mewla docs

Zen v0.1.6#

This release contains the reviewed changes on main since v0.1.5.

What changed#

  • Checkpoint remote desktop WIP (ac2b314)
  • Serialize desktop input and revocation (6f8218e)
  • Integrate opt-in Wayland portal capture (d743406)
  • Document bounded Android module verification (0270b8f)
  • Isolate debug packaging from local dotenv (5f0b7fc)
  • Fix native desktop streaming and keyboard input (47fd681)
  • Move Settings to the fixed drawer footer (5ecce42)
  • Allow paired LAN desktop access with explicit consent (bfad184)
  • Implement scoped Linux unattended desktop (5035da0)
  • Fix standalone Android password entry (a29f620)
  • Fix completed-session cleanup mistaking missing tmux targets for unowned (e1674d7)
  • Refuse completed cleanup when a present owned identity cannot be proven (cf0cfc0)
  • Dispatch desktop helper, broker and agent from one zen ELF (4ddee53)
  • Prove zen-dev native rebuilds with linked C markers and keep last-good ELF (e653466)
  • Render fenced Mermaid flowcharts in shared Markdown (f4d329a)
  • Bound mermaid WebViews and isolate desktop LAN storage tests (e14ea6d)
  • Admit unattended desktop over identity TLS with distinct native recovery codes (85ca9f3)
  • Accept Unicode ellipsis in OpenCode composer readiness probe (20b0742)
  • Reverse OpenCode large-paste artifact before admission digest (f0f5d3e)
  • Preserve raw OpenCode user text in provider projection (f8b9fac)
  • Model OpenCode paste transport in delegated admission digest (bd5c1bb)
  • Remove provider-specific tmux admission digest modeling (eaa4ba5)
  • Accept successful delegated tmux transport as submission (15e863e)
  • Require confirmed transport receipt before delegated replay success (f0c7dcc)
  • Normalize and name desktop identity preflight failures (bd3b3a2)
  • Name desktop identity preflight stage and reject empty identifiers (915ac0f)
  • Redesign Git Diff review and fix bottom scroll rebound (800abf3)
  • Fix desktop capability identity echo and Android TLS negotiation (fb72c3d)
  • Reject corrupt Link transport identity without mutation (9fca158)
  • Repair delegated turn liveness absence and busy signal follow-up (7085999)
  • Unify Git Diff back handling and wide master-detail context (d6c8d41)
  • Synchronize broker owner handshake before capability (9705e27)
  • Retry broker admission while the previous agent retires (f9f2e2c)
  • Rely on listener SO_PASSCRED and prove the credential race (4ec343f)
  • Wait once for the previous owner to retire before admission (3eb003c)
  • Align owner admission deadline and abort cancelled waits (6b681cf)
  • Repair iOS remote desktop lifecycle and provision daemon native test deps (041b043)
  • Align remote desktop contract test with guarded iOS presentation signal (3a35136)
  • Provision CI encoder stack and fall back to system Xvfb (03b7d33)
  • Excuse stale live turns named by a resolved loss review (b4ba5ae)
  • Tighten resolved-loss excuse to exact Turn payload identity (5772dec)
  • Enforce system-unit cgroup owner contract and harden desktop admission (2760c7b)
  • Enforce tmux -N no-autostart on externally selected sockets (8a9e5b0)
  • Isolate tmux fixtures from user config; liveness-oracle tests; quote fixture paths (41d7ac0)
  • Guard chat worker sessions against nil watcher in fixture route (b449e85)
  • Add fixture Link v2 mint route and nil-watcher chat regression (bda97a3)
  • Require network timeout in nil-watcher chat regression (f3616a3)
  • Add persistent Agent service discovery to Services sheet (5c9a0f6)
  • Harden persistent service discovery per review (2bf3826)
  • Bound managed discovery under shared frontend-safe budget (a56a132)
  • Fix desktop pan offset across PanResponder recreation (bc40d30)
  • Raise Android version code to 28 and record native acceptance (f827110)
  • Package Metro-connected Android debug launcher (4f6a2ec)
  • Unify the runtime: one daemon, optional system-unit owner scope (7892885)
  • Isolate the runtime parity test in an owned source snapshot (d8049ee)
  • Add zen boot user-unit installation for the same runtime (0b6b34d)
  • Document the optional zen boot entry (b68cf72)
  • Fix zen boot unit ownership, paths and truthful verification (2930e38)
  • Bind zen boot ownership to the unit cgroup (a514934)
  • Bind the DEV daemon child lifetime to its watcher (638a993)
  • Confirm zen boot owner with a stable second observation (83421e6)
  • Update the DEV child-lifetime note after the pdeathsig fix (cd3261d)
  • Use real flock ownership for zen boot state ownership (79e6885)
  • Fail closed on unattributable zen boot state ownership (5fed4d2)
  • Treat unknown process owner as unresolved in boot scans (d6ee6ed)
  • Harden the runtime parity test around owned builds (bda3f94)
  • Skip zombies and proven-foreign processes in boot ownership scans (6df46b1)
  • Scope boot ownership tests to an owned proc fixture (1898416)
  • Correct boot scan ownership-attribution wording (afd37ba)
  • Unify Telegram conversation recipients (9f0cc63)
  • Improve desktop host setup and connect flow (e1cdec9)
  • Validate desktop setup and prove native connection flow (b37c602)
  • Preserve Telegram conversation routes and topic history (c1a8e54)
  • Register and verify the current desktop during host install (d91a683)
  • Fix Telegram topic navigation and local status (b12c556)
  • Support Telegram media and persistent Brain navigation (782b767)
  • Preserve Telegram file follow-up input order (ff50fc0)
  • Keep ordinary Telegram messages content-only (f3dfb9d)
  • Delete Telegram topics for removed Sessions (3d919f6)
  • Grant desktop scope in place for trusted devices (945ed7e)
  • Keep desktop host success output brief and English (f3f9d40)
  • Enable remote desktop in place from the phone (3c34a57)
  • Fix desktop grant purpose contract across TS and Go (854537a)
  • Add Wayland desktop portal and X11 host broker support (e227820)
  • Add commit-aware remote desktop keyboard and route rotation (d63db2c)
  • Support in-place desktop broker upgrade with rollback sidecar (d4ed278)
  • Fix broker upgrade rollback, live switch and backup safety (237376c)
  • Restore complete upgrade state only after verified commit (34a108f)
  • Stop the desktop helper after a synchronous portal denial (5e97c47)
  • Retain one-step rollback state across successful upgrades (a5b20da)
  • feat: add Zen orchestration verification skill (831d35f)
  • Keep upgrade rollback backups unique and preflight previous metadata (82436d7)
  • fix: harden Zen verification boundaries (13f07f0)
  • fix: reap bounded verification probes (dd80b2e)
  • fix: use timeout process groups safely (08dd0d2)
  • Embed pinned moonlight-common-c client core in zen-remote-desktop (417ea63)
  • Fix moonlight bridge to the real upstream session lifecycle (cebca65)
  • Add injected Sunshine host supervision and revoke (7f8604e)
  • Internalize Brain engineering judgment (f0e5ed3)
  • Fix callback-driven stop and bind sessions to generations (d7420d5)
  • Add the upstream paired host path into the C core (17d3de1)
  • Wire the paired path into the app and fix connection boundaries (f71ba1e)
  • Connect the app entry and harden session, view and recovery boundaries (befd1c4)
  • Resolve BouncyCastle resource merges for the Android app build (3b692aa)
  • Authenticate the Moonlight bootstrap and fix mounted controls (9d516a6)
  • Keep v1 capability compatibility and target engine ownership (408b2d3)
  • Use the pinned Sunshine per-client APIs for target revocation (2f0f3f2)
  • Pin the exact Sunshine leaf and bind generated client UUIDs (2e54197)
  • Add the authenticated Moonlight enrollment handshake and admission state (7ea69b4)
  • Align the admission binding and make enrollment ownership atomic (1045661)
  • Wire the production enrollment caller and gate launch on admission (558db05)
  • Verify enrollment receipts and use the signed control channel (891672e)
  • Restore the mandatory TLS boundary on Moonlight enrollment (4bb56a6)
  • Adopt the user-approved trusted deployment boundary (d12547f)
  • Complete the documented trusted deployment paths (5a58316)
  • Authenticate deployment evidence and fix the enrollment fixture contract (06b1902)
  • Report both legacy and trusted tunnel counts in the service harness (1fdd212)
  • Exercise Brain review against a pinned production caller (7d1349b)
  • Refine Brain retrospectives and diagnostic evidence (0455f95)
  • Document Amp BYOK integration boundaries (d4001aa)
  • Add Amp external handoff interface (ea98148)
  • Present Amp as a gated peer executor (7a856c2)
  • Preserve SignalProtocol ownership during provider finalization (6de1a50)
  • fix Pi startup trust admission (7ead63f)
  • Hold scoped KDE idle/suspend inhibitors for unattended authorization (20de2ce)
  • Prove inhibitor legs against a real private D-Bus transport (5ddca56)
  • Invalidate the screen-saver cookie when its service restarts (6010dca)
  • Fix mobile Session file preview lifecycle (b3351f5)
  • Fix Session file preview hydration lifecycle (2a73728)
  • Harden SSH desktop authorization and handoff (6202010)
  • Qualify user-manager polkit verification (3cfdd71)
  • Add one-command remote desktop authorization (f56e682)
  • Make remote desktop command reachable (7d9f76d)
  • Add one-line Metro debug APK build (4e72958)
  • Reuse running daemon during desktop authorize (ccfc1c1)
  • Document canonical desktop authorize path (c60d07b)
  • Expose SSH lock recovery in desktop status (7809118)
  • Initialize Zen Sunshine desktop app (7253372)
  • Block desktop fallback when Sunshine is unavailable (c5bce7d)
  • desktop: keep Wayland portal as single product route (2914936)
  • Use KDE portal as remote desktop authorize path (c37d1de)
  • Document KDE headless consent boundary (a364f1e)
  • Hide remote desktop navigation and update release checks (0f91940)

Install#

Download zen-linux-amd64.tar.gz, zen-linux-arm64.tar.gz, or zen-darwin-arm64.tar.gz for your host, plus the Android APK and SHA256SUMS. Extract the archive, install zen on your PATH, run zen, then create a pairing link with zen pair https://your-origin.

Apple Silicon support requires tmux (brew install tmux). The macOS binary is cross-built; validate it on a real Apple Silicon host before operational use.

The iOS Preview is distributed through TestFlight at https://testflight.apple.com/join/rTKCDzMt, subject to Apple's beta approval and processing.

iOS Preview identity#

  • Bundle: com.daoleno.zen.preview
  • Marketing version: 0.1.6
  • TestFlight build: 28
  • Source tag: v0.1.6

The iOS build number is tracked independently from Android because App Store Connect build history can be ahead.

Android identity#

  • Package: com.daoleno.zen
  • versionCode: 30
  • ABI: arm64-v8a
  • Signing certificate SHA-256: C2:FC:5B:09:B3:86:92:EE:70:59:71:1F:E7:ED:B8:79:4C:E3:65:FE:1C:7A:06:AB:95:4E:5D:D1:BD:CD:A4:FD

Android may require permission to install from unknown sources or display a Play Protect warning. Obtainium can follow this repository's GitHub Releases. Zen does not currently provide a Play Store package; iOS Preview distribution uses TestFlight.