Releases: caixax/opensesh
Release list
OpenSesh v1.0.0
Install
- Windows 10/11:
OpenSesh-1.0.0-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-1.0.0-windows-x64-portable.zip. With Scoop:scoop install https://github.com/caixax/opensesh/releases/download/v1.0.0/opensesh.json
- Linux (Debian 13, Ubuntu 26.04, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb(Debian 13, or theubuntu26.04one),.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
-
Sprint 18: packaging and the 1.0 release (ADR 0039, user guide).
- Every package is installed and started on a clean system before a release is public: the Release workflow builds them on GitHub's runners when a version is tagged, installs each one with its system's package manager (Debian 13, Ubuntu 26.04, Fedora, Arch; the installer and the portable zip on Windows), and checks that it starts. A dry run tries all of it without publishing.
- Ubuntu 26.04 LTS has its own
.deb(the Debian 13 one needs Debian's exact Qt), and the install script picks the right package. - Scoop:
scoop install https://github.com/caixax/opensesh/releases/latest/download/opensesh.jsoninstalls the portable app and keeps it up to date. - The AUR:
PKGBUILDs foropensesh(the release's source) andopensesh-git(this repository), built and checked by the Release workflow; each release also carries the winget manifests, ready to submit. - Code signing of the Windows executables, installer and uninstaller, as soon as a certificate is configured.
- A user guide (docs/user-guide.md) and a README with screenshots of the app.
-
Sprint 17: polish before 1.0 (ADR 0038, security review).
- High contrast (Settings, Appearance, Contrast): follows the system's preference, or on or off; text at 7:1, stronger outlines and status colors, a wider focus ring.
- Error messages in plain words, with a "Details" button for what the system or a library said, selectable and copyable.
- A welcome on first start: import hosts, add one, open a local terminal or quick connect, one click each.
- Faster start, less memory: dialogs are created the first time they open; start-up went from 889 to 720 ms and the idle window from 168 to 137 MB on the measuring machine (perf).
- Fuzzing of every parser of untrusted input (quick connect, pastes, terminal themes, the remote monitor,
~/.ssh/config, MobaXterm, PuTTY, Remmina, CSV, bundles, the sync merge), an hour per parser every week in CI. - Checks: a leak check in the smoke test;
lint-qmlasks every icon-only button for a name.
-
Sprint 16: importers, export and sync (ADR 0037, guide).
- Import hosts from MobaXterm (
.mxtsessions,.moba,MobaXterm.ini: SSH, SFTP, RDP and VNC sessions with their gateways, keys, proxies and comments), PuTTY (the Windows registry,.regexports,~/.putty/sessions: SSH, Telnet and serial), Remmina (RDP, VNC, SSH and SFTP profiles) and CSV files (columns mapped to host fields, guessed from the headers). Folders become groups; what is left out is listed, and so is any command an import would run on this computer. - OpenSesh bundles: hosts and groups, snippets, profiles and themes in one file, and optionally the keychain (identities, keys, passwords) sealed with an export password, as the vault is.
- Export to an OpenSSH config file: every SSH host, or the selected ones.
- The settings folder anywhere, such as a Git repository or a Syncthing folder (Settings, Data and sync): saving merges what changed on another computer, record by record, instead of overwriting it; Syncthing's conflict copies and Git's conflict markers are found and resolved in a dialog, per host, group or snippet; a Git helper commits, pulls and pushes when asked. The vault and the keychain stay on each computer.
- Import hosts from MobaXterm (
-
Sprint 15: remote graphical programs (ADR 0036, guide).
- X11 forwarding in the built-in SSH client (it was OpenSSH only): untrusted (the X SECURITY extension keeps remote programs from reading your other windows) or trusted, per host. The server only ever gets a cookie made up for the connection; the real one is put in here, for each connection to the display.
- The display:
DISPLAYon Linux (X11, or Xwayland under GNOME, KDE Plasma, Hyprland, Sway), and on Windows an X server such as VcXsrv, X410 or Xming onlocalhost:0.0(the guide says how to set one up; none is bundled). - Waypipe: with a host's Waypipe setting on (Linux, a Wayland desktop here,
waypipeon both sides), the session runs insidewaypipe server, and the server's Wayland programs open here (on a server without a login session, a private runtime folder stands in for the missing/run/user/<uid>). - What's missing is said in the terminal, in yellow (no display, no
xauth, a display without the SECURITY extension,waypipehere or on the server), and the session starts without it. - Tests: the cookie swap and
DISPLAYparsing; a forwarded X11 connection to a made-up display through the in-process server; in CI,xdpyinfothrough OpenSSH to Xvfb (trusted and untrusted) andwayland-infothrough Waypipe to a headless sway.
