Skip to content

[Tracker] AeroFTP 4.1.7 - Known issues, patches & updates #458

Description

@axpnet

AeroFTP 4.1.7, Rolling Tracker

Umbrella issue for the next AeroFTP point release (v4.1.7): known issues reported against v4.1.6 and the patches/updates landing on main after the v4.1.6 tag.

Status note: the current release line is v4.1.6 (release notes, its tracker is #422, now closed); this tracker collects what lands on main for v4.1.7.

Before opening a new issue, please check the lists below. If your problem is already tracked here, just add a thumbs-up reaction or a comment with your environment (OS, version, provider) instead of filing a duplicate. We update this issue as bugs are found and fixed.

Found something that is not listed? Open a new issue and we will link it here.

What shipped in 4.1.6

See the v4.1.6 tracker (#422) and the release notes for the full 4.1.6 change set: the AeroRsync Y-RSC wave closing the distance to stock rsync (md4 and sha1 as first-class negotiated checksums in both roles with the whole-file reconstruction genuinely verified, symlinks end-to-end on unix, streaming download signatures, and retirement of the legacy RSNP server stack so production has one path against stock rsync --server), a stabilised DAG transfer engine (process-global hierarchical governor, durable multipart checkpoints, journal-aware verify and commit, a streaming work frontier bounded over ten million items, endpoint-aware adaptive AIMD, SizeFair scheduling, and five more providers on native multipart workers), MTP and WPD portable devices as a new protocol with its own fingerprint-keyed profile type, AeroCrypt v4 keyslots so a vault unlocks from more than one credential without re-encrypting, measured performance work (multi-file FTPS from 8-18% behind rclone to parity, the FTPS single-stream default 41% ahead, an opt-in SFTP read-ahead about 58% ahead at 12 connections), and the AUDIT-03 sync stack audit closing a remote command execution through a crafted remote filename in rsync-over-SSH plus a class of scan-completeness holes that could drive mass deletion off a truncated listing. 47 languages translated.

Patches & updates queued for 4.1.7

Landed on main after the v4.1.6 tag; shipping in v4.1.7.

