ThothTerm Ubuntu 0.3.0 — Garden File Bridge Golden Baseline
ThothTerm Ubuntu 0.3.0 — Garden File Bridge Golden Baseline
Feature release on top of 0.2.1 (com.thothterm.ubuntu, versionCode 300). This is the new Ubuntu Garden Golden baseline. Everything in 0.2.1 is kept: Ubuntu 26.04 environment, sudo and apt, the hard-link fix, window hang-up and nohup, LAN Mode on 7681, Arabic in the browser, the manual Keep screen awake. No rootfs change.
New: Garden File Bridge
- Upload files and Upload folder — from the phone's overflow menu (Android's document picker; no storage permission) and, with LAN Mode on, from the paired browser's header — copy into the current working directory of that terminal session: wherever its shell has
cd'd to, a different directory for each phone window and each browser tab. The target is read on the phone from the session itself (the PTY's foreground process's working directory in/proc, made visible under PRoot by the new PRoot patch 0005). Nothing is typed into the shell or read from the screen, and a browser can never choose the directory. - Before anything is sent, the dialog shows Upload to: …. A
cdduring the transfer does not move it. Progress (bytes, percent) and Cancel. - Never overwrites. An existing
notes.txtstays; the upload becomesnotes (1).txt. A folder is never merged:projectbecomesproject (1). - Never partial. Files are streamed (never held in memory) into a hidden staging directory and moved into place only when complete. Cancel, errors, a full device, a dropped connection, sign-out, LAN Mode off and Exit remove unfinished work; if the app is killed mid-upload it is removed at the next start.
- Folder uploads keep the hierarchy, Unicode names (Arabic, CJK, accents), hidden files and — from the phone — empty folders. Browsers do not send empty folders, so none arrive from a browser.
- Names are checked like any untrusted input (
.., absolute paths, separators, encoded traversal, NUL and control characters, over-long names); existing symlinks in the directory are never followed. Uploaded files get the permissions acpin that shell would give them and are never executed, sourced, made executable or unpacked. - The browser header is now Upload files | Upload folder | Sign out. The header Copy button is gone; mouse selection, Ctrl+Shift+C and the browser clipboard (logical Arabic included) are unchanged.
New: Keep screen awake while charging
- Settings → Keep screen awake while charging (on by default): while the phone is on AC, USB, wireless or dock power and the terminal is in front, the display stays on. With another app in front, or unplugged, it sleeps at the normal timeout.
- It is the window's
FLAG_KEEP_SCREEN_ON, computed as manual OR (setting AND charging). No wake lock, no permission, no battery-optimization exemption, and the system screen timeout is never changed. While only charging keeps the screen on, the menu says Screen awake while charging and opens the setting; the manual Keep screen awake / Allow screen to sleep action is unchanged.
Security
Browser file uploads are local-network only and require the existing authenticated LAN session (PIN pairing, 256-bit bearer token, exact Host and Origin; a terminal and an upload are usable only by the browser that owns them; no second password, nothing in URLs). LAN traffic, including uploaded file contents, is plain HTTP and is NOT encrypted. Use LAN Mode only on trusted networks. The phone's LAN Mode screen and the browser page say so.
Validation (Samsung SM-A165F, Android 16, the minified release build from a fresh clone)
- Browser uploads (Chromium, LAN 7681): two tabs
cd'd to~/upload-test/aand~/upload-test/beach received only their own files, SHA-256 equal; folderproject/withsrc/,docs/,.hiddenand Arabic names arrived whole, hashes equal; a second copy becameproject (1); a 150 MB file in ~7 s, SHA-256 equal, app memory flat; cancel at 25 % and LAN Mode off mid-transfer left no file and no staging; 15/15, 4/4 and the LAN-off check pass. - Forged requests 38/38: missing, wrong and expired (earlier LAN run) credentials, wrong/missing Origin, wrong Host, unknown terminal, another browser's terminal and upload, a browser-sent target ignored, 19 forged paths (
../, absolute,%2e%2e, double-encoded, backslashes,C:, NUL, 300-byte names…), and a folder named after a plantedevil -> /etcsymlink becameevil (1)with nothing written to/etc. The existing LAN negative suite 13/13. - Phone uploads: two windows in
AandB; each upload landed in the window in front; files, folder (incl. empty folder,.hidden, Arabic), SHA-256 equal; no staging left. - Charging, 15 s timeout: on the charger the display stayed on 48 s with the terminal in front (window flag + WindowManager hold, no partial wake lock); behind another app and unplugged it slept at ~14 s; returning while charging kept it on. Device tests
KeepScreenAwakeTest+UploadFsDeviceTest19/19. - Regression: guest suite 12/12 on the new PRoot (sudo,
dpkg --audit,apt-get update, coreutils, hard links, DNS, TLS,cd-heavy work); browser suite (pairing, real PTY, sudo, Arabic logical UTF-8 and RTL, Ctrl+Shift+C copy, paste, resize, Ctrl-C, scrollback, reconnect, separate PTYs, sign-out) 35/35 — three of its items re-checked by hand after a script timing race; phone smoke 12/12 (PTY, Ctrl-C, zoom, windows, busy close withnohup, notification, Exit with nothing left, relaunch). App data preserved acrossadb install -r. - Build: 235 unit tests per flavour; PRoot host tests incl. 11 new working-directory cases (all fail without patch 0005); R8 with the same two JNI keep rules, 7/7 natives (new
renameNoReplace); all 64-bit ELFs 16 KB aligned;zipalign -c -P 16; F-Droidfdroid build --test --refresh-scanner --on-server com.thothterm.ubuntu:300succeeds.
Assets
*-release-unsigned.apk are unsigned. *-test.apk are the same release builds signed with the Android debug key, for testing only. full embeds the Ubuntu userland; fdroid downloads it after consent. SHA-256 values are in SHA256SUMS.txt.