Ghost FTP 0.30.3
Released: 3 October 2026
Interaction reliability
- Android remote actions now reflect real session state instead of remaining clickable while disconnected.
- Connect is unavailable while a live session exists or a connection operation is in flight.
- Refresh, Disconnect, Upload, Download, New Folder, Rename and Delete become actionable only with the required active-session context.
- The local Android document picker remains available before connection so a file can be selected in advance without exposing invalid remote actions.
- Connection completion updates enabled state only after the session result is committed, removing stale control state during success/failure transitions.
Windows/Linux sync interaction reliability
- Sync-pair Enable/Disable, Sync now and Remove mutations are serialized per row.
- Conflicting row actions are disabled while a mutation is in flight, preventing duplicate or racing IPC requests.
- Sync rows expose an aria-busy state during mutations while keeping their read-only status/path information visible.
- Free up space keeps its independent busy guard and cannot race a simultaneous row mutation.
Click-by-click Android QA
- Instrumentation verifies idle remote actions are disabled.
- Instrumentation verifies the local Pick file control remains enabled without a session.
- Invalid connection validation verifies Refresh and Disconnect remain disabled.
- Existing workspace navigation, protocol defaults, Activity recreation privacy, preview install/reinstall and launcher smoke remain release blockers.
Dead-code hardening
- Android production CI now audits private Kotlin functions and fields and rejects declaration-only symbols.
- Existing TypeScript unused-local checks, TypeScript/Rust source reachability, compiler/Clippy checks and operational-script reachability remain mandatory.
- Android dead-code enforcement is part of the production contract, so declaration-only private code cannot accumulate silently.
Build-tool security validation
- Runtime npm dependencies remain zero-tolerance for high/critical findings.
- The unresolved upstream
bracesadvisory is accepted only for the proven development-only Tailwind 3 chain, matched by exact advisory URL and lockfiledev: truenodes. - Any unrelated high/critical npm finding remains release-blocking.
Release validation
The exact release SHA must pass:
- Ghost FTP quality
- Ghost FTP protocol E2E
- Ghost FTP native build
- Ghost FTP Android
- Validate Windows hardening
The canonical release workflow may publish v0.30.3 only from the exact verified main SHA.