-
Sprint 14: VNC (ADR 0035).
- Saved VNC hosts and
vnc://hostquick connect (vnc://host:1is display 1, port 5901) open in the remote desktop pane of Sprint 13: the questions in the pane, the bar, full screen, scaling, jump hosts, reconnecting. - Our own RFB client (
opensesh-vnc), versions 3.3 to 3.8:- Security: none, VNC authentication, and VeNCrypt with a certificate (trusted on first use, like RDP's) and VNC authentication or a user name and password. Servers that offer only anonymous TLS get an explanation, and a session without TLS says "Not encrypted" in the pane's bar.
- Encodings: CopyRect, Tight (with JPEG), ZRLE, Hextile and Raw, the server's cursor, and the desktop's size as the server changes it.
- Input: keys as X keysyms (characters land as typed, whatever the server's layout), the mouse and the wheel; Ctrl+Alt+Del from the bar.
- The clipboard both ways (Latin-1, RFB's own).
- The pane's size asked of servers that resize (TigerVNC) when the desktop follows the pane; otherwise it is fitted.
- Host settings: scaling, picture quality (lossless, or JPEG at high, medium or low), view only (nothing typed or clicked reaches the server; a tag in the bar says so), clipboard sharing, and whether other viewers stay connected.
- Tests: the decoders, VNC authentication against OpenSSL's DES, VeNCrypt, sessions against an in-process RFB server (also the smoke test and screenshots), and TigerVNC, x11vnc and wayvnc in CI.
- Not yet: RSA-AES and anonymous TLS, the extended (UTF-8) clipboard, H.264.
- Saved VNC hosts and
-
Sprint 13: remote desktops over RDP (ADR 0034).
- Saved RDP hosts and
rdp://user@hostquick connect open a remote desktop in a tab, next to terminals: splits, workspaces and moving tabs between windows work as for them. - The engine is IronRDP, in a helper program (
opensesh-rdp) next to the app, one per desktop: NLA (CredSSP) where the server has it, TLS without it (xrdp), RemoteFX and bitmap graphics. - The server's certificate is trusted on first use, like a host key: the first one is shown with its fingerprint and subject to trust once or remember (
trusted_certificates.toml), a changed one warns. Nothing is sent before it is accepted. - Credentials: the host's identity (user, password from the vault, and a domain from the host or
DOMAIN\user), else the password is asked in the pane, and again after a refusal. - The desktop:
- follows the pane's size (asking the server for the new size once the pane stops changing), or keeps a fixed resolution scaled to fit, or pixel for pixel;
- keys go as scan codes, in the server's keyboard layout, with the mouse and the wheel; while the desktop has the keyboard, OpenSesh's shortcuts go to it too, except Ctrl+Alt+Home (a setting in Settings > Shortcuts), which gives the keyboard back;
- the text clipboard is shared both ways (a host setting, on by default);
- a bar with Ctrl+Alt+Del, full screen and a menu (scaling, reconnecting, disconnecting);
- a disconnected desktop connects again with the overlay's Reconnect.
- Through jump hosts: a local tunnel over the built-in SSH client to the last jump host, started and stopped with the pane; its questions are asked in the pane.
- The host editor has the RDP rows: domain, scaling, resolution and clipboard; jump hosts work for RDP hosts too.
- Packages ship the helper: next to
OpenSesh.exeon Windows, in/usr/lib/opensesh/on Linux.cargo xtask rdpbuilds it for development. - Tests:
- the helper against an in-process IronRDP s...
- Saved RDP hosts and
OpenSesh v0.1.4
Install
- Windows 10/11:
OpenSesh-0.1.4-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-0.1.4-windows-x64-portable.zip. - Linux (Debian 13, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb,.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
- Sprint 11: the remote monitor and host info (ADR 0031).
- The status bar shows how the server of the current terminal is doing: CPU, memory, network, the disk of
/, uptime, load and users, every 3 seconds, with the details in a tooltip. Nothing is installed on the server: a small shell loop reads what the system already has, on a separate channel of the SSH connection, and ends when the connection does. - Where it works: Linux (busybox too), FreeBSD and macOS. A server without
sh(a Windows server, a router) simply has no monitor, and says why. - The side panel's Info tab: the host's system, kernel, architecture, CPUs, uptime and load, live CPU, memory, swap and network, disks, IP addresses and logged-in users, with Refresh and "Copy as text".
- Settings > SSH: watch servers or not, the interval, and what the status bar shows; the host and group editors can turn it off for a host.
