Repository navigation
Releases: jyb114/pocket-bridge
Release list
Pocket Bridge 1.0.0-preview.15 (Windows preview)
Release notes - 1.0.0-preview.15
Optional primary and backup tunnels
An explicit desktop-console opt-in can maintain two independent Cloudflare
Quick Tunnel processes for the same Windows gateway. The feature is off by
default. Each slot has separate ownership, health and repair state; a fresh
public probe must identify the current gateway boot before its address is
offered. Repair is bounded and leaves the sibling slot alone. Unknown process
ownership or uncertain termination blocks replacement.
On a full phone-page reload, a reminder can offer to copy the latest verified
alternate address. First visits use an optional Settings entry and do not
automatically open the reminder. Conversation changes, reconnections and
returning to a background tab do not trigger that modal. Copy
requires a tap, and there is no automatic failover navigation or message resend.
The copied address contains no access key, encryption fragment or recovery
token. A different hostname has separate browser cookies and encryption-key
storage. The explicit Prepare backup action asks for confirmation, opens a
new window, and verifies an origin-bound one-use ticket/receiver receipt before
transferring the encryption key through a document-owned MessagePort. The
receiving origin must complete its own authenticated encrypted check and browser
storage readback before it reports success. No credential enters a navigation
URL or copied address. A blocked popup, old pinned component, changed key or
stale backup fails closed with guidance; there is no automatic transfer.
A replaced hostname needs preparation again. Both paths still share the PC, internet connection, gateway
and Cloudflare; they cannot cover failure of those shared dependencies.
Older single-tunnel sessions are not adopted without ownership proof. Enabling
the managed pair may require one desktop Stop/Start cycle. Named/fixed tunnels,
private-only connections and other operating systems do not automatically gain
a backup. See the dual-tunnel guide for configuration,
disable/refresh behavior and verification limits.
Safer diagnostic exports
Diagnostic device summaries now contain only a fixed device/browser
classification, timestamps and state flags. Stored device labels are omitted:
unknown-device labels can contain a source IP address, and custom labels may
contain other private information. Local labels, device records and pairing
behavior are unchanged.
The exporter still applies redaction rules and checks collected local
credentials before writing a bundle. This is not a guarantee that every private
detail or message body has been removed from status or log text. The bundle and
desktop success message now explain this limit and ask for manual review before
sharing. SECURITY.md describes minimal public bug reports and asks
for synthetic examples when a redaction rule misses private content. Do not post
an unreviewed bundle, raw logs or complete connection links.
Clearer DSH discovery failures
Runtime status distinguishes a successful scan with no recognized DSH process
from a timed-out or failed process inventory. The existing target views show
fixed timeout/error guidance in Chinese, English and Spanish, including a
console language change while the status is cached. Failure explanations use fixed
wording, and the inventory summary exposes only a bounded status and the
eight-second command timeout; it does not copy OS error messages, command lines
or raw process output.
The production deadline remains eight seconds per inventory command. A failed
or incomplete scan does not establish runtime identity or authorize access to an
unverified listener. Successful refreshes clear obsolete failure status. These
diagnostic changes do not start, stop or reconfigure DSH.
Installation and requirements
The source package and planned Windows installer, source archive and plugin
tarball share version 1.0.0-preview.15. Use only assets actually published on
Releases; a source version is
not evidence that release binaries are available. The plugin tarball for this
version is named pocket-bridge-1.0.0-preview.15.tgz. Follow the
plugin guide for the correct host profile and installation
procedure.
The gateway requires a genuine Node.js 24+ runtime. Public internet tunnels
also require cloudflared; private HTTPS does not. The Windows installer
supplies those runtimes, while the plugin tarball does not. DSH and model
credentials remain separate. Managed configuration, keys, paired devices and
uploads remain outside the replaceable plugin package. Earlier releases remain
available.
Verification boundaries
Dual-tunnel regressions use synthetic children, process queries, clocks and
public-probe responses. Mobile reminders, clipboard handling, stale results,
visibility and credential-context changes use controlled browser/DOM fixtures.
Preparation admission, recipient receipts, MessagePort document ownership and
storage rollback have synthetic unit/DOM coverage. These do not establish a
working public backup or preparation on a real phone.
The new offline regression runs the actual exporter with synthetic credentials,
device records and logs in an owned temporary directory. It covers public and
private IPv4, compressed and mapped IPv6, arbitrary labels, stdout and file
output, useful summary preservation and residual private-key-block refusal.
Runtime regressions cover empty, failed, timed-out and recovered inventory
outcomes, closed diagnostic fields and retained identity checks. Source-renderer
fixtures verify the visible guidance, recovery and cached language changes;
they are not physical-phone or pixel-level browser acceptance. No real user's
logs or device records are needed for these tests.
The cookie regression injects synthetic egress data before the gateway imports
its routing module and refuses unexpected fetches or non-loopback TCP. This
test does not need to query a public-IP service.
Publication still requires independent Windows CI for the exact commit,
verified plugin packaging and the existing compiled-installer smoke checks.
Linux-only results do not establish those Windows gates. Physical-phone,
cellular/public-tunnel and model-provider acceptance remain separate; earlier
evidence belongs to the exact revisions recorded in the
plugin acceptance record and
compatibility matrix.
No telemetry or third-party npm runtime dependency is added. Local
control authentication and encrypted phone-content boundaries are unchanged.
This remains an unofficial, DSH-only preview.
Pocket Bridge 1.0.0-preview.14 (Windows preview)
Release notes - 1.0.0-preview.14
Safer startup and clearer recovery
The optional DSH plugin now explains missing or outdated Node.js 24+ and
shows actionable startup recovery without assuming that a Windows shortcut exists.
Diagnostics remain read-only: an unprobed dependency is unknown, and a previous
failed start is identified as historical evidence rather than a new probe.
An explicit tunnelProvider: "none" no longer falls through to automatic
Cloudflare startup. Disabled policy skips public-tunnel discovery, reachability
probes and rebuilding; unsupported providers fail closed. Public work is cancelled
if the selected policy changes across asynchronous waits. The documented
cloudflare alias and supported dynamic/fixed modes remain available.
Important: disabling tunnel startup does not terminate an existing tunnel,
revoke old access, or disable LAN listeners. Gateway Stop pauses the gateway only;
an old tunnel can reconnect after restart. Verify and stop an existing tunnel
separately before relying on local-only operation. For isolated loopback-only
checks, also disable enableLanAccess and lanHttps.enabled.
Easier local operation
- The desktop console labels disabled public startup accurately, hides disabled
LAN HTTP entries, and shows configured private HTTPS separately. - Console Chinese, English and Spanish switching updates navigation, headings
and controls without a reload or an additional service request. Connection-card
headings no longer collapse into one-character columns beside status badges. - The plugin panel follows the host page/browser language and offers a panel-only
override. Known recovery and diagnostic messages use the same language. The
override lasts for the mounted panel and does not change DSH or browser settings. - Plugin controls wrap within the space the DSH host provides. Primary actions
precede detail fields, with complete prerequisites and lifecycle notes available
in an expandable section. DSH's own navigation is unchanged. - Lite startup and emergency update guidance remains available in Chinese,
English and Spanish when the main language scripts cannot load. Update identity,
capability, fingerprint verification, failure and retry rules are unchanged.
Installation and requirements
Install pocket-bridge-1.0.0-preview.14.tgz through the supported DSH plugin
manager. For an npm DSH Web profile:
dsh plugin --profile web add https://github.com/jyb114/pocket-bridge/releases/download/v1.0.0-preview.14/pocket-bridge-1.0.0-preview.14.tgz
A Web profile is separate from a desktop application's profile. Follow the host's
normal restart instructions when existing tasks permit. The plugin requires a
genuine Node.js 24+ runtime. Public internet tunnels also need cloudflared;
private HTTPS does not. The Windows installer supplies those two runtimes, while
the plugin tarball does not. DSH and any model credentials remain separate.
Managed gateway configuration, keys, devices and uploads remain outside the
replaceable plugin package. Removing the plugin does not stop a running gateway
or remove retained data. Hiding a connection or stopping the gateway does not
revoke paired devices or copied links.
Verification boundaries
Isolated regressions cover startup recovery, local control and stale-result
guards, disabled tunnel policies, connection-state presentation, live language
events, missing localization modules and failed verified-update transactions.
Publication requires exact-commit Windows CI, package verification and the
existing compiled-installer smoke checks. Passing those gates is not a substitute
for physical-phone, cellular/public-tunnel or model-provider acceptance.
The local browser checks use official npm DSH Web 0.2.0-rc.2 in an isolated
Linux/Chromium environment, without model credentials, model calls or public
exposure. Controlled failure fixtures are identified separately from actual DSH
operation. Earlier Windows/native-host and model-operation evidence belongs to
its recorded revision in the plugin acceptance record
and compatibility matrix; it is not a new universal
compatibility claim for this preview.
Privacy and distribution
Local control authentication, loopback restrictions and encrypted phone-content
routes are unchanged. Tunnel providers still see metadata and serve the initial
page; an actively replaced page remains a separate trust boundary. No telemetry,
external translation/QR service, remote font or additional runtime dependency is
introduced. See SECURITY.md.
The Windows installer, source archive and verified plugin tarball use the same
preview version. Packages exclude private configuration, authentication material,
logs, uploads, private QA harnesses and recovery files. Earlier releases remain
available. This remains an unofficial, DSH-only preview.
Pocket Bridge 1.0.0-preview.13 (Windows preview)
Release notes - 1.0.0-preview.13
Optional DSH plugin
Pocket Bridge now has an installable DSH plugin. Open Settings → Pocket Bridge
to start or pause phone access, reveal a private connection and locally generated
QR code, open the computer's controls, and diagnose the selected gateway.
The plugin reuses the existing lightweight phone interface and encrypted content
transport. It does not load the original desktop interface over the tunnel.
Download pocket-bridge-1.0.0-preview.13.tgz from this release and install it
through the desktop plugin manager. For the tested npm Web profiles:
dsh plugin --profile web add https://github.com/jyb114/pocket-bridge/releases/download/v1.0.0-preview.13/pocket-bridge-1.0.0-preview.13.tgz
Use the host's normal reload or restart instructions. Installing into a Web
profile does not install into the desktop application's separate profile.
Do not close a running DSH task merely to reload a plugin.
Connection and lifecycle
- Manage only an identified Pocket Bridge installation. Foreign listeners and
a gateway serving another DSH instance are rejected rather than adopted. - Pin a plugin-started gateway to its DSH host. Pausing phone access stops the
bridge; it does not terminate DSH or its tasks. - Keep managed gateway configuration, connection keys and uploads under DSH_HOME,
outside the replaceable plugin package. Verify public source hashes before an
installation or upgrade, and retain private state when removing the plugin. - Keep connection secrets hidden until requested, then hide them after two
minutes, loss of authorization, or connection changes. Hiding a displayed
connection does not revoke it; rotate the connection through local controls
when revocation is needed. - Clear old diagnostics when gateway identity, target or connection state changes.
Show the check time and require another check for the current state.
Requirements and tested hosts
The plugin requires genuine Node.js 24+. Temporary internet tunnels also
require cloudflared. The Windows installer supplies both; the source plugin
tarball does not bundle their binaries or run install hooks. DSH and model
credentials remain separate requirements.
Actual plugin operations covered native Windows DSH 0.1.7-rc.2,
npm DSH Web 0.1.7-rc.2, and npm DSH Web 0.2.0-rc.2 in isolated profiles.
Real encrypted HTTPS sessions returned model replies. The newer npm host also
completed an actual workspace-file download and an upload read by the model.
Native plugin removal and reinstallation retained configuration and both keys.
Read the plugin acceptance record for the exact
operations, lifecycle results and limitations.
These tests used a desktop browser with a 390 x 844 phone viewport. They do not
certify physical iPhone/Android, cellular networks, every plugin, arbitrary old
versions or future releases. Historical standalone gateway tests are recorded
separately in the compatibility matrix.
Privacy and distribution
Plugin control routes require DSH authentication and direct loopback admission.
Origin-less native requests additionally use an in-memory host control token.
Conflicting Origins and relay headers remain rejected. No central telemetry,
external QR service, remote fonts or private notification helper is added.
Protected message and file routes use application-layer encryption. Tunnel
providers still see metadata and serve the initial page; an actively replaced
page is a separate trust boundary. This is not a claim that every byte is
end-to-end encrypted. See SECURITY.md.
This release includes the Windows installer, source archive, verified plugin
tarball, package verification record and SHA256SUMS. Public packages exclude
personal reminders, connection links, credentials, configuration, logs and
uploads. New installers remain DSH-only; earlier combined Codex/Dot releases
remain available. Independent CI for the exact published commit remains required
before packaging and again before release publication.
Pocket Bridge 1.0.0-preview.12 (Windows preview)
Release notes - 1.0.0-preview.12
Loading and runtime performance
- Reuse compressed representations of fixed public page assets in a bounded memory cache. Every request still reads and hashes the actual source and verifies stable file identity. Changed, missing or unreadable source cannot produce a stale cached success. Compression settings, exact decoded bytes, representation validators and page security headers are preserved. The cache holds at most 64 entries and 8 MiB; source files over 2 MiB bypass it and remain available. First-miss compression is unchanged.
- Share only concurrent modern-session projection reads, so the foreground queue, goal and model refresh can use one encrypted request instead of three. Settled results are not cached. Join eligibility expires after one second, and mutations, reconnects and key changes fence earlier reads. Writes are still dispatched individually and are not automatically retried by this optimization.
- Reconcile project and conversation buttons in place instead of rebuilding every row for repeated catalog snapshots. Unchanged refreshes preserve keyboard focus; names, paths, ordering, selection, search and language changes still update the visible interface.
These changes preserve the existing DSH feature surface, explicit image loading, protected transport and compatibility limits. They do not certify new DSH versions, physical phones or every desktop plugin. Network and model response times remain separate from local page processing.
Pocket Bridge continues as a lightweight, unofficial mobile interface for DeepSeek Harness on your own Windows computer. New installers are DSH-only. Previous combined Codex/Dot releases and installers remain available; this release does not delete target applications or historical conversations.
Privacy improvements
- Persist replay receipts for protected inbound mobile HTTP and WebSocket content and one-shot device proofs before dispatch. An already consumed packet stays refused after a gateway restart. Invalid authentication does not consume a receipt. Corruption, storage failure, conflicting ownership or capacity exhaustion refuses the request rather than clearing protection.
- Reject malformed, fragmented, oversized and unsupported WebSocket frames before forwarding. Retain legitimate control frames and bounded encrypted content.
- Apply a restrictive same-origin policy to the bridge-owned phone page, with no third-party scripts or fonts, no referrer and no framing. This reduces unintended loading; it does not authenticate a page that an active serving provider has replaced.
- Require an exact screenshot request schema. An encrypted ordinary RPC body cannot be redirected to this route to trigger the tested unintended screen capture.
- Add an optional private Tailscale HTTPS entrance, disabled by default. It checks the configured local Serve mapping and keeps Bridge authentication, device proof and encryption. It does not install Tailscale, log in, change network settings or enable Funnel. See setup and limits.
Passive tunnel relays receive ciphertext for protected content, but still see metadata. The initial web application remains a separate trust boundary. Encryption is not forward-secret and does not bind HTTP method/path, device cookie or packet order. This is not an exactly-once execution guarantee. Model providers receive the instructions DSH submits to them, and local files/drafts have separate storage boundaries. See SECURITY.md.
Compatibility and usability
- Show the observed distribution, exact runtime version and adapter in Settings → Connection and compatibility. Separate implemented interfaces from workflows accepted by real operation. Unknown future versions remain unverified.
- Make unsupported legacy permission, plan, goal, queue and generic-file interfaces explicit. Keep available model and tool controls usable instead of disabling the whole conversation.
- Implement legacy model and blank-session tool-preset selection through the old runtime's actual methods, with independent readback before claiming success. Selection writes trigger fresh runtime verification.
- Repair legacy history refresh markers: record a revision only after its matching history has been read successfully. A failed initial read or periodic read can therefore be fetched again even when the upstream revision is unchanged.
- Preserve history and drafts during a specifically recognized temporary legacy background-read failure. Continue read retries, show a scoped warning, and clear only that warning after recovery. Authorization, protocol and operation errors remain visible. Messages and other writes are never automatically resent.
The existing compact phone layout, explicit image loading, local artwork, 44-pixel primary touch targets and Chinese/English/Spanish interface remain. Public product documentation and release notes are in English. Private notification scripts, access links, credentials and user files are excluded from published source and installers.
Actual operation and limits
The current desktop baseline is DSH 0.1.7-rc.2. Four real published npm packages were also run locally in separate D-drive homes: 0.1.0-rc.8, 0.1.1-rc.2, 0.1.7-rc.2 and 0.2.0-rc.2. Project/session, file, model, preset and image flows have different acceptance scopes. Modern npm sessions returned real replies and completed actual question/answer and approval allow/reject operations. Old npm project/session, file preview, staged image and model/preset readback were operated; successful model replies and model-triggered interactions remain blocked by unavailable valid legacy credentials.
Prepared historical dependency graphs are not certification of today's default fresh npx installation. A fresh unmodified old npm installation timed out before startup; that result does not establish either success or a dependency-resolution defect. The lost laptop's desktop executable, arbitrary plugins, future releases, physical iPhone/Android and cellular workflows remain unverified. Current in-app-browser Save operations did not confirm a completed download. Historical successful downloads and controlled byte-exact fixtures are recorded separately.
Publication is gated on independent CI for the exact commit, compiled installer acceptance and source/payload/privacy checks. These are separate from actual runtime operation and device acceptance. See the compatibility matrix and acceptance record.
Pocket Bridge 1.0.0-preview.11 (Windows preview)
Release notes - 1.0.0-preview.11
List row layout fix
This patch prevents project and conversation rows from shrinking inside scrollable lists, so long titles and their secondary text no longer overlap the next row. It changes only this layout rule. Preview.10 functionality, compatibility scope and security limits remain unchanged; the existing release information follows.
Pocket Bridge continues as a lightweight, unofficial mobile interface for DeepSeek Harness on your own Windows computer. New installers are DSH-only. Previous combined Codex/Dot releases and installers remain available; this release does not delete target applications or historical conversations.
Privacy improvements
- Persist replay receipts for protected inbound mobile HTTP and WebSocket content and one-shot device proofs before dispatch. An already consumed packet stays refused after a gateway restart. Invalid authentication does not consume a receipt. Corruption, storage failure, conflicting ownership or capacity exhaustion refuses the request rather than clearing protection.
- Reject malformed, fragmented, oversized and unsupported WebSocket frames before forwarding. Retain legitimate control frames and bounded encrypted content.
- Apply a restrictive same-origin policy to the bridge-owned phone page, with no third-party scripts or fonts, no referrer and no framing. This reduces unintended loading; it does not authenticate a page that an active serving provider has replaced.
- Require an exact screenshot request schema. An encrypted ordinary RPC body cannot be redirected to this route to trigger the tested unintended screen capture.
- Add an optional private Tailscale HTTPS entrance, disabled by default. It checks the configured local Serve mapping and keeps Bridge authentication, device proof and encryption. It does not install Tailscale, log in, change network settings or enable Funnel. See setup and limits.
Passive tunnel relays receive ciphertext for protected content, but still see metadata. The initial web application remains a separate trust boundary. Encryption is not forward-secret and does not bind HTTP method/path, device cookie or packet order. This is not an exactly-once execution guarantee. Model providers receive the instructions DSH submits to them, and local files/drafts have separate storage boundaries. See SECURITY.md.
Compatibility and usability
- Show the observed distribution, exact runtime version and adapter in Settings → Connection and compatibility. Separate implemented interfaces from workflows accepted by real operation. Unknown future versions remain unverified.
- Make unsupported legacy permission, plan, goal, queue and generic-file interfaces explicit. Keep available model and tool controls usable instead of disabling the whole conversation.
- Implement legacy model and blank-session tool-preset selection through the old runtime's actual methods, with independent readback before claiming success. Selection writes trigger fresh runtime verification.
- Repair legacy history refresh markers: record a revision only after its matching history has been read successfully. A failed initial read or periodic read can therefore be fetched again even when the upstream revision is unchanged.
- Preserve history and drafts during a specifically recognized temporary legacy background-read failure. Continue read retries, show a scoped warning, and clear only that warning after recovery. Authorization, protocol and operation errors remain visible. Messages and other writes are never automatically resent.
The existing compact phone layout, explicit image loading, local artwork, 44-pixel primary touch targets and Chinese/English/Spanish interface remain. Public product documentation and release notes are in English. Private notification scripts, access links, credentials and user files are excluded from published source and installers.
Actual operation and limits
The current desktop baseline is DSH 0.1.7-rc.2. Four real published npm packages were also run locally in separate D-drive homes: 0.1.0-rc.8, 0.1.1-rc.2, 0.1.7-rc.2 and 0.2.0-rc.2. Project/session, file, model, preset and image flows have different acceptance scopes. Modern npm sessions returned real replies and completed actual question/answer and approval allow/reject operations. Old npm project/session, file preview, staged image and model/preset readback were operated; successful model replies and model-triggered interactions remain blocked by unavailable valid legacy credentials.
Prepared historical dependency graphs are not certification of today's default fresh npx installation. A fresh unmodified old npm installation timed out before startup; that result does not establish either success or a dependency-resolution defect. The lost laptop's desktop executable, arbitrary plugins, future releases, physical iPhone/Android and cellular workflows remain unverified. Current in-app-browser Save operations did not confirm a completed download. Historical successful downloads and controlled byte-exact fixtures are recorded separately.
Publication is gated on independent CI for the exact commit, compiled installer acceptance and source/payload/privacy checks. These are separate from actual runtime operation and device acceptance. See the compatibility matrix and acceptance record.
Pocket Bridge 1.0.0-preview.10 (Windows preview)
Release notes - 1.0.0-preview.10
Pocket Bridge continues as a lightweight, unofficial mobile interface for DeepSeek Harness on your own Windows computer. New installers are DSH-only. Previous combined Codex/Dot releases and installers remain available; this release does not delete target applications or historical conversations.
Privacy improvements
- Persist replay receipts for protected inbound mobile HTTP and WebSocket content and one-shot device proofs before dispatch. An already consumed packet stays refused after a gateway restart. Invalid authentication does not consume a receipt. Corruption, storage failure, conflicting ownership or capacity exhaustion refuses the request rather than clearing protection.
- Reject malformed, fragmented, oversized and unsupported WebSocket frames before forwarding. Retain legitimate control frames and bounded encrypted content.
- Apply a restrictive same-origin policy to the bridge-owned phone page, with no third-party scripts or fonts, no referrer and no framing. This reduces unintended loading; it does not authenticate a page that an active serving provider has replaced.
- Require an exact screenshot request schema. An encrypted ordinary RPC body cannot be redirected to this route to trigger the tested unintended screen capture.
- Add an optional private Tailscale HTTPS entrance, disabled by default. It checks the configured local Serve mapping and keeps Bridge authentication, device proof and encryption. It does not install Tailscale, log in, change network settings or enable Funnel. See setup and limits.
Passive tunnel relays receive ciphertext for protected content, but still see metadata. The initial web application remains a separate trust boundary. Encryption is not forward-secret and does not bind HTTP method/path, device cookie or packet order. This is not an exactly-once execution guarantee. Model providers receive the instructions DSH submits to them, and local files/drafts have separate storage boundaries. See SECURITY.md.
Compatibility and usability
- Show the observed distribution, exact runtime version and adapter in Settings → Connection and compatibility. Separate implemented interfaces from workflows accepted by real operation. Unknown future versions remain unverified.
- Make unsupported legacy permission, plan, goal, queue and generic-file interfaces explicit. Keep available model and tool controls usable instead of disabling the whole conversation.
- Implement legacy model and blank-session tool-preset selection through the old runtime's actual methods, with independent readback before claiming success. Selection writes trigger fresh runtime verification.
- Repair legacy history refresh markers: record a revision only after its matching history has been read successfully. A failed initial read or periodic read can therefore be fetched again even when the upstream revision is unchanged.
- Preserve history and drafts during a specifically recognized temporary legacy background-read failure. Continue read retries, show a scoped warning, and clear only that warning after recovery. Authorization, protocol and operation errors remain visible. Messages and other writes are never automatically resent.
The existing compact phone layout, explicit image loading, local artwork, 44-pixel primary touch targets and Chinese/English/Spanish interface remain. Public product documentation and release notes are in English. Private notification scripts, access links, credentials and user files are excluded from published source and installers.
Actual operation and limits
The current desktop baseline is DSH 0.1.7-rc.2. Four real published npm packages were also run locally in separate D-drive homes: 0.1.0-rc.8, 0.1.1-rc.2, 0.1.7-rc.2 and 0.2.0-rc.2. Project/session, file, model, preset and image flows have different acceptance scopes. Modern npm sessions returned real replies and completed actual question/answer and approval allow/reject operations. Old npm project/session, file preview, staged image and model/preset readback were operated; successful model replies and model-triggered interactions remain blocked by unavailable valid legacy credentials.
Prepared historical dependency graphs are not certification of today's default fresh npx installation. A fresh unmodified old npm installation timed out before startup; that result does not establish either success or a dependency-resolution defect. The lost laptop's desktop executable, arbitrary plugins, future releases, physical iPhone/Android and cellular workflows remain unverified. Current in-app-browser Save operations did not confirm a completed download. Historical successful downloads and controlled byte-exact fixtures are recorded separately.
Publication is gated on independent CI for the exact commit, compiled installer acceptance and source/payload/privacy checks. These are separate from actual runtime operation and device acceptance. See the compatibility matrix and acceptance record.
Pocket Bridge 1.0.0-preview.9 (Windows preview)
Release notes - 1.0.0-preview.9
DSH-only direction
New Pocket Bridge releases focus on DeepSeek Harness. Codex and Dot are removed from current gateway startup, routes, target discovery, desktop controls, and Windows payload requirements. Old bookmarks receive an unsupported response. Previous GitHub releases and installers remain available; they are not deleted or updated.
An upgrade retains the installed directory, connection keys, devices, configuration, uploads, and historical journals. It does not close the target applications or erase their conversations. The new installer does not bundle DSH, model access, or a subscription.
