Skip to content

Releases: architector-dev/TORchIM-public

TORchIM v0.1.4.161 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 11 Sep 23:40
6c86ba5

TORchIM v0.1.4.161 - Alpha

IMPORTANT: BUILDS v0.1.4.36 AND OLDER ARE NOT TRANSPORT-COMPATIBLE WITH THIS RELEASE. ALL CLIENTS SHOULD BE UPDATED.

This security-focused alpha release updates the Tor components bundled with TORchIM Desktop.

Security update

  • Updated bundled C-Tor to 0.4.9.12.
  • Refreshed the bundled Windows x64 Tor Expert Bundle files.
  • Updated bundled lyrebird to 0.8.1.
  • Verified the downloaded Tor archive using the official Tor Browser Developers signing key.
  • Tor Project reports that Tor 0.4.9.12 addresses a series of high-severity security issues and strongly recommends updating as soon as possible.

Tor Project announcement:
https://forum.torproject.org/t/security-release-0-4-9-12/22096

Compatibility and testing

  • Portable Windows x64 builds were manually tested on Windows 10 and Windows 11.
  • Direct Tor and obfs4 transport configurations remain supported.
  • Signed update metadata, package integrity verification, resumable downloads, and portable replacement remain enabled.

Package

  • Windows x64 portable ZIP.
  • Bundled Java runtime.
  • Bundled Tor and lyrebird components.
  • SHA256SUMS.txt is included as a separate release asset.

This is an Alpha release intended for testing. Back up important data before testing new builds.

TORchIM v0.1.4.51 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 04 Sep 15:21

IMPORTANT: PROTOCOL COMPATIBILITY

TORCHIM v0.1.4.51 IS NOT COMPATIBLE WITH v0.1.4.36 OR EARLIER PUBLIC RELEASES. ALL PARTICIPANTS MUST UPGRADE TO v0.1.4.51 TO CONNECT TO EACH OTHER.

The incompatibility is intentional and limited to the peer transport protocol. The protocol was hardened after v0.1.4.36 with signed Ed25519 session identity binding, and v0.1.4.51 rejects legacy unsigned handshakes fail-closed.

Alpha release for testing purposes only.

Security and identity

  • Signed each ephemeral X25519 session key with the long-term TORchIM Ed25519 identity.
  • Bound handshake transcripts to both identities, onion addresses, client/server roles, and fresh nonces.
  • Reject unsigned, replayed, tampered, role-mismatched, onion-mismatched, and fingerprint-mismatched handshakes before a session becomes active.
  • Publish online presence only after successful peer authentication and enforce the authenticated fingerprint on subsequent wire messages.
  • Validate onion address, public-key, fingerprint, QR import, and Unknown-request identity consistency.
  • Preserve stable network message IDs and suppress duplicate private, Unknown, and Temporary Group deliveries.
  • Removed private identity fragments from diagnostics and clear temporary secret-key buffers after use.

Unknown contacts and local data

  • Persist Unknown requests and their messages in SQLite across restarts without popup windows.
  • Added transactional Accept, Reject, and Block handling, Settings-backed automatic Reject/Block policies, and bulk Reject/Block for larger Unknown queues.
  • Hardened contact deletion and blocking cleanup while preserving Temporary Group data only until its TTL expires.
  • Implemented configurable retention for read private messages from known contacts.
  • Fixed contacts assigned to multiple tags so they appear in every assigned section.

Tor connectivity and Settings

  • Bound Tor bootstrap state to the exact TORchIM-owned Tor process and reject stale ControlPort readiness.
  • Added safe cleanup of authenticated orphan TORchIM Tor processes and improved shutdown waiting and reconnect diagnostics.
  • Added rate-limited adaptive contact probing with startup priorities, jitter, retry backoff, and recovery after disconnects.
  • Added Direct Tor, bundled obfs4, and validated custom obfs4 modes with inline Tor Project bridge guidance.
  • Added persisted soft country exclusions for Tor relays, with clear notice that Tor may still use an excluded country when required.
  • Added a live read-only Bridge/Guard/Middle/Exit circuit view and hardened ControlPort response parsing.
  • Improved responsive Settings layouts and removed or clearly disabled misleading unfinished controls.

