Skip to content

v0.8.0

Latest

Choose a tag to compare

@fr34aky fr34aky released this 27 Sep 20:14
· 22 commits to main since this release
ff3a917

Feature release: mesh names can be pulled from a node you run with fips-ui. Installs in place over any earlier release via the automatic update prompt, Check for updates, or sideload — identity, settings and app data are kept.

Changes since v0.7.0

  • Sync mesh names from a fips-ui node (Overview → Mesh names → Sync from another node, off by default). The phone joins fips-ui's own name-sync scheme as a follower: it fetches the other node's name list over the mesh and keeps it next to your own names, so every mesh app can use the same name.fips names as the rest of your nodes.
    • Setup: on the fips-ui node, enable Access → Web UI over the mesh and add this phone's npub (Overview) as a viewer; on the phone, enter that node's npub — or a name you already gave it — plus its UI port (default 8321).
    • When: hourly by default and on Sync now, only while connected; a reconnect resumes the schedule rather than fetching again. (fips-ui's own default is every 5 minutes — too many wake-ups for a phone.)
    • What it changes: your own names stay as they are; a synced name wins over one of yours with the same name (marked overridden by sync). Invalid entries are skipped, at most 2000 are taken, and the names synced last stay in effect while the other node is unreachable (retries then drop to once a day; Sync now always tries at once). Turning sync off removes the synced names.
    • The other node lists the phone among the nodes syncing from it.
    • If the phone is not on the node's viewer list, fips-ui drops its connection silently, so the error is a timeout that points at the viewer list — not a "refused".
  • Overview's mesh-names line and the Diagnostics probe also resolve synced names.

Under the hood: the app's own traffic sits outside its VPN whenever mesh apps are selected, so the fetch is made inside the embedded node by a small userspace TCP client (new dependency smoltcp, 0BSD; THIRD-PARTY-NOTICES.md lists it and its five dependencies). The embedded fips daemon is unchanged (android-hooks @ f4a811e).

Known issues

  • After the mesh reconnects itself — a mesh-app or relay change, a !FIPS hotspot joining or leaving, an IPv6 route change — the link to a peer can take ~15 s to come back even though Overview already shows Connected. Under investigation; seen since 0.5.0.
  • Peers listed in Diagnostics still show npubs, not the mesh names you gave them.

Install

Sideload the APK matching your device (adb install -r or open it on the phone); min SDK 26 (Android 8.0). Verify the download against the matching .sha256, or update from within the app.

  • universal — all three ABIs in one file. Installs anywhere; larger. Use this if unsure.
  • arm64-v8a — every 64-bit ARM phone from roughly 2016 on.
  • armeabi-v7a — old 32-bit phones. Compiles and packages; not exercised on real 32-bit hardware.
  • x86_64 — Android emulator, Chromebooks.

Release APKs are signed with the key whose certificate SHA-256 is
aa905e32bd0058874d252990abba26c78ddd8fca018195ebd1cd232a99a7a8e1 — check a
fresh download with apksigner verify --print-certs <apk>. This matters most on a
first install: there is no previously installed signature for Android to
compare against, so the checksum and this fingerprint are the only things
identifying a genuine build. Subsequent updates are enforced against the key
automatically.

Caveats

This release's arm64 APK was installed in place over 0.7.0 on a Pixel 9 Pro and works as expected (checked after publishing). The name sync was verified beforehand on the Android 14 emulator (x86_64, debug build) against a workstation running fips-ui 0.8.0: names synced as a viewer, an unlisted device got the viewer-list hint, a sync interrupted by a mesh restart retried after 30 s instead of backing off, and turning sync off removed the synced names. armeabi-v7a compiles and packages but has not been run on a 32-bit device.