# Type Change Status Commit Ref
1 Fix winget publishes both installers again, so the package stops duplicating one and stops losing machine-scope upgrades. Details. 🟢 done 7bd78ccf5 winget-pkgs#407642
2 Fix Security Published release assets are immutable, so re-running a tag build can no longer swap the binaries under a manifest that already pinned their digests. Details. 🟢 done d3a03d135 winget-pkgs#407672
3 Security The periodic russh unblock check now tests the actual blocker instead of always failing for the wrong reason. Details. 🟢 done 23b39ee32 dependabot
4 Docs The public rsync comparison now separates what AeroFTP does at another layer on purpose from what is genuinely not implemented yet. Details. 🟢 done 382c638c8 -
5 Fix Nextcloud features are detected by asking the server, not by how the profile URL was typed. Details. 🟢 done 63636e867 -
6 Feature The server-side trash is reachable from the CLI. Details. 🟢 done 63636e867 -
7 Fix size names the real reason a figure is a lower bound. Details. 🟢 done 63636e867 -
8 Fix The AeroRsync vs rsync comparative benchmark measures what it claims again. Details. 🟢 done 2f0a1087c -
9 Fix The trash manager showed a raw i18n key as a column header. Details. 🟢 done 683d669df -
10 Feature Roadmap AeroRsync now speaks the extended-attribute block that rsync appends to a file-list entry, the first real step toward metadata parity with the native client. Details. 🟢 done ab8067126 -
11 Fix The update toast shows the completed download, and the verification badge says what was actually verified. Details. 🟢 done 60e09505b #459
12 Feature Roadmap AeroRsync now handles the extended attributes that are too large to fit in a file-list entry. Details. 🟢 done bdee1d737 -
13 Fix The three decisions that control whether extended attributes are on the wire now come from one place instead of three. Details. 🟢 done b926656e7 -
14 Fix The Snap GUI paints again, and CI now proves it with a captured frame instead of a log line. Details. 🟢 done 04e477318, d688efadc, d3c5f71d8 #462
15 Fix The AeroRsync Docker lane no longer dies on a Docker Hub timeout before any protocol test runs. Details. 🟢 done 92202590a #467
16 Fix The intermittent invalid rsync protocol version: 2015297409 failure is fixed: the write path was discarding the server preamble. Details. 🟢 done cbc6701d8 #467
17 Feature Roadmap AeroRsync can now read and apply local user.* extended attributes when a session opts into -X (B3), without changing any default transfer. Details. 🟢 done 4235b8664, 5dcc3a904 #467
18 Fix A portable install can be deleted again, because the vault files no longer lock out the user who owns them. Details. 🟢 done 1c455ff4d -
19 Fix Linux builds now ask EGL before switching WebKit's GPU compositor off, instead of switching it off for everyone. Details. 🟢 done a740a3291, d000d41b9 #466
20 Fix The pricing filter on Add Service is a preference again, not a per-visit choice. Details. 🟢 done 7dcc3ce59 #274
21 Fix A dropped profile lands on the blue line instead of one row past it, and a stale text selection no longer locks a row in place. Details. 🟢 done 512b18a6f #453
22 Fix Zoho WorkDrive moves a file or folder across directories again. Details. 🟢 done ec9899891 #451
23 Fix Jottacloud delete and Move to Trash work, end to end, confirmed against a live account. Details. 🟢 done 5bf8f57ee, b721d66dd #397
24 Fix A folder deleted on MEGAcmd goes to the Rubbish Bin, like a file does. Details. 🟢 done c27d64b16 #397
25 Fix One delete action on Jottacloud instead of two that did the same thing. Details. 🟢 done 2f26f4ac1 #397
26 Fix Docs TAB.DIGITAL is capitalised on the documentation site too, and the suggested profile name is a brand name rather than an internal slug. Details. 🟢 done 02f80507e, docs 12424a2 #347
27 Fix An exported profile carries the OAuth app that refreshes its token, and the region that picks its data centre. Details. 🟢 done f16b8934d -
28 Fix Docs The health cell stops being a drag handle exactly when it becomes a button. Details. 🟢 done cf36833f5 #453
29 Fix A 4shared profile carries its own token and its own app, and a profile exported from an install that never migrated its credentials can refresh again. Details. 🟢 done de5b9f6ab #469
30 Fix The multipart resume test cancels from inside the part instead of from a poller, so it stops reporting a scheduling accident as the defect it guards. Details. 🟢 done 2671a9f47 #470, #488