- The status bar shows how the server of the current terminal is doing: CPU, memory, network, the disk of
- Sprint 10: snippets, macros, paste protection and recordings (ADR 0030).
-
Paste protection: before a paste, OpenSesh looks at the text:
- lines that would run at once, and hidden, control or bidirectional characters;
- letters from another alphabet in Latin words;
curl … | shand decoded text run by a shell;- writes to shell profiles or
authorized_keys,sudoin a pipe, destructive commands.
When it finds something, a dialog shows the text (editable) with what was found, and a click on a finding selects its text. On by default; off in Settings > Terminal, per profile, group or host. A paste into several broadcast panes goes through the same dialog.
-
Snippets (
snippets.toml), in folders and tags, with a description and an optional shortcut:{{name}}asks for a value when the snippet runs (the last one is offered), once for every pane.{{secret:identity}}types a keychain identity's password, which never leaves the vault's side.- A snippet runs in the focused terminal, every pane of the tab or the broadcast panes.
-
Where snippets run from: the Snippets view (search, folders, tags, run, edit, duplicate, delete), the side panel's Snippets tab, the quick picker (Ctrl+Shift+Space) and each snippet's own shortcut.
-
Macros: a snippet can be steps: type text, pause, or wait for a pattern in the output (a regular expression, with a timeout). A wait that runs out stops that pane's run and says why.
-
The macro recorder (a terminal's menu) turns what is typed, with its pauses, into a macro to review and save. It warns that typed passwords were recorded too.
-
Session recordings: "Record the session" in a terminal's menu writes what it shows to
recordings/in the data folder, in asciinema's format (never the keys typed), with a chip while it records. A recording plays in its own tab: play, pause, jump, restart and speed. -
The History view: the recent connections (a click connects again), the recordings (play, open the folder, delete) and the session and app logs folders.
-
Closing with work running asks first: closing OpenSesh, or one of its windows, while terminals, tunnels or file transfers still run lists what would end, with "Don't ask again". On by default in Settings > General ("Confirm before closing with active sessions", which did nothing until now).
-
Settings > About: links to the project on GitHub, to report a problem and to the release notes.
-
Windows:
OpenSesh.exehas the app's icon (Explorer, the taskbar, shortcuts, Installed apps) and its version information (Task Manager shows "OpenSesh"); so do the installer and the uninstaller.
-
- Sprint 9: tunnels (ADR 0029).
- Local (
-L), remote (-R) and dynamic (-D, a SOCKS5 proxy) forwarding through the built-in SSH client, saved intunnels.toml. - The Tunnels view: each tunnel with a switch, its route in words, what it is doing (running, connecting, waiting for a session, retrying, failed) and its traffic (bytes each way, connections), and a menu to edit, duplicate, copy its address or delete it. A tunnel that listens beyond localhost is marked, and saving one asks first.
- Independent or tied to a host: a tunnel runs on a connection of its own (through a saved host or
user@host), can start with OpenSesh and reconnects by itself (1, 2, 4… up to every 30 s); or it runs while a terminal session to its host is connected, on that session's connection. - Questions of a tunnel's own connection (host key, password) wait in its row, with an Answer button; a tunnel that started by itself says so with a notification.
- Import from
~/.ssh/config: itsLocalForward,RemoteForwardandDynamicForwardlines become tunnels tied to their hosts. - Command palette: start and stop each tunnel. The status bar shows how many run.
- Tests:
curlthrough each kind of tunnel, in-process and against OpenSSH, and a tunnel that comes back by itself after its session is killed (how).
- Local (
Fixed
- Multi-line text in the host notes and in the private key import showed only its first line.
OpenSesh v0.1.3
Install
- Windows 10/11:
OpenSesh-0.1.3-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-0.1.3-windows-x64-portable.zip. - Linux (Debian 13, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb,.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
- Sprint 8: SFTP (ADR 0028).
- The SFTP view: two panes, each this computer, a saved host or
user@host(connecting with the same prompt cards as a terminal pane), with a transfer queue below. F5 and F6 copy or move the selection to the other side; the sides swap. - The side panel's files (Ctrl+Shift+E): the files of the focused terminal, on a new channel of an SSH pane's connection (no second login, again after a reconnection), or this computer for a local shell. "Follow the terminal" goes where the shell goes (OSC 7); for servers whose shell doesn't say, OpenSesh shows a few lines for
~/.bashrcor~/.zshrc, and adds them there only when asked. - File panes: breadcrumbs or a typed path, sortable columns (name, size, modified, permissions, owner), hidden files (Ctrl+H), multi-selection with the mouse and the keyboard, and a 10,000-entry folder that stays smooth. New folder and file, rename, delete (with confirmation), permissions (an rwx grid and octal), symbolic links, properties, a quick look at text and images (Space), copy, cut and paste, and the server's free space.
