Zen v0.1.6#
This release contains the reviewed changes on main since v0.1.5.
What changed#
- Checkpoint remote desktop WIP (
ac2b314) - Serialize desktop input and revocation (
6f8218e) - Integrate opt-in Wayland portal capture (
d743406) - Document bounded Android module verification (
0270b8f) - Isolate debug packaging from local dotenv (
5f0b7fc) - Fix native desktop streaming and keyboard input (
47fd681) - Move Settings to the fixed drawer footer (
5ecce42) - Allow paired LAN desktop access with explicit consent (
bfad184) - Implement scoped Linux unattended desktop (
5035da0) - Fix standalone Android password entry (
a29f620) - Fix completed-session cleanup mistaking missing tmux targets for unowned (
e1674d7) - Refuse completed cleanup when a present owned identity cannot be proven (
cf0cfc0) - Dispatch desktop helper, broker and agent from one zen ELF (
4ddee53) - Prove zen-dev native rebuilds with linked C markers and keep last-good ELF (
e653466) - Render fenced Mermaid flowcharts in shared Markdown (
f4d329a) - Bound mermaid WebViews and isolate desktop LAN storage tests (
e14ea6d) - Admit unattended desktop over identity TLS with distinct native recovery codes (
85ca9f3) - Accept Unicode ellipsis in OpenCode composer readiness probe (
20b0742) - Reverse OpenCode large-paste artifact before admission digest (
f0f5d3e) - Preserve raw OpenCode user text in provider projection (
f8b9fac) - Model OpenCode paste transport in delegated admission digest (
bd5c1bb) - Remove provider-specific tmux admission digest modeling (
eaa4ba5) - Accept successful delegated tmux transport as submission (
15e863e) - Require confirmed transport receipt before delegated replay success (
f0c7dcc) - Normalize and name desktop identity preflight failures (
bd3b3a2) - Name desktop identity preflight stage and reject empty identifiers (
915ac0f) - Redesign Git Diff review and fix bottom scroll rebound (
800abf3) - Fix desktop capability identity echo and Android TLS negotiation (
fb72c3d) - Reject corrupt Link transport identity without mutation (
9fca158) - Repair delegated turn liveness absence and busy signal follow-up (
7085999) - Unify Git Diff back handling and wide master-detail context (
d6c8d41) - Synchronize broker owner handshake before capability (
9705e27) - Retry broker admission while the previous agent retires (
f9f2e2c) - Rely on listener SO_PASSCRED and prove the credential race (
4ec343f) - Wait once for the previous owner to retire before admission (
3eb003c) - Align owner admission deadline and abort cancelled waits (
6b681cf) - Repair iOS remote desktop lifecycle and provision daemon native test deps (
041b043) - Align remote desktop contract test with guarded iOS presentation signal (
3a35136) - Provision CI encoder stack and fall back to system Xvfb (
03b7d33) - Excuse stale live turns named by a resolved loss review (
b4ba5ae) - Tighten resolved-loss excuse to exact Turn payload identity (
5772dec) - Enforce system-unit cgroup owner contract and harden desktop admission (
2760c7b) - Enforce tmux -N no-autostart on externally selected sockets (
8a9e5b0) - Isolate tmux fixtures from user config; liveness-oracle tests; quote fixture paths (
41d7ac0) - Guard chat worker sessions against nil watcher in fixture route (
b449e85) - Add fixture Link v2 mint route and nil-watcher chat regression (
bda97a3) - Require network timeout in nil-watcher chat regression (
f3616a3) - Add persistent Agent service discovery to Services sheet (
5c9a0f6) - Harden persistent service discovery per review (
2bf3826) - Bound managed discovery under shared frontend-safe budget (
a56a132) - Fix desktop pan offset across PanResponder recreation (
bc40d30) - Raise Android version code to 28 and record native acceptance (
f827110) - Package Metro-connected Android debug launcher (
4f6a2ec) - Unify the runtime: one daemon, optional system-unit owner scope (
7892885) - Isolate the runtime parity test in an owned source snapshot (
d8049ee) - Add zen boot user-unit installation for the same runtime (
0b6b34d) - Document the optional zen boot entry (
b68cf72) - Fix zen boot unit ownership, paths and truthful verification (
2930e38) - Bind zen boot ownership to the unit cgroup (
a514934) - Bind the DEV daemon child lifetime to its watcher (
638a993) - Confirm zen boot owner with a stable second observation (
83421e6) - Update the DEV child-lifetime note after the pdeathsig fix (
cd3261d) - Use real flock ownership for zen boot state ownership (
79e6885) - Fail closed on unattributable zen boot state ownership (
5fed4d2) - Treat unknown process owner as unresolved in boot scans (
d6ee6ed) - Harden the runtime parity test around owned builds (
bda3f94) - Skip zombies and proven-foreign processes in boot ownership scans (
6df46b1) - Scope boot ownership tests to an owned proc fixture (
1898416) - Correct boot scan ownership-attribution wording (
afd37ba) - Unify Telegram conversation recipients (
9f0cc63) - Improve desktop host setup and connect flow (
e1cdec9) - Validate desktop setup and prove native connection flow (
b37c602) - Preserve Telegram conversation routes and topic history (
c1a8e54) - Register and verify the current desktop during host install (
d91a683) - Fix Telegram topic navigation and local status (
b12c556) - Support Telegram media and persistent Brain navigation (
782b767) - Preserve Telegram file follow-up input order (
ff50fc0) - Keep ordinary Telegram messages content-only (
f3dfb9d) - Delete Telegram topics for removed Sessions (
3d919f6) - Grant desktop scope in place for trusted devices (
945ed7e) - Keep desktop host success output brief and English (
f3f9d40) - Enable remote desktop in place from the phone (
3c34a57) - Fix desktop grant purpose contract across TS and Go (
854537a) - Add Wayland desktop portal and X11 host broker support (
e227820) - Add commit-aware remote desktop keyboard and route rotation (
d63db2c) - Support in-place desktop broker upgrade with rollback sidecar (
d4ed278) - Fix broker upgrade rollback, live switch and backup safety (
237376c) - Restore complete upgrade state only after verified commit (
34a108f) - Stop the desktop helper after a synchronous portal denial (
5e97c47) - Retain one-step rollback state across successful upgrades (
a5b20da) - feat: add Zen orchestration verification skill (
831d35f) - Keep upgrade rollback backups unique and preflight previous metadata (
82436d7) - fix: harden Zen verification boundaries (
13f07f0) - fix: reap bounded verification probes (
dd80b2e) - fix: use timeout process groups safely (
08dd0d2) - Embed pinned moonlight-common-c client core in zen-remote-desktop (
417ea63) - Fix moonlight bridge to the real upstream session lifecycle (
cebca65) - Add injected Sunshine host supervision and revoke (
7f8604e) - Internalize Brain engineering judgment (
f0e5ed3) - Fix callback-driven stop and bind sessions to generations (
d7420d5) - Add the upstream paired host path into the C core (
17d3de1) - Wire the paired path into the app and fix connection boundaries (
f71ba1e) - Connect the app entry and harden session, view and recovery boundaries (
befd1c4) - Resolve BouncyCastle resource merges for the Android app build (
3b692aa) - Authenticate the Moonlight bootstrap and fix mounted controls (
9d516a6) - Keep v1 capability compatibility and target engine ownership (
408b2d3) - Use the pinned Sunshine per-client APIs for target revocation (
2f0f3f2) - Pin the exact Sunshine leaf and bind generated client UUIDs (
2e54197) - Add the authenticated Moonlight enrollment handshake and admission state (
7ea69b4) - Align the admission binding and make enrollment ownership atomic (
1045661) - Wire the production enrollment caller and gate launch on admission (
558db05) - Verify enrollment receipts and use the signed control channel (
891672e) - Restore the mandatory TLS boundary on Moonlight enrollment (
4bb56a6) - Adopt the user-approved trusted deployment boundary (
d12547f) - Complete the documented trusted deployment paths (
5a58316) - Authenticate deployment evidence and fix the enrollment fixture contract (
06b1902) - Report both legacy and trusted tunnel counts in the service harness (
1fdd212) - Exercise Brain review against a pinned production caller (
7d1349b) - Refine Brain retrospectives and diagnostic evidence (
0455f95) - Document Amp BYOK integration boundaries (
d4001aa) - Add Amp external handoff interface (
ea98148) - Present Amp as a gated peer executor (
7a856c2) - Preserve SignalProtocol ownership during provider finalization (
6de1a50) - fix Pi startup trust admission (
7ead63f) - Hold scoped KDE idle/suspend inhibitors for unattended authorization (
20de2ce) - Prove inhibitor legs against a real private D-Bus transport (
5ddca56) - Invalidate the screen-saver cookie when its service restarts (
6010dca) - Fix mobile Session file preview lifecycle (
b3351f5) - Fix Session file preview hydration lifecycle (
2a73728) - Harden SSH desktop authorization and handoff (
6202010) - Qualify user-manager polkit verification (
3cfdd71) - Add one-command remote desktop authorization (
f56e682) - Make remote desktop command reachable (
7d9f76d) - Add one-line Metro debug APK build (
4e72958) - Reuse running daemon during desktop authorize (
ccfc1c1) - Document canonical desktop authorize path (
c60d07b) - Expose SSH lock recovery in desktop status (
7809118) - Initialize Zen Sunshine desktop app (
7253372) - Block desktop fallback when Sunshine is unavailable (
c5bce7d) - desktop: keep Wayland portal as single product route (
2914936) - Use KDE portal as remote desktop authorize path (
c37d1de) - Document KDE headless consent boundary (
a364f1e) - Hide remote desktop navigation and update release checks (
0f91940)
Install#
Download zen-linux-amd64.tar.gz, zen-linux-arm64.tar.gz, or zen-darwin-arm64.tar.gz for your host, plus the Android APK and SHA256SUMS. Extract the archive, install zen on your PATH, run zen, then create a pairing link with zen pair https://your-origin.
Apple Silicon support requires tmux (brew install tmux). The macOS binary is cross-built; validate it on a real Apple Silicon host before operational use.
The iOS Preview is distributed through TestFlight at https://testflight.apple.com/join/rTKCDzMt, subject to Apple's beta approval and processing.
iOS Preview identity#
- Bundle:
com.daoleno.zen.preview - Marketing version:
0.1.6 - TestFlight build:
28 - Source tag:
v0.1.6
The iOS build number is tracked independently from Android because App Store Connect build history can be ahead.
Android identity#
- Package:
com.daoleno.zen versionCode:30- ABI:
arm64-v8a - Signing certificate SHA-256:
C2:FC:5B:09:B3:86:92:EE:70:59:71:1F:E7:ED:B8:79:4C:E3:65:FE:1C:7A:06:AB:95:4E:5D:D1:BD:CD:A4:FD
Android may require permission to install from unknown sources or display a Play Protect warning. Obtainium can follow this repository's GitHub Releases. Zen does not currently provide a Play Store package; iOS Preview distribution uses TestFlight.