natives; all ELFs 16 KB aligned;
zipalign -c -P 16 -v 4. F-Droidfdroid build --test --refresh-scanner --on-serversucceeds for 201.
Assets
*-release-unsigned.apk are unsigned. *-test.apk are the same release builds signed with the Android debug key, for testing only. full embeds the Ubuntu userland; fdroid downloads it after consent. SHA-256 values are in SHA256SUMS.txt.
ThothTerm Trixie 0.2.0 — Garden File Bridge Golden Baseline
ThothTerm Trixie 0.2.0 — Garden File Bridge Golden Baseline
Feature release on top of 0.1.1 (com.thothterm.debian, versionCode 200). This is the new Trixie Garden Golden baseline, built on garden-common, which every future Garden edition inherits. Everything in 0.1.1 is kept: the Debian GNU/Linux 13 (trixie) environment, apt, dpkg and sudo, LAN Mode on 7682 (7683 fallback), the pink/maroon palette, Arabic, the manual Keep screen awake. The downloadable environment is unchanged and reused: release debian-rootfs-trixie-arm64-f6520ff1c6ee (SHA-256 f6520ff1…0677); the full APK embeds the same bytes.
New: Garden File Bridge
- Upload files and Upload folder — from the phone's overflow menu (Android's document picker; no storage permission) and, with LAN Mode on, from the paired browser's header — copy into the current working directory of that terminal session: wherever its shell has
cd'd to, a different directory for each phone window and each browser tab. The target is read on the phone from the session itself (the PTY's foreground process's working directory in/proc, made visible under PRoot by the new PRoot patch 0005). Nothing is typed into the shell or read from the screen, and a browser can never choose the directory. - Before anything is sent, the dialog shows Upload to: …. A
cdduring the transfer does not move it. Progress (bytes, percent) and Cancel. - Never overwrites. An existing
notes.txtstays; the upload becomesnotes (1).txt. A folder is never merged:projectbecomesproject (1). - Never partial. Files are streamed (never held in memory) into a hidden staging directory and moved into place only when complete. Cancel, errors, a full device, a dropped connection, sign-out, LAN Mode off and Exit remove unfinished work; if the app is killed mid-upload it is removed at the next start.
- Folder uploads keep the hierarchy, Unicode names (Arabic, CJK, accents), hidden files and — from the phone — empty folders. Browsers do not send empty folders, so none arrive from a browser.
- Names are checked like any untrusted input (
.., absolute paths, separators, encoded traversal, NUL and control characters, over-long names); existing symlinks in the directory are never followed. Uploaded files get the permissions acpin that shell would give them and are never executed, sourced, made executable or unpacked. - The browser header is now Upload files | Upload folder | Sign out. The header Copy button is gone; mouse selection, Ctrl+Shift+C and the browser clipboard (logical Arabic included) are unchanged.
New: Keep screen awake while charging
- Settings → Keep screen awake while charging (on by default): while the phone is on AC, USB, wireless or dock power and the terminal is in front, the display stays on. With another app in front, or unplugged, it sleeps at the normal timeout.
- It is the window's
FLAG_KEEP_SCREEN_ON, computed as manual OR (setting AND charging). No wake lock, no permission, no battery-optimization exemption, and the system screen timeout is never changed. While only charging keeps the screen on, the menu says Screen awake while charging and opens the setting; the manual Keep screen awake / Allow screen to sleep action is unchanged.
Security
Browser file uploads are local-network only and require the existing authenticated LAN session (PIN pairing, 256-bit bearer token, exact Host and Origin; a terminal and an upload are usable only by the browser that owns them; no second password, nothing in URLs). LAN traffic, including uploaded file contents, is plain HTTP and is NOT encrypted. Use LAN Mode only on trusted networks. The phone's LAN Mode screen and the browser page say so.
Validation (Samsung SM-A165F, Android 16, the minified release build from a fresh clone)
- Browser uploads (Chromium, LAN 7682): two tabs into
~/upload-test/aand~/upload-test/breceived only their own files, SHA-256 equal; folderproject/whole with.hiddenand Arabic names, hashes equal; second copyproject (1); 150 MB in ~6 s, SHA-256 equal; cancel and LAN Mode off mid-transfer left no file and no staging. 15/15, 4/4, LAN-off check pass. - Forged requests 38/38 (missing/wrong/expired credentials, Origin, Host, other browser's terminal and upload, browser-sent target ignored, 19 forged paths, planted
evil -> /etcsymlink →evil (1), nothing in/etc). Existing LAN negative suite 13/13; with 7682 taken, LAN Mode bound 7683. - Phone uploads: two windows in
AandB, each upload in the window in front; files and folder (empty folder,.hidden, Arabic) SHA-256 equal; no staging left. - Charging, 15 s timeout: 48 s awake on the charger in front; ~14 s to sleep behind another app and unplugged; back in front while charging stays on; no partial wake lock. Device tests 19/19.
- Regression: Debian GNU/Linux 13 (trixie); guest suite 12/12 on the new PRoot (sudo,
dpkg --audit,apt-get update, coreutils, hard links, DNS, TLS,cd-heavy work); browser suite 35/35 (pairing, edition branding, real PTY, sudo, Arabic, Ctrl+Shift+C logical copy, paste, resize, Ctrl-C, scrollback, reconnect, separate PTYs, sign-out); phone smoke 12/12; data preserved acrossadb install -r. Embedded rootfs byte-identical to the published one. - Build: garden-common 253 and garden-debian 20 unit tests per flavour (incl. the pairing check that keeps garden-common and term-ubuntu's upload code identical); R8 two JNI keep rules, 7/7 natives; 16 KB aligned;
zipalign -c -P 16; F-Droidfdroid build --test --refresh-scanner --on-server com.thothterm.debian:200succeeds.
Assets
*-release-unsigned.apk are unsigned. *-test.apk are the same release builds signed with the Android debug key, for testing only. full embeds the Debian environment; fdroid downloads it after consent from debian-rootfs-trixie-arm64-f6520ff1c6ee. SHA-256 values are in SHA256SUMS.txt.
ThothTerm Trixie is not affiliated with or endorsed by the Debian Project.