- Transfers: one queue for every window, several files at once (3 by default), with progress, speed and ETA; pause, resume, cancel, retry (after a lost connection, on the new one) and clear. Partial files continue where they stopped once their end matches. A file already there asks (replace, replace if newer, continue, skip, keep both, for one file or all) or follows the setting. Times, and optionally permissions, are kept. Copies within one server run
cp -R -pthere. - Drag and drop: files from the file manager are uploaded, files move between the panes, and this computer's files drag out to other applications.
- Editing a server's file: it opens in the editor of Settings > SFTP or the system's; each save is uploaded after checking that nobody changed the server's copy meanwhile (replace it, take theirs, or wait); when the server refuses, "Save with sudo" is offered with a warning.
- Settings > SFTP: files at once, what to do with a file already there, keeping times and permissions, hidden files, following the terminal, confirming deletes, and the editor command.
- Tests against a real server: 1 GiB both ways with the same SHA-256 on both sides, an upload cut off and resumed on a new connection, a copy within the server, and a server without SFTP (how), in CI and in WSL.
- SCP spike (
spikes/scp-fallback): copying with SCP over an exec channel for servers without SFTP; the app says "This server has no SFTP" for now.
- The SFTP view: two panes, each this computer, a saved host or
- Sprint 7: SSH (ADR 0027).
- The built-in SSH client (
russh): SSH hosts and quick connections connect with it in tabs and splits. Hosts that chooseopensshstill run the system'sssh. - Questions in the pane, each pane on its own: a card with the fingerprint of a new host key (trust once, or trust and remember), a warning that stops the connection when a known key changed, passwords, key passphrases and keyboard-interactive prompts (one-time codes). A chip shows the progress through each hop.
- Host keys: checked against
~/.ssh/known_hosts(hashed names, ports, wildcards,@revoked) and OpenSesh's ownknown_hosts, where trusted keys go. - Authentication in a per-host order: the identity's key from the vault, the key file (and its
-cert.pubcertificate), the agents (SSH_AUTH_SOCK, the Windows OpenSSH agent, Pageant), then OpenSSH's default key files; keyboard-interactive; the identity's password or one typed in the pane. A locked vault is opened only when a connection needs it ("Unlock and connect"). - Connections: jump hosts of any length (saved hosts or
user@host:port), SOCKS5 and HTTP proxies or a proxy command for the first hop, keepalive, compression, and a per-host "legacy algorithms" switch for old servers. - Sessions: the host's environment and the locale, a remote command or a startup snippet, agent forwarding (off by default, with a warning), and an optional session log (text or raw). When the connection drops, the pane says why and Enter reconnects; hosts can reconnect by themselves.
- OS detection: hosts with the automatic icon show the OS they run (from
/etc/os-release). - Install my key (host menu): picks a key from the keychain or an agent and adds it to the server's
authorized_keys. - Settings > SSH: the client, authentication order, keepalive, reconnection, language settings, OS detection and session logs for every host that doesn't set them.
- Editors: the host and group editors have every new SSH option.
- Keychain > Known hosts: the search finds hashed names typed in full, and entries of OpenSesh's file can be removed.
- Tests against real servers: OpenSSH and Dropbear, two jump hosts with an agent, a TOTP code after a key, a user certificate, agent forwarding and reconnection (how), in CI and in WSL.
- X11 forwarding spike (
spikes/x11-forwarding): works onto X.Org and Xwayland; in the app in Sprint 15.
- The built-in SSH client (
- Sprint 6: keychain and vault.
- Vault (ADR 0023, format): passwords and private keys are encrypted in
vault.bin(XChaCha20-Poly1305). Its key is held by the system keyring (Credential Manager on Windows, the Secret Service on Linux) or by an optional master password (Argon2id, 64 MiB). "Remember on this computer" opens a password-protected vault without typing it. The master password can be set, changed or removed at any time without re-entering secrets. A vault whose password is lost can be reset. - Locking: a vault with a master password locks after a chosen time without using OpenSesh (15 minutes by default) or on request, from the status bar, the command palette or Settings. After three wrong passwords each attempt waits longer (5 seconds, doubling to 5 minutes), also after a restart.
- Identities: a user name with a password and/or a key, given to hosts and groups (inherited like the other fields). With OpenSSH, a host without its own user uses its identity's.
