Skip to content

ThothTerm Trixie 0.2.0 — Garden File Bridge Golden Baseline

Choose a tag to compare

@Lord1Egypt Lord1Egypt released this 27 Sep 18:07
· 150 commits to master since this release

ThothTerm Trixie 0.2.0 — Garden File Bridge Golden Baseline

Feature release on top of 0.1.1 (com.thothterm.debian, versionCode 200). This is the new Trixie Garden Golden baseline, built on garden-common, which every future Garden edition inherits. Everything in 0.1.1 is kept: the Debian GNU/Linux 13 (trixie) environment, apt, dpkg and sudo, LAN Mode on 7682 (7683 fallback), the pink/maroon palette, Arabic, the manual Keep screen awake. The downloadable environment is unchanged and reused: release debian-rootfs-trixie-arm64-f6520ff1c6ee (SHA-256 f6520ff1…0677); the full APK embeds the same bytes.

New: Garden File Bridge

  • Upload files and Upload folder — from the phone's overflow menu (Android's document picker; no storage permission) and, with LAN Mode on, from the paired browser's header — copy into the current working directory of that terminal session: wherever its shell has cd'd to, a different directory for each phone window and each browser tab. The target is read on the phone from the session itself (the PTY's foreground process's working directory in /proc, made visible under PRoot by the new PRoot patch 0005). Nothing is typed into the shell or read from the screen, and a browser can never choose the directory.
  • Before anything is sent, the dialog shows Upload to: …. A cd during the transfer does not move it. Progress (bytes, percent) and Cancel.
  • Never overwrites. An existing notes.txt stays; the upload becomes notes (1).txt. A folder is never merged: project becomes project (1).
  • Never partial. Files are streamed (never held in memory) into a hidden staging directory and moved into place only when complete. Cancel, errors, a full device, a dropped connection, sign-out, LAN Mode off and Exit remove unfinished work; if the app is killed mid-upload it is removed at the next start.
  • Folder uploads keep the hierarchy, Unicode names (Arabic, CJK, accents), hidden files and — from the phone — empty folders. Browsers do not send empty folders, so none arrive from a browser.
  • Names are checked like any untrusted input (.., absolute paths, separators, encoded traversal, NUL and control characters, over-long names); existing symlinks in the directory are never followed. Uploaded files get the permissions a cp in that shell would give them and are never executed, sourced, made executable or unpacked.
  • The browser header is now Upload files | Upload folder | Sign out. The header Copy button is gone; mouse selection, Ctrl+Shift+C and the browser clipboard (logical Arabic included) are unchanged.

New: Keep screen awake while charging

  • Settings → Keep screen awake while charging (on by default): while the phone is on AC, USB, wireless or dock power and the terminal is in front, the display stays on. With another app in front, or unplugged, it sleeps at the normal timeout.
  • It is the window's FLAG_KEEP_SCREEN_ON, computed as manual OR (setting AND charging). No wake lock, no permission, no battery-optimization exemption, and the system screen timeout is never changed. While only charging keeps the screen on, the menu says Screen awake while charging and opens the setting; the manual Keep screen awake / Allow screen to sleep action is unchanged.

Security

Browser file uploads are local-network only and require the existing authenticated LAN session (PIN pairing, 256-bit bearer token, exact Host and Origin; a terminal and an upload are usable only by the browser that owns them; no second password, nothing in URLs). LAN traffic, including uploaded file contents, is plain HTTP and is NOT encrypted. Use LAN Mode only on trusted networks. The phone's LAN Mode screen and the browser page say so.

Validation (Samsung SM-A165F, Android 16, the minified release build from a fresh clone)

  • Browser uploads (Chromium, LAN 7682): two tabs into ~/upload-test/a and ~/upload-test/b received only their own files, SHA-256 equal; folder project/ whole with .hidden and Arabic names, hashes equal; second copy project (1); 150 MB in ~6 s, SHA-256 equal; cancel and LAN Mode off mid-transfer left no file and no staging. 15/15, 4/4, LAN-off check pass.
  • Forged requests 38/38 (missing/wrong/expired credentials, Origin, Host, other browser's terminal and upload, browser-sent target ignored, 19 forged paths, planted evil -> /etc symlink → evil (1), nothing in /etc). Existing LAN negative suite 13/13; with 7682 taken, LAN Mode bound 7683.
  • Phone uploads: two windows in A and B, each upload in the window in front; files and folder (empty folder, .hidden, Arabic) SHA-256 equal; no staging left.
  • Charging, 15 s timeout: 48 s awake on the charger in front; ~14 s to sleep behind another app and unplugged; back in front while charging stays on; no partial wake lock. Device tests 19/19.
  • Regression: Debian GNU/Linux 13 (trixie); guest suite 12/12 on the new PRoot (sudo, dpkg --audit, apt-get update, coreutils, hard links, DNS, TLS, cd-heavy work); browser suite 35/35 (pairing, edition branding, real PTY, sudo, Arabic, Ctrl+Shift+C logical copy, paste, resize, Ctrl-C, scrollback, reconnect, separate PTYs, sign-out); phone smoke 12/12; data preserved across adb install -r. Embedded rootfs byte-identical to the published one.
  • Build: garden-common 253 and garden-debian 20 unit tests per flavour (incl. the pairing check that keeps garden-common and term-ubuntu's upload code identical); R8 two JNI keep rules, 7/7 natives; 16 KB aligned; zipalign -c -P 16; F-Droid fdroid build --test --refresh-scanner --on-server com.thothterm.debian:200 succeeds.

Assets

*-release-unsigned.apk are unsigned. *-test.apk are the same release builds signed with the Android debug key, for testing only. full embeds the Debian environment; fdroid downloads it after consent from debian-rootfs-trixie-arm64-f6520ff1c6ee. SHA-256 values are in SHA256SUMS.txt.

ThothTerm Trixie is not affiliated with or endorsed by the Debian Project.