Releases: smbpal/smbpal-desktop
Release list
SMBPal 0.2.7
What changed
- macOS can mount a share, end to end, against a real server. On Linux this
release changes nothing you can see. - The daemon asks your own agent to do the mounting. It connects to a socket
in your home directory and the agent checks which user is on the other end
before it acts, so root never holds the password and never reaches into
your Keychain. - The password goes into your login Keychain, and the agent reads it back
from there. macOS will not consult the Keychain on behalf of a mount that
is forbidden to ask you anything, so SMBPal looks the password up itself. - macOS picks the mountpoint, not SMBPal. A share named
Testsharearrives
at/Volumes/Testshare, because/Volumesbelongs to root and an agent
cannot prepare a directory there — so SMBPal records where the share
landed instead of deciding beforehand. - Every mount asks for a fresh session. macOS caches a server's credential
somewhere SMBPal cannot clear, which made a corrected password look broken
and a deleted one look as though it were still in use. - Two macOS messages stopped misleading. Disconnecting says what it did once
rather than twice; and a machine that is serving a share is no longer
reported unreachable, which it never was — macOS refuses local network
access to a program that has not been granted it, and SMBPal cannot ask
for that yet, so it now says nothing rather than something false.
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.7_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Install on Fedora
sudo dnf install ./smbpal-0.2.7-1.fc44.noarch.rpm
sudo usermod -aG smbpal $USER
sudo systemctl enable --now smbpald
sudo systemctl enable --now smbThen log out and back in, for the same reason as above.
Two more steps than Debian, and neither is ours to skip. A Fedora
package does not start a service, so the daemon has to be started by
hand — and so does Samba itself, which is installed as a dependency
and left stopped. A share added before Samba is running is configured
correctly and reachable by nobody; SMBPal says so when that is the
case, rather than leaving you to find out from another machine.
There is a build for each Fedora the workflow builds; take the one
matching your release. The package is noarch.
If you share a folder from your home directory, SELinux will not let
Samba serve it: the share will mount and authenticate and then refuse
writes. smbpal share add prints the two commands that fix it.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.7_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
This release, automatically: the .deb installed, used to share a
folder, removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and
Ubuntu 26.04, and the .rpm built, installed, used and erased on two
Fedora releases, with smb.conf compared byte for byte before and
after in every case. This release was not published unless all of
them passed.
Across releases, by hand on real machines: every distribution
marked Tested at https://smbpal.app, each named with the desktop it
actually ran. Those runs cover what a container cannot — the tray,
the window, the polkit prompt, a share served to a second machine,
and removal.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.7 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.7
There is no warranty, to the extent permitted by law.
SMBPal 0.2.6
What changed
- macOS groundwork. On Linux this release changes nothing you can see,
except that the package now ships ansmbpal-agentcommand which exists
for macOS and says so when it is run here. - Mounting on macOS is implemented, and it runs in a per-user agent rather
than in the daemon. Two measurements put it there: mounting on macOS
needs no elevation at all, and the login Keychain — where the password
belongs — cannot be read by root. - The agent installs itself with
smbpal-agent --install, which writes a
LaunchAgent and loads it.--statussays whether launchd has it, is
retrying it after a failure, or is pointing at a program that has moved,
becauselaunchctlreports all three the same way. smbpalno longer tells a Mac user to runsystemctl. There is no
SMBPal daemon on macOS yet, and naming a command the platform does not
have sent people looking for something they could not install.
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.6_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Install on Fedora
sudo dnf install ./smbpal-0.2.6-1.fc44.noarch.rpm
sudo usermod -aG smbpal $USER
sudo systemctl enable --now smbpald
sudo systemctl enable --now smbThen log out and back in, for the same reason as above.
Two more steps than Debian, and neither is ours to skip. A Fedora
package does not start a service, so the daemon has to be started by
hand — and so does Samba itself, which is installed as a dependency
and left stopped. A share added before Samba is running is configured
correctly and reachable by nobody; SMBPal says so when that is the
case, rather than leaving you to find out from another machine.
There is a build for each Fedora the workflow builds; take the one
matching your release. The package is noarch.
If you share a folder from your home directory, SELinux will not let
Samba serve it: the share will mount and authenticate and then refuse
writes. smbpal share add prints the two commands that fix it.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.6_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
This release, automatically: the .deb installed, used to share a
folder, removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and
Ubuntu 26.04, and the .rpm built, installed, used and erased on two
Fedora releases, with smb.conf compared byte for byte before and
after in every case. This release was not published unless all of
them passed.
Across releases, by hand on real machines: every distribution
marked Tested at https://smbpal.app, each named with the desktop it
actually ran. Those runs cover what a container cannot — the tray,
the window, the polkit prompt, a share served to a second machine,
and removal.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.6 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.6
There is no warranty, to the extent permitted by law.
SMBPal 0.2.5
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.5_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Install on Fedora
sudo dnf install ./smbpal-0.2.5-1.fc44.noarch.rpm
sudo usermod -aG smbpal $USER
sudo systemctl enable --now smbpald
sudo systemctl enable --now smbThen log out and back in, for the same reason as above.
Two more steps than Debian, and neither is ours to skip. A Fedora
package does not start a service, so the daemon has to be started by
hand — and so does Samba itself, which is installed as a dependency
and left stopped. A share added before Samba is running is configured
correctly and reachable by nobody; SMBPal says so when that is the
case, rather than leaving you to find out from another machine.
There is a build for each Fedora the workflow builds; take the one
matching your release. The package is noarch.
If you share a folder from your home directory, SELinux will not let
Samba serve it: the share will mount and authenticate and then refuse
writes. smbpal share add prints the two commands that fix it.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.5_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand, on real machines: Raspberry Pi OS Trixie on a Pi 4,
Raspberry Pi OS Bookworm 32-bit, Ubuntu 26.04, Debian 12, Debian 13
and Fedora 44 — install, the tray, the window, a connection to
another machine, a share served to a second machine, and removal.
The desktop rows were run in virtual machines.
Automatically, on every build: the .deb installed, used to share a
folder, removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and
Ubuntu 26.04, and the .rpm built, installed, used and erased on two
Fedora releases, with smb.conf compared byte for byte before and
after in every case. This release was not published unless all of
them passed.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.5 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.5
There is no warranty, to the extent permitted by law.
SMBPal 0.2.4
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.4_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Install on Fedora
sudo dnf install ./smbpal-0.2.4-1.fc44.noarch.rpm
sudo usermod -aG smbpal $USER
sudo systemctl enable --now smbpald
sudo systemctl enable --now smbThen log out and back in, for the same reason as above.
Two more steps than Debian, and neither is ours to skip. A Fedora
package does not start a service, so the daemon has to be started by
hand — and so does Samba itself, which is installed as a dependency
and left stopped. A share added before Samba is running is configured
correctly and reachable by nobody; SMBPal says so when that is the
case, rather than leaving you to find out from another machine.
There is a build for each Fedora the workflow builds; take the one
matching your release. The package is noarch.
If you share a folder from your home directory, SELinux will not let
Samba serve it: the share will mount and authenticate and then refuse
writes. smbpal share add prints the two commands that fix it.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.4_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand, on real machines: Raspberry Pi OS Trixie on a Pi 4,
Raspberry Pi OS Bookworm 32-bit, Ubuntu 26.04, Debian 12, Debian 13
and Fedora 44 — install, the tray, the window, a connection to
another machine, a share served to a second machine, and removal.
The desktop rows were run in virtual machines.
Automatically, on every build: the .deb installed, used to share a
folder, removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and
Ubuntu 26.04, and the .rpm built, installed, used and erased on two
Fedora releases, with smb.conf compared byte for byte before and
after in every case. This release was not published unless all of
them passed.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.4 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.4
There is no warranty, to the extent permitted by law.
SMBPal 0.2.3
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.3_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.3_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand: Raspberry Pi OS Trixie, on a Pi 4. Nothing else has been
run in anger on a desktop.