Updater and releases

  • Added semantic validation and positive/negative tests for signed release manifests, rollback/minimum-version policy, mirror URLs, package size, and SHA-256.
  • Added resumable package downloads through Tor using SHA-bound partial files and strictly validated HTTP Range responses.
  • Preserve partial downloads across transient failures and safely restart from zero when a mirror ignores or rejects Range.
  • Added graceful JavaFX shutdown before portable replacement: stop UI activity, hide windows, shut down core services once in the background, then exit.
  • Retained final package size and SHA-256 verification, signed metadata, verified package caching, portable backup, replacement, and automatic restart.
  • GitHub release includes the portable Windows x64 ZIP and SHA256SUMS.txt.

Testing status

  • Signed transport sessions, text delivery, status/read events, ping, queued delivery, Direct-to-obfs4 interoperability, custom obfs4, Tor lifecycle recovery, and portable updates have been exercised across multiple Windows laptops.
  • Focused automated tests cover session crypto, signed handshake rejection cases, contact lifecycle, Tor configuration/lifecycle parsing, updater release policy, and resumable HTTP downloads.
  • This remains an alpha build. Additional negative, long-offline, interrupted-download, and update-restart testing is still in progress.

TORchIM v0.1.4.36 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 31 Aug 11:18

Alpha release for testing purposes only. Validates the update release publishing helper, including SHA256SUMS.txt release assets and signed metadata publication.

TORchIM v0.1.4.35 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 31 Aug 10:16

Alpha release for testing purposes only. Restores Install from a locally re-verified cached update package and keeps only the latest portable backup after successful update installation.

TORchIM v0.1.4.34 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 30 Aug 22:19

Alpha release for testing purposes only. Adds updater recovery status in Settings and cleans old cached portable update packages after verification.

TORchIM v0.1.4.33 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 30 Aug 20:59

Alpha release for testing purposes only. Adds retry handling for portable updater backup, install, and rollback file moves when Windows temporarily locks the app directory.

TORchIM v0.1.4.32 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 30 Aug 20:08

Alpha release for testing purposes only. Includes portable updater restart fixes, safer app-folder handoff during replacement, clearer update helper logging, and reuse of already downloaded verified update packages.

TORchIM v0.1.3.25 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 29 Aug 18:14

Alpha desktop build for testing.

Highlights:

  • Contact tags/folders with nested accordion organization, unread badges, and persistent expansion state.
  • Temporary Groups for up to 5 participants with host-relayed messaging.
  • One-time and reusable invitations, Join/Cancel/Leave flow, confirmed member counts, replies, mentions, unread state, and TTL cleanup.
  • Stable group ordering and sidebar rendering fixes.
  • Tor bootstrap verification and reconnect-related diagnostics.
  • UI and localization polishing across the desktop themes.

Known alpha limitations:

  • The temporary-group host must remain online for group messages to be relayed.
  • Participant submenus show only contacts known locally; unknown confirmed members are represented by the group member count.
  • Update checks and automatic installation are not included in this build.

This Windows x64 package includes only the required Windows Tor and lyrebird bundle; unrelated Android, Linux, macOS, and x86 bundles are intentionally excluded.

Package: TORchIM-0.1.3.25-alpha-portable-win.zip
SHA-256: 102932805FEFA70EC09925660B94ED9D4F8F279651996197CD68F9C1FF01D3AC
Source commit: c5c0677

TORchIM v0.1.2.21 - Alpha

Choose a tag to compare

@architector-dev architector-dev released this 17 May 17:32
6034f07

Alpha release for testing purposes only. - After startup or reconnect, Tor and peer connections may need a few minutes to stabilize. Improve p2p stability, fix offline status, fix css in themes, updated welcome, news and help screens.