Haven

sh.haven.app
by Zapstore _@zapstore.dev

Republished from GitHub / F-Droid by the Zapstore main account.

First release: Jul 31, 2026, 79 total releases.

Most recent release: Sep 25, 2026.

Repo

Appears in 3 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Sep 25, 2026 5.89.14
    - **Terminal macros in the long-press selection menu.** Selecting text by long-press now shows a Macros button next to Copy, Paste and Open (#661). It opens the snippet library the keyboard toolbar edits and sends the tapped snippet to the session as keystrokes — snippets with a trailing Enter execute, the rest land at the prompt unexecuted. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.13...v5.89.14
  • Sep 23, 2026 5.89.13
    - **The tab bar works past three tabs.** On a narrow screen, a fourth tab collapsed the strip into a horizontal scroller where one long title could fill the whole bar and nothing scrolled to the selected tab — closing a tab made the others reappear. Past three tabs the strip is now a single chip for the active tab that opens a dropdown listing every tab; the active row is set in bold and carries a close button, and long-pressing the chip still opens the per-tab actions menu. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.12...v5.89.13
  • Sep 22, 2026 5.89.12
    - **Paste suggestions in the keyboard reach the terminal.** IMEs that offer paste through the input connection's context-menu actions (GBoard's paste suggestion strip) had those actions silently dropped. Paste and paste-as-plain-text now run the same paste handler the terminal's context menu uses. - **psmux joins the session managers.** Saved psmux connections get the same auto-attach, session list, kill and rename handling as tmux/screen/Herdr (#658, thanks @Bearmancer). The feature docs list which session managers are covered and note that on a stock Windows OpenSSH host the default shell is cmd or PowerShell, so POSIX-shell session managers only apply where a POSIX sh is the configured login shell. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * feat(ssh): add psmux session manager entry for Windows hosts by @Bearmancer in https://github.com/GlassHaven/Haven/pull/659 ## New Contributors * @Bearmancer made their first contribution in https://github.com/GlassHaven/Haven/pull/659 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.11...v5.89.12
  • Sep 20, 2026 5.89.10
    - **Enter works in the guest agent TUI, and ctrl-c no longer kills the guest.** The guest console's host-side pty ran in cooked mode, so the terminal's carriage return was translated into a newline before the TUI ever saw it (Enter inserted a line break instead of submitting), and ctrl-c was delivered as SIGINT to the guest kernel process itself, killing the guest. The guest console pty is now raw (local shells keep their cooked mode) and the launcher sets raw tty on the guest side too. Guest rootfs bumped to uml-transport `uml-guest-8`. - **The guest's share folder mounts on every boot again.** The rootfs's init table mounted `/host` at sysinit with stderr discarded, and the mount silently failed there on every boot (the same command run by hand succeeds) — guests came up with an empty `/host`, so the endpoint backup couldn't be restored after a re-stage. The discard is gone and a failed mount now prints `HOSTFSFAIL` on the console (uml-guest-8). - **The guest agent survives long sessions.** A session mid-task grew past the 1 GB memory cap and the kernel OOM-killed opencode (device, 2026-09-20). The cap is now 2 GB; UML only touches pages the guest actually uses, so an idle guest costs the same as before. - **A terminal the agent opened keeps its alt-screen state when it becomes a tab.** Sessions claimed by the agent before a tab existed were adopted with the alternate-screen and application-cursor modes hardcoded off, so a full-screen program's (vim, less) swipe gestures misrouted and stale scrollback could paint over the live screen. The session registry now carries the live mode flows and adopting tabs consume them. - **The guest agent TUI starts reliably.** The rootfs image grew to 1 GiB (512 MiB filled up and broke the TUI's graphics library load) and ships that library preplaced; the guest's DHCP bring-up step was restored after the guest-5/6 rebase dropped it, so guests boot with a route again; and the console prints a note while the TUI's first frame loads. - **The agent endpoint survives a rootfs update.** After the first-run prompt the endpoint file is backed up to the share (in-guest, values never cross the console) and restored after a re-stage, so re-staging no longer re-asks for the key. Existing goose-format share backups are migrated too. - **Escape hatch when the TUI owns the console.** Creating `agent-shell` in the guest's share folder (Files → uml share) drops the next boot to a login shell instead of the agent. - **The guest agent's first-run prompt no longer crash-loops on model ids with spaces.** The one-time endpoint prompt on a fresh guest saved the model id unquoted, so an id like "Qwen 3.8 Max" failed to source, the launcher died on the missing variable, and init respawned it into a loop that ended the guest. Values are now written single-quoted, and a malformed endpoint.env (hand-edited, unquoted) is dropped and re-prompted instead of looping. - **Mosh screens no longer freeze for seconds during scroll bursts.** When a burst of terminal output arrived as diffs built on a state the client had already passed (its acknowledgement of that state was lost), the client skipped them and sent nothing back until the next 3-second keepalive — the server spent that whole window retransmitting a diff that could never apply (#421). A skipped diff now triggers a prompt, rate-limited resend of the acknowledgement carrying the client's actual state, which is what moves the server onto the right base.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.9...v5.89.10
  • Sep 19, 2026 5.89.9
    - **The guest terminal opens onto a coding agent.** UML guest profiles now boot straight into the opencode TUI instead of a bare shell. The guest rootfs ships opencode preinstalled (uml-transport `uml-guest-5`); on first run it asks once for your AI endpoint — base URL, API key and model id — on the console. The key is read with echo off and stored only in the guest's `/root/endpoint.env` (chmod 600), and handed to the agent through an environment-variable indirection, so no config file ever holds it. Quitting the TUI drops to a shell; logging out respawns the agent. `touch /root/no-agent` in the guest to skip it and get a plain login shell. - **Guests get enough memory to run the agent.** The guest memory cap was 384 MB, fine for a shell but an out-of-memory death for any coding agent TUI (opencode needs over 512 MB to start). The cap is now 1 GB — UML only touches pages the guest actually uses, so an idle guest costs the same as before. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.8...v5.89.9
  • Sep 18, 2026 5.89.7
    - **Linux guests come up with a working network on every boot.** The guest rootfs configured its `vec0` interface with a single `ifup -a` whose errors were silenced, and on some boots its DHCP lost the race against the passthrough helper not yet accepting on the socket — the guest booted with no interface and nothing on the console saying why. A `haven-net` sysinit step now retries DHCP a few times and prints a visible warning if the interface never comes up. - **Guest TCP no longer stalls under sustained agent load.** passt's raw-Ethernet input path could overwrite frames still queued in its packet pool; each datagram now drains into its own slot (uml-transport `uml-guest-3`). Upgrading re-stages the guest rootfs, which clears guest user data. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.6...v5.89.7
  • Sep 18, 2026 5.89.6
    - **Editing a saved Cloudflare-routed connection no longer strips its Cloudflare settings.** The edit dialog pre-populated its fields once, at a moment when the saved tunnel config hadn't loaded yet, so a saved profile came back as a plain SSH profile — and saving it deleted the embedded tunnel and the captured JWT. Opening Edit and saving without re-doing the sign-in was the one-way trip to a broken profile. The fields now apply the saved tunnel when its load completes (#643). - **Cloudflare sign-in starts from a clean session.** Each sign-in now clears every cookie the WebView holds for both the app hostname and the team domain, not just the app domain's `CF_Authorization` — stale team-domain sessions were surfacing Cloudflare's "Invalid login session" interstitial on repeat sign-ins and made users tap through a recovery link (#643). --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.5...v5.89.6
  • Sep 17, 2026 5.89.3
    - The Connections screen's peer-discovery scan no longer probes Tailscale's LocalAPI (`100.100.100.100`) when the Tailscale app isn't installed. That address only exists on the app's own TUN interface, so without it installed every scan fired a doomed connect attempt that firewall apps reported as Haven phoning out (#654). With Tailscale installed, discovery works exactly as before. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.89.2...v5.89.3
  • Sep 16, 2026 5.89.0
    - **AI chat routes through SSH and Reticulum.** An OPENAI profile gains an AI-route setting next to its endpoint: Direct (default), Via SSH, or Via Reticulum. Via SSH opens a local port forward through a connected SSH carrier profile — jump-host auth and prompts included — and the chat's HTTP dials the loopback forward while URL rewriting stays off, so TLS hostname verification still runs against the real endpoint name. Via Reticulum forwards over a connected Reticulum carrier the same way; the carrier must already be connected (a forward-only consumer can't keep the RNS stack alive by itself). A route and tunnel/proxy routing are mutually exclusive — setting one clears the other. The route is torn down on every disconnect path: disconnecting the endpoint closes its forward, and a carrier dying fails the endpoint's sessions and drops the forward, so the next send refuses until a fresh connect rather than silently bypassing the route. - **Chat images from the Files tab.** The chat attach sheet gains a Files option alongside gallery and camera: pick a file from any Files-tab backend to attach. Files above 20 MiB are rejected with the size shown; the pick banner has a Cancel, and cancelling leaves no staged attachment. - **Take photo from the terminal attach sheet.** The terminal paperclip sheet gains a Take photo option next to send-file and the scanner entries: the capture rides the existing send-file path, uploading through the Files tab and inserting the remote path at the cursor. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.88.0...v5.89.0
  • Sep 14, 2026 5.87.86
    - **USB card rescue console (live route)**. A failing SD card can now be rescued in seconds instead of minutes: Desktop tab → Manage → "Open USB card directly (rescue console)". The card's raw sectors are served over NBD to the Linux guest, which attaches it as `/dev/nbd0` and prints the `ddrescue`/`mdir` command lines — the VM route stays for file browsing. Read-only by default; rescued images are written to Haven's `uml/share` app folder via the guest's new hostfs share. The guest rootfs image gains ddrescue, nbd-client, mtools, e2fsprogs and util-linux (same 512 MB image, one re-unpack on update, tracked by a version marker). MCP: `open_usb_drive` gains `route:"guest"`, `list_usb_drives` reports `live[]`, `close_usb_drive` takes `kind`. - Mosh sessions that die on their own now write their transport trace into the connection log. The in-memory trace was only captured on a manual disconnect, so after an auto-recovery the log showed just the healthy replacement session and the freeze window was lost (#421). --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.85...v5.87.86
  • Sep 13, 2026 5.87.85
    - Fixed the app closing when opened from the launcher right after using Disconnect All in the connection notification (#640). Disconnect All is meant to close Haven itself at disconnect time, but on devices that silently block the service's background launch the pending exit flag survived, and the next launcher open was finished immediately. Only the service's own launch can exit the app now; a plain open clears the flag instead. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.84...v5.87.85
  • Sep 13, 2026 5.87.83
    - Fixed terminal Copy replacing the selection with surrounding TUI content (#639). The smart-copy panel detection matched any multi-row selection inside a full-screen TUI such as zellij, whose pane borders sit at the same column of every row, and copied whole rows between the borders instead of the highlighted text. Border stripping now applies only when the selection itself crosses a border column, and the border character is excluded when the selection starts on one. - Fixed the terminal Copy button overwriting the clipboard with an empty clip when the selected rows had scrolled out of the snapshot between the long-press and the tap. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.82...v5.87.83
  • Sep 12, 2026 5.87.81
    - Fixed WireGuard tunnels failing to start in v5.87.80 with `socket protection function not set` (#637). The NetBird integration registers an Android socket-protection hook that was also applied to the WireGuard tunnel's UDP binds, and no protect function exists for Haven's userspace tunnels; the WireGuard tunnel start now clears the shared hook list before binding. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.80...v5.87.81
  • Sep 12, 2026 5.87.80
    - A new GUEST connection type boots a real Linux kernel on the device (UML, arm64 full flavour). - NetBird is a new tunnel type, added with a setup key like Tailscale's auth key (#492). - Fixed a rootfs import that aborted when the tarball names directories like `dir/.` (#546). - **The Linux guest transport** (#uml). A GUEST connection runs a whole Linux kernel as one of Haven's own processes — user-mode Linux — with its own root filesystem and network. The connection editor needs nothing but a name; the kernel args are fixed. The rootfs image (~512 MB unpacked) is staged to app storage on first connect, with a free-space check. Networking goes through passt in app context, so no root or VPN permission is involved. Closing the tab sends `poweroff` and waits up to 5 s before killing, so the ext4 image gets a clean unmount. arm64 full-flavour builds only: the payload is four native files (~13 MB in the APK after the kernel's debug-symbol strip) and the picker drops GUEST when any of them is missing. - **NetBird tunnels** (#492). The tunnels screen gains NetBird as a third standalone backend, next to WireGuard and Tailscale. Add one with a setup key from the NetBird dashboard; an optional management URL selects a self-hosted management service instead of the hosted one. The netstack runs in Haven's own process (the same gomobile bridge that carries WireGuard and tsnet), so no VPN permission and no second app is involved. Connection profiles route through it like any other tunnel.