- SSH keys (ADR 0024): generate Ed25519, ECDSA (P-256, P-384, P-521) or RSA-4096; import OpenSSH keys and PuTTY
.ppkfiles (versions 2 and 3), with their passphrase; copy the public key; export the public or the private key (optionally with a new passphrase). - Agents (ADR 0025): the keys of
SSH_AUTH_SOCK, the Windows OpenSSH agent and Pageant. - Keychain view: identities, keys, agent keys and known hosts (
~/.ssh/known_hosts, read-only until the SSH client), with search and the vault's state. Settings > Security gathers the vault's options. - Documentation: a threat model and the vault format.
- A test exercises every kind of secret and then searches the data and config folders for each one in clear (raw, hex, base64, UTF-16).
- Vault (ADR 0023, format): passwords and private keys are encrypted in
Changed
- The host and group editors have an Identity field.
- Test runs (
--smoke-test,--screenshots) keep settings changes in memory, connect only to their in-process SSH server, and remove their temporary folder at exit. - The minimum Rust version is 1.89, for
russh0.63.3 (ADR 0026). deny.tomland.cargo/audit.tomlaccept RUSTSEC-2023-0071 (thersacrate, no fixed release) with its reason: the vault uses RSA locally, and the SSH client only signs with it, once per connection (ADR 0027).- The status bar shows an SSH pane's state and host instead of "Local terminal".
OpenSesh v0.1.2
Install
- Windows 10/11:
OpenSesh-0.1.2-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-0.1.2-windows-x64-portable.zip. - Linux (Debian 13, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb,.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
- Sprint 5: hosts and sessions.
- Saved hosts (ADR 0019): hosts and nested groups in
hosts.toml, with tags, favorites, color, icon, markdown notes and group defaults (user, port, jump hosts, key file, terminal profile, SSH and SFTP options) that hosts inherit unless they set their own. Edits made outside the app apply live; a file that can't be read is never overwritten. - Hosts view: Favorites, Recent, the group tree with counts, fuzzy search on name, address, user, tags and group (under 8 ms for 1000 hosts), protocol and tag filters, four orders, cards or a list, multi-selection with the mouse and the keyboard, dragging hosts onto a group (and groups into groups), and a menu to connect, connect in a split, duplicate, edit, copy the
sshcommand, favorite, move and delete. A dot shows the hosts with an open session. - Host and group editors: Basic, Authentication, Advanced, Terminal, SFTP and Notes, checked as you type, with every inherited value shown with the group it comes from.
- Connecting: SSH hosts open in a tab or a split through the system's OpenSSH until the built-in client arrives (ADR 0022), with their group's and their own terminal profile; workspaces remember and reconnect them. Other protocols can be saved already.
- Quick connect (Ctrl+Shift+O):
user@host:port, IPv6,ssh://,sftp://,telnet://,rdp://,vnc://,-J,-p,-landserial:///dev/ttyUSB0?baud=115200, with suggestions from the saved hosts and the recent targets; the command palette lists "Connect to ". ~/.ssh/configimport (ADR 0020): hosts withHostName,User,Port,IdentityFileandProxyJump, followingInclude, either linked (read-only, following the file) or copied into a group; wildcard patterns andMatchare skipped with a note.- Command line and single instance (ADR 0021):
opensesh list,opensesh connect <host>andopensesh open <target>, shipped in the packages; starting OpenSesh again, or the CLI, hands the request to the running window; targets from outside ask before connecting.
- Saved hosts (ADR 0019): hosts and nested groups in
Changed
- Quick connect (Ctrl+Shift+O) and the Hosts view's Import button work now instead of announcing their sprint.
deny.tomlallows the 0BSD license (two small dependencies ofinterprocess).- On Windows the
openseshcommand isbin\opensesh.exein the install or portable folder.
Fixed
- The Windows packages kept the app: the command-line tool, copied as
opensesh.exenext toOpenSesh.exe, replaced it on a case-insensitive file system. - The release script no longer garbles the non-ASCII characters of
Cargo.tomlwhen it sets the version.
OpenSesh v0.1.1
Install
- Windows 10/11:
OpenSesh-0.1.1-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-0.1.1-windows-x64-portable.zip. - Linux (Debian 13, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb,.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
- Sprint 4: tabs, splits and workspaces.
- Split panes (ADR 0017): a tab holds a tree of panes of any depth, each with its own shell. Split right or down (Alt+Shift+= / Alt+Shift+-), close a pane (Ctrl+Shift+W, the tab with its last pane), move the focus (Alt+arrows) and resize (Alt+Shift+arrows) while a tab has several panes, drag the dividers (double click centers one), swap panes, make them all the same size, and maximize one (Ctrl+Shift+Z). A new pane starts with the profile, directory and zoom of the one it splits.
