v0.5.0
A new interface, live settings, and a hotspot fix. Installs in place over any earlier release via the automatic update prompt, Check for updates, or sideload — identity, settings and app data are kept.
Changes since v0.4.1
New
- Redesigned interface, with a real dark mode. A complete Material 3 theme in light and dark (navy surfaces from the app icon). The old theme only set one colour, which left dark mode with dark teal on a dark surface, and light mode with white status-bar icons on white.
- One connect button. Overview's Connect/Disconnect pair is a single toggle that shows the state it is in — Disconnected, Connecting…, Connected, Reconnecting… — with tiles for mesh size, links and role. Tapping it while it is connecting cancels.
- Mesh apps apply while connected. Changing the app selection used to need a manual disconnect and connect. The mesh now reconnects once, for a couple of seconds, when you leave the picker. The picker also gained search and a live count, and sorts your selected apps first.
- Choose your Nostr relays. Overview → Manage relays: add your own or remove any of the three defaults. Addresses are validated before they are saved (a single address the relay client rejects would take the whole rendezvous down), the last relay cannot be removed, and a change made while connected is applied with one reconnect. Overview lists the relays in use, each with its live state.
- Settings are grouped into cards, and Save changes appears only while something is unsaved.
- Copy buttons for the public key and mesh address; the selected apps' icons on Overview; notices no longer cover the bottom navigation.
Fixed
- Joining a
!FIPShotspot no longer takes the node off the mesh. Since 0.4.0 the node's main transport failed to start once the hotspot transport was up (Address already in use), leaving it on the hotspot alone and unable to reach its bootstrap peer. Both transports now come up on the shared port. The embedded fips daemon moves toandroid-hooks@ 876e62a for this. - Disconnect followed quickly by Connect could end "Disconnected" with a leftover tunnel interface, because the old session was still shutting down (about 5 s on a phone). The connect now waits its turn and then comes up.
- A settings change followed immediately by Disconnect could bring the VPN back up ~1.5 s later. It stays off.
- A second connect request arriving while one was in progress could tear down the live connection. It is ignored.
- If every selected app had been uninstalled, the tunnel captured every app on the phone. It now falls back to capturing nothing but fips2go.
- Restore and Regenerate identity are refused while a reconnect is in progress, not only while connected.
Changed
- Always-on VPN is no longer offered. It never worked — Android's always-on start was not treated as a connect, so with Block connections without VPN on, the selected apps had no connectivity until the app was opened. The app now declares the mode unsupported and Android greys both toggles out. If you had Always-on enabled for fips2go, connect from the app instead.
Known issues
- With no mesh apps selected, a connect can take ~10 s and the first link another ~15 s: the app's own DNS lookup of the bootstrap server is sent into a tunnel whose resolver is not up yet. Selecting any app avoids it. Fix planned for 0.5.1.
Install
Sideload the APK matching your device (adb install -r or open it on the phone); min SDK 26 (Android 8.0). Verify the download against the matching .sha256, or update from within the app.
- universal — all three ABIs in one file. Installs anywhere; larger. Use this if unsure.
- arm64-v8a — every 64-bit ARM phone from roughly 2016 on; the device-verified build.
- armeabi-v7a — old 32-bit phones. Compiles and packages; not exercised on real 32-bit hardware.
- x86_64 — Android emulator, Chromebooks.
Release APKs are signed with the key whose certificate SHA-256 is
aa905e32bd0058874d252990abba26c78ddd8fca018195ebd1cd232a99a7a8e1 — check a
fresh download with apksigner verify --print-certs <apk>. This matters most on a
first install: there is no previously installed signature for Android to
compare against, so the checksum and this fingerprint are the only things
identifying a genuine build. Subsequent updates are enforced against the key
automatically.
Caveats
Only arm64-v8a is exercised on real hardware. On a Pixel 9 Pro (Android 17): connect, cancel and disconnect; the live mesh-app and relay changes; Wi-Fi ↔ cellular hand-over; a 3-minute forced Doze; the quick disconnect/connect; and the !FIPS hotspot with both transports up. Emulator only: the relay editor's error messages and the Always-on opt-out. Not exercised: rotation inside the pickers and the uninstalled-app fallback. armeabi-v7a compiles and packages but has not been run on a 32-bit device; x86_64 is emulator-verified.