·
25 commits
to master
since this release
ThothTerm Terminal Emulator 1.4.1
Security patch on top of 1.4.0 (terminal-v1.4.0). Update recommended; 1.4.0 and earlier are affected.
- Text that another installed app supplied through the share target or the "Term here" / window-opening integration could be typed into a terminal session as a command. Nothing from outside the app is typed any more: the directory is passed as a structural working-directory value.
- Add-on applications are trusted only when signed with the terminal's own certificate, not by package name.
- The local socket server refuses a connection from another app and keeps serving.
- Permanent regression tests pin the exported components and the integration surface (
docs/security/THORNS.md).
Features, permissions, package id (com.thothterm) and data are unchanged from 1.4.0. Details of the report stay in the private advisory for now.
Built from commit 760d54e. *-release-unsigned.apk are the R8 release builds; *-test.apk are signed with the public Android debug key for testing only. No AAB is attached to this release. Hashes: terminal-v1.4.1-SHA256SUMS.txt.
Checked: 1275 unit tests, 0 failures; release APK checks pass. lintFullRelease reports one error, GestureBackNavigation in Term.java, which is unchanged from 1.4.0.