Repository navigation
Ghost FTP 0.94.0
Ghost FTP 0.94.0 — Android cloud network and transfer safety
Source candidate only. The previously published release is 0.93.0. This document does not claim that 0.94.0 has been released, installed on a physical device, or tested against live cloud accounts. The source SHA and six passing workflows are mandatory before any merge.
Android — transport security
- Replace disconnected
InetAddress.getAllByNamepreflight +HttpsURLConnectionwith a direct-only, cancellable OkHttp client. PublicCloudDnsblocks the actual HTTP transport's DNS result when any IP is local, private, shared/CGNAT, link-local, documentation/reserved IPv4 or non-global IPv6. Mixed safe/unsafe DNS answers fail closed.- Disable network proxies, redirects (including HTTPS redirects) and automatic replay retries. Preserve the platform's standard TLS certificate chain and hostname validation; never trust-all.
- Stream 1 GiB-bounded signed PUT/GET objects and reject compressed/unexpected content encoding. Presigned links remain transient bearer secrets and never appear in logs.
Android — lifecycle and SAF recovery
- Add a Cancel cloud transfer UI action that cancels the active OkHttp
Calland interrupts the worker. - Guard against stale callbacks after Activity destruction and remove pending signed links after empty picker results.
- On failed/canceled download, attempt to delete the newly created SAF destination. If deletion fails or is not supported, tell the user the incomplete file may remain.
- Distinguish failed upload (remote state must be checked before retry) from failed download (possible incomplete local destination).
Unit tests
- Add
CloudNetworkSafetyTest.ktfor address allowlisting, IPv4 CGNAT/private/metadata ranges, IPv6 global vs local, mixed-answer rejection, provider-host restrictions, proxy/redirect/retry configuration and cancellation. - Preserve
SignedCloudLinkTest.ktfor provider-specific signature query validation.
Packaging
Android continues shipping separately labeled unsigned release APK/AAB and installable signed Preview APK. New production signing identity, actual Google Play delivery and account OAuth are not part of this release.
Boundaries and remaining acceptance
- Issue #126: macOS still needs transport-bound DNS/peer routing, and Android needs adversarial device DNS rebinding/VPN/IDNA/provider tests. The new OkHttp resolver is source-level protection, not a penetration test.
- Issue #127: Android SAF deletion is best effort; real document providers can reject deletion or commit partially. File-integrity validation and reliable failure recovery need device E2E.
- Issue #128: No Android/macOS account-level Google Drive OAuth, bucket browsing or cloud directory synchronization was added.
- A URL's signature query shape is not proof of provider authenticity. Actual cloud services validate request signature, HTTP method and signed headers.
- Validate real AWS S3/R2/GCS/Azure GET/PUT, expired or wrong signatures, cancellation during streaming, 401/403/429/5xx, DNS rebinding, SAF provider permission errors, Unicode and 1 GiB limits before production promotion.
Review provider support, threat model, cloud QA, and production readiness.
Release controls
Merge only after the six exact-SHA PR gates succeed. Verify the same gates again on the resulting main SHA, allow the official ghostftp-release.yml workflow alone to publish and verify all package hashes. Never retarget v0.93.0 or another public tag.