- Tabs: rename, eight colors that stay readable in dark and light, pin (pinned tabs come first), duplicate (Ctrl+Shift+D), close others, to the left or to the right, reopen closed tabs (Ctrl+Alt+Shift+T), drag to reorder or Ctrl+Shift+PgUp / PgDn, all from the tab's menu too. Activity and bell indicators cover every pane of a tab.
- Ctrl+Tab switches to the tab used before; holding Ctrl shows the tabs in the order they were used. Ctrl+PgUp / PgDn keep the strip's order.
- Windows: drag a tab out of the window, or use "Move to a new window", to give it its own window, and move it back from its menu or by dropping it on another window. Its shells keep running. Detached windows have the tabs and the status bar; the views open in the main window.
- Broadcast input (MultiExec, Ctrl+Shift+B): what is typed in a receiving pane goes to every receiving pane of the tab, each key encoded for the program in that pane. Receiving panes, and only those, get a red border and a chip to leave or rejoin; the tab and the status bar show it too. A paste into several panes asks once per broadcast, and scrolling can follow along.
- Workspaces (ADR 0018): save the tabs of every window, with their layouts, profiles and directories, in
workspaces/*.toml, and open, rename or delete them (the palette, or the Terminal view). "Restore sessions at startup" (Settings > General) now brings back the last session, with new shells in the same folders.
- Sprint 3: terminal customization.
- Profiles (ADR 0016): every terminal option of PLAN §6.2 lives in profiles (
profiles/*.toml) that inherit from the default one; the chain global, group, host, tab is inopensesh-core(groups and hosts use it once they exist). Each tab can switch profile from its menu, and new tabs use the profile chosen in Settings > Profiles. Every change reaches open terminals at once; files edited outside the app apply live too. - Fonts: family (monospaced fonts listed, all on request), fallback fonts, size, normal and bold weight, italics on or off, line height, letter spacing, antialiasing, hinting, and per-tab zoom (Ctrl+= / Ctrl+- / Ctrl+0). Programming ligatures are experimental and off by default (ADR 0015, with a spike in
spikes/ligatures/). - Themes: the own TOML format, a dark and a light theme per profile, 15 built-in themes (OpenSesh Dark and Light, Catppuccin Mocha, Macchiato, Frappé and Latte, Dracula, Nord, Gruvbox Dark and Light, Tokyo Night, Storm and Day, Solarized Dark and Light) with their licenses, import from iTerm2, Windows Terminal, Alacritty, Kitty and base16 files, export to OpenSesh and Alacritty, and a visual editor.
- More options: bold as bright, a minimum contrast, cursor and selection colors, cursor shape and blinking, hollow cursor without focus, padding, background opacity (the window gets an alpha channel when a profile uses it) and a background image with dimming and fit, scrollback, scroll speed and smooth scrolling, word separators, copy on select, right click pastes or opens the menu, the Linux primary selection, opt-in OSC 52 copying, the bell (flash, sound, notification or none),
TERM, Backspace and Delete, Alt as Meta, legacy encodings throughencoding_rs, an answerback and a pause between pasted lines. - Keyword highlighting (PLAN §6.5): regex rules with colors from the theme, bold and underline, in rule sets that profiles turn on (logs, network addresses, status words, paths and URLs built in, and your own in
highlights.toml), applied as rows are drawn and switchable per tab. - Settings pages: Terminal (every option, inherited values marked and resettable, a live preview drawn by the real terminal), Profiles, Themes and Shortcuts (capture, conflicts, keys terminal programs need, restore defaults; changes in
keybindings.toml). - Tooling:
cargo xtask noticesregeneratesTHIRD_PARTY_NOTICES.md(now with the themes) without the network; the Debian package needsqml6-module-qtquick-dialogsfor the file dialogs.
- Profiles (ADR 0016): every terminal option of PLAN §6.2 lives in profiles (
Changed
- Ctrl+Shift+W closes the focused pane (PLAN §6.4); "Close tab" has no default shortcut. Ctrl+Tab and Ctrl+Shift+Tab follow the order tabs were used in.
- The tab strip scrolls with the wheel instead of flicking, so tabs can be dragged.
- Screenshot runs add split terminal tabs with and without broadcast.
- Smoke tests and screenshot runs never write profiles, themes, rules or shortcuts.
