Releases: Soko-Aerial/Flash
Release list
Flash v2.0.0-beta
Flash v2.0.0-beta — Cross-Platform LAN & Wi-Fi Direct Peer-to-Peer Transfer & Messaging
We are thrilled to announce the v2.0.0-beta release of Flash! This milestone delivers full cross-platform parity between Android and Windows Desktop, introducing end-to-end encryption, an adaptive dual-pane UI, deep Android system integration, native Windows desktop integration, and resilient offline networking.
🌟 Key Highlights
🔒 Dual-Layer Security & True End-to-End Encryption
- Wire-Level TLS 1.3 Transport (WSS): Authenticated communication over local Wi-Fi / Hotspot with Trust-On-First-Use (TOFU) certificate fingerprint pinning.
- Pairwise AES-256-GCM E2E Messaging: ECDH P-256 key agreement with HKDF-SHA256 session keys. Chat messages, replies, reactions, and typing signals are encrypted on the wire.
- Binary Chunk AES-256-GCM Encryption: Large file streams and chunks are cryptographically authenticated with 128-bit authentication tags.
- Interactive Verification & Device Fingerprints: Compare safety numbers and view SHA-256 device fingerprint hashes directly in the app.
- AndroidKeyStore TLS Resilience (ERROR-070): Hardware-backed P-256 private keys on Android now support
DIGEST_NONEfor Conscrypt TLS signatures, with self-healing key migration.
📱 Android System Integration
- System Share Target (
ACTION_SEND&ACTION_SEND_MULTIPLE): Select photos, videos, or documents in Google Photos, Files, or WhatsApp and share directly with Flash. - Android 14+ DataSync Foreground Service: Persistent, uninterrupted background transfers with real-time transfer speed, ETA, and progress notifications. Includes Android 15
onTimeouthandling. - Quick Settings Tile: Toggle discoverability or jump straight to Nearby sharing with one tap from the Android notification shade.
- App Shortcuts: Long-press the app icon to quickly jump to "Send Files", "Nearby Devices", or "Chats".
- Adaptive Dual-Pane Layout: Automatically transforms on tablets (Pixel Tablet, Galaxy Tab), foldables, and landscape mode into a responsive Navigation Rail and List-Detail view.
💻 Windows Desktop Native Experience
- No Java Required: Ships with native
.exeand.msiinstallers bundling an embedded private runtime. - Adaptive Two-Pane Layout: Modern 68dp Navigation Rail, clamped list pane (320–480dp), and comfortable reading measure (up to 580dp message bubble width) inspired by WhatsApp & Telegram desktop.
- System Tray & "Close to Tray": Keeps transfers running in the background when clicking the close button (
X), with an active tray menu to manage Flash. - Dynamic Taskbar Icon Badging: Windows taskbar badge counter alerts you to unread messages in the background, accompanied by native Windows OS notifications.
- Drag-and-Drop File & Folder Transfers: Drop single files or entire directory trees directly onto a chat window to send them instantly.
- Relative Path Preservation: Preserves folder structures on transfer while enforcing strict path-traversal safeguards.
- Upright Mobile Photos & Video Thumbnails: Integrated JPEG EXIF parser automatically rotates smartphone camera photos; JCodec extracts high-fidelity video thumbnails without external codecs.
- Native Windows Explorer Reveal: One-click "Reveal in folder" directly selects and highlights completed files in Windows Explorer.
- Windows Startup: Optional auto-start on boot via Windows Registry integration.
📚 Android Library / SDK Modules
Developers can now consume Flash's core engine and UI modules via JitPack:
// settings.gradle.kts
dependencyResolutionManagement {
repositories {
mavenCentral()
maven { url = uri("https://jitpack.io") }
}
}
// app/build.gradle.kts
dependencies {
implementation("com.github.Kali452345.Flash:core-engine:v2.0.0-beta")
}📦 Installation Guide
Android
- Download
app-release-signed-beta.apk. - Open the file on your device and tap Install (allow "Install unknown apps" if prompted).