Automatically, on every build: installed, used to share a folder,
removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and Ubuntu
26.04, with smb.conf compared byte for byte before and after.
This release was not published unless all four passed. That proves
the package installs and uninstalls cleanly there; it says nothing
about the window or the tray on those desktops.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.3 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.3
There is no warranty, to the extent permitted by law.
SMBPal 0.2.2
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.2_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.2_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand: Raspberry Pi OS Trixie, on a Pi 4. Nothing else has been
run in anger on a desktop.
Automatically, on every build: installed, used to share a folder,
removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and Ubuntu
26.04, with smb.conf compared byte for byte before and after.
This release was not published unless all four passed. That proves
the package installs and uninstalls cleanly there; it says nothing
about the window or the tray on those desktops.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.2 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.2
There is no warranty, to the extent permitted by law.
SMBPal 0.2.1
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.1_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.1_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand: Raspberry Pi OS Trixie, on a Pi 4. Nothing else has been
run in anger on a desktop.
Automatically, on every build: installed, used to share a folder,
removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and Ubuntu
26.04, with smb.conf compared byte for byte before and after.
This release was not published unless all four passed. That proves
the package installs and uninstalls cleanly there; it says nothing
about the window or the tray on those desktops.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.1 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.1
There is no warranty, to the extent permitted by law.
SMBPal 0.2.0
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.2.0_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Verify the download
sha256sum -c SHA256SUMS
gh attestation verify smbpal_0.2.0_all.deb --repo smbpal/smbpal-desktopThe first shows the download arrived intact. On its own that is all
it shows — it sits beside the file it describes, so anyone who could
replace one could replace the other.
The second shows where the file came from: that these exact bytes
were built by this repository's workflow from this tag, attested
through sigstore's public transparency log. There is no key involved
and none to trust; the proof is the log entry.
Neither replaces a signed apt repository, which is the version
apt checks on your behalf rather than the version you have to
remember to run.
Tested on
By hand: Raspberry Pi OS Trixie, on a Pi 4. Nothing else has been
run in anger on a desktop.
Automatically, on every build: installed, used to share a folder,
removed and purged on Debian 12, Debian 13, Ubuntu 24.04 and Ubuntu
26.04, with smb.conf compared byte for byte before and after.
This release was not published unless all four passed. That proves
the package installs and uninstalls cleanly there; it says nothing
about the window or the tray on those desktops.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.2.0 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.2.0
There is no warranty, to the extent permitted by law.
SMBPal 0.1.0
Install
Raspberry Pi OS, or any Debian-based system. Three steps, and the
second is not optional.
sudo apt install ./smbpal_0.1.0_all.deb
sudo usermod -aG smbpal $USERThen log out and back in.
The second step is what lets you talk to the daemon: SMBPal's socket
is guarded by the smbpal group, and the package deliberately does
not add anyone to it, because granting it is granting access to a
service running as root and that is the machine administrator's
decision. Installing by double-clicking the file will appear to work
and then leave the app unable to reach the daemon — graphical
installers hide the message that tells you this.
Use apt install ./... rather than dpkg -i. It pulls in samba,
cifs-utils and polkit; dpkg will stop on them and leave the
package half-configured. The leading ./ matters — without a slash
apt reads the argument as a package name.
One file for every machine: the package is Architecture: all, so
the same download installs on arm64, armhf and amd64.
Verify the download
sha256sum -c SHA256SUMSBoth files come from the same automated build. Note what that does
and does not show: a checksum published beside the file it describes
proves the download arrived intact, not that it is authentic —
anyone who could replace one could replace the other. Signed
verification is the apt repository's job, where apt checks it
without anyone having to remember to.
Tested on
Raspberry Pi OS Trixie, on a Pi 4. Nothing else has been run in
anger — it is expected to work on other Debian-based systems, but
that is an expectation and not a report.
Source
SMBPal is free software under the GNU General Public License,
version 3 or later. The complete corresponding source for this build
is the v0.1.0 tag of this repository:
https://github.com/smbpal/smbpal-desktop/tree/v0.1.0
There is no warranty, to the extent permitted by law.