v0.5.1
Bug-fix release: connecting with no mesh apps selected no longer stalls. Installs in place over any earlier release via the automatic update prompt, Check for updates, or sideload — identity, settings and app data are kept.
Changes since v0.5.0
- No more ~10-second connect when no app is selected. With nothing selected the tunnel has to allow something (an empty allow-list would capture the whole phone), so it allows fips2go itself. It used to claim the default route and the in-tunnel DNS server as well — which sent the app's own DNS lookup of the bootstrap server into a tunnel whose resolver is not running yet while the node starts. The lookup sat in a ~10 s timeout, the first handshake failed, and the retry came ~15 s later: up to 25 s to a first link, on exactly the zero-config first run where nobody has picked an app yet. That tunnel now claims only the mesh prefix (
fd00::/8); the app's own traffic never enters it. On a Pixel 9 Pro the node start went from ~10 s to 0.3 s, with the first peer linked 0.03 s later. Selecting an app still rebuilds the tunnel with the full routes, as before.
No change to the embedded fips daemon (still android-hooks @ 876e62a) or to any screen. Repository-side: a CI action pin was updated (Dependabot) and its version comment corrected.
Known issues
- After the mesh reconnects itself — a mesh-app or relay change, a
!FIPShotspot joining or leaving, an IPv6 route change — the link to a peer can take ~15 s to come back even though Overview already shows Connected. Under investigation; seen in 0.5.0 too.
Install
Sideload the APK matching your device (adb install -r or open it on the phone); min SDK 26 (Android 8.0). Verify the download against the matching .sha256, or update from within the app.
- universal — all three ABIs in one file. Installs anywhere; larger. Use this if unsure.
- arm64-v8a — every 64-bit ARM phone from roughly 2016 on; the device-verified build.
- armeabi-v7a — old 32-bit phones. Compiles and packages; not exercised on real 32-bit hardware.
- x86_64 — Android emulator, Chromebooks.
Release APKs are signed with the key whose certificate SHA-256 is
aa905e32bd0058874d252990abba26c78ddd8fca018195ebd1cd232a99a7a8e1 — check a
fresh download with apksigner verify --print-certs <apk>. This matters most on a
first install: there is no previously installed signature for Android to
compare against, so the checksum and this fingerprint are the only things
identifying a genuine build. Subsequent updates are enforced against the key
automatically.
Caveats
Only arm64-v8a is exercised on real hardware. This release's change was verified on a Pixel 9 Pro (Android 17) — a cold connect with no apps selected, then reselecting three apps while connected, which rebuilt the tunnel with the default route and the in-tunnel DNS — and on the Android 14 emulator. armeabi-v7a compiles and packages but has not been run on a 32-bit device; x86_64 is emulator-verified.