31 Feature Roadmap AeroRsync preserves user.* extended attributes end to end against stock rsync, and turns -X on in production on Unix. Details. 🟢 done f6f91f930, 77e38681a, a39e7d6f7 #471
32 Fix The AeroRsync lane 3 gate reports a Docker Hub outage instead of exiting 0 on it. Details. 🟢 done 43c3c1b7f #481
33 Fix Reading extended attributes no longer follows a symlink to its target, which would have broken symlink uploads now that -X is live. Details. 🟢 done 964e44734 #482, #487
34 Fix The "attributes before rename" invariant is pinned, so moving that block can no longer pass unnoticed. Details. 🟢 done fe9e8db1e #483
35 Fix A batch transfer carries the extended-attribute policy of the transport that opened it, instead of dropping it in silence. Details. 🟢 done 5acfd3bbe #484
36 Fix The snap GPU gate now checks the whole graphics userspace instead of two filename patterns, and the first thing it caught was that the migration it guards has never actually been packaged. Details. 🟢 done 028ef4d01 #485, #465
37 Fix The durable checkpoint store is a parameter now, so a test can no longer reach into the developer's own configuration, which is where the reopened #470 flake was actually coming from. Details. 🟢 done 97c8bab9e #488, #470
38 Fix The two acceptance gaps that #484 and #482 each declared open are closed against a real rsync, and one of them corrects what #482 predicted would happen. Details. 🟢 done 1a5f47973 #487, #484, #482
39 Fix Docs Six reports from Ehud closed in one pass, two of them cases where an earlier fix was correct and incomplete. Details. 🟢 done 4c810ee76, b02b98e4d, 7ef33a44f, 97a17ea23 #274, #277, #347, #369, #486
40 Fix Docs A NAS that is too old for zstd gets real delta sync again, and the bug that hid it was one predicate asking the wrong question. Details. 🟢 done b6de141cb, 9660e3847, a2afd6b86, bfa3c8048, d6d4f2aae, 0c084c2ba #491
41 Feature Docs The Checksum tab says what a backend can hash before you click, and hashing works inside the Overlays Path again. Details. 🟢 done 4b68a188c #494, #347
42 Feature The status bar describes the page you are on, and 📜 Log joins ↑↓ Queue. Details. 🟢 done 170967239 #493, #347
43 Docs The README logo grid is generated from the catalog, so it cannot drift from the other two public tables or list a company twice. Details. 🟢 done e9fdc8bec #495, #347
44 Feature Blomp (40 GB, OpenStack Swift) is a production provider now, after its API turned out to work. Details. 🟢 done a205ba2c2 #496, details
45 Fix AeroSync Compare stopped reporting "no differences" over a folder that is not, and Filen stopped dating every upload at the moment it was transferred. Details. 🟢 done 5a7efeecb #497, details, #347
46 Fix We were advertising four compressors while driving two, and ranking one we cannot drive above one we can, so a NAS-era peer lost its delta to our own capability list. Details. 🟢 done d6951d72f, 11c1777f2 #498
47 Security Three russh advisories are closed in the tree, and cargo audit was never going to say so. Details. 🟢 done 616140317 #489
48 Fix The snap stopped shipping a payload its own base cannot load, and the invariant is now proven before publishing instead of assumed. Details. 🟢 done 19519567d, fb44b9a91, d94cee4cb, edfe61f0f #461, #460
49 Build The md4 bump stops coming back every Monday. Details. 🟢 done 2b07ce5d5 #490
50 Build Nine routine dependency bumps, merged in two groups split by risk. Details. 🟢 done 94c5d33d2 #472, #473, #474, #475, #476, #478, #479, #480, #492
51 Build Security The exit condition on the n0-mainline fork is watched now, and the check that was supposed to watch it had quietly become a liar. Details. 🟢 done 950267687 #499
52 Fix The Quick Connect buttons stopped showing the Google Drive and OneDrive marks that were retired in 2026, and the last 20 untranslated keys are translated in all 46 locales. 🟢 done 41754e855 #500, details, #347
53 Fix Docs Two parity-matrix claims that nothing was checking, found by asking every 🟢 row which test proves it. Details. 🟢 done be9537c17, 87f011461 #501
54 Fix Build The n0-mainline watcher could not tell "still blocked" from "I no longer work", which is the one failure it was written to prevent. Details. 🟢 done 9ea9bc95b #503
