v0.22.10
What's Changed
Added
- KeePass databases protected with a YubiKey Challenge-Response second factor can now be unlocked (issue #350) — RustConn only ever passed a master password (over stdin) and an optional
--key-filetokeepassxc-cli, so a KDBX secured with a YubiKey CR slot could not be opened: every unlock failed with "invalid credentials" no matter the password.
A new optional "YubiKey slot (Challenge-Response)" setting under Settings ▸ Secrets ▸ Authentication takes a slot asslotorslot:serial(e.g.2or2:12345678) and is threaded through tokeepassxc-clias-y <slot[:serial]>, composing with the master password and/or key file. The slot value is not a secret — it identifies the key, it does not authenticate as it — so it is passed as a plain argument and serialized in plaintext like the key-file path, while the master password stays on stdin as before. Because a CR unlock blocks until the key is physically touched,-yreads get a longer 30 s budget instead of the 10 s KDF-only one, and the Settings "Check" button, the on-demand unlock dialog and therustconn secret verify-keepass --yubikeyCLI flag all show a "touch your key when it blinks" hint. The setting defaults to unset, so password-only and key-file-only unlocking are unchanged. Slot composition is covered by unit tests insecret/status.rs, and the config field's default and forward/backward TOML compatibility by tests inconfig/settings.rs. - The terminal can now paste on right-click instead of showing the context menu (issue #349) — some users expect the xterm/rxvt convention where the secondary mouse button pastes the clipboard directly, rather than opening a menu.
A new opt-in "Right-click pastes" terminal setting (off by default, so the native context menu — Copy, Paste, Select All, snippets — stays the default) makes a right-click paste the clipboard immediately. The paste still goes through the shared safe-paste path, so a multi-line clipboard is previewed and confirmed exactly as a Ctrl+V paste is, honouringconfirm_multiline_paste. The menu model and the right-click gesture are mutually exclusive by construction, so the two never fight over the popover.
Changed
rustconn-cli secret verify-keepassis now available in the default CLI build — it previously lived behind thesecret-managementfeature, which also pulls the platform Secret Service / Keychain dependencies (oo7,security-framework) needed only by the keyring-backedsecret get/set/delete/statussubcommands. Becauseverify-keepassonly shells out tokeepassxc-cliand touches no system keyring, it now rides a new lightweightkeepass-verifyfeature that is on by default, soverify-keepass(including the YubiKey--yubikey/-yflag) works out of the box without dragging keyring dependencies into a minimalcargo install. The keyring backends stay behindsecret-managementas before, and packaged builds (.deb/OBS/Flatpak/snap, which usefull) are unaffected.
Fixed
- Tracked down the root cause of the embedded RDP artifacts in GFX/AVC420 mode (issue #262) — a Windows 11 25H2 host in Auto/GFX mode rendered as horizontal lines and unfilled rectangle outlines at 0 fps once the server switched from full frames to partial AVC420 updates. The defect is upstream in the pinned
ironrdp-egfxdecoder, not in RustConn: its AVC420 decode path ignored theregionRectsmetadata and copied every partial update as a single block from the decoded frame's origin, so each changed region drew pixels from the top-left corner and the gaps between regions were overwritten. RustConn inherits the bug correctly and needs no local change — it advertises only AVC420 (never AVC444) and hands the stream straight to IronRDP. A fix (iterateregionRects, copy each region from its own coordinates, one surface update per rectangle) has been prepared and submitted upstream to Devolutions/IronRDP with a regression test; this note will become a resolved entry once a releasedironrdp-egfxcarrying the fix can be pinned.
Installation
Flatpak (Recommended)
flatpak install flathub io.github.totoshko88.RustConnSnap
sudo snap install rustconnDebian/Ubuntu (.deb from this release)
sudo dpkg -i rustconn_0.22.10_amd64.deb
sudo apt-get install -f # Install dependencies if neededFedora (.rpm from this release)
sudo dnf install rustconn-0.22.10-1.fc44.x86_64.rpmAppImage
chmod +x RustConn-0.22.10-x86_64.AppImage
./RustConn-0.22.10-x86_64.AppImagemacOS (Homebrew)
brew tap totoshko88/rustconn
brew install rustconn
open $(brew --prefix)/opt/rustconn/RustConn.appAll dependencies (GTK4, libadwaita, VTE, Adwaita icons) are installed automatically.
Requires macOS 13 (Ventura) or later.
OBS Repositories
Packages available at: https://build.opensuse.org/package/show/home:totoshko88:rustconn/rustconn
# Debian 13 (Trixie)
echo 'deb http://download.opensuse.org/repositories/home:/totoshko88:/rustconn/Debian_13/ /' \
| sudo tee /etc/apt/sources.list.d/rustconn.list
curl -fsSL https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/Debian_13/Release.key \
| gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/rustconn.gpg > /dev/null
sudo apt update && sudo apt install rustconn
# Ubuntu 24.04 LTS (Noble)
echo 'deb http://download.opensuse.org/repositories/home:/totoshko88:/rustconn/xUbuntu_24.04/ /' \
| sudo tee /etc/apt/sources.list.d/rustconn.list
curl -fsSL https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/xUbuntu_24.04/Release.key \
| gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/rustconn.gpg > /dev/null
sudo apt update && sudo apt install rustconn
# Ubuntu 26.04 LTS (Resolute)
echo 'deb http://download.opensuse.org/repositories/home:/totoshko88:/rustconn/xUbuntu_26.04/ /' \
| sudo tee /etc/apt/sources.list.d/rustconn.list
curl -fsSL https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/xUbuntu_26.04/Release.key \
| gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/rustconn.gpg > /dev/null
sudo apt update && sudo apt install rustconn
# Fedora 44
sudo dnf config-manager addrepo --from-repofile=https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/Fedora_44/home:totoshko88:rustconn.repo
sudo dnf install rustconn
# Fedora 43
sudo dnf config-manager addrepo --from-repofile=https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/Fedora_43/home:totoshko88:rustconn.repo
sudo dnf install rustconn
# openSUSE Tumbleweed
sudo zypper ar https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/openSUSE_Tumbleweed/ rustconn
sudo zypper ref && sudo zypper in rustconn
# openSUSE Leap 16.0
sudo zypper ar https://download.opensuse.org/repositories/home:/totoshko88:/rustconn/openSUSE_Leap_16.0/ rustconn
sudo zypper ref && sudo zypper in rustconnArch Linux (AUR)
yay -S rustconnFreeBSD (Ports)
pkg install rustconnFull installation guide: https://github.com/totoshko88/RustConn/blob/main/docs/INSTALL.md