- Requires Android 7.0 (Nougat, API 24) or higher.
Windows (No Java Needed)
- Option 1 (Recommended): Download and run
Flash-2.0.0.exe. Follow the setup wizard to install Flash. - Option 2 (Enterprise / MSI): Download and run
Flash-2.0.0.msi. - Option 3 (Portable JAR): If you already have Java 11+ installed, you can run
java -jar Flash-windows-x64-2.0.0.jar.
Flash 1.1.0 — voice & video calling, self-healing sessions
Flash 1.1.0 — voice/video calling, and a session that heals itself.
dependencies {
implementation("com.github.Kali452345.Flash:core-engine:v1.1.0")
implementation("com.github.Kali452345.Flash:core-calling:v1.1.0") // calls
implementation("com.github.Kali452345.Flash:ui-callui:v1.1.0") // in-call screen
}New: voice & video calls
core-calling and ui-callui are published for the first time. Calling is deliberately
not reachable through Flash.create — it needs a signaling channel the app already owns,
runtime mic/camera grants, and a microphone|camera foreground service in the app's own
manifest. Wire two seams (sendFrame out, onInboundText in) and calling.activeCall drives
a navigation route. See README → Voice & video calls and docs/architecture/public-api.md §7.
Audio is now prioritised over video. Previously there was no priority at all: the audio
RtpSender was discarded and only video was tuned, so 8 Mbps of video on a shared half-duplex
phone hotspot made voice unintelligible. Audio is pinned (Priority.HIGH, bitratePriority
4.0), video demoted, and the ceiling dropped to 2.5 Mbps. MaxBundle + rtcpMux put both
streams on one 5-tuple, so DSCP cannot separate them — the priority lives in the bandwidth
allocator. A quality governor on the 1 Hz stats loop sheds video bitrate, then resolution, then
the stream itself when audio degrades, with asymmetric hysteresis (2 bad samples to concede,
5 clean to recover) and a user-visible reason. Controlled by a default-on Prioritise voice
quality setting.
Fixed: sessions that looked alive and weren't
A peer could hold a zombie session — present in activeSessions, dead on the wire — that
nothing could reap or replace. It made one device latch Offline, the other read falsely Online,
showed a pending clock under an Online header, and let a message tick once and never arrive.
Force-stopping both apps was the only recovery.
- Glare arbitration compared originator ids, so two same-direction sessions for one peer
always tied — and a tie kept the incumbent, so a stale session rejected the peer's fresh
reconnect forever. Now scoped to genuine simultaneous glare; same-direction means newest wins. - Keepalive forgave late scheduler ticks without bound, so the liveness watchdog never
fired under repeated Doze freezes. Forgiveness is now episode-scoped. - Buffered frames on a replaced or rejected connection were discarded, losing inbound
delivery receipts. They now transfer to the surviving session. - The outbox treated "the kernel accepted the bytes" as delivery and deleted its row. Rows
now survive until the peer acknowledges, so a write into a half-open socket retries instead
of vanishing. Delivery status can no longer walk backwards. - Presence gained a real
Connectingstate — Online / Reconnecting / Offline — replacing a
hold that every upstream emission silently cancelled. - Recovery paths treated any session as a working one; they now require recent inbound
traffic before declining to reconnect. - A refused foreground promotion no longer tears down the screen-on re-arm with the
service instance.
Packaging
Twelve modules publish, up from eight — core-calling, ui-theme, ui-chat and ui-callui
join the core set. core-calling now ships consumer ProGuard rules for WebRTC's JNI, without
which a minified consumer build crashed inside PeerConnectionFactory init; the WebRTC AAR
ships none of its own. The ui-* artifacts had been hardcoding version 1.0.0 in their own
publication blocks and now track the root version.
core-calling bundles native WebRTC (~30 MB per ABI). Nothing else in Flash depends on it, so
an app that does not call does not pay for it.
Requires Android 8.0 (API 24)+, AGP 9.3+, Gradle 9.5+, Kotlin 2.2+.
Full changelog: v1.0.0...v1.1.0