55 Fix Security AUDIT-04 hardened AeroTools across hostile imports, secret-bearing exports and remote probes. Details. 🟢 done 82d0f1ebc #504
56 Fix Build Security Deterministic proof that the Linux file chooser really leaves the process, plus a finding that the source comment about the no-portal case is wrong. Details. 🟢 done / fixed (pending release) b9ea098f7 #464, #505
57 Fix The last open finding of the parity sweep is closed: the mtime applied to a downloaded symlink is now asserted, and the helper that applies it no longer swallows its own outcome. Details. 🟢 done 186ddf5ee, 91f7bed0f #508
58 Fix The 29 linguist proposals that were left outside the review's perimeter are closed, and three of them turned out not to be defects at all. Details. 🟢 done cdf7069d8 #509
59 Fix The file picker that did nothing now says why, in all 68 places, and the mechanism the previous row blamed for the silence was the wrong one. Details. 🟢 done / fixed (pending release) 5d9b47f9c #510, #515
60 Fix The titlebar would not drag from its right half, and AeroSync could not export a template in any of its four formats. Details. 🟢 done / fixed (pending release) 6d497ba21, 644e27791 #511, #514, #516
61 Fix aeroftp-cli connect reported a plausible port and an empty username instead of the real ones, because it rebuilt them by parsing the human server_info text. Details. 🟢 done 687d6d597, bb463d1cb #507
62 Build The build toolchain moved to TypeScript 7, which is a release-note item and not a lockfile detail because tsc sits on the production build chain. Details. 🟢 done 64efc8f56 #413
63 Fix Docs A 46-locale linguist round, and the contradiction that round itself introduced in the S3 ETag caveat by saying an ETag is both omitted and advisory. Details. 🟢 done 56dbd12d8, 249adf75 #502
64 Fix Security Ehud triage across seven reports, plus two defects the review pass surfaced: a traversal guard missing from server_copy, and the AeroCrypt modal rebuilding the silent salt downgrade. Details. 🟢 done c5369ee22, d75887175 #506
65 Fix Docs The company is called Drime, not Drime Cloud. Their own title tag and page body say Drime; "Drime Cloud" appears only inside the app.drime.cloud URL. The catalogue also had it inverted, company: 'Drime Cloud', parentCompany: 'Drime', as though the drive were a product under a parent the way pCloud Drive sits under pCloud. README, docs/PROVIDERS.md and cli_catalog.json are regenerated from the corrected entry. Details. 🟢 done 52d907d3c #520
66 Fix AeroSync stopped deleting the Plan and Sync settings on a tab switch. The tabs are rendered conditionally, so leaving one unmounts it and React drops all fourteen of its state values; they now live in a store owned by the dialog. Asked as "how am I supposed to schedule a Plan with Update if the settings are deleted", which was the right question. Details. 🟢 done 2969103b3 #519
67 Fix The fuzzy duplicate distance was a hash value, not a distance. .max() of the members' signatures rather than of the hamming distances between them, on the raster and text arms both, so a pair two bits apart could report billions and any sort by similarity was meaningless. Test pins it and fails on the old expression. Details. 🟢 done 5c92e91c4 #519
68 Feature Find Duplicates shows the hashes, sorts by similarity and takes a cutoff. Per-file signatures behind a toggle, identical groups first then closest-first, and a Fuzzy cutoff field: the threshold had never reached the engine, so the per-type defaults were the only thing anyone could run. Details. 🟢 done 5c92e91c4 #519
69 Fix The crypt toggle leaves the path bar outside the Overlays Path even when the vault is locked. Locking cleared the session overlay and the badge read its anchor from there, falling back to a value that means "the whole remote is the anchor", so the grey toggle rendered in plaintext folders and the jump button never appeared. Details. 🟢 done 0fc60cdd2 #519
70 Feature Compare and Find Duplicates show files, folders, bytes, depth and elapsed time while they scan. Compare needed no new backend: the events had been emitted since the recursive scan landed and nothing listened. Find Duplicates emits its own, throttled so the reporting cannot slow the scan. Details. 🟢 done 197ba20a5 #519