- README: how to install OpenSesh (the Linux install script and its options, the Windows installer and portable zip), how updates work, how to check a download and how releases are made.
Fixed
- The release script now keeps the blank line under a new version's heading in the changelog.
OpenSesh v0.1.0
Install
- Windows 10/11:
OpenSesh-0.1.0-windows-x64-setup.exe(per-user install, no administrator rights, updates itself), or the portableOpenSesh-0.1.0-windows-x64-portable.zip. - Linux (Debian 13, Fedora, Arch):
or install the
curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash.deb,.rpmor.pkg.tar.zstbelow with your package manager.
Check the downloads against SHA256SUMS.txt.
Changes
Added
- Releases and updates:
- Windows: a portable zip and a per-user NSIS installer (no administrator rights) with Qt, the MSVC runtime and the bundled ConPTY (
cargo xtask dist windows). - Linux: a
.debfor Debian 13, an.rpmfor Fedora and a pacman package for Arch, built against each distribution's Qt (scripts/linux/build.sh), andinstall.sh(curl ... | bash), which picks the right package, verifies it and installs it with the package manager. scripts/release.batcuts a release from a Windows machine with the WSL distros in minutes; a manual GitHub Actions workflow is the fallback.- Update checks (off by default, PLAN §6.1): at startup and daily when enabled, or with "Check now". The installed Windows app downloads the new installer, verifies it against
SHA256SUMS.txtand restarts updated; portable copies and Linux packages link to the download.
- Windows: a portable zip and a per-user NSIS installer (no administrator rights) with Qt, the MSVC runtime and the bundled ConPTY (
- Sprint 2: terminal engine and local terminal.
- Engine (
opensesh-term, ADR 0012):alacritty_terminalbehind aTerminalBackendtrait; a local PTY backend (your shell; PowerShell or cmd on Windows through ConPTY); one engine thread per session that parses in bounded chunks, answers terminal queries at once and sends damage-aware snapshots; OSC 7, X10 mouse, OSC 8 links, regex search; hostile output bounded (OSC strings, combining marks, synchronized updates). - Input: xterm key encoding (Alt, F1-F24, keypad and cursor modes, Windows AltGr and Alt codes), mouse reporting (X10, normal, button, any; SGR), bracketed paste with filtering, focus reports, URL detection.
- Renderer (ADR 0013): a scene-graph
QQuickItemwith a glyph atlas and custom shaders; truecolor, every underline style, wide and combining characters, emoji, box drawing and Powerline, all cursor shapes; only damaged rows are rebuilt, and new glyphs are rasterized within a per-frame budget. - Local terminal tabs: selection (character, word, line, block), copy and paste (Ctrl+Shift+C/V, Shift+Insert, context menu, primary selection on Linux), scrollback with a thin scrollbar, regex search (Ctrl+Shift+F), Ctrl+click links, titles from OSC 0/2, activity and bell indicators, the working directory in the status bar, an exit banner with Restart.
- Windows: the modern ConPTY bundled by
cargo xtask conpty(ADR 0014), AltGr through Qt'swindows:altgroption, a hardened DLL search order. - Quality: real-PTY tests, tmux/htop/less/nvim/mc/fzf tests, vttest goldens (vttest.md), performance against PLAN §9 (perf.md), IME notes (ime.md); the smoke test runs a real shell.
- Project: published at github.com/caixax/opensesh with CI on every push.
- Engine (
- Sprint 1: design system and app skeleton.
- Theme (
opensesh-core::theme,ThemeQML singleton):- Dark and light palettes from PLAN §5.2, following the system color scheme live.
- Every text token is checked against WCAG AA in tests, for both schemes and 216 sample accents.
- Text on accent and status fills is computed for contrast (
accentText,Theme.textOn()), so any user accent stays readable; low-contrast accents raise a warning. - Comfortable and compact density, UI scale (80-150 %), UI font and reduce motion (all durations become 0).
- Settings (
config.toml):- A lenient per-field reader: an invalid value costs only that setting and produces a warning naming the key. Unknown keys and sections survive a save.
schema_versionwith a migrations hook. A file from a newer OpenSesh, or one with a syntax error, is never overwritten.- Atomic writes (temporary file, fsync, rename) with 5 rotated backups, on a background writer with a 300 ms debounce.
- Hot reload with
notify, which tells the app's own writes from external edits by sequence number. - On Windows, read-only backups can't block a save, and a symlinked
config.tomlstays a link. - Problems (a broken or newer file, a failed save) reach the UI as translated toasts, also at startup.
- Window geometry, side panel and last view in a separate
state.toml.
- Settings > General and Appearance: every PLAN §6.1 option for them, applied live, with a preview card, language selector, restore defaults and the settings file location. The other sections show what sprint they arrive in.
- Component library: 42
Os*QML files built on Qt Quick Templates, using onlyThemetokens, with keyboard focus rings and accessible names and roles (ADR 0008, contract). - Gallery (
--gallery): tokens with live contrast figures, typography and spacing, every icon, and every component in its states, with live dark/light, density, accent and reduce-motion switches that never write the user's settings. - Shell:
- Custom title bar with tabs, and window decoration modes
auto,custom,nativeandnone.autodrops the window buttons on tiling compositors (Hyprland, Sway, niri, i3) (ADR 0010). - Frameless move and resize through
startSystemMove()/startSystemResize(). On Windows the frameless window keeps Win+arrows, taskbar minimize and the system menu. - Navigation rail (left, right or hidden, optional labels), placeholder views with empty states, collapsible side panel (left or right), status bar.
- Window size, position and maximized state are restored, fitted to the screen, skipping positions that no longer fit any screen.
- Switching views or tabs never leaves the keyboard focus on a hidden control, and popups give the focus back when they close.
- Custom title bar with tabs, and window decoration modes
- Command palette and shortcuts: a central action registry drives the palette (Ctrl+Shift+P, fuzzy search, recent actions first) and the PLAN §6.4 default shortcuts, with conflict detection. Apart from F6 / Shift+F6, which move the focus between the window regions, no shortcut takes a combination terminal programs need. From Sprint 2 the terminal passes function keys to its programs, and Ctrl+F6 / Ctrl+Shift+F6 always move the focus (ADR 0011).
- Notifications: in-app toasts plus a notification history in the status bar.
- Icons and fonts:
- Icons are rendered by a
QQuickImageProvider(image://icon/<name>?color=&size=) from the pinned SVGs, recolored and cached. - Operating system logos come from pinned Tabler and Simple Icons packages.
- Inter and JetBrains Mono are bundled from their pinned, sha256-verified releases (
cargo xtask fonts) and set as the UI and monospace fonts.
- Icons are rendered by a
- i18n (ADR 0009):
cargo xtask i18nruns lupdate and lrelease and generates a pseudo-locale (debug builds only). Changing the language retranslates the running UI. English is the only real language for now. - Crash dialog rebuilt with the component library.
- Quality:
- The smoke tests of the main window and the gallery visit every view and overlay, and fail on any QML warning (exit code 6).
--screenshots <dir>captures the main window, the gallery and the crash dialog in dark/light × comfortable/compact, and fails on a QML warning (exit code 6) or a failed capture (exit code 7).- CI runs the gallery smoke tests, uploads the screenshots and checks that translations are up to date.
- Docs: ADRs 0006-0011, the component contract, developer setup and the manual test matrix.
- Theme (
- Sprint 0: foundations.
- Workspace:
- Cargo workspace (edition 2024) with the toolchain pinned to the MSRV (Rust 1.88.0).
- Every dependency pinned in
[workspace.dependencies]and locked byCargo.lock. - Workspace lints deny
unwrap/expectoutside tests.
opensesh-core:- The application identity (
cc.caixa.OpenSesh). - Data directory resolution: XDG on Linux,
%APPDATA%/%LOCALAPPDATA%on Windows, and portable mode through aportablemarker file. - Private (
0700) directories on Unix.
- The application identity (
opensesh-app(Qt 6 / QML bootstrap window, built with cxx-qt 0.10):- A Rust
SesameDoorobject driven from a QML button, and anAppInfosingleton that exposes startup data to QML. - Sets the Wayland
app_idand the window icon. - Forwards Qt/QML log messages to
tracing. - Placeholder Qt Quick Controls style (Fusion).
- A Rust
- Smoke tests:
--smoke-testfor headless CI. It checks that a frame renders, that the QML/Rust bridge works, and that non-ASCII text survives the build.--crash-report <file> --smoke-testchecks the crash dialog.
- Logging: to stderr and to a daily-rotated file, 14 days kept. The filter comes from
OPENSESH_LOG, and an invalid value falls back to the default. - Crash reporting:
- Panics write a synchronous crash report and open a QML crash dialog in a separate process. Only the first panic of a process opens the dialog, and later panics (such as cxx's FFI unwind guard) are appended to the first report.
- Qt fatal errors are written as crash reports before Qt aborts.
- Debug builds:
OPENSESH_DEBUG_PANICmakes the Knock button panic, to test the whole path.
- Windows release builds: attach to the parent console f...
- Workspace: