UScreen 1.1.0 — USB second monitor for Linux with S Pen support
The security release, plus packages, multi-tablet support and update checks.
Security
Two problems an audit turned up, both real:
- The loopback ports had no authentication. The tablet reaches them through
adb reverse, but so could any process on the machine — or any other app on
the tablet: read the raw screen on 8890, inject mouse/pen input on 8891. The
daemon now generates a random session token per run and hands it to the app
over adb (on stdin, never in a command line, which any local process can
read). Clients that don't present it first get nothing. An app older than
1.1.0 cannot authenticate: update both sides together, or set
require_token = falsewhile you migrate. - The capture FIFO was
/tmp/uscreen_capture.fifo, mode 0666 — any local
account could read the frames, a live copy of the screen. It now lives in
the per-user runtime directory, mode 0600, opened withO_NOFOLLOW.
Packages, and binaries that actually run
Every release now ships a .deb (Debian, Ubuntu, Mint, Pop), an .rpm
(openSUSE; Fedora with RPM Fusion) and a PKGBUILD for Arch, so the package
manager resolves the dependencies that install.sh used to guess at. All of
them install the udev rule that opens /dev/uinput to the logged-in user —
on anything but Bazzite that was missing, and without it no input ever reached
the desktop.
The tarball binaries are built against Debian 12's glibc (2.36) and run on
anything released since. The 1.0.x binaries were built on a rolling system and
needed glibc 2.43, which no Debian or Ubuntu has — if you saw
GLIBC_2.43' not found, this is the fix.
Several tablets at once
max_tablets (up to 4) gives every attached tablet its own virtual screen,
with its own pen and touch devices mapped to it. Verified with one physical
tablet plus a loopback stand-in; a report from anyone with two real tablets
would be welcome.
Update checks
The app checks when it comes to the front, the GUI when its window opens, the
daemon once a day for the tray icon and uscreen doctor. All of them only
tell you; none of them installs anything.
Fixes
- A daemon shutting down could delete the PID file of the daemon that replaced
it, leaving the new one untracked —uscreen stopthen fell back to a
pattern match that could kill the very shell it was typed into. - Config writes are atomic now and log exactly which settings changed;
settings had been drifting between runs with nothing saying who wrote what. - The GUI said "no tablet" whenever two adb devices were reachable (the normal
state withadb tcpip), becauseadb get-statefails outright then. - The tray's Settings entry and the app menu entry both failed to launch the
GUI for~/.local/bininstalls; both now use full paths. - Android 8.0 never actually worked — the theme used API 27 attributes — so
the app is honest about it now: minimum is Android 8.1.
Install
Pick your file from the table in the README. Upgrading works in place — same
signing key as every earlier release. Update the APK and the Linux side
together: the session token needs both.