71 Feature One sortable trash table for all seventeen providers. Sorting, a Type column, a Name header that lines up with the names, timestamps on one line, Shift ranges, Ctrl adding and a rubber band, in a shared component rather than seventeen copies of the same table, none of which had any sorting at all. Details. 🟢 done 621946b88 #519
72 Feature Copy and open buttons on every duplicate row. The Copy glyph in that dialog was decorative, so comparing two candidates meant reading the path off the screen with an OCR app. Copy on the name and on the folder, plus open in the default app and reveal in the file manager. Details. 🟢 done 197ba20a5 #519
73 Feature My Servers says which providers encrypt on this device. The badge Add Service has always shown, now next to the saved profile name, with both surfaces reading one list and a test holding them to it. MEGA S4 stays unbadged on purpose: it is S3 and the server holds the keys. Details. 🟢 done f3287f23d #519
74 Docs The last four Tab.digital on the docs site were in the VitePress data and config modules, which the 27 July markdown sweep could never reach: the plan snapshot heading, its source label, the sidebar entry and the meta keywords. Verified on the built artefact, zero mixed-case occurrences across the generated site. Details. 🟢 done 3e81e42 docs#4
75 Fix A failed portal session no longer reports a cascade of chooser regressions. An app_ready environmental miss is retried once with a visible log line; if it still fails, the gate emits one primary failure and skips every assertion whose evidence the session could not produce. Details. 🟢 done 6b748fe08 #521
76 Fix A slow Ubuntu mirror stops looking like a broken commit. Details. The delta-sync fixture job died twice in its 25 minute cap inside apt install, cancelling the job with every test skipped. The packages come from the Actions cache now, and the step has its own budget 🟢 done / fixed (pending release) 3b6cde409 #518
77 Security Fix An STS session token stops being replayed to whatever host an S3 redirect names, and a hostile rsync peer stops being able to land a setuid binary. The S3 client had no redirect policy and x-amz-security-token is not on reqwest's strip list; aerorsync applied the peer's mode with & 0o7777 in two sites. Details. 🟢 done / fixed (pending release) f9b77aca8 #526
78 Fix Discover stops promising a perpetual free tier on three providers that only offer a trial, and Blomp's free quota is corrected to 40 GB. AWS S3 and Azure Blob give 5 GB for 12 months, Alibaba OSS 1 to 3 months. Details. 🟢 done / fixed (pending release) 5768937e3 #528
79 Fix Four Major review findings left open on merged PRs are closed (E2E catalogue multiline matcher, portal empty-bus fail-closed, NetworkMonitor v3 pin, speedtest cancelable mkdir, refuse public web roots as speedtest remote_dir). Details. 🟢 done / fixed (pending release) 981e64e63, 2fad7a153 #525
80 Fix Twelve Minor review findings from the post-merge pass (Drime 20 GB copy, Duplicate Finder open errors, FileLu trash date, dedupe oversize skip, local scan final tick, fuzzyCutoff i18n). Details. 🟢 done / fixed (pending release) 05d30ec41, 182a1e3c9, 3c7db9c89 #525
81 Fix CLI catalog New(N) pages 20 rows with Enter=next, and the connect-metadata pin names what it tests. Details. 🟢 done / fixed (pending release) e8df66b98 #525
82 Fix My Servers table drag under a protocol chip reorders the visible list, not the wrong vault slots. Details. 🟢 done / fixed (pending release) 259ea7548 #453, #525
83 Fix Portal gate cold-start: one precondition red instead of eleven chooser accusations, with a no-build pin and selective app_ready retry. Details. 🟢 done / fixed (pending release) 40a5a880b #521, #525
84 Fix The Tauri commands that blocked stopped doing it on the window's thread. Details. A synchronous #[tauri::command] runs on the GTK thread, so list_subdirectories walking a dead network mount froze the whole window. The scoping count was wrong too: 82 synchronous out of 853, not 38 🟢 done / fixed (pending release) c2f7e489d #517
85 Fix Security The Speed Test no longer leaks a connected session when cancelled mid-setup, and the public web root guard now rejects everything inside a protected tree (descendants, per-user public_html subtrees, and paths that only land in one after ./.. resolution), while the portal gate stops turning a missing baseline into a chooser-shaped red. Details. 🟢 done af109a068 #525, #534

Requested / under consideration

Community requests and internal follow-ups being evaluated for this or a later release.

Effort: 🟩 quick win · 🟧 medium · 🟥 large / epic. Ordered by effort (quick wins first).

# Effort Type Request Status Source
1 🟧 Feature Eager-evaluation preview and a single-vs-multi-target placeholder for the -i selectors (prioritised by the reporter ahead of Edit(E) and the 2-letter semantics; exact behaviour to be pinned) 🔵 idea #311 (@EhudKirsh)
2 🟥 Feature Lossless .jpg to .jxl transcode in AeroFile: JXL re-encodes an existing JPEG losslessly and reversibly (the original JPEG bytes reconstruct exactly), for a real size win with no quality loss. Candidate framing: AeroFile as a GUI for libjxl 🔵 idea aerovault#2 (@EhudKirsh)
3 🟥 Feature Roadmap macOS shell integration for the OS extract feature (Deliverable G macOS, deferred): Finder Sync "Extract Here / Extract to Folder" menu items mirroring the Linux Nautilus and Windows verbs, plus macOS custom document-type icons (CFBundleDocumentTypes) for the five aero formats and the generic fallback, and rebuilding the mimetype .icns multi-size (the v4.1.0 ones are single-resolution drafts). Needs a Mac to build and live-test 🔵 planned #361 (Deliverable G)
4 🟥 Feature Filen Encrypted Notes: exit Beta: take Filen Notes out of Beta. Fix the participants/add contactUUID format (currently a best-effort workaround), investigate the Filen free-plan 10-note limit ghost-note cleanup, and add a rich text editor for the rich note type 🔵 planned -
5 🟥 Fix PRIORITY: Linux tray/GTK heap corruption, still-uncovered off-main-thread corruptor. A GDBus worker thread aborts with malloc(): unaligned fastbin chunk detected while deserializing a D-Bus message, the classic GLib heap-corruption signature (that worker is the victim tripping over an already-poisoned fastbin, not the corruptor). Two marshalling fixes already shipped and are safe: tray badge (31db84f8b) and app_ready + splash-timeout (cae95ee91), present since v4.0.5. But the SIGABRT STILL recurs (v4.0.9 on 2026-06-25, and the v4.1.2-era build on 2026-07-05, identical signature): the marshalling is INCOMPLETE, a still-uncovered off-main-thread GTK path remains. Sync Tauri commands are provably main-thread (safe), so the suspects are the event/plugin callbacks whose thread context is unconfirmed: tray on_menu_event / on_tray_icon_event, the single-instance plugin callback, and on_window_event CloseRequested. Pre-existing across versions, intermittent, triggered by D-Bus storms on suspend/resume or monitor standby; it can corrupt the whole app until restart. Definitive path (owner-approved): adopt self-hosted crash reporting with native minidumps to capture the real corruptor, plus an ASan/valgrind repro, then finish the marshalling on the remaining callbacks 🔵 planned -
6 🟥 Feature User-supplied custom CSS snippets (Obsidian snippets-folder style) to restyle app chrome such as the preview scrollbar, applied across desktop and future mobile. Noted when the preview scrollbar was widened in v4.1.1 🔵 idea #347 (@EhudKirsh)
7 🟥 Feature Recommended-protocol highlight on the Add Service / Quick Connect pages, after real benchmarks land (#368) 🔵 idea #274 (@EhudKirsh)
8 🟧 Feature File association opt-out (deferred, design parked): two switches, AeroFTP's own five formats vs the eight general archive formats, with the choice persisted in HKCU\Software\AeroFTP\Settings and re-read by NSIS_HOOK_POSTINSTALL so an in-app update cannot silently restore it (POSTINSTALL runs on every install, and an update is an install), plus a /NOASSOC setup switch. A visible components-page checkbox is out of reach without forking the Tauri NSIS template, which is why it is parked rather than half built. Raised in #454; deferred because AeroFTP never claims the default handler for the general formats, it only adds itself to "Open with" plus its own context-menu entries, so with the uninstall residue fixed (queued #59) what remains is menu visibility 🔵 planned #454
9 🟧 Fix Roadmap CLI / GUI / MCP parity audit across the whole inventory. Three independent findings on 2026-07-25 converge on one root cause: capabilities implemented in the engine, exposed to the GUI, absent from CLI and MCP. (a) ssh_exec.rs / ssh_shell.rs exist and ssh_shell_* are registered Tauri commands (lib.rs:19360), but none of the 92 CLI subcommands and no MCP tool expose them, and MCP's server_exec is file-ops only (ls/cat/stat/find/df) despite the name. (b) nextcloud_empty_trash() (webdav.rs) was reachable only from NextcloudTrashManager.tsx; same for the Koofr, pCloud, Yandex and Dropbox trash managers. Cost already paid: 30 GB of Nextcloud trash on the lab server that no command-line tool could reclaim, diagnosed over SSH with occ instead of one click. Partially closed: the trash surface now exists on the CLI (aeroftp-cli trash list/empty/restore/delete), SSH exec/shell does not. The repo already has the instrument to close the class rather than the instances: diffing aeroftp-cli inventory against the #[tauri::command] set registered in lib.rs yields the full gap list in one pass 🔵 planned -
10 🟧 Fix The durable checkpoint store has no ceiling and no way out for orphans. Queued #37 closed the test-isolation half of this, so the suite no longer writes into a real user's configuration, but it did not touch the retention rule and was deliberately kept separate from it. stale_nonterminal() only surfaces records past the 7-day TTL, and the scavenger then aborts only those whose provider, protocol, host and account match the endpoint you are currently connecting to. So the condition for cleaning a record is going back to the very server that produced it: stop using a server and its records are not old, they are immortal. Nothing else prunes them, and there is no cap on the directory. The machine where this was found held 325 records accumulated since 21 July, all from mock endpoints that by construction nobody will ever connect to again, which is the pathological case of the same rule a real user hits with a decommissioned server. Wants a decision rather than a patch, since each option has a different failure mode: a hard cap loses the oldest resumable transfer, a global age sweep abandons a session the user might still want, and an explicit "forget this endpoint" is honest but manual. Worth deciding before the store grows on a user's machine rather than a developer's 🔵 idea #488, 20260728T074500Z-E4-flaky-multipart-cancel-ROOTCAUSE.md
11 🟩 Fix Two hardening items found on the #497 review, bundled for the next pass. Neither is a live defect on the shipped path, which is why they were not folded into #497: the first is unreachable from the current GUI and the second is a diagnosability gap, and both were verified against the code rather than taken from the review as read. (a) The compare's overlay-key precedence is imprecise. resolve_compare_overlay_keys consults this connection's cached overlay whenever the kind matches, without checking that vault_id has the provider-overlay:<kind>:<owner> sentinel shape. Today no caller can reach it: the command is called only by the GUI, and every non-null write of rcloneCryptVaultId / aeroCryptVaultId builds a sentinel, so a real standalone vault UUID never arrives, which also makes the documented vault-map fallback dead code for this command. The moment one does arrive (and the CLI / GUI / MCP parity audit on row 9 is exactly the work that would wire it) the cache would silently outrank a vault the user named explicitly, normalize with the wrong key material, drop every row and read as "no differences": the very symptom #497 closed. Gating the cache branch on the sentinel shape restores the rule that an explicitly named vault wins, and leaves the error surface unchanged (a sentinel with a mismatched kind still falls through to "Crypt vault is not unlocked"). To be taken with a test that passes a real UUID while the cache is armed on the same kind, otherwise the guard is removable as redundant later, which is the same trap already closed for the normalization guard. (b) The Filen multipart mtime capture fails silently. begin_multipart_upload reads the source mtime through tokio::fs::metadata(p).await.ok(), so an I/O error is swallowed and the commit stamps its own time, indistinguishable from the regression #497 just fixed, with no log line to separate the two. filen_log already exists, so it is a match in place of .ok() with the fallback unchanged 🔵 planned #497 (CodeRabbit review 4800472122)

Known issues found after release

Reported against v4.1.6. Carried over from the #422 tracker where still open.

# Area Description Status Linked issue
1 OAuth / pCloud pCloud trash returns "⚠ Authentication failed: Log in required"; the crypt error is gone, a residual OAuth token/scope issue remains on the trash surface. Code review (4.1.6): the trash path is already correct, it authenticates with the access_token query param (pCloud rejects the Bearer header on trash) and refreshes via get_valid_token (both since v3.1.4), with the crypt fix in d1e0bef90, so no code defect remains. The residual is a stale-token / re-auth condition, pending a live re-auth re-test. Carried over from #422 known issue #4 🟡 investigating #397
2 Security / dependencies Closed on main by queued #47. Three moderate russh Dependabot advisories (GHSA-g9hv-x236-4qp3, GHSA-5xvq-cp9x-6p6r reachable client-side; GHSA-cqjc-rmpq-xprq server-side only, not reachable), all availability-only panics, all predating v4.1.6 and disclosed in the v4.1.6 release notes. The fix is russh 0.62.4, which was previously unreachable because it requires ed25519-dalek ^3 against the =3.0.0-rc.0 exact pin held by n0-mainline in the iroh P2P graph, with both upstreams already at their newest release so no local version selection resolved it. It is resolved now by a [patch.crates-io] on axpdev-lab/n0-mainline pinned by rev, which is the v0.5.0 release commit plus the single line that relaxes that requirement, and 3.0.0-rc.0 is gone from the lockfile. Two things stay true and should not be read as closed by the green: cargo audit still reports clean because none of the three has a RustSec counterpart, so only the Dependabot graph surfaces them and its silence certifies nothing; and the patch section carries an exit condition that nobody is watching automatically, namely delete it as soon as n0-mainline publishes a release admitting 3.0.0 final, still not the case upstream on 2026-07-28. Analysis in docs/security-evidence/RUSSH-DEPENDABOT-ADVISORIES-2026-07.md; re-check with .github/scripts/check-russh-unblock.sh (queued #3) 🟢 done / fixed (pending release) dependabot
3 CI / AeroRsync integration native_rsync_upload_against_stock_rsync_preserves_bytes intermittently failed with a preamble desync; root cause found and fixed on main (queued #16). The upload leg of the stock-rsync integration lane failed with HardRejection(InvalidFrame): server preamble: invalid rsync protocol version: 2015297409 (bytes 81 ff 1e 78), then passed on rerun with no code change, twice on 2026-07-25 (3deea6f3f and 63636e867) and again later. The value was identical every time: LE 81 ff 1e 78 is the server preamble starting at offset +4 after a discarded 4-byte protocol version. Root cause: ssh2::Channel::flushlibssh2_channel_flush_ex empties the read buffer, so a flush after writing the client preamble could drop the already-arrived server reply under CI contention (upload more often than download). Fix in cbc6701d8 removes that flush from the raw write path and frame writes, with a unit pin for the misaligned value. Delta Sync Integration and Aerorsync Protocol (including Docker lane 3) green on the merge of #467 🟢 done / fixed (pending release) #467

Status legend: 🔴 confirmed · 🟡 investigating · 🔵 planned / idea · 🟢 done / fixed (pending release) · ✅ released

Affected platforms

  • Windows
  • macOS
  • Linux

Maintained by the AeroFTP team. Current release v4.1.6 (#422), next v4.1.7. Patches accumulated here; each release line still gets its own tracker.

Metadata

Metadata

Assignees

No one assigned

    Labels

    🔍 release-trackerUmbrella issue tracking known bugs found after a release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions