Repository navigation
Releases: Ulzuhan/arveil
Release list
Arveil 0.2.0 — relay and CLI
Arveil 0.2.0 — relay and command-line client
Companion relay/CLI release for client beta 6 (0.1.0+27). Built from d660f087f8252adcbdfea226029e374f2aac01b5. Arveil remains experimental, uses wire protocol 0 and has not had an independent security review.
Changes since v0.1.0
- Registered credential lookup required by QR contact cards and conversation requests.
- Personal invitations: authorized owner issuance/list/revocation, durable admission and claim receipts, quotas and replay checks. The host CLI can promote an explicitly selected existing identity with
make-owner. - Joining links and terminal QR output, with configurable link base and advertised endpoint.
- Relay, CLI and container binaries report both the release tag version and full source commit. Core/protocol versions and the already published app packages are unchanged.
Artifacts and verification
Relay and CLI binaries are supplied for Linux x86-64 and macOS Apple silicon. Download the four binaries and SHA256SUMS-cli-relay.txt; run shasum -a 256 --check SHA256SUMS-cli-relay.txt. Verify each binary with gh attestation verify <binary> --repo Ulzuhan/arveil.
Container: ghcr.io/ulzuhan/arveil-relay:0.2.0 for Linux x86-64 and ARM64, also tagged with the full source commit. Verify provenance with gh attestation verify oci://ghcr.io/ulzuhan/arveil-relay:0.2.0 --owner Ulzuhan. Run arveil-relay -version or arveil version to check the release identity. macOS CLI binaries are not Apple-notarized.
Upgrade order
Back up the realm consistently before replacing the relay. This release upgrades relay schema 4 to 5; beta 6 migrates app profiles to schema 8. Upgrade the relay before clients that need credential lookup or personal invitations. Relay v0.1.0 does not implement these operations.
Keep each backup with its matching older binary. Do not run an older binary on a migrated database. Restore into a separate directory, preserve the realm keys and highest known signed-endpoint counter, and account for changes made after the backup; prefer a forward fix. An identity kit or history import does not restore live MLS sessions.
See operation and verification, invitations and owner setup and Podman deployment.
Verification and remaining acceptance
- Required PR CI passed before merge: PR #143, CI. Tagged binary build and container build identify the release commit.
- All four downloaded binaries matched their checksum manifest; GitHub provenance was verified against the release workflow and exact source commit. macOS ARM64 binaries report
0.2.0+d660f087f8252adcbdfea226029e374f2aac01b5 (protocol 0). - Downloaded v0.1.0 and v0.2.0 macOS ARM64 CLI/relay packages: new contact credential lookup fails on v0.1.0 and the same profile succeeds after relay upgrade; old and new CLIs exchange messages in both directions. Relay schema 4→5 preserves memberships and realm keys. Known diagnostic limitation: the new CLI against the old relay reports a WebSocket connection reset, not an explicit upgrade-required message.
- Selected distributed v0.2.0 package acceptance passes: joining links; linking/number confirmation; wrong-number, duplicate, declined and expired links; contact verification/cards; accepted and declined contact requests. Complete phase-3b enrollment/mailbox/recovery-retry assertions also pass. These use the downloaded binaries; the selected phase-3 run excludes attachment crash injection and push fixtures.
- Installed Android beta 3/build 21 on a disposable Android 15/API 35 ARM64 emulator exchanges messages before and after upgrading the relay. Its own update screen sees beta 6/build 27, downloads/verifies it and opens Android's system installer. The in-place update keeps the profile, earlier conversation history and original install time; beta 6 then exchanges new messages in both directions. The installed APK matches the published beta 6 SHA-256. No app data clearing or re-enrollment was used.
- These are package/emulator checks. Physical phones, fresh downloaded Mac app acceptance, personal-invitation trials with external people, background notification reliability and independent security review remain in their existing issues.
- Public OCI manifest access and the commit tag match were checked without registry credentials; linux/amd64 and linux/arm64 are present. The exact index digest has verified GitHub provenance:
sha256:74ffed4f5688e63c22ded35877a4eca00f54c6ffea7f7890ba772e510f5f2694.
Physical Android/clean Mac acceptance, the external-user trial, suspended notification behavior and independent security review remain tracked separately. See #133, #134, #135, #136, #137 and #140. Publishing these artifacts does not certify those device or production criteria.
Arveil 0.1.0 beta 6
Arveil 0.1.0 beta 6
Personal invitations now combine joining your server and starting a conversation in one private link or QR. Create one in Contacts → Invite someone, share it privately, and have the recipient review and accept it. Issuing invitations requires the relay owner permission. The recipient gets an independent identity; neither person is marked verified automatically.
What changed
- Single-use personal invitations, valid for seven days, with copy/share/QR, status and revocation.
- First-run scanning/pasting before server details, plus clear consent and resumable encrypted progress after interruption.
- One conversation across repeated opens and retries. The inviter can be offline and receives it after reopening the device that issued the invitation.
- Existing members of the same server keep their identity and role. Other linked inviter devices can list/revoke invitations; this beta does not synchronize the first chat to them automatically.
- Updated installation guidance in Spanish and English. After installing, return to the original invitation; installation does not recover the link automatically.
Packages and updates
Client version 0.1.0+27, clean source e4011f3f2781aa48888d7da35114aa475d6ff71e.
- Android ARM64, Android 7.0/API 24 or later. Google Play internal testing uses build 27; Play handles its updates. The direct APK uses the maintained release certificate and the signed update feed.
- macOS ARM64, macOS 12 or later. Update using
brew updatefollowed bybrew upgrade --cask arveil, or replace the app with the ZIP download. The Mac app is ad-hoc signed, without Developer ID or Apple notarization. - Keep the app's storage and profile when updating. Never uninstall or clear data to update. Profile schema 8 and relay schema 5 must not be opened with older binaries; retain backups and prefer a forward fix.
- Verify
SHA256SUMS-clients.txtand the platformBUILDmetadata. The signed announcement has its own increasing sequence.
Validation and limits
The full Go/Rust/Flutter checks and CI validate this source. Nine real Go–Rust scenarios include 22 persistence-failure boundaries, relay restore and linked-device behavior. Native invitation creation, QR rendering, offline reopen/resume and duplex chat pass on macOS 26.6.2 and Android 15/API 35 ARM64 emulation. A prior-relay rollback was rehearsed with compatible backup data and preserved endpoint sequence.
This remains an experimental beta without an independent security review. Physical-phone camera/QR, fresh WhatsApp/Play installation and Gatekeeper on a fresh downloaded Mac installation remain user acceptance work. Missing/revoked issuer routes or resumption beyond receipt retention need explicit recovery; uncertain operations are retained for resumption. A bearer invitation can be used by the first eligible person it is forwarded to. Play tester eligibility remains separate from relay admission.
Español
Una invitación personal reúne alta y contacto en un enlace o QR privado. En Contactos → Invitar a alguien, una identidad autorizada por el relay puede crearla, compartirla y revocarla. Dura siete días y sirve una vez. Al aceptarla se crea una identidad independiente y un chat; la verificación de la persona sigue siendo un paso separado.
Puedes reanudar después de perder conexión o cerrar el perfil sin duplicar el chat. El emisor recibe la conversación al volver al dispositivo que emitió la invitación. Actualiza encima de la app instalada: no desinstales ni borres sus datos. Las pruebas físicas de instalación y cámara siguen pendientes en esta beta.
Arveil 0.1.0 beta 5
Arveil 0.1.0 beta 5
Build 26 adds file previews and optional activity notifications to the experimental Arveil client. Source revision: f5dfd190b97f13de694c91a7cf4b5257ca59cc26 (16/16 CI checks passed). The project has not had an independent security review.
Changes
- Preview PNG, JPEG and WebP images inside Arveil, with zoom. Open PDFs and other files in an installed application; saving a separate copy remains available.
- On Mac, enable generic activity notices and optional background synchronization. Closing the window can keep Arveil running; reopen or quit it from the menu bar.
- On Android, experimental notices use the official ntfy F-Droid application and your own HTTPS server. Configure both applications with the same server. Authenticated servers also require a subscriber account in ntfy. Arveil does not use FCM or Google Play Services for delivery.
- An activity hint received while Arveil is visible can produce one notice after switching to the background before synchronization finishes. Repeated hints and visibility changes do not repeatedly show it.
- Includes the QR/device-linking, contact-card and public-route fixes tested in the intervening internal builds.
Install or update
- Google Play: build 26 is distributed in the existing internal testing channel. Update from Play if that is how you installed Arveil.
- Direct Android APK: ARM64, Android 7.0/API 24 or newer. This uses the maintained direct-download signing key. Install over an earlier direct APK, preserving app data; do not replace a Google Play installation with this APK.
- Mac: Apple silicon, macOS 12 or newer. Run
brew updateandbrew upgrade --cask arveil, or replace the app with the ZIP download. The app remains ad-hoc signed, without Apple Developer ID or notarization. - The direct APK and Mac app include the existing signed beta-update feed.
clients-beta-*.jsonis the signed announcement;SHA256SUMS-clients.txtandBUILD-*.jsonidentify the exact packages.
Verification and current limits
Flutter analysis and 298 unit/widget tests pass. Native Mac tests cover file handoff/cleanup, generic notification-center delivery and window hide/reopen. Android emulator tests cover official distributor registration, native notices, foreground/background transitions, coalescing and unregistration. The relay-to-ntfy and ntfy-to-Android segments also passed separate acceptance runs against an authenticated self-hosted HTTPS service, including server restart persistence.
The complete path with a real phone profile, notification taps, Doze/battery restrictions, process death and changing networks still needs physical-device acceptance. Packaged Mac permission prompts, notification taps, Gatekeeper and sleep/wake remain interactive checks. Notifications are generic hints: they do not contain message text, unlock a profile or guarantee delivery. The relay currently makes one best-effort attempt without retries. PDFs open externally; internal PDF rendering is not included.
Use a current compatible relay with QR pairing and credential-route validation (the tested deployment uses revision b328668d355c3f7e8ee3360baf0ef2165fba2f21). The old relay v0.1.0 does not support all of these client flows. Build a compatible relay from the recorded source using the repository's operator tooling before upgrading clients that depend on those flows.
Arveil 0.1.0 — relay and command-line client
Arveil 0.1.0 — relay and command-line client
The first release of the Arveil relay and command-line client, published alongside the first public beta of the apps, clients-v0.1.0-beta.1. Built from dc03eef99ca2bdeadc4a52e9578b10a86cb6267a. The project has not had an independent security review.
Artifacts
- Relay:
arveil-relay-linux-x86_64andarveil-relay-macos-aarch64. Command-line client:arveil-linux-x86_64andarveil-macos-aarch64. Each prints its source commit with-version(versionfor the client). The version label in front of it reads0.0.1-devfor the relay and0.0.1for the client, because this release's build sets only the commit; the commit identifies the release, and later releases will carry their own version. SHA256SUMS-cli-relay.txtlists their checksums.- Container image
ghcr.io/ulzuhan/arveil-relay:0.1.0for Linux x86-64 and ARM64. - The binaries and the image carry build provenance attestations:
gh attestation verify <file> --owner Ulzuhan, oroci://ghcr.io/ulzuhan/arveil-relay:0.1.0for the image.
What the relay does
It moves encrypted envelopes between devices and never sees content or identities. Devices reach it through a Noise channel inside WebSocket, over LAN, tailnet, a tunnel or the Internet, and the relay signs the list of addresses they may use. It keeps its data in SQLite and a folder and ships with limits, health and metrics endpoints, optional TLS and backups.
Behind a proxy you trust, -trust-forwarded-for reads the client address from the last X-Forwarded-For entry, and the relay groups IPv6 addresses by /64 for its limits.
Running and upgrading
See running a realm, rootless Podman and Cloudflare Tunnel. Back up the realm before upgrading, and keep the previous image until the new one is healthy.
Arveil 0.1.0 beta 3
Arveil 0.1.0 beta 3
The third public beta of Arveil, a self-hosted, end-to-end encrypted messenger for families and small circles of trust. It makes linking a second device, joining a server and starting a conversation easier. The project has not had an independent security review.
Packages
- Client version
0.1.0+21, clean source9489ce6613a776f5554234cbd9e304115f14b38a. - Android ARM64, Android 7.0 (API 24) or newer, signed with the maintained release certificate, SHA-256
e3ca47a1f3d8b52dc6aea63107399f63a092a412d544d651b3eff67a41d256ba. With update checks turned on, Settings → Updates offers this version to beta 1 and beta 2. You can also install the APK over the existing app. Never uninstall or clear the app's storage to update. - macOS ARM64, macOS 12 or newer, ad-hoc signed, with no Developer ID or Apple notarization.
- From this version on, with update checks turned on, the app announces new versions and opens their download. It never installs anything itself.
- Beta 2 cannot announce this one. Quit Arveil and replace the app in Applications, or run
brew upgrade --cask arveil.
- Check
SHA256SUMS-clients.txt,BUILD-android.jsonandBUILD-macos.json. Theclients-beta-*.jsonfile is the signed update announcement for this build.
Changes since beta 2
- Linking another device.
- The new device keeps listening for as long as its code is valid, ten minutes by default. Before, it stopped after 90 seconds, which left too little time to carry the code by hand.
- When you come back to the app after sending the code, the wait resumes by itself.
- The code has a Copy code button.
- Link another device offers Copy server details, which the new device asks for first.
- Joining a server. If the server details and the invitation arrive in one message, paste it whole: the app finds both.
- Talking before verifying.
- You can start a conversation with someone before comparing your safety number.
- An unverified person shows Unverified · Verify under the conversation's name.
- The conversation details show the number to both people, with They match and They differ.
- Only people you confirm are marked verified; comparing is still what makes a contact verified.
- Mac update notice, described above.
- Android package. The APK carries native code only for
arm64-v8a. - Proposed, not implemented:
Relay
Use relay v0.1.0; this beta needs nothing newer.
Acceptance
- Both packages passed the signature, architecture, checksum and content-privacy audits and report clean source
9489ce6and build 21; the APK's versionCode is 21. - Every CI check passes on
9489ce6, including the Rust core, both Flutter bridge builds and the phase 0–4 acceptance runs. - The Flutter suite passes (254 tests) on the combined changes.
Not yet verified
- On physical devices: linking an Android phone to a Mac, and an update installed from the public feed.
- A freshly downloaded macOS installation (Gatekeeper) and VoiceOver on macOS.
- The Mac update notice against a newer announcement. The first one it can see is beta 4.
Keep a saved identity kit.
See the installation guide and the website. No endpoints, invitations, logs, local paths, signing material or test profiles are included.
Arveil 0.1.0 beta 2
Arveil 0.1.0 beta 2
The second public beta of Arveil, a self-hosted, end-to-end encrypted messenger for families and small circles of trust. The project has not had an independent security review.
Packages
- Client version
0.1.0+20, clean source8e3ccd4d10fab3cde437be348f13bbe8a4ca0602. - Android ARM64, Android 7.0 (API 24) or newer, signed with the maintained release certificate, SHA-256
e3ca47a1f3d8b52dc6aea63107399f63a092a412d544d651b3eff67a41d256ba. With beta 1 installed, Settings → Updates offers this version; you can also install the APK over the existing app. Never uninstall or clear the app's storage to update. - macOS ARM64, macOS 12 or newer, ad-hoc signed, with no Developer ID or Apple notarization. Quit Arveil and replace the app in Applications; macOS has no in-app updates yet.
- Check
SHA256SUMS-clients.txt,BUILD-android.jsonandBUILD-macos.json.clients-beta-4.jsonis the signed update announcement for this build.
Changes since beta 1
- People without a name. Names in Arveil are local: each person names their contacts, and the name is never sent. Someone you have not named now reads Unnamed · a1b2c3d4 in the chat list, the conversation title and Contacts, instead of eight bare characters. An open conversation with someone unnamed offers Name this person; the conversation details now name and rename people; and a new conversation asks for a name for each person as it is created.
- A name each person chooses for themselves, shared end to end with their conversations and never with the server, is proposed in ADR-011. It is not implemented.
Relay
Use relay v0.1.0; this beta needs nothing newer.
Acceptance
- Both packages passed the signature, architecture, checksum and content-privacy audits and report clean source
8e3ccd4and build 20; the APK's versionCode is 20. - Every required CI check passes on
8e3ccd4. - The signed update path was accepted on Android emulators at API 24, 28, 29 and 35 for beta 1; this release adds no updater change. See the platform record.
Not yet verified
A physical Android phone, a freshly downloaded macOS installation (Gatekeeper), VoiceOver on macOS, and an update installed from the public feed on a real device. Keep a saved identity kit.
See the installation guide and the website. No endpoints, invitations, logs, local paths, signing material or test profiles are included.
Arveil 0.1.0 beta 1
Arveil 0.1.0 beta 1 — first public beta
Arveil is a self-hosted, end-to-end encrypted messenger for families and small circles of trust. This is a beta for people who want to try it with someone they trust. The project has not had an independent security review.
Packages
- Client version
0.1.0+19, clean sourcedc03eef99ca2bdeadc4a52e9578b10a86cb6267a. - Android ARM64, Android 7.0 (API 24) or newer. Signed with the maintained release certificate, SHA-256
e3ca47a1f3d8b52dc6aea63107399f63a092a412d544d651b3eff67a41d256ba. Install it over an earlier candidate; never uninstall or clear the app's storage to update. - macOS ARM64, macOS 12 or newer. Ad-hoc signed, with no Developer ID or Apple notarization; the installation guide explains how to open it.
- Check
SHA256SUMS-clients.txt,BUILD-android.jsonandBUILD-macos.json.clients-beta-3.jsonis the signed update announcement for this build.
Signed updates on Android
Settings → Updates can check for a newer version, download it, verify it and hand it to Android's installer, which asks you to confirm. Checking is off until you turn it on, runs at most once a day in the foreground, and sends no version, identity or cookie; it never contacts your server. This build uses the beta channel, https://arveil.kaicorplabs.com/updates/clients-beta.json, signed with the Ed25519 key UpQxOMiqgKJE… recorded in BUILD-android.json. macOS updates are still manual.
Changes since alpha 3
- A redesigned app: design system and bundled fonts, Spanish and English interface, adaptive navigation with desktop shortcuts, chat list with search, conversations with grouped bubbles and delivery details, contacts and verification, and sectioned settings.
- A welcome with three ways in, a stepwise invitation and an identity-kit offer; kit reminders, device-change notices and sync status.
- Personal appearance (theme, accent, background, text size, language) and accessibility: TalkBack labels, spoken messages, reduced motion and 200 % text without overflow.
- Unread counts that survive restarts, message authors in the encrypted history, search within a conversation (⌘F on macOS) and a diagnostic report without secrets.
- Signed, opt-in updates on Android, described above.
- The profile schema is versioned, and a newer profile is refused instead of damaged.
Relay
Use the relay from v0.1.0, published alongside this beta, or build it from the same source. It reads the last X-Forwarded-For entry behind a proxy you trust and groups IPv6 addresses by /64 for its limits.
Acceptance
- Both packages passed the signature, architecture, checksum and content-privacy audits, report clean source
dc03eefand build 19, and the APK's versionCode is 19. - Every required CI check passes on
dc03eef. - Android emulators at Android 7.0, 9, 10 and 15 (API 24, 28, 29 and 35), on client code identical to this release: the whole update flow against a signed test feed updated the app through Android's confirmation and kept the encrypted profile and its key. With checks off, a network capture showed no update traffic; a check sent only the host and
Accept-Encoding; with the server down or hostile, the check behaved the same. See the platform record. - On Android 15, this exact APK installed over build 18 and opened with its update channel configured.
Not yet verified
A physical Android phone, a freshly downloaded macOS installation (Gatekeeper), VoiceOver on macOS, and update installation from the public feed. Keep a saved identity kit: without it or another linked device, losing the device loses the identity.
See the installation guide and the website. No endpoints, invitations, logs, local paths, signing material or test profiles are included.