Mobile interface
- Replace the narrow persistent phone rail with a compact top bar and full-width conversation area. Move secondary actions to a labelled menu and give primary controls at least 44-pixel touch targets.
- Keep model, tool preset, permission, and goal controls visible in their own row. Phone Return inserts a newline; Send remains explicit.
- Use original Pocket Bridge SVG/PNG/Windows artwork and local system fonts. The 512-pixel app icon is 5,314 bytes instead of 289,816 bytes; the matching master artwork is 5,314 instead of 1,403,547 bytes. These are asset-size reductions, not a measured claim of equal startup improvement.
- Preserve queued-message and goal edits until an authoritative read confirms the change. An uncertain response keeps the edit and offers readback rather than silently discarding or resending it.
- Bind asynchronous command actions to their original session. Report command errors and unsupported results instead of inventing completion. Permission success requires a current-runtime readback.
- Hide Stop after the latest task has ended. Preserve the last goal when reading its current state fails, with an unavailable-state explanation.
- Reuse unchanged message rows, retain opened reasoning and loaded images, and coalesce streaming layout work. Images remain explicit, and a decoder failure exposes a working Retry instead of retaining a broken source.
- Read supported image references through DSH's session-authorized attachment API. Validate raster bytes and metadata before returning encrypted content. Generic uploaded images have a separate bounded preview on the current page; it is temporary and does not claim remote history retrieval.
- Run process, listener and cold installation discovery asynchronously. Keep runtime identity checks, cache expiry and failure invalidation, while avoiding blocking the gateway during slow system queries.
Privacy and compatibility
Remote original-interface HTTP and unknown WebSocket paths are closed before upstream dispatch. The supported phone uses the bridge-owned encrypted Lite protocol. Computer-local access to the original DSH interface remains available. Authentication, device proof, encryption, file boundaries, and size limits remain enforced.
Malformed, oversized or non-101 upstream WebSocket handshakes fail closed, and a transform failure closes only the connection. The phone requires a secure browser context: an HTTPS tunnel or trusted local HTTPS. Plain LAN HTTP is not an encrypted phone fallback.
The current desktop baseline is DSH 0.1.7-rc.2. This is an exact-version statement, not a promise about every future desktop release. Historical actual npm tests for 0.1.0-rc.8, 0.1.1-rc.2, 0.1.7-rc.2 and 0.2.0-rc.2 cover different subsets. The oldest model replies and several approval workflows remain unverified. See DSH compatibility for evidence and limits.
Content encryption protects the supported channel from a passive tunnel relay. Traffic metadata and the initial web application remain outside that body-confidentiality boundary; a malicious serving endpoint or compromised device is not covered. Model providers receive the prompts DSH submits to them. Local storage is a separate boundary. See SECURITY.md.
Verification status
The release acceptance record separates isolated browser/security checks, current-desktop public-route operations, historical npm operations, compiled installer checks, and physical-device limits. A displayed card or a successful service startup is not counted as a completed action. See DSH mobile acceptance.
Actual public-route operation with desktop DSH 0.1.7-rc.2 passed project/conversation creation, assistant replies, model and permission readback, file preview, uploaded-image model reading, temporary fresh-upload preview, one historical official tool-image preview, encrypted computer-screen reading and the 390/320-pixel layout checks. Updating and reloading the installed page also preserved English across static and dynamic controls. Old generic pathless uploads do not gain remote retrieval from the official image-reference result. Public download completion and physical-device workflows remain unverified.
The current controlled Chromium action fixture passed 192 checks. An earlier candidate passed 89 isolated CI entries; the latest language/runtime edits still require fresh final CI and installer validation. Release assets are published only after the final source, compiled installer, payload and privacy gates pass. Earlier candidate results must not be presented as final release acceptance.
Pocket Bridge 1.0.0-preview.8 (Windows preview)
Pocket Bridge 1.0.0-preview.8 — Windows preview
Pocket Bridge is a free, independent, open-source gateway for using DeepSeek Harness or OpenAI Codex on your own Windows computer from a phone browser. This preview adds experimental text sending to Your dot in the official desktop app. Desktop Codex relay can send through the conversation's existing writer without closing Codex or taking its lock. Keep the computer on, signed in and free from simultaneous desktop use during native phone actions.
Use matching preview.8 source and installer assets once available. This is a Windows x64 preview, not complete compatibility with every app version, desktop state or phone network.
Preview.8 stabilizes the isolated pagination fixture's pending-load/Retry timing and adds an independent release gate. Packaging waits for the latest ci.yml push run to succeed for the exact publication commit, then verifies the same successful run attempt again before publication. Its own isolated CI and compiled installer smoke remain required. The changes preserve preview.7 product behavior, compatibility scope and privacy limits described below; fresh preview.8 CI, package and privacy acceptance must be completed separately.
What changed
The Dot page now connects, reads recent loaded messages, sends plain text through the normal desktop composer and checks the exact new user row in the verified Dot conversation. One actual local browser Connect, Send and Refresh flow passed 14 checks with one native Send invocation and a unique assistant reply. It used a real AES content wrapper and the production private-storage provider, with isolated device proof. A later public Cloudflare Send followed by Connect and Refresh re-reads exercised production authentication separately, as recorded below. These cases establish bounded native text operation on the exact baseline, not complete Dot functionality or physical-phone acceptance. A desktop delivery receipt alone does not prove server acknowledgement or local task execution.
The actual send uncovered a transcript bug: joining UI Automation fragments inserted two line feeds into the copied user message. Reader and sender now concatenate the fragments exactly while retaining authored whitespace. Strict source checks stop ambiguous navigation or sending, including outgoing compact Codex pages and Dot pages whose app header still shows Codex. Native actions preserve existing desktop drafts and share a fail-fast desktop-operation lease. Unknown delivery is retained for checking and is never automatically resent.
Check receipt now performs a read-only native observation for an original unresolved send. It preserves the original operation and encrypted baseline, verifies the original process lifetime, window and conversation, and requires the entire previous message prefix plus exactly one matching new user row. It never pastes, changes a draft, invokes Send or Stop, or navigates to another conversation. A dismissed profile popover can be reopened only after the original rendered viewport and message-list identities match. Repeated checks share one observer and shutdown waits for that helper to close. A failed check gives an actionable hint without rewriting the receipt; changed context remains unknown. A 19-check actual local run sent once, deliberately lost the terminal result, recovered the unknown receipt through one native observation and observed the unique reply without another Send. Normal close and reopening of the real DPAPI/ACL-protected store retained the accepted receipt. That run used isolated device proof, not full production authentication or a physical phone.
The phone reader shows at most 40 recent loaded rows. Send uses the complete loaded baseline up to 128 rows and permits at most five appended rows when checking delivery. Oversized or incomplete scopes are refused instead of silently using a recent tail. A rejected proof retains its unresolved-send fence without disabling a healthy journal for a later exact check.
Bounded Dot drafts and unresolved request text survive a same-tab reload only after an encrypted snapshot verifies the same connection and durable Dot identity. Session drafts are plaintext and can be lost when a tab or browser storage is cleared. Restoring text never connects or sends automatically. Compact layout and connection/delivery guidance were improved. Attachments are not restored or sent through the native text routes.
The Bridge-owned DSH page now gives list failures an explicit Retry action, translates more controls, explains desktop presets and copies one assistant turn without thinking text or the next turn. A pending send or recovering connection no longer prevents typing; successful delivery clears only the original unchanged draft and attachment objects, including across conversation switches. Voice stop/watchdog and stale callbacks were hardened, and screenshot download feedback distinguishes download initiation from confirmed disk saving. Local browser fixtures passed at 320 pixels. This merge retains the 64 KB text-preview limit, legacy image-only uploads, reconnect cleanup and in-memory draft separation; it does not add persistent message drafts or certify phone speech/provider behavior. Public static source assets now support ETag, HEAD and 304 responses without caching private content.
The Codex chat now follows the visible viewport directly during keyboard changes and Safari-style page panning. Its composer, Latest button and settings stay within that viewport, and older-history position or latest-following behavior is preserved. A short keyboard viewport folds secondary status into Details, leaves readable reply space and retains a 44-pixel Send target; authorization forms remain independent. Fifty-six actual desktop-browser interaction checks passed at 390 and 320 pixels with simulated keyboard viewport samples and mock RPC; they performed no sends or lock operations. Current mobile-control and relay UI fixtures passed 83 and 98 checks. Physical iPhone keyboard acceptance remains pending.
Older Codex history now loads chronologically and remains in the message index. Late responses are bound to their conversation and connection; initial and older-history errors show Retry instead of a false empty chat. Retry preserves drafts, recovered content and writer state. Completed conversations keep lightweight status polling while routine full-history reads wait up to 15 seconds. A new, active or uncertain turn reads history immediately, manual Refresh forces a read, and content reads allow 30 seconds. Unchanged rows avoid redundant DOM work. Actual read-only browser use also covered manual refresh of completed work and a deliberately injected initial transport failure followed by Retry loading real backend content.
Encrypted history now uses lossless gzip and fresh connection-scoped HMAC revisions, preserving complete output, page fields and cursors. The app-server is still queried on every poll. Browsers without gzip receive identity content; only a correlated method-not-found enables the older read-only RPC. Verification failures never silently downgrade or retry writes. Optimized results have an 8 MiB limit, with a deliberate full-page retry; all encrypted frames, including that retry and other RPCs, retain a 16 MiB cap. TCP splitting/coalescing is supported; fragmented WebSocket application messages are refused before AES frame normalization. The server transport and browser transport suites passed 63 and 65 isolated checks, respectively.
A 38-check actual read-only browser run loaded 450 records from the real app-server through private AES transport. At modelled 218 KB/s bandwidth, 150 ms latency and 4× CPU throttling, a 1,176,356-byte page used 95,698 encrypted bytes and loaded in 2.376 seconds, versus 9.964 seconds before compression. An unchanged active page used 326 encrypted bytes instead of its 41,583-byte full result, with no row rebuilding. These measurements are not production-gateway, physical-device or Cloudflare performance acceptance. Full content is preserved rather than removed.
The history changes were then installed on D: and the live gateway reloaded with its verified tunnel and connection keys retained. Actual operation of the public Cloudflare page at a 390-by-844 viewport loaded latest and older real history without errors. Latest returned to the bottom, and the composer stayed within the visible page. This accepts those installed public UI operations, separately from the modelled measurements and physical iPhone/Android behavior.
The native Codex source check now recognizes the exact attachment-free compact and expanded composers of a running task even when Chromium exposes no readable text selection. The compact dictation wrapper may carry its actually observed offscreen flag only while its exact button and icon remain visible and enabled. Other controls, drafts, process/window identity and ancestry remain strict; 117 complete source/outgoing guard regressions passed. Actual native testing confirmed uniquely attributable Send receipts and model replies, including a separate noncurrent-conversation reply verified in about 25 seconds. A prior refusal correctly preserved a real test-owned draft; only that precisely identified draft was cleared for its test. No automatic clearing of user drafts or broader target/Send authority was added.
One actual 390-pixel browser Send over the public Cloudflare route passed production authentication, device proof and encrypted HTTP, reaching a noncurrent Codex conversation. Its unique model reply was visible in the phone view and the unchanged draft cleared. An earlier current-conversation public send remains unknown; it was not resent, reset or counted as passed. This accepts the recorded public send case, not every desktop state or physical phone.
Native checks now retain a read-only process handle after the exact fresh CIM comparison and verify its full process cr...
Pocket Bridge 1.0.0-preview.7 (Windows preview)
Pocket Bridge 1.0.0-preview.7 — Windows preview
Pocket Bridge is a free, independent, open-source gateway for using DeepSeek Harness or OpenAI Codex on your own Windows computer from a phone browser. This preview adds experimental text sending to Your dot in the official desktop app. Desktop Codex relay can send through the conversation's existing writer without closing Codex or taking its lock. Keep the computer on, signed in and free from simultaneous desktop use during native phone actions.
Use matching preview.7 source and installer assets once available. This is a Windows x64 preview, not complete compatibility with every app version, desktop state or phone network.
What changed
The Dot page now connects, reads recent loaded messages, sends plain text through the normal desktop composer and checks the exact new user row in the verified Dot conversation. One actual local browser Connect, Send and Refresh flow passed 14 checks with one native Send invocation and a unique assistant reply. It used a real AES content wrapper and the production private-storage provider, with isolated device proof. A later public Cloudflare Send followed by Connect and Refresh re-reads exercised production authentication separately, as recorded below. These cases establish bounded native text operation on the exact baseline, not complete Dot functionality or physical-phone acceptance. A desktop delivery receipt alone does not prove server acknowledgement or local task execution.
The actual send uncovered a transcript bug: joining UI Automation fragments inserted two line feeds into the copied user message. Reader and sender now concatenate the fragments exactly while retaining authored whitespace. Strict source checks stop ambiguous navigation or sending, including outgoing compact Codex pages and Dot pages whose app header still shows Codex. Native actions preserve existing desktop drafts and share a fail-fast desktop-operation lease. Unknown delivery is retained for checking and is never automatically resent.
Check receipt now performs a read-only native observation for an original unresolved send. It preserves the original operation and encrypted baseline, verifies the original process lifetime, window and conversation, and requires the entire previous message prefix plus exactly one matching new user row. It never pastes, changes a draft, invokes Send or Stop, or navigates to another conversation. A dismissed profile popover can be reopened only after the original rendered viewport and message-list identities match. Repeated checks share one observer and shutdown waits for that helper to close. A failed check gives an actionable hint without rewriting the receipt; changed context remains unknown. A 19-check actual local run sent once, deliberately lost the terminal result, recovered the unknown receipt through one native observation and observed the unique reply without another Send. Normal close and reopening of the real DPAPI/ACL-protected store retained the accepted receipt. That run used isolated device proof, not full production authentication or a physical phone.
The phone reader shows at most 40 recent loaded rows. Send uses the complete loaded baseline up to 128 rows and permits at most five appended rows when checking delivery. Oversized or incomplete scopes are refused instead of silently using a recent tail. A rejected proof retains its unresolved-send fence without disabling a healthy journal for a later exact check.
Bounded Dot drafts and unresolved request text survive a same-tab reload only after an encrypted snapshot verifies the same connection and durable Dot identity. Session drafts are plaintext and can be lost when a tab or browser storage is cleared. Restoring text never connects or sends automatically. Compact layout and connection/delivery guidance were improved. Attachments are not restored or sent through the native text routes.
The Bridge-owned DSH page now gives list failures an explicit Retry action, translates more controls, explains desktop presets and copies one assistant turn without thinking text or the next turn. A pending send or recovering connection no longer prevents typing; successful delivery clears only the original unchanged draft and attachment objects, including across conversation switches. Voice stop/watchdog and stale callbacks were hardened, and screenshot download feedback distinguishes download initiation from confirmed disk saving. Local browser fixtures passed at 320 pixels. This merge retains the 64 KB text-preview limit, legacy image-only uploads, reconnect cleanup and in-memory draft separation; it does not add persistent message drafts or certify phone speech/provider behavior. Public static source assets now support ETag, HEAD and 304 responses without caching private content.
The Codex chat now follows the visible viewport directly during keyboard changes and Safari-style page panning. Its composer, Latest button and settings stay within that viewport, and older-history position or latest-following behavior is preserved. A short keyboard viewport folds secondary status into Details, leaves readable reply space and retains a 44-pixel Send target; authorization forms remain independent. Fifty-six actual desktop-browser interaction checks passed at 390 and 320 pixels with simulated keyboard viewport samples and mock RPC; they performed no sends or lock operations. Current mobile-control and relay UI fixtures passed 83 and 98 checks. Physical iPhone keyboard acceptance remains pending.
Older Codex history now loads chronologically and remains in the message index. Late responses are bound to their conversation and connection; initial and older-history errors show Retry instead of a false empty chat. Retry preserves drafts, recovered content and writer state. Completed conversations keep lightweight status polling while routine full-history reads wait up to 15 seconds. A new, active or uncertain turn reads history immediately, manual Refresh forces a read, and content reads allow 30 seconds. Unchanged rows avoid redundant DOM work. Actual read-only browser use also covered manual refresh of completed work and a deliberately injected initial transport failure followed by Retry loading real backend content.
Encrypted history now uses lossless gzip and fresh connection-scoped HMAC revisions, preserving complete output, page fields and cursors. The app-server is still queried on every poll. Browsers without gzip receive identity content; only a correlated method-not-found enables the older read-only RPC. Verification failures never silently downgrade or retry writes. Optimized results have an 8 MiB limit, with a deliberate full-page retry; all encrypted frames, including that retry and other RPCs, retain a 16 MiB cap. TCP splitting/coalescing is supported; fragmented WebSocket application messages are refused before AES frame normalization. The server transport and browser transport suites passed 63 and 65 isolated checks, respectively.
A 38-check actual read-only browser run loaded 450 records from the real app-server through private AES transport. At modelled 218 KB/s bandwidth, 150 ms latency and 4× CPU throttling, a 1,176,356-byte page used 95,698 encrypted bytes and loaded in 2.376 seconds, versus 9.964 seconds before compression. An unchanged active page used 326 encrypted bytes instead of its 41,583-byte full result, with no row rebuilding. These measurements are not production-gateway, physical-device or Cloudflare performance acceptance. Full content is preserved rather than removed.
The history changes were then installed on D: and the live gateway reloaded with its verified tunnel and connection keys retained. Actual operation of the public Cloudflare page at a 390-by-844 viewport loaded latest and older real history without errors. Latest returned to the bottom, and the composer stayed within the visible page. This accepts those installed public UI operations, separately from the modelled measurements and physical iPhone/Android behavior.
The native Codex source check now recognizes the exact attachment-free compact and expanded composers of a running task even when Chromium exposes no readable text selection. The compact dictation wrapper may carry its actually observed offscreen flag only while its exact button and icon remain visible and enabled. Other controls, drafts, process/window identity and ancestry remain strict; 117 complete source/outgoing guard regressions passed. Actual native testing confirmed uniquely attributable Send receipts and model replies, including a separate noncurrent-conversation reply verified in about 25 seconds. A prior refusal correctly preserved a real test-owned draft; only that precisely identified draft was cleared for its test. No automatic clearing of user drafts or broader target/Send authority was added.
One actual 390-pixel browser Send over the public Cloudflare route passed production authentication, device proof and encrypted HTTP, reaching a noncurrent Codex conversation. Its unique model reply was visible in the phone view and the unchanged draft cleared. An earlier current-conversation public send remains unknown; it was not resent, reset or counted as passed. This accepts the recorded public send case, not every desktop state or physical phone.
Native checks now retain a read-only process handle after the exact fresh CIM comparison and verify its full process creation time, PID and executable on subsequent boundaries. They do not reopen a failed pin or authorize a replacement process. Actual cross-project operation then found a focus-settling refusal before Send. A bounded 1.2-second wait after one SetFocus requires the same fresh composer and bound process/window/foreground, with no input while waiting and the existing strict final focus check. Process and focus suites passed 48 and 52 checks. With these changes installed, a public different-project Send was accepted with its unique rep...
Pocket Bridge 1.0.0-preview.6 (Windows preview)
Pocket Bridge 1.0.0-preview.6 — Windows preview
Pocket Bridge is a free, independent, open-source gateway for using DeepSeek Harness or OpenAI Codex on your own Windows computer from a phone browser. This update adds an experimental way to send text through desktop Codex while that app owns the conversation, and a native Your dot view for recent messages. Keep the computer on, signed in and free from simultaneous desktop use during native phone actions.
This is an experimental preview. Use the matching preview.6 source and Windows installer. The compatibility table below records the operated scope; it does not promise full compatibility with every DSH version, desktop state or phone network.
What changed
Desktop relay locates the selected conversation by UUID and project directory before using the official desktop Send button. Actual tests returned completed assistant replies when another conversation or project was open, when the window was minimized, and when the app initially showed ChatGPT/Your dot. A separate real test refused to send over an existing desktop draft. After the outgoing-draft guard changed, controlled noncurrent, different-project, minimized and blank Your dot reruns passed. Cross-source drafts were safely refused and preserved; the same-source rerun encountered other desktop automation and remains pending. Bridge checks delivery without closing desktop Codex or changing the writer lock. A desktop queue receipt does not prove that execution has started, and an uncertain result is never automatically resent.
Nineteen real read-only phone UI interactions passed, including actual page reloads that preserve the chosen sending mode and typed multiline draft. A separate 98-check UI fixture covered draft protection, denied storage and pending-send races; it does not replace live interaction. Bounded text drafts use plaintext session storage within the same browser tab. Attachments are not restored. Restoring a draft or sending-mode preference never sends a message automatically.
Controlled Bridge shutdown now stops admission before waiting for owned native helpers and the complete receipt tail. The console distinguishes a scheduled restart from a new gateway process using a fresh boot identifier. Cleanup failure leaves a visible blocked state rather than forcing an exit. The local reload command verifies its installation, process and boot before requesting this coordinated restart; it does not kill a process or launch a replacement itself. These are isolated lifecycle checks, not an accepted production stop/restart.
Tray Stop now targets the verified gateway belonging to this installation. It waits for pending managed startups, checks physical process completion and refreshes tunnel ownership before cleanup. A verified already-stopped installation can quit or rotate keys without attempting another shutdown. Unknown ownership remains blocked. The 56 isolated tray checks and 22 daemon/provider checks do not certify actual tray responsiveness or a live production shutdown. The obsolete live test that assumed age-based daemon-lock takeover was replaced by the isolated operation-fence suite.
The new Dot page connects to the real Your dot desktop conversation and refreshes only recent loaded message rows. Connect and Refresh passed actual local browser tests at 390- and 320-pixel widths, with encrypted transcript responses. Four strict draft cases passed, but Dot sending is still disabled and under implementation. This does not provide full cloud history, approvals, task controls, calls or file transfer.
DSH discovery tolerates one transient transport failure on a freshly verified process-owned listener. Negative HTTP responses, including truncated authorization failures, are not retried. No project, conversation, message or approval write is replayed by this discovery change. The npm CLI 0.2.0-rc.2 fallback is limited to its inspected protocol.
The installer uses English and remembers a valid existing per-user InstallLocation, including D-drive installations. An explicit /D destination still takes priority. Marked compiled install, reinstall and uninstall checks kept shared shortcuts and registration untouched and preserved private configuration and data. Upgrading does not delete unknown obsolete program files. The desktop shortcut verifies its own installation identity before opening a gateway instead of selecting another installation's listener.
Stop and exit the existing Bridge using its current tray before upgrading, then reopen after installation. The shortcut refuses older running gateways without the new identity/boot proof. The installer does not terminate the old service.
Actual compatibility
| Target | Accepted scope | Limits |
|---|---|---|
| DSH 0.1.7-rc.2 desktop build previously tested on the PC | Bridge-owned project, conversation and file/message interface. | Other desktop wrappers are not certified. |
| Official desktop product 26.928.31416, Windows package 26.928.3736.0, Codex CLI 0.159.2 | Desktop relay delivery and completed reply with a noncurrent conversation, another project, a minimized window and an initial ChatGPT/Your dot view; a preserved-draft refusal also passed. | Text only, desktop model/mode; no native approval/question forwarding or interrupt guarantee. A staged app update has not yet passed fresh acceptance. |
| npm DSH 0.1.0-rc.8 and 0.1.1-rc.2 | Project creation, two conversations, actual download and Bridge-staged legacy image receipt. | No valid API key was available for successful model replies. No image-to-model, reasoning, choices or approval round-trip acceptance. |
| npm DSH 0.1.7-rc.2 | Project/conversation, actual reply, download, upstream image receipt and image message. | DeepSeek Account provider selected explicitly; questions and approval round trips unaccepted. |
| npm DSH 0.2.0-rc.2 CLI web | The same operations plus an actual displayed question and answer. | Account provider selected; a separately displayed approval card did not establish allow/reject completion. No other 0.2 version or desktop wrapper certified. |
| Your dot in the tested official desktop app | Connect and Refresh of bounded loaded messages; strict draft safety cases. | Dot sending disabled; official local execution still fails on the test Windows 10 PC. |
The old prepared npm installations used compatible dependency pins. These tests do not certify a fresh unmodified old-version npx installation or the original lost-laptop desktop wrapper. All new phone tests were local mobile-sized browser operation with real target processes, not physical iPhone/Android or 5G/Cloudflare tunnel acceptance.
Privacy and security
Protected remote content routes use application-layer encryption, gateway authentication and device proof. Missing, short or unreadable content keys close those routes instead of returning plaintext. Plaintext responses cannot forge a successful decryption marker. For trusted original pages and scripts, a passive tunnel observer sees ciphertext on covered routes. An active intermediary replacing the initial page is outside that protection. Cloudflare still terminates TLS and can see URL paths, cookies, timing, sizes and the first page. The explicit original DSH frontend and separate cloud MCP prototype have additional plaintext limits. This is not a claim that all traffic is invisible to Cloudflare.
Local request journals and saved-message queues can contain plaintext submitted text. The transport protections are not encryption at rest. Personal notification destinations, private reminder content, credentials, runtime data and private test artifacts must stay out of source and installer assets.
Validation and remaining limits
Isolated CI completed with no failures or whole-check skips; six separately classified live segments were not run. Ten installer source contracts passed. The compiled package passed marked install, reinstall and uninstall, exact installed-source comparison, bundled Node execution and isolated first-run without DSH credentials. Shared registration and shortcuts were unchanged; private configuration, keys and data were retained byte for byte. The unpacked compiled payload and public source/history passed comparison against known current private values. The package smoke did not start a gateway or user backend, and it is not acceptance of normal interactive installation, live tray/startup or a physical phone. Real Codex relay and Dot read/draft checks above remain separate evidence. Native Dot Send is disabled. The staged official desktop update has not been applied for this baseline, and the official Dot local executor pin failure has not been repaired.
Windows x64 is the only packaged platform. The installer is unsigned; verify assets against SHA256SUMS.txt from this release. The installer bundles Node.js and cloudflared, not DSH, Codex, accounts or model access.
Pocket Bridge is not affiliated with or endorsed by DeepSeek, OpenAI or Cloudflare.