    More…
    - **Fixed a rootfs import that aborted on `dir/.` tar entries** (#546). Some rootfs producers write directory entries with a trailing `/.` instead of a trailing slash, sometimes with a plain regular-file typeflag. The extractor wrote through that name, the OS resolved it to the existing directory, and the import died with EISDIR part-way through. Entry names are now normalized before use: a trailing `/` or `/.` marks the entry as a directory, and such an entry extracts as a plain directory. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.79...v5.87.80
  • Sep 9, 2026 5.87.79
    - A connection can pin its outgoing SSH socket to a local address, like ssh -b (#636). - Fixed a gap in the extended keyboard toolbar's second row (#628). - **Connections can bind the outgoing SSH socket to a local address** (#636). The SSH edit dialog gains an optional "Bind address" field: set it and Haven dials the server from that local interface or IP instead of letting the OS choose, the same role ssh -b plays on the command line. Useful on multi-homed hosts and with source-address firewalls. A bind address and a jump site are mutually exclusive — the dialog keeps them apart. - **Fixed a gap in the extended keyboard toolbar's second row** (#628). The v5.87.78 unpinning of the toolbar placed a left-side Desktop key beside the keyboard toggle, which grew that row by a column and left empty cells under the second row whenever the rows held unequal numbers of keys. The Desktop key now shares the keyboard toggle's column in the opposite row and takes no extra cell, so both rows stay paired. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.78...v5.87.79
  • Sep 8, 2026 5.87.78
    - Six new terminal color schemes (#627). - The keyboard toolbar no longer leaves a dead cell where the Desktop key was hidden (#628). - Navigation-bar tabs are configurable per tab: reorder them and choose Auto, Show or Hide (#629). - **Six new terminal color schemes** (#627). The terminal color picker gains six schemes; persistence is by name, so saved selections survive the addition unchanged. - **The keyboard toolbar's fixed keys are unpinned** (#628). The keyboard toggle and the auto-shown Desktop (VNC/RDP) key were pinned to a fixed column: hiding the Desktop key left an empty dead cell under the keyboard toggle, and the keyboard key could not be moved. Both are now ordinary toolbar items, and a Desktop key placed on the left now sits beside the keyboard in the top row instead of at the bottom of the first column.
    More…
    - **Navigation-bar tabs are configurable per tab** (#629). The bottom navigation bar was already reorderable; each tab now also has an Auto / Show / Hide choice, replacing the single show-all-tabs switch. Auto keeps the default behaviour, Show pins a tab on even when empty, Hide removes it. An existing show-all-tabs preference carries over as Show on every tab. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * Update the Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/626 * add(themeing): various new themes by @HolgerHuo in https://github.com/GlassHaven/Haven/pull/627 * fix: desktop/voice button position by @HolgerHuo in https://github.com/GlassHaven/Haven/pull/628 * feat(ui): togglable nav bar items by @HolgerHuo in https://github.com/GlassHaven/Haven/pull/629 * Update of the Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/630 ## New Contributors * @HolgerHuo made their first contribution in https://github.com/GlassHaven/Haven/pull/627 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.77...v5.87.78
  • Sep 6, 2026 5.87.77
    - A USB drive Android can mount opens in the Files tab instead of booting a VM (#603). - A preference keeps session names on tabs when a multiplexer sets its own title (#625). - **USB drives now offer a mount route before the VM boots** (#603). Opening a USB drive used to commit to a minutes-long QEMU boot before anything was known about the drive. Android mounts vfat/exFAT sticks itself, so there is often nothing to boot: when Haven recognises the Android mount for the drive, a picker offers Browse directly (Files tab, no VM) or Open in Linux VM (for ext4/GPT/LUKS and anything Android can't mount). Drives Android can't claim keep the VM-only flow, with a note on why the VM exists. `open_usb_drive` gains `route=vm|android|auto` (`vm` stays the default, so existing automation is unchanged) and `list_usb_drives` reports the Android mount per drive. - **A new preference, "Prefer session names in tab titles", controls whether program titles override session names on tabs** (#625). Tabs attached to tmux/zellij/screen/byobu keep their session name in the tab strip instead of letting a program's OSC 0/2 title paint over a Rename. On by default — it only ever bites on multiplexer tabs; tabs without a multiplexer name (plain SSH, local shells) keep the v5.87.76 behaviour either way. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.76...v5.87.77
  • Sep 5, 2026 5.87.76
    - The terminal title a program sets shows on its session tab (#625). - Five new MCP tool groups for the agent endpoint. - **The terminal title a program sets now shows on its session tab** (#625). Shells and CLI agents that set the window title (OSC 0/2) drive the tab label; tabs whose program never sets one keep the session label. Fixes two layers: the emulator never captured the title at all (it matched prop 7; `VTERM_PROP_TITLE` is 4), and nothing in the tab strip read it. SSH and local tabs both pick it up; long titles ellipsize. - **The agent endpoint gains five MCP tool groups** (senses, notifications, reflexes, cross-protocol verbs, credentials). One-shot device reads (state, sensors, location, camera frames), a notification listener ring for inbound presence, terminal scrollback search plus directory watches, workspace save/compose, and credential/age-identity/TOTP listing. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * Update of the Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/624 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.75...v5.87.76
  • Sep 4, 2026 5.87.75
    - FIDO2 keys over NFC work with the Nitrokey 3A (#623). - Keyboard-icon behavior in VNC and RDP sessions refined (#511). - **FIDO2-over-NFC key import now works with the Nitrokey 3A** (#623). The Nitrokey answers the applet SELECT with status word 6106 ("more data available") instead of 9000, expecting the reader to fetch the rest with GET RESPONSE. Haven treated that as a failure. SELECT now drains the chained response before deciding, so the key imports. - **The keyboard icon in VNC and RDP sessions now enables the hardware keyboard** (#511). Follow-up to the physical-keyboard support in 5.87.74: when a physical keyboard is attached, tapping the keyboard icon routes hardware keystrokes to the guest instead of opening the on-screen IME; with no hardware keyboard it still shows the IME. Tapping the session canvas re-claims hardware-key focus. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.74...v5.87.75
  • Sep 3, 2026 5.87.74
    - Herdr joins tmux, Zellij, Screen and Byobu as an SSH session manager (#615). - Adding a distro asks before it downloads (#620). - Physical keyboards reach VNC guests (#511). - **Herdr is now a session manager for SSH connections** (#615, contributed by @w3lld1). Attach through Herdr the way you attach through tmux or Zellij: pick it in the profile editor and Haven lists, attaches to, and creates named Herdr sessions. Detach is prefix+q, Herdr's default prefix being ctrl+b. - **Adding a distro now asks before it downloads** (#620). Tapping "+ Ubuntu (~400 MB)" used to start the download straight away. It confirms first, so a mis-tap on a metered connection costs nothing.
    More…
    - **Physical keyboards work in VNC sessions** (#511). Keys typed on a hardware keyboard now reach the VNC guest instead of only the on-screen keyboard. The session view takes key events at the window level, mirroring the fix that landed for RDP. - Serbian (sr) translation refresh. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * Update Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/616 * build(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 by @dependabot[bot] in https://github.com/GlassHaven/Haven/pull/617 * feat(ssh): add Herdr session manager support by @w3lld1 in https://github.com/GlassHaven/Haven/pull/615 * Update of the Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/619 * Update of the Serbian translation by @eevan78 in https://github.com/GlassHaven/Haven/pull/621 ## New Contributors * @w3lld1 made their first contribution in https://github.com/GlassHaven/Haven/pull/615 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.73...v5.87.74
  • Aug 31, 2026 5.87.73
    - **The suggestion strip is gone from password fields on Samsung keyboards** (#614). Honeyboard kept drawing its autocorrect/suggestion bar over secure fields, where it has no business appearing. The field type now carries the signal Samsung actually honours — "this holds a free-form token, don't rewrite it" — so the strip stays away, on the secure fields and on the ones that gate autocorrect for the commit path. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.72...v5.87.73
  • Aug 31, 2026 5.87.72
    - **Typed characters no longer double up in RDP sessions** (#606). Some soft keyboards (AOSP's Spanish layout among them) fire a synthetic hardware-key event alongside the text commit for the same press, so the guest received the character twice — doubled glyphs and, on the IME's flush cadence, a stream of repeats. While the soft keyboard holds focus, printable keys now go through the commit path only; arrows, F-keys, Enter, Tab and modifiers still pass through the hardware path as before. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.71...v5.87.72
  • Aug 30, 2026 5.87.71
    - **Swiping between tabs works again after exiting the last terminal** (#609). With the Swipe key latched, pressing Ctrl+D to exit the final session left the latch holding the horizontal gesture on the empty Terminal page, so left/right swipes did nothing and you were stuck. The latch now owns the gesture only while a terminal tab is open; the empty page releases it to the tab switcher, and the latch stays armed for your next terminal. - **A Dictate key that works without a mic on the keyboard** (#604). On devices whose keyboard has no dictation of its own (an e-ink reader forcing its own keyboard, or a voice IME that isn't the active one), the old Voice key could start nothing. The new key launches the system speech recognizer and sends the transcript to the active tab regardless of keyboard; the recognition service owns the microphone, so no recording permission is added to the app. The Voice lock toggle keeps its old behaviour for Gboard users. - **The mouse cursor shows before the first move on SPICE** (#598). A SPICE guest that hadn't pushed a cursor shape yet left no pointer on screen until the first interaction, even though clicks already worked. A built-in arrow is now drawn at the tracked position until the guest's own shape arrives. - **Serbian (sr) localization**. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid
    More…
    carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * Add Serbian localization strings by @eevan78 in https://github.com/GlassHaven/Haven/pull/612 ## New Contributors * @eevan78 made their first contribution in https://github.com/GlassHaven/Haven/pull/612 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.70...v5.87.71
  • Aug 28, 2026 5.87.70
    - **Security keys (sk-) now work through agent forwarding** (#602). A server whose authorized_keys entry is an sk-* FIDO2 key could not be reached with "Forward authentication agent" on: the agent refused the key types it didn't recognise. Forwarded requests for security-key identities are now answered by the same on-device FIDO logic as direct connections, including the per-sign touch prompt, and an unsupported request fails cleanly instead of wedging the session. - **A second Reticulum tab no longer ends up as a live session with no terminal** (#601). The duplicate connect succeeded but the terminal could miss its shell and never attach, leaving the notification counting a session the screen didn't show. The shell is now published before the session is marked connected, and any attach that still skips says why in the logs. - **USB-drive VM failures now name the failed stage** (#506). "sshd never answered on 127.0.0.1:<port>" left no way to tell whether the VM's network or its SSH server was at fault. The VM retries its internal address until it has one, and the error now says "no network inside the VM", "SSH server did not start", or "port forward did not relay" instead. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.69...v5.87.70
  • Aug 28, 2026 5.87.68
    - **Opening a large file from the Files tab no longer crashes Haven** (user-reported). Opening a file over 20 MB in the editor read the whole file into memory and killed the app (reproduced with a 58 MB JSON export). Oversized files are now refused before any data is read, with a message naming the file size and the limit, including when the file is opened by an agent over MCP. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.67...v5.87.68
  • Aug 28, 2026 5.87.67
    - **The FIDO PIN prompt clears when a wrong PIN is retried** (#531). After the security key rejected a PIN, the dialog reopened prefilled with the rejected value, so tapping OK again just burned another attempt. Each fresh prompt now starts with an empty field. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the
    More…
    desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.66...v5.87.67
  • Aug 26, 2026 5.87.63
    - A Reticulum shell session whose link dies now disconnects cleanly and drops the tab, instead of freezing with a dead input line (#599, split out of #588). - **A dead Reticulum link left the shell frozen** (#599, split out of #588). When the link under an open rnsh shell went away, the session's exit code never completed. The disconnect watcher was waiting on it, so it never ran and the tab stayed frozen: every keystroke failed and nothing reconnected. The shell path now fails the session's exit code when the link closes, the same wiring the command path already had. A dead link now runs the normal disconnect: the session is dropped and you can reconnect. This does not reconnect the shell on its own. The remote PTY dies with the link, so a reconnect would land in a fresh shell; reconnecting in place is a separate follow-up. Verified on a host loopback rig against a live link, with a new regression test on the dead-link path (mutation-checked). The reporter's exact repro, restarting rnsh on the server, has not yet been retested on a device. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.62...v5.87.63
  • Aug 25, 2026 5.87.61
    - RDP sessions that use H.264 video, which is every KRDP session, no longer lose about 80ms per frame to moving the decoded frame between the decoder and the renderer (#466, reported by @ysalmon). - **The decoded frame was being handed back the expensive way** (#466, reported by @ysalmon). Haven decodes H.264 with the phone's hardware decoder and then has to get the picture from the Android side to the Rust side that draws it. It did that by returning the frame as a buffer for the bridge between the two languages to carry across. That crossing cost about 47ms for a single 1080p frame. It is not the copying. The same 3MB copied inside Rust takes 0.06ms, and every individual step of the bridge's own conversion runs at tens of gigabytes per second. The cost is in the crossing itself, it is proportional to the number of bytes, and it works out at about 62 MB/s — roughly 725 times slower than moving the same bytes any other way. The decoder now writes the frame straight into the buffer the renderer already owns, so nothing is carried across. Same picture, same decoder, same packing code and the same tests over it; only the handoff changed. Measured with a stand-in decoder that does no decoding at all, so the number is the crossing and nothing else: **47.4ms to 0.30ms for a 1080p frame.** There is a rig for this in the repository, because the measurement needs no RDP server, no H.264 and no phone, and the next person to touch this boundary should be able to check it in a minute.
    More…
    What this does not fix, from the same reporter's measurements: the hardware decode itself at 9-25ms per frame, and packing the decoder's output at 6-29ms. Those remain, and the second one is now the largest thing left. Not verified end to end on a device. The only H.264 server available here needs a Wayland session that this machine cannot give it, so the boundary is measured directly and the pixel path is covered by unit tests rather than by a real KRDP session. The reporter has captured logs through six releases; this one changes what those logs should say. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. ## What's Changed * fix(navigation): restore terminal after unlock by @tsubus in https://github.com/GlassHaven/Haven/pull/590 ## New Contributors * @tsubus made their first contribution in https://github.com/GlassHaven/Haven/pull/590 **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.60...v5.87.61
  • Aug 25, 2026 5.87.60
    - A Reticulum session one hop behind a shared instance now completes its handshake (#588, reported by @Slayerx96). - Reconnecting after a Reticulum disconnect works, and the gateway refusal now clears without force-stopping Haven (#588). - A security key that signs without the PIN you asked for is now refused with a reason, not an unexplained "Permission denied" (#531, reported by @pixel4696). - A Reticulum connection can import an identity file you already have (#585, reported by @Slayerx96). - **A link was being addressed as though it were a node** (#588, reported by @Slayerx96). Every established Reticulum link is filed in the path table, and outgoing packets were then routed against it. One hop away behind a shared instance that meant wrapping the packet in a transport header addressed to the link id itself. No transport node carries that address, so the shared instance dropped it, and the session died of silence 15 seconds later reporting a version handshake timeout. Two hops took a different branch and worked, which is why the same setup could reach a shell through one app and not another.
    More…
    A link id names a link, not a node, so it is never routed now. The decision is a pure function with 12 tests; removing the link exclusion fails three of the four link cases. Verified on a OnePlus 13 against a real shared instance one hop from an rnsh server. Before: `Sending to <link> via path (1 hops)`, and the server log stops at "link request accepted". After: `Broadcasting to <link> on 1 interfaces`, link established at 14ms round trip, identity sent, session connected, and the server logs the incoming session. This also changes how link proofs are sent, which is wider than the reported symptom. - **The Reticulum stack outlived the session that started it** (#588, reported by @Slayerx96). The stack is a process singleton and nothing released it, so the mode chosen by the first connection stood until Haven was force-stopped. The v5.87.59 message explaining that a gateway cannot be added to a shared instance was correct, and then would not go away after disconnecting. The stack is now dropped once the last session ends. Doing that turned every connect into a cold start and exposed two further faults, both fixed here and both only found by testing on hardware: the shared-instance interface was being used before its read loop had connected, so the first packet met an interface that was not up and a link request is not retried; and stopping Reticulum left its detached interfaces registered, so the next session could transmit onto a dead one. The passing device run above is a reconnect, so it covers these. Still not fixed: a link request logs as sent even when the transmit errored. - **A signature that skipped the verification you asked for** (#531, reported by @pixel4696). A key marked "Require PIN at sign-in" makes Haven run the CTAP2 PIN exchange, and the authenticator is then supposed to mark the assertion as verified. Haven never checked that it had. It assembled the signature from whatever came back and sent it, and a server that requires verification answered "Permission denied (publickey)" — the same thing it says for a key it has never seen. The two cases were indistinguishable from the phone. Haven now refuses to send such a signature and names the flags byte in the failure. This does not yet explain #531; it makes the difference visible on screen rather than only in logcat. Worth naming as a behaviour change: a setup with "Require PIN" on, a token that returns no verification, and a server that does not insist on it authenticates today and will now be refused. - **Importing a Reticulum identity you already have** (#585, reported by @Slayerx96). A Reticulum server whitelists a client by identity hash. Haven minted its own and kept it, but there was no way to arrive with one, so the whitelist entry had to be built around whatever Haven generated. The connection form now shows the hash this device presents and offers to import an identity file. Only a file can work — the hash is a fingerprint of a private key, not the key itself. Nothing is touched until the source parses, the key being replaced is moved aside rather than overwritten, and a failure part way through puts it back. Reading the stored hash deliberately does not create one, so a connection screen on a fresh install reads "none yet" instead of minting a key as a side effect of being looked at. Six tests on the file rules, checked to fail against the mistakes they describe. Not verified: the picker and the import have not been run on a device, and no identity from another Reticulum install has been imported yet. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.59...v5.87.60
  • Aug 25, 2026 5.87.59
    - A stray tap no longer refuses an MCP consent prompt you never read (#556, #576). - A second Reticulum gateway in one session now gets its own interface (#588, reported by @Slayerx96). - **A tap outside the sheet counted as an answer** (#556, #576). Consent prompts are meant to be non-skippable, and the code said so in a comment: tapping outside the sheet does not dismiss it, the user must tap Allow or Deny. Nothing implemented that, so the default applied. The tap closed the sheet and was recorded as a deliberate refusal, with no sheet left on screen to show what had been refused. The first tap of a reconnect could refuse a request nobody had read, and because a refusal counts as considered, it also armed the cooldown that suppresses repeats. Any dismissal that is not a button press now puts the sheet back. A request that should go away still does, through the existing timeout, which is the outcome that fails closed rather than open. Measured on the phone. With the fix, a tap near the top of the screen puts the sheet back 0.13s later and the request is still pending afterwards, then answers normally. On v5.87.57 the same tap produced a refusal that was never shown.
    More…
    #576 was filed as rotation denying an open prompt. Rotation was measured not to dismiss the sheet at all, so that reading was wrong and the guard shipped for it in v5.87.45 never ran. A stray tap fits the symptom, which is why both numbers are here, but the original denials in that report stay unexplained. - **A connection profile adds an interface instead of replacing the stack** (#588, reported by @Slayerx96). The first Reticulum connection of a session decided the whole network stack and every later one was ignored, so a second gateway reached nothing and looked connected while doing it. A profile now contributes an interface. A second gateway adds a second interface, reconnecting to one that is already up does not duplicate it, and a shared instance mixed with a gateway in the same session is refused with a reason, because the shared instance owns the interfaces and Haven has no business adding its own alongside. The planning is covered by tests, checked to fail against the old behaviour. Only the shared-instance path is verified on hardware; two real gateways in one session have not been run. Declaring all interfaces up front, independent of any profile, is still not done. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.58...v5.87.59
  • Aug 24, 2026 5.87.55
    - SPICE servers that ask for a password can now be connected to at all (#584). - **A password that was collected and never sent** (#584). Haven's SPICE profile has a ticket field. The value was saved, carried down through the session layer, handed to the native client — and then dropped one step short of the code that puts it on the wire. Only the WebSocket build of that client ever read the password back; the path Haven actually uses had no password argument on any of its channel connections, so it authenticated with an empty string and the server refused it. Anyone with a password on their SPICE server saw the connection fail and had no way to tell it was not their own configuration. Servers without a password were never affected, which is why this went unnoticed for so long — it is invisible unless you set one. All four of the connections a SPICE session opens have to authenticate separately, so fixing only the first would have moved the failure along to the next one. Verified against a password-protected QEMU server: the right password connects and the picture arrives, while a wrong password and a missing password are both still refused, which is the part that shows the password is genuinely being checked rather than skipped. - Agent-facing: the update check's daily throttle and its already-notified marker can now be read and cleared over MCP (#578), so the launch-time check can be exercised on a device instead of only in tests.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.54...v5.87.55
  • Aug 24, 2026 5.87.52
    - The update check is now drivable by an AI agent: a `check_for_update` tool and the `update_check_enabled` preference (#578). - **The agent endpoint can now see the update check** (#578). Verifying the feature that shipped in v5.87.51 meant tapping through Settings by hand and reading the device log, because the one switch the whole flow hangs off was not in the MCP preference whitelist and there was no verb to run a check. Both are now there. `check_for_update` reports the channel, the installed version and the verdict in one call, and it reports the channel even when the answer is that no update is offered — so an agent can see *why* nothing was offered rather than only that nothing was. It asks for consent before running, because it makes a request to GitHub and the whole point of this feature is that the request is something you opt into. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.51...v5.87.52
  • Aug 24, 2026 5.87.49
    - Copying a selection that was dragged down and to the left no longer copies more text than was highlighted. - The RDP desktop size now accepts 800x600 and 640x480. Anything shorter than 640 was silently rounded up (#572). - **Copy now returns what you highlighted.** Selecting across several rows and finishing to the left of where you started copied more than the highlight showed. This included up to a row's worth of extra characters at each end, while the screen kept showing the smaller region. The two halves disagreed. The code that draws the highlight followed the anchors you dragged between, and the code that built the clipboard text took the leftmost and rightmost columns instead. Those agree only when a selection happens to run down and to the right. Both now read the same bounds from one place. The fix is also open as a pull request against upstream termlib, since the bug is theirs as much as ours. - **An RDP desktop shorter than 640 pixels is no longer rounded up** (#572). Asking for 800x600 stored 800x640, silently, and 640x480 could not be set at all. This was awkward for a protocol whose classic mode is 640x480, and a real obstacle if the machine at the other end only runs at one size. The floor exists to reject a nonsense request and was simply set far too high. 🔍 **Neither of these was reported as itself.** The copy bug was found while investigating a different copy complaint that turned out to have another cause entirely. The RDP floor turned up while checking a claim I had made about an unrelated SPICE problem, a claim that was wrong. Chasing a wrong answer honestly is a reasonable way to find the thing next to it. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.48...v5.87.49
  • Aug 23, 2026 5.87.47
    - The network scan on a connection can now scan through that connection's jump host. This allows it to find machines on the far side rather than the ones next to your phone. - **The host scan works through a jump host**. When a connection has one selected, a second button appears next to "Scan Network". This button sweeps the jump host's own network instead of yours. This feature is most useful in the case where the local scan is least useful, such as on a VPN or anywhere the machines you want are not on the network your phone is currently connected to. The system asks the jump host which networks it is on and sweeps the one carrying its default route. This detail is more important than it may seem. A developer machine is routinely on four networks at once, including a docker bridge, a libvirt bridge, a compose network, and the real LAN. Sweeping all of them would turn one 254-address scan into over a thousand probes across three networks that were not requested. Results are addresses only, by design. Resolving names would ask your phone's resolver about a network it cannot see. A confidently wrong hostname is worse than no hostname at all. The jump host needs to be connected first. Dialling it from inside the edit dialog would cause host-key prompts and passphrases to appear on top of whatever you were typing. Therefore, the system asks you to connect it rather than attempting to do so poorly.
    More…
    🛰️ **The scan probes with an ordinary TCP connect, which is why this was a small change.** Pointing that probe at a SOCKS proxy moves where it originates without altering what it does. Haven already spoke SOCKS over SSH on both of its engines. The work was not in the tunnel. It was in asking the right machine which network to sweep and in not hiding the answers behind a filter meant for something else. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.46...v5.87.47
  • Aug 22, 2026 5.87.46
    - Haven can now pair a computer for wireless adb debugging on its own. It finds the pairing port and asks for the six digits in a notification. This keeps the system's pairing dialog on screen while you read them (#575). - **Pairing a computer over wireless debugging no longer means hunting for a port** (#575). Android advertises its pairing listener only while the pairing dialog is open. It uses a fresh port every time. This is why a port written down once never works twice. Haven now discovers it live over mDNS while it opens the dialog for you. It asks for the six digits in a notification reply field rather than in a window of its own. That reply field matters more than it sounds. The first version of this drew an overlay over the pairing dialog. That approach cannot work. Android's Settings windows set an anti-tapjacking flag that hides every third-party overlay while they are in front. The overlay sat in the window list the whole time and was simply never drawn. Hiding it is precisely what the flag exists to do. This means there was no workaround worth looking for. A notification reply field is drawn by the system instead. The flag does not apply to it. It needs no "display over other apps" permission. It arrives at the top of the screen above the dialog without taking focus away from it. What this does not do yet: Haven hands the code to the agent, which runs the pairing command from the computer. Completing the pairing on the device itself needs a key exchange Haven has no implementation of. That is a separate piece of work. 🧭 **The overlay design was ruled out by a single command, and that command should have been the first one run.** Establishing that a permission can be granted is not the same as establishing that the platform permits the thing the permission enables. The first question was asked for days. The second took one line and ended the design immediately.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.45...v5.87.46
  • Aug 22, 2026 5.87.45
    - The terminal keyboard could stop reaching the session after a reconnect, until you disconnected and reconnected by hand. This was a regression from v5.87.43. - A screen rotation while an agent permission prompt was open counted as a refusal (#576). - **The terminal keyboard no longer goes deaf after a reconnect.** This is a regression from v5.87.43's HyperOS crash fix, reported the same day, and it is the reason for this release. That fix deliberately takes the hidden input view out of its parents' focus record during Compose's teardown. It relies on the view being re-added, or on the next recomposition, to put it back. When a teardown did neither, the result was silent and self-sustaining. The view believed it held focus, so nothing re-requested it. The parent chain did not record it, so the keyboard delivered to nobody. Rebuilding the session was the only way out, which is exactly the workaround the reporter had found. The view now repairs that disagreement itself, on window-visible and when the keyboard is asked for. The repair is targeted at its own parent rather than a search from the top of the window. This ensures it cannot re-enter the disposing hierarchy that v5.87.43 exists to protect. Stated plainly: the sequence that produces the broken state has not been reproduced on a device. This closes the state rather than the path into it, and logs the repair so the next occurrence names its own cause. - **A rotation is no longer an answer** (#576). Rotating the device while an agent was asking permission denied the request, and the sheet vanished mid-read. Every dismissal was treated as a refusal. This is right for a swipe or a tap outside, but wrong for a configuration change. Android recreates the screen and the sheet goes with it, through the same code path. Worse than the interruption, that phantom refusal was recorded as a deliberate one. This armed the cooldown that suppresses repeated prompts. Consequently, a decision nobody made could silence the retry that followed. Genuine dismissals still refuse. - **Agent permission prompts now say who asked and why**, and the adb pairing flow can find its own pairing port instead of sending you to hunt for one (#575). This is groundwork. The on-device code box still needs a permission Android withholds from sideloaded apps, and the release notes will say so when it lands.
    More…
    🪞 **Every defect fixed here was found by someone using the app, not by the tests that shipped alongside it.** The focus regression, the rotation denial, and four more in the pairing work were all reported from a device within hours of shipping. None were logic errors. They were assumptions about the environment and about what the person on the other end is told. The tests pinned the behaviour that was imagined. The device supplied the behaviour that was real. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.44...v5.87.45
  • Aug 22, 2026 5.87.44
    - Terminal crash on HyperOS/Android 16 warm return, round two. The v5.86.8 fix relied on a 100ms assumption that a Xiaomi Mi 17 does not honour (thanks Maksimus). - The file editor now carries the same Compose interop-teardown guard, on the same code path. - **The HyperOS warm-return crash fix now holds, regardless of how late the device performs the teardown** (thanks Maksimus, whose second line-by-line trace of the disposal path was as precise as the first). v5.86.8 stopped the terminal's hidden input view from holding focus while the app was away. It handed focus back 100ms after the return, which was intended to be past the frame where Compose flushes its deferred composition teardown. On a Xiaomi Mi 17, that flush arrives later than 100ms. Consequently, the view took focus back before the flush landed, and the crash remained unchanged. Compose runs an `onReset` callback on the same stack frame as the view removal that triggers the fault. The guard now sits there and depends on no timing at all. Investigating the report revealed a second defect underneath. The flag used by the July fix to relinquish focus is not safe to touch during a teardown. Android's `View.setFlags` surrenders focus by calling the public `clearFocus()` method. This starts a focus search from the root of the window. This is precisely the call that re-enters the half-disposed Compose hierarchy and throws an exception. The guard now uses the one primitive that does not search. It removes the view from its parents' record of who holds focus and leaves the view's own focus flag alone. Android then re-establishes the chain by itself when Compose puts the view back. - **The file editor received the same guard.** It is a page of the same pager. Its editor view holds focus for the entire time the app is backgrounded. It had no protection at all. Nobody has reported a crash there. This is the same mechanism on the same code path, fixed before it is reported. 🧿 **Neither defect was found by reading the code.** The timing hole came from a reporter who traced the disposal path line by line on the failing device. The unsafe flag came from a regression test that failed for a reason the fix had not anticipated. Both guards are pinned by tests that fail when the guard is removed. However, those tests do not include a Compose hierarchy. Therefore, they establish that no focus search runs during teardown, not the absence of the exception on a Mi 17. The final step is the reporter's retest.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.43...v5.87.44
  • Aug 21, 2026 5.87.42
    - New setting: hide Haven's bottom tab bar on the terminal screen, leaving the Android status and navigation bars visible (#521 — thanks a8645322) - **The terminal screen can now shed the app's own tab bar** (#521). The existing fullscreen toggle bundled two decisions — hide Haven's chrome and hide Android's chrome — that have no business being the same switch: wanting the clock and notifications while working in a terminal is entirely reasonable. The new toggle (Settings → Terminal → "Hide app tab bar in terminal", off by default) hides only Haven's bottom tab bar while the terminal screen is selected. The swipe gestures that switch screens keep working, the bar returns as soon as the pager settles anywhere else, and the ≥600dp side rail is unaffected. Translated into all 11 shipped locales. Not yet exercised on a device; the reporter's retest is the closing verification. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.41...v5.87.42
  • Aug 21, 2026 5.87.41
    - SPICE mouse motion is paced against the server's acknowledgements, fixing the lag and intermittent stalls left after v5.87.40 made the pointer work (#572 — thanks empanadablues) - **SPICE pointer messages are now flow-controlled** (#572). The moment v5.87.40 made the relative mouse work, the reporter found the next layer: lag, and stalls that only extra movement cleared. The client had been sending pointer messages as fast as the finger moved and discarding the server's acknowledgements as unknown messages — an unpaced stream into QEMU's tiny PS/2 packet queue that the guest replays late, then chokes on. Sends now claim a slot in an eight-message window; when it fills, the newest position is parked and the acknowledgement handler flushes it, so a drag's final position always lands. Verified against a live PS/2-only QEMU: the server acknowledges every fourth motion and the client now consumes and paces on those acknowledgements. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.40...v5.87.41
  • Aug 20, 2026 5.87.40
    - The SPICE mouse fix, round three — now verified against a live PS/2-only QEMU guest down to the guest's mouse device (#549) - SPICE sessions now record input events in the connection log, closing the "No detailed log for this entry" gap (#549) - **The SPICE relative mouse now works, verified end to end** (#549). v5.87.39's parse fix was correct but repaired a message QEMU never sends at connect: the server delivers the initial mouse mode *inside* its INIT message and no separate announcement follows, so the corrected parser sat waiting for bytes that never came — the reporter's immediate "no changes" was accurate, and this time the investigation ran against a live QEMU with a PS/2-only guest instead of stopping at unit tests. Two layers were wrong: the init-carried mode was parsed and dropped, and even stored it would have been lost, because init is handled before the input path wires up its view of the mode. The mode is now cached and replayed when the input path attaches. Verification went to the bottom: the client's relative motion messages were captured hitting QEMU's PS/2 device byte-identically to QEMU's own native input injection. A one-command probe now reproduces that whole check against any PS/2-only QEMU, so this path can never again ship untested against the thing it talks to. 🪞 **The second fix failing the same way as the first would have been unforgivable; the difference is where verification stopped.** Round one verified mode plumbing against a hand-fed mode. Round two verified parsing against hand-fed bytes. Round three put a real server on the wire and read the guest's device driver — and only that level found both remaining defects. The probe stays in the tree because the lesson has now been paid for twice. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.39...v5.87.40
  • Aug 20, 2026 5.87.38
    - YubiKey ECDSA SSH keys (sk-ecdsa-sha2-nistp256) now authenticate instead of failing after the touch (#531 — thanks pixel4696) - **Security-key ECDSA SSH auth fixed** (#531 — thanks pixel4696, whose "touch works, then publickey fails" report pointed straight at the signature leaving the phone malformed). The two FIDO key types hand back their signatures in different shapes: an ed25519 assertion is already the raw 64 bytes SSH wants, but an ECDSA assertion arrives as a DER structure that OpenSSH expects re-encoded as two SSH mpints. Haven passed the DER through untouched, so every sk-ecdsa signature failed server-side verification while sk-ed25519 sailed through the identical code path. The conversion now happens (and rejects malformed input outright), with the padding edge cases pinned by unit tests. The live round trip against a real server with a hardware key is the reporter's retest. 🔐 **Two key types, one code path, one silent divergence.** The ed25519 flow working made the shared path look proven, but "shared" only covered the framing; the signature payload inside it had a per-algorithm shape nobody was converting. A path is only as tested as its least-tested branch. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.37...v5.87.38
  • Aug 20, 2026 5.87.37
    - SSH "Address family: Auto" now falls back across all resolved addresses instead of gambling on the first (#566) - The System VM import form no longer clips its architecture chips in landscape (#558) - **SSH now tries every address a hostname resolves to** (#566). Auto mode used to take whichever address the resolver listed first and hand it to the SSH engine — so a dead AAAA record on a dual-stack mobile network, or one stale entry in a round-robin A set, produced a connect timeout while a working address sat unused in the same DNS answer. Auto now probes each resolved address in order with a short TCP handshake budget and connects to the first one that answers; a single-address answer is passed straight through, the explicit IPv4-only/IPv6-only settings keep their exact old meaning, and if nothing answers the probe the engine still gets the first address so you see its normal connection error, not a fake resolution failure. Both SSH engines share the path. - **The System VM import form fits landscape now** (#558). A Material dialog window caps its own height on a short screen no matter what the content asks for — six different in-dialog layout attempts are catalogued on the issue, all rendering identically — so the guest-architecture chips clipped in half. On height-compact windows (landscape phones) the form now opens as a bottom sheet, the app's existing pattern for content that owns the short axis; portrait keeps the dialog it always had. 🧭 **When six modifiers change nothing, the constraint is outside the box they modify.** The dialog's height ceiling belonged to its window, not its content — no amount of arranging furniture recovers space the room doesn't have. The fix was never a seventh modifier; it was a different room. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.36...v5.87.37
  • Aug 20, 2026 5.87.36
    - RDP no longer logs every keystroke to logcat (#504 — thanks pawlosck for calling it out) - Per-profile SSH keepalive settings now actually take effect (#537 — thanks kanazawahere) - Korean translations polished and missing content restored (#561 — thanks Nergis0318) - **RDP no longer logs every keystroke** (#504 — thanks pawlosck, who rightly called it out). The per-key wire logging was added as a diagnostic for the stuck-modifier investigation, and it did its job: the log it produced exonerated Haven's input path conclusively, with every modifier combination leaving the wire correctly ordered and every press paired with its release. A diagnostic that logs each key you type is a keylogger the moment the investigation ends, so it is removed outright rather than hidden behind a setting. - **Per-profile SSH keepalive settings now actually take effect** (#537 — thanks kanazawahere for the find). Setting `ServerAliveInterval` or `ServerAliveCountMax` in a profile's SSH options has been silently inert since the option parser was added: the values were forwarded into JSch's config map, which JSch never consults for those two — they live as session fields behind setters. The overrides now reach the real setters with OpenSSH semantics: the interval is in seconds, 0 disables keepalive, and a value that does not parse leaves the default untouched. - **Korean translations polished** (#561 — thanks Nergis0318): more natural phrasing throughout, and missing content restored, with key and placeholder parity verified against the English source. 🔑 **A diagnostic earns its keep once, then becomes a liability.** The keystroke log existed to answer exactly one question, and the first complete capture answered it. Everything it could record after that point is cost without return — and this kind of cost lands on users who never saw the issue it was for.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.35...v5.87.36
  • Aug 19, 2026 5.87.35
    - Returning to zellij or tmux no longer repaints the whole screen when the keyboard was open (#554 — thanks paour) - Dependency updates: Compose BOM 2026.08.00, AppCompat 1.8.0, org.json 20260814, golang.org/x/crypto 0.55.0 - **Returning to a full-screen TUI no longer repaints it** (#554 — thanks paour, whose keyboard-open/keyboard-closed comparison identified the trigger). Backgrounding Haven with the soft keyboard up made zellij visibly redraw every tab on return. The cause was a pair of resizes nobody asked for: Android takes the keyboard down a moment *before* the app is paused, so the terminal briefly became full height and the guest was told to grow; on return Haven restores the keyboard and the guest was told to shrink back. Both signals now cancel out — a grow that looks like a keyboard hide waits long enough to see whether the app is being backgrounded, and one caught mid-backgrounding is held until the return settles, by which point there is nothing to resize. The earlier theory on that issue (a stray refresh keystroke) was wrong, and the evidence that killed it — a byte-level trace showing nothing injected — came from the reporter. ⌛ **The two halves of a round trip each looked correct alone.** Reflowing to the keyboard is right while the user watches; restoring the keyboard on return is right too. Composed across a backgrounding, they became grow-then-shrink — two truthful size reports whose net effect was zero, except that the guest repainted for each. The fix is not to report less truthfully but to wait out the moment when the truth is about to reverse itself. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.34...v5.87.35
  • Aug 19, 2026 5.87.34
    - Declining a key's biometric prompt now stops the connection (#559 — thanks andar1an) - Connection failures say which half failed — reaching the host, or SSH itself — and against which address (#557) - The rootfs import field accepts `file://` paths and says so when handed a bare one (#560) - **Declining a key's biometric prompt now stops the connection** (#559 — thanks andar1an). The prompt itself was honest: press back and the key is never unlocked, never offered to the server. But every kind of failure was flattened into the same "no key" value on its way up, so the connect could not tell your refusal from a key that does not exist — and it did what it does for a missing key, which is carry on with whatever else the profile had: another key, a stored password, keyboard-interactive. On the "try every key" path a decline just removed that one key from the list. A refusal is now its own outcome all the way up, and every connect path — SSH, Mosh, Eternal Terminal, and the jump host under a VNC/RDP/SMB tunnel — reports it and stops before a socket is opened. The near-miss version is guarded too: the first fix's message contained the word "authentication", which the error classifier read as an auth failure and answered by offering the password prompt — a politer form of the same mistake, now pinned by tests on all four paths. - **Connection failures name which half failed** (#557). "Socket error" covered everything from a typo in the hostname to a firewall dropping the port to the SSH handshake dying. Failures now say whether Haven couldn't reach the host or the SSH exchange itself failed, and name the address it was trying — so a wrong port and a wrong password no longer look identical. - **The rootfs import field takes `file://` paths** (#560). Pasting a `file://` URI — the form most file managers put on the clipboard — was rejected with a message that named neither what was wrong nor what would work. It's accepted now, and the error for a bare content URI says what kind of path it wants. 🔐 **A "no" that only removes one option is indistinguishable from bad luck.** Haven's biometric gate did refuse — the key stayed locked — but refusal was encoded as absence, and absence already meant "try the next thing". Consent that matters has to be a first-class value, not a gap where a credential used to be; otherwise every layer above helpfully routes around it, each one sure it is being resilient.
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.33...v5.87.34
  • Aug 18, 2026 5.87.33
    - **The mouse works over SPICE on older guests** (#549, #543 — thanks empanadablues, who kept testing after the connection itself was fixed). SPICE lets the *server* choose how the pointer is described: a guest with a USB tablet is sent absolute positions, while a guest with only a PS/2 mouse — a Windows 98 VM, say — expects relative movements and silently discards absolute ones. Haven only ever sent absolute, so on those guests the pointer sat perfectly still while the keyboard worked fine. Haven now honours the mode the server asks for, which it had been reading and then ignoring. - **A failed port-knock or SPA packet is no longer invisible** (#557). These run just before a connection to open a firewall port, and they are deliberately non-fatal — so when one failed to send, the connection carried on and died later as an ordinary timeout, indistinguishable from the network being down. The failure now appears in the connection log with its reason, instead of only in verbose logging that you had to know to switch on first. 🖱️ **Both of tonight's bugs were a message nobody was listening to.** The SPICE server announced how it wanted the mouse described and Haven parsed the announcement, logged it, and dropped it. The SPA packet reported that it never left, and that report went somewhere nobody reads. Neither was a hard problem once seen; both were invisible for months because the thing that knew was not talking to the thing that decided. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid
    More…
    carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.32...v5.87.33
  • Aug 17, 2026 5.87.31
    - **Fixed the F-Droid build**, which has failed at clone time since 2026-08-16 and left that channel stuck on v5.87.22 (#525, thanks connesc — the build-monitor link found it twice now). A submodule of `wayland-android` was pinned to a commit that exists only on a personal mirror, and F-Droid's build server reuses its build directory, where `git submodule init` never overwrites an already-registered submodule URL — so it kept fetching from the original remote, which legitimately does not have that commit. The pin now points at upstream, which is reachable whichever of the two URLs a cached clone happens to use. - System VMs can now boot **arm64 guests**, not just x86_64 (#326). `-M virt` is a different machine rather than a flag: it needs UEFI firmware (installed automatically), virtio-gpu instead of VGA, and USB HID — without which a VNC viewer connects to a guest it cannot type into. The guest architecture is chosen when you import an image and shown beside it in the list, because a disk image does not record what CPU it is for, and the wrong target does not error, it simply never boots. - Acceleration is now **reported rather than assumed**: Haven probes `/dev/kvm` and says in plain words why a VM is emulated. On ordinary arm64 phones there is no `/dev/kvm` at all — the vendor hypervisor owns EL2, and rooting does not change that — so guests run under emulation. KVM also cannot accelerate a foreign-architecture guest, so an x86_64 image on an arm64 phone is emulated no matter what. - The system-VM import dialog no longer loses what you typed when the screen rotates. 🧱 **A pin that only one machine can resolve is not a pin.** The broken submodule passed every local check and every CI run, because a fresh clone reads the current URL and a fresh clone was all anyone ever did. The one machine that reuses its checkout — the one that actually ships the app to F-Droid users — kept the old address and quietly failed for a day. Reproducibility is not "it builds here"; it is "it builds somewhere that does not already have your assumptions cached". --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.30...v5.87.31
  • Aug 17, 2026 5.87.30
    - Mail-rule actions queued for approval no longer bury the notification shade. Instead of one card per queued action — ten emails meant ten stacked notifications, and tapping any of them did nothing, because they carried no tap action at all — there is now a single "N mail actions awaiting approval" notification on a dedicated Mail rules channel. It updates its count in place, opens the approval queue when tapped, and clears itself when the queue drains. - The approval queue gained **Approve all** and **Reject all** with a progress bar. Approving previously cost one tap and one IMAP round trip per action, which didn't scale past a handful; the bulk run executes the same per-action path sequentially, leaves failures queued, and reports the split. - Notifications raised by MCP agents now open Haven when tapped instead of ignoring the touch. - Zellij sessions no longer receive an injected Ctrl+L when the keyboard hides or the app goes to background (#554, thanks paour). This was a redraw workaround from before zellij repainted resizes properly; testing on-device against zellij 0.44 showed the bare resize repaints every row cleanly, so the injection — which echoed `^L` into running commands and force-cleared the screen on every background/foreground cycle — is gone entirely. The toolbar's `^L` macro preset remains for a manual redraw. - RDP logs every slow-path keyboard event as it is sent, to pin down keystrokes that only register after Tab/Caps Lock/Shift on VirtualBox guests (#504, thanks pawlosck) — this is the diagnostic build for that investigation. 📵 **An unprompted byte is never helpful twice.** The Ctrl+L was sent with good intent — repaint the rows the keyboard uncovered — but software that types into your terminal uninvited becomes indistinguishable from a bug the moment conditions drift. The workaround's reason retired versions of zellij ago; nobody told the workaround. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.29...v5.87.30
  • Aug 16, 2026 5.87.29
    - Fixed the unstoppable "zombie" desktop session (#550, #551, thanks sugerpersion — the screen recording made this findable). A Custom-command desktop whose command died at startup kept a green "running" row that Stop couldn't clear, while the actual failure vanished without a word. Four layered causes, all fixed: the dead command no longer leaves the VNC server holding the session open; the container now tears down every process when the session script ends (previously a leaked dbus-daemon kept it alive invisibly — one leaked per desktop start, forever); the orphan cleanup on Stop had never actually matched container-hosted processes; and a command that dies moments after the port check now reports as a startup failure carrying its own error output instead of silently disappearing. - Stop is now unconditional: whatever happens during cleanup, the session entry always clears — force-killing Haven is never the way out again. - Agents can now set the Custom (X11) desktop command via MCP (`custom_desktop_command`), which is how these fixes were verified end-to-end on a real device. 🧟 **A session that can't die is worse than one that can't start.** Every one of the four bugs was invisible alone; stacked, they made a corpse with a green light. The fix that matters most is the boring one: when the thing you started ends — however it ends — say so, and let go of everything it held. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.28...v5.87.29
  • Aug 16, 2026 5.87.28
    - Fixed SPICE connections in release builds (#549, thanks empanadablues — first to report it). Every release build's code shrinking was mangling the generated SPICE bindings, killing the connection 7 milliseconds in, before a single byte reached the server — SPICE has likely been broken in every release build for months while debug builds worked perfectly. One missing keep rule (its RDP twin existed, which is why RDP worked). Reproduced against a local QEMU, fixed, and re-verified on-device: connected, all channels up. - SPICE connection failures now log the exception class and stack trace to the connection log, not just a message — this bug's only symptom was the word "null", which is what made it invisible for so long. - For Windows 9x-era VMs (#543): with SPICE now working, its native relative-pointer mode is the recommended path — VNC's protocol can only carry absolute positions, which old guests' mouse acceleration desyncs. 🧪 **A debug build is not the product.** The product is what the shrinker ships. This failure lived exclusively in release builds, where reporters live and test rigs usually don't — the fix rides with a release-build smoke gap now visibly on the list. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.27...v5.87.28
  • Aug 14, 2026 5.87.26
    - Two diagnostics that turn open bug reports into readable data. For GNOME Remote Desktop's session-redirection black screen (#117, thanks MrTomiCZ), the redirect error now logs the packet's parsed structure — which fields the server populated and the routing token the eventual reconnect must replay, with the one-time password reduced to a length. For the runaway-scroll report (#524 follow-up in #542), the gesture classifier's one-line-per-swipe outcome record now survives release builds, so `adb logcat -s HavenGesture` shows exactly which path claimed a swipe. - Fixed the F-Droid build of the two previous releases: the new Reticulum engine's JVM bindings demanded a specific Java 17 toolchain, which F-Droid's single-JDK build server cannot satisfy (fdroiddata!45740). The bindings already target JVM 1.8, so the pin bought nothing — dropped. - Otherwise no behaviour changes — the rest is log lines. 🔬 **A bug report is a measurement problem.** Both of these issues stalled at the same wall: the reporter could see the symptom, but the build they were holding couldn't record the cause. The cheapest fix Haven can ship is the instrument. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.25...v5.87.26
  • Aug 14, 2026 5.87.25
    - RDP to a VirtualBox VM no longer starts as a permanent black screen after the guest has sat idle (#422, thanks pawlosck). The cause was hiding in plain sight for months: an idle Windows guest turns its virtual display *off*, VirtualBox's RDP server only ever transmits changed regions, and the one kind of input that wakes the display is a keyboard event — pointer motion is filtered as noise. Touch input is all pointer-class, so on Android there was no way to wake it. Haven now watches the first 1.5 seconds of a session; if nothing at all has been painted, it sends a single silent Ctrl tap and the full screen streams in. If the server painted anything, the nudge never fires. 🖥️ **The screen wasn't broken — it was asleep.** Ten seconds of continuous mouse movement: nothing. One Ctrl tap: full repaint in 150 milliseconds. Every desktop RDP client accidentally sends that key-shaped "wake up" via its connect-time input burst, which is why only touch users ever saw the void. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.24...v5.87.25
  • Aug 14, 2026 5.87.24
    - The toolbar's Swipe mode now repeats: hold a swipe and the arrow key repeats until you let go — drag a bit further to speed through, reverse direction mid-hold without lifting (#524, thanks a8645322). Before, each swipe sent exactly one arrow, which made cursoring across a long shell line an exercise in wrist endurance. Tab-switch gestures are suppressed while Swipe mode is latched, so a horizontal swipe means ← / → and never "jump to the Files tab". - RDP now types accented characters on AltGr-overlay layouts by synthesising real AltGr scancode sequences (#504, thanks pawlosck). Polish programmers layout ships first: ą ć ę ł ń ó ś ź ż (both cases) reach servers that only accept scancodes — VirtualBox's VRDP being the reporter's case, where these letters previously vanished. QWERTZ/AZERTY-style base-remapped layouts are a separate, tracked follow-up. ⌨️ **Input is a conversation with a stubborn listener.** Both fixes are about meeting the other side where it is: a VRDP server that refuses Unicode gets the raw scancode dance a physical Polish keyboard would send; a touchscreen that has no key-repeat hardware gets repeat synthesised from what a finger naturally does — staying put. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid
    More…
    carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.23...v5.87.24
  • Aug 14, 2026 5.87.23
    - VNC through an SSH tunnel now connects to the VNC host you configured (#538, thanks connesc). The tunnel's remote target was hardcoded to the SSH server's own loopback — fine when the VNC server *is* the jump host, wrong for every server behind it. The field is now honoured verbatim, with loopback kept only when it names the jump host itself. - Mosh over a Tailscale or WireGuard tunnel now works with hostnames and MagicDNS names, not just literal IPs (#539, thanks drauh — who arrived with the complete root-cause analysis and the fix design). The UDP stream's destination is now the address the tunnel actually connected to during the SSH bootstrap; and when no usable address exists, the connect fails with a clear message instead of retrying forever while mosh-server times out on the other side. - Groundwork for a second, Rust-based Reticulum engine (Prns) landed in the build — inert in this release, nothing user-visible yet. 🕳️ **Two tunnels, one lesson.** Both fixes are the same bug wearing different hats: code answering a question ("where do I connect?") from the wrong namespace — the phone's resolver instead of the tunnel's, the jump host's loopback instead of the profile's field. A tunnel is its own little world with its own names; this release makes Haven ask the tunnel. --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.22...v5.87.23
  • Aug 13, 2026 5.87.22
    - Hard links inside local Linux environments now survive and behave (#536 discussion). The emulation used to park a link's real data next to the *source* file, so when a program deleted its temp directory — the standard lockfile dance of git, dpkg, and Nix — the data vanished and the other name was left dangling. Payloads now live in a per-environment store that outlives any directory you delete, links are readable through every name (they previously failed with "No such file or directory" while `ls` looked fine), and failures report their real errno instead of a blanket "Operation not permitted" — the mystery behind years of intermittent dpkg errors (#324, #328, #329). - Concretely: Nix's flake commands now work out of the box on a fresh install — no more `could not find repository at ~/.cache/nix/tarball-cache`, no manual `git init` workaround. Verified on-device end to end, and guarded by a new emulation test suite that runs on every CI build. 🔗 **An emulated hard link is a promise about durability.** Android denies apps real hard links, so Haven's proot emulates them with symlink chains — and a chain is only as durable as its weakest directory. Moving the real bytes into a stable per-environment store (guest path `/.l2s`) makes the promise hold: any name you keep is a name that still opens tomorrow. - Attach → "Send a file" now reliably pastes the uploaded path at the terminal cursor (#535, thanks kanazawahere). The upload itself always worked, but the path injection raced the navigation back to the terminal screen and usually lost; it now rides the same injection channel the QR-scan paste uses, bracket-paste wrapped when the shell has it enabled. - If no terminal tab is active when a paste lands (file path or QR scan), Haven now says so in a toast instead of silently dropping the payload. ---
    More…
    ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.21...v5.87.22
  • Aug 13, 2026 5.87.21
    - Attach → "Send a file" now reliably pastes the uploaded path at the terminal cursor (#535, thanks kanazawahere). The upload itself always worked, but the path injection raced the navigation back to the terminal screen and usually lost; it now rides the same injection channel the QR-scan paste uses, bracket-paste wrapped when the shell has it enabled. - If no terminal tab is active when a paste lands (file path or QR scan), Haven now says so in a toast instead of silently dropping the payload. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.20...v5.87.21
  • Aug 13, 2026 5.87.19
    - Haven now reads its own death certificates (#494). When Android kills Haven in the background — a force stop, the app freezer, low memory — the next launch says so on the Connections screen: when, and by which mechanism, including the sneaky one where Developer options' "Select debug app" points at Haven and Android force-stops it. Agents get the same records via a new `get_process_exits` MCP verb; no entry at the disconnect time means the process survived and the network was cut instead. - If your battery-optimization exemption for Haven gets switched off behind your back — some ROMs quietly reset it when an app updates — Haven notices the change and re-offers the exemption with an explanation, instead of staying silent because you once tapped "Not now". A new "Don't ask again" makes the quiet permanent if that's what you want. 🪦 **You can't fix what you can't attribute.** Every "my sessions disconnect in the background" report starts with the same three-way ambiguity: the process was killed, or the network was cut under a live process, or only a listener died. They look identical from the outside and need three different fixes. Android has handed apps their own exit records since Android 11; Haven read them only for native crash tombstones. Now it reads the kills too, tells you about the ones that took your sessions with them, and exposes the history to agents — turning the opening question of every such report into data the app answers itself. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid
    More…
    carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.18...v5.87.19
  • Aug 12, 2026 5.87.16
    - A USB device that stops responding — a flaky card reader, or one drawing more power than the phone's port can supply — no longer freezes Haven when you plug it in or unplug it. The stuck device is now handled off the UI thread, so the app stays responsive even while the device itself has wedged. - Physically unplugging an open USB drive now tears down its background VM and export on its own, instead of leaving them running until you close the drive by hand. 🔌 **When a USB drive stops answering, the app shouldn't freeze with it.** Haven opens a plugged-in USB drive by handing it to a small Linux VM, and it used to close the device connection on the UI thread when the drive was pulled. If the drive had stopped responding at the kernel level — a failing reader, or a high-capacity card browning out an unpowered USB-C port — that close would block, and the whole app would hang (an ANR) on both plug and unplug. All of that USB lifecycle work now runs off the UI thread: the app stays responsive and simply reports the drive as gone, even while the device is wedged. A physical unplug now also unwinds the drive's VM and export by itself, and the keep-alive that pokes an open drive backs off after repeated failures instead of hammering a dead device. A device that has stopped answering is a hardware problem Haven can't fix — but it no longer takes the app down with it. --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid
    More…
    carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.15...v5.87.16
  • Aug 12, 2026 5.87.14
    - Zooming or rotating no longer silently destroys scrollback content — wide history lines now wrap when pulled back onto a narrower screen instead of losing their tails. - An RDP/VNC/SPICE/SMB profile's "Route via" tunnel or proxy choice now actually saves — it used to revert to "None (direct)" every time. - A locked Ctrl or Alt now unlocks itself when your last session ends, instead of ambushing the next connection. - New optional "Swipe" toolbar key: while on, swiping sends ↑/↓ even at a plain shell prompt — command history without arrow keys on the bar. 📜 **The scrollback that quietly stopped existing.** When the terminal gains rows — a zoom out, a rotation — it pulls lines back out of the scrollback to fill them. The engine asked for each line at the old width, deleted it from the store on handover, then kept only what fit the new width: on any resize where rows grew while columns shrank, every wide line's tail was destroyed, permanently and invisibly. "Scrollback isn't fully scrollable" was literal — the content was gone. The engine now asks at the width it can accept, and the store hands back one row's worth while re-queuing the rest as a soft-wrapped continuation, so wide lines wrap across the boundary instead of ceasing to exist. Reproduced and fixed under test against the real terminal engine: a 70-character line survives where it previously came back as its first 40. Not yet re-verified on a device — that retest is what #478 is waiting on. (#478, reopened by @skeezmoe's "the issue still exists" — they were right) 🔀 **The routing picker that never saved.** The "Route via" picker (WireGuard/Tailscale tunnel or SOCKS/HTTP proxy) is shown for six connection types, but only the SSH and EMAIL save paths ever persisted what it wrote — for VNC, RDP, SPICE and SMB a picked tunnel or proxy silently reverted to "None (direct)" on save, every time. All four now go through one shared save helper. (#527, @VaneEcho) 🔒 **The lock that outlived its sessions.** Lock Ctrl, exit your last session with Ctrl+D, connect somewhere else later — and the new session started with Ctrl still locked. The lock now dies with the last tab; closing one tab among several leaves it alone, since the toolbar state is shared and a surviving session may be mid-use of it. (#522, @a8645322's exact sign-off sequence is the regression test)
    More…
    👆 **Swipe as arrow keys, everywhere.** Haven already turns swipes into arrow keys inside full-screen apps and scrolls its own scrollback at the shell — automatically. But no automation can know you want *command history* at a plain prompt: the application state is identical either way. The new Swipe toolbar key (add it from toolbar customisation) latches that choice on, freeing the four arrow-key slots for other keys. Vertical only for now — horizontal swipes still switch tabs. (#524, argued for and won by @a8645322) --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.13...v5.87.14
  • Aug 11, 2026 5.87.12
    - The fullscreen menu button moved to the top centre, so it no longer covers the remote's own minimise/restore/close buttons — and it fades out when you're not using it. 🖥️ **The menu button that sat on the remote's close button.** In a fullscreen RDP session, Haven's menu chip lived in the top-right corner — exactly where Windows keeps minimise, restore and close — so the remote's own window controls were unreachable underneath it. It now sits top-centre, the spot desktop RDP clients reserve for their connection bar for precisely this reason, and after five idle seconds it fades to a ghost so it stops competing with the remote's content. It returns to full strength the moment you open it. Watched working on a device: chip top-centre with the corner clear, dimmed on idle, menu opens and exits fullscreen. (#528, from @pawlosck's "move or hide hamburger menu") --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one.
    More…
    **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.11...v5.87.12
  • Aug 11, 2026 5.87.10
    - A locked Ctrl or Alt now stays on until you tap it off — it no longer dies after one keypress while still showing as locked. - The "delete key?" title now shows the count in Bengali, French, Hindi and Portuguese instead of assuming "one" means exactly one. 🔒 **The lock that spent itself.** v5.87.8's double-tap Ctrl lock worked for exactly one keypress: the first Ctrl+C landed, the second sent a bare `c`, and the key sat there blue and inert. Keyboard input passes through two hand-off points and only one of them knew the lock existed — the other cleared Ctrl unconditionally after use, which is also why the indicator (a separate flag) never noticed. Fixing it also settled what "locked" means: v5.87.8 released the lock by itself after two keystrokes; the requester's follow-up said it plainly — locked means every keypress carries the modifier until you tap it off — and that is now the behaviour. Tap for one keypress, double-tap to hold, tap again to release. Watched working on a device: two Ctrl+C's, then a plain `c` after unlock. (#522, caught the day it shipped by @a8645322) 🌐 **Plural titles that assumed "one" means 1.** In Bengali, French, Hindi and Portuguese the "one" plural category covers more than the number 1, so the bulk-delete confirmation title ("Delete this key?") could sit over a count it didn't show. Those four now say the number. (found by the nightly lint run) --- ### Which APK?
    More…
    **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.9...v5.87.10
  • Aug 9, 2026 5.87.6
    - The status bar now matches the terminal instead of clashing with it — no more white strip above a dark terminal. - Fixed a stray "%" in the background-opacity help text. - Groundwork for the keyboard-closing-on-return bug: Haven now records why, so a log can say which cause it is. 🎨 **A white strip above a dark terminal.** If your app theme is light but your terminal colours are dark — Classic Green, Ocean, anything with a dark background — the top of the screen showed a band of app-theme colour with the terminal starting abruptly beneath it. The status bar was following the *theme*, while the terminal follows its own colour scheme, so the two disagreed by design. The status bar now takes its colour from the terminal that's actually on screen, and picks light or dark icons from how bright that colour really is — so a light scheme like Solarized Light gets dark icons rather than invisible ones. (#523, reported by @a8645322) 🔤 **"Below 100%%" in the opacity help text.** A stray escape that was never being processed, in English and all eleven translations. ⌨️ **Why the keyboard closes when you come back to Haven.** Not fixed yet — and worth being straight about that, because the fix I shipped for this in v5.87.2 has been running ever since and doing nothing. Rather than guess a second time, Haven now records whether the keyboard was up when it was sent to the background and whether it asked for it back, which separates the two possible causes. They need opposite fixes, so this is the step that decides which one to write. (#515, from @paour's testing)
    More…
    --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.5...v5.87.6
  • Aug 9, 2026 5.87.5
    - Number-pad keys now work in remote desktop sessions — previously they did nothing at all. - If SSH connections feel slow, Haven now records where the time went, so a log can say which part is slow. ⌨️ **The number pad did nothing in remote desktop sessions.** Not the digits, not the arrows, not Enter, not the operators — every key on the pad was dropped before it left the phone. Invisible if you use a touchscreen, which is why it lasted; obvious the moment you attach a real keyboard. Fixed. (#507, from a report by @pawlosck) ⏱️ **Haven now records how long each part of an SSH connection takes.** This is a diagnostic, not a fix: @frebib reported connections that used to take under a tenth of a second now reliably taking more than one, and there was no way to tell which part had got slow. (#519) Each connection now writes one line saying how long it spent looking up the address, preparing the session, and doing the SSH handshake — so a log can point at the culprit instead of just saying "it was slow". It deliberately contains no hostnames or usernames, so it is safe to attach to a bug report. **If SSH connecting feels slow to you**, updating and sending a log would genuinely help. The line begins `connect timing:`.
    More…
    - Haven no longer writes hostnames, usernames or clipboard contents to the device log. - If you have shared a log with anyone, it may contain more than you intended — worth checking. 🔒 **Haven was writing private details into the device log.** Connection details — username, hostname, IP address, port — and, worse, **anything copied to the clipboard from a remote session** were being recorded in Android's log. A password taken from a password manager, an API token, a private key: if it went through the clipboard in a terminal session, it was written down in plain text. (#518, thanks @skeezmoe) **What this does and does not mean.** Since Android 4.1 no other app on your phone can read Haven's log, so nothing was quietly harvesting this. The exposure is **sharing**: the log is captured by `adb logcat` and by system bug reports, Haven displays it in Settings, and Haven asks you to send logs when reporting a problem — including through the crash-report feature added in v5.87.3. The person who reported this had to edit their own details out of a log before it was safe to attach. **If you have shared a Haven log with anyone** — attached one to a bug report, sent one to someone helping you — it is worth going back and checking what was in it. Sorry; it should not have been there. Haven still logs enough to diagnose problems. Hostnames and names you chose are replaced with a short marker that stays consistent within one run, so a support log still shows which connection did what without saying where it went. Clipboard contents are simply never logged. A test now fails the build if anyone reintroduces this, in any of the fifty-odd places it could happen. - If Haven closes unexpectedly, the crash report is now waiting for you in Settings → Connection log. - Fixed a crash that a remote program could trigger just by setting a window title. 🐞 **Haven can finally tell you why it crashed.** Two open bug reports have been stuck for days on the same missing piece: the crash log stops at the moment of the crash, right before the part that says *where*. That was Haven's fault. It recorded its log from inside itself, so when it died the recorder died too, and the report the system writes afterwards arrived when Haven was no longer there to read it. Haven now picks that report up the next time it starts, and shows it in **Settings → Connection log** with a **Copy report** button. If Haven closes unexpectedly, please open that screen and paste what you find into a bug report — it names the exact place the crash happened, which is usually the difference between a fix and a guess. (#509, #517) Two caveats worth stating. It needs **Android 11 or newer**; on older versions the system simply doesn't offer this, and Haven says so rather than showing you an empty screen and letting you think nothing happened. And it only covers crashes of this specific low-level kind — the sort that close the app instantly, which is exactly the sort that has been hardest to diagnose. 🔡 **Fixed a crash triggerable by a remote program.** When a program on the far end set a window title — or sent one of several other routine terminal messages — containing text Haven couldn't interpret as valid Unicode, Haven closed instantly, with no error and nothing to catch. A window title from a Windows console not set to UTF-8 does this as a matter of course. Such text is now shown as `�` instead. A terminal that displays a replacement character for a mis-encoded title is behaving correctly; one that vanishes is not. This was found while investigating #517 and is **not** that crash — that one is still open, and the report above is now the fastest way to solve it. - Toolbar arrows and other repeating keys no longer stop working after you hold one. - The keyboard comes back when you switch back to Haven, instead of always hiding. - Three new terminal colour schemes: Campbell, Modern Dark and Modern Light. ⌨️ **Toolbar arrows could stop working until you closed the session.** Hold an arrow to repeat, tap another one, and the first arrow was dead — it still lit up when you touched it, but nothing reached the shell. Only closing and reopening the session brought it back. (#515, thanks @paour) Two separate faults caused it, either one on its own enough. Haven was reading the wrong field from the touch event, so once a second finger was involved it never saw the release; and the flag that tells a tap from the tail of a hold was cleared in a place that a fast tap could skip entirely. Both are fixed, and the key-repeat logic now has tests covering the exact sequence that was reported — it had none before, which is how this shipped. Arrows are what got reported, but Home, End, PgUp, PgDn and custom symbol keys behaved the same way, as did the equivalent buttons on the VNC and RDP screens. All fixed together. ⌨️ **Haven remembers whether the keyboard was up.** Android hides the soft keyboard when an app goes to the background, and nothing brought it back — so returning to a session always found it down, even though you left it up. It now restores what you had, and survives Android killing Haven while it's away. (#515, thanks @paour) 🥽 **The virtual keyboard no longer covers the screen when a real keyboard is attached.** On a Meta Quest 3 with a physical keyboard, every keypress raised the on-screen keyboard over the session. Haven was explicitly overriding Android's own rule that a usable hardware keyboard suppresses the soft one. You can still raise it deliberately from the toolbar. (#511, thanks @sae13) 🎨 **Three more terminal colour schemes**, for anyone who wants a dark theme whose default text is plain grey rather than tinted: **Campbell** (Windows Terminal), **Modern Dark** and **Modern Light** (VS Code). Palettes taken from the upstream projects rather than approximated. Note that the 16 ANSI colours only apply if "Apply scheme palette" is switched on in settings — it's off by default so that full-screen terminal programs keep their own colours. (#516, thanks @connesc) 📄 **Release pages now say what the two downloads are.** Every release lists a full APK and a smaller Terminal one per CPU, and nothing on the page explained the difference. Each release now carries a short guide. (#514, thanks @jeyjai) --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.4...v5.87.5
  • Aug 9, 2026 5.87.4
    - Haven no longer writes hostnames, usernames or clipboard contents to the device log. - If you have shared a log with anyone, it may contain more than you intended — worth checking. 🔒 **Haven was writing private details into the device log.** Connection details — username, hostname, IP address, port — and, worse, **anything copied to the clipboard from a remote session** were being recorded in Android's log. A password taken from a password manager, an API token, a private key: if it went through the clipboard in a terminal session, it was written down in plain text. (#518, thanks @skeezmoe) **What this does and does not mean.** Since Android 4.1 no other app on your phone can read Haven's log, so nothing was quietly harvesting this. The exposure is **sharing**: the log is captured by `adb logcat` and by system bug reports, Haven displays it in Settings, and Haven asks you to send logs when reporting a problem — including through the crash-report feature added in v5.87.3. The person who reported this had to edit their own details out of a log before it was safe to attach. **If you have shared a Haven log with anyone** — attached one to a bug report, sent one to someone helping you — it is worth going back and checking what was in it. Sorry; it should not have been there. Haven still logs enough to diagnose problems. Hostnames and names you chose are replaced with a short marker that stays consistent within one run, so a support log still shows which connection did what without saying where it went. Clipboard contents are simply never logged.
    More…
    A test now fails the build if anyone reintroduces this, in any of the fifty-odd places it could happen. - If Haven closes unexpectedly, the crash report is now waiting for you in Settings → Connection log. - Fixed a crash that a remote program could trigger just by setting a window title. 🐞 **Haven can finally tell you why it crashed.** Two open bug reports have been stuck for days on the same missing piece: the crash log stops at the moment of the crash, right before the part that says *where*. That was Haven's fault. It recorded its log from inside itself, so when it died the recorder died too, and the report the system writes afterwards arrived when Haven was no longer there to read it. Haven now picks that report up the next time it starts, and shows it in **Settings → Connection log** with a **Copy report** button. If Haven closes unexpectedly, please open that screen and paste what you find into a bug report — it names the exact place the crash happened, which is usually the difference between a fix and a guess. (#509, #517) Two caveats worth stating. It needs **Android 11 or newer**; on older versions the system simply doesn't offer this, and Haven says so rather than showing you an empty screen and letting you think nothing happened. And it only covers crashes of this specific low-level kind — the sort that close the app instantly, which is exactly the sort that has been hardest to diagnose. 🔡 **Fixed a crash triggerable by a remote program.** When a program on the far end set a window title — or sent one of several other routine terminal messages — containing text Haven couldn't interpret as valid Unicode, Haven closed instantly, with no error and nothing to catch. A window title from a Windows console not set to UTF-8 does this as a matter of course. Such text is now shown as `�` instead. A terminal that displays a replacement character for a mis-encoded title is behaving correctly; one that vanishes is not. This was found while investigating #517 and is **not** that crash — that one is still open, and the report above is now the fastest way to solve it. - Toolbar arrows and other repeating keys no longer stop working after you hold one. - The keyboard comes back when you switch back to Haven, instead of always hiding. - Three new terminal colour schemes: Campbell, Modern Dark and Modern Light. ⌨️ **Toolbar arrows could stop working until you closed the session.** Hold an arrow to repeat, tap another one, and the first arrow was dead — it still lit up when you touched it, but nothing reached the shell. Only closing and reopening the session brought it back. (#515, thanks @paour) Two separate faults caused it, either one on its own enough. Haven was reading the wrong field from the touch event, so once a second finger was involved it never saw the release; and the flag that tells a tap from the tail of a hold was cleared in a place that a fast tap could skip entirely. Both are fixed, and the key-repeat logic now has tests covering the exact sequence that was reported — it had none before, which is how this shipped. Arrows are what got reported, but Home, End, PgUp, PgDn and custom symbol keys behaved the same way, as did the equivalent buttons on the VNC and RDP screens. All fixed together. ⌨️ **Haven remembers whether the keyboard was up.** Android hides the soft keyboard when an app goes to the background, and nothing brought it back — so returning to a session always found it down, even though you left it up. It now restores what you had, and survives Android killing Haven while it's away. (#515, thanks @paour) 🥽 **The virtual keyboard no longer covers the screen when a real keyboard is attached.** On a Meta Quest 3 with a physical keyboard, every keypress raised the on-screen keyboard over the session. Haven was explicitly overriding Android's own rule that a usable hardware keyboard suppresses the soft one. You can still raise it deliberately from the toolbar. (#511, thanks @sae13) 🎨 **Three more terminal colour schemes**, for anyone who wants a dark theme whose default text is plain grey rather than tinted: **Campbell** (Windows Terminal), **Modern Dark** and **Modern Light** (VS Code). Palettes taken from the upstream projects rather than approximated. Note that the 16 ANSI colours only apply if "Apply scheme palette" is switched on in settings — it's off by default so that full-screen terminal programs keep their own colours. (#516, thanks @connesc) 📄 **Release pages now say what the two downloads are.** Every release lists a full APK and a smaller Terminal one per CPU, and nothing on the page explained the difference. Each release now carries a short guide. (#514, thanks @jeyjai) --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.3...v5.87.4
  • Aug 8, 2026 5.87.2
    - Toolbar arrows and other repeating keys no longer stop working after you hold one. - The keyboard comes back when you switch back to Haven, instead of always hiding. - Three new terminal colour schemes: Campbell, Modern Dark and Modern Light. ⌨️ **Toolbar arrows could stop working until you closed the session.** Hold an arrow to repeat, tap another one, and the first arrow was dead — it still lit up when you touched it, but nothing reached the shell. Only closing and reopening the session brought it back. (#515, thanks @paour) Two separate faults caused it, either one on its own enough. Haven was reading the wrong field from the touch event, so once a second finger was involved it never saw the release; and the flag that tells a tap from the tail of a hold was cleared in a place that a fast tap could skip entirely. Both are fixed, and the key-repeat logic now has tests covering the exact sequence that was reported — it had none before, which is how this shipped. Arrows are what got reported, but Home, End, PgUp, PgDn and custom symbol keys behaved the same way, as did the equivalent buttons on the VNC and RDP screens. All fixed together.
    More…
    ⌨️ **Haven remembers whether the keyboard was up.** Android hides the soft keyboard when an app goes to the background, and nothing brought it back — so returning to a session always found it down, even though you left it up. It now restores what you had, and survives Android killing Haven while it's away. (#515, thanks @paour) 🥽 **The virtual keyboard no longer covers the screen when a real keyboard is attached.** On a Meta Quest 3 with a physical keyboard, every keypress raised the on-screen keyboard over the session. Haven was explicitly overriding Android's own rule that a usable hardware keyboard suppresses the soft one. You can still raise it deliberately from the toolbar. (#511, thanks @sae13) 🎨 **Three more terminal colour schemes**, for anyone who wants a dark theme whose default text is plain grey rather than tinted: **Campbell** (Windows Terminal), **Modern Dark** and **Modern Light** (VS Code). Palettes taken from the upstream projects rather than approximated. Note that the 16 ANSI colours only apply if "Apply scheme palette" is switched on in settings — it's off by default so that full-screen terminal programs keep their own colours. (#516, thanks @connesc) 📄 **Release pages now say what the two downloads are.** Every release lists a full APK and a smaller Terminal one per CPU, and nothing on the page explained the difference. Each release now carries a short guide. (#514, thanks @jeyjai) --- ### Which APK? **`haven-<version>-<abi>-release.apk`** — the full app, and what F-Droid carries. If in doubt, take this one. **`haven-<version>-<abi>-terminal-release.apk`** — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works. Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download. `<abi>` is your device's CPU: `arm64` for essentially every modern phone, `armv7` for older 32-bit devices, `x64` for emulators. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.1...v5.87.2
  • Aug 8, 2026 5.87.1
    - Backups now include your authenticator entries. They never did before — restoring onto a new device silently lost them. - Haven no longer shows settings for features a build doesn't include. - The lighter Terminal download is now 35 MB, down from 54 MB. 🔐 **Your backups were missing your authenticator codes.** Haven's encrypted backup carried connections, SSH keys, known hosts, port-forwards, tunnels and settings — but not the TOTP entries from the Keys screen. Restore onto a new phone and they were simply gone, with nothing to say so. That is the worst thing in there to lose. A connection can be retyped and a key regenerated; an authenticator secret means going back to every service and enrolling again by QR, if it even lets you. They are included now. Old backup files still restore exactly as before — they just don't have the entries in them, because they were never written. **If you keep backups, make a fresh one.**
    More…
    📦 **The lighter build is a lot lighter: 35 MB, against 54 MB last release and 75 MB for the full app.** The largest thing left in it was the Go library behind cloud storage — but the same file also carries Tailscale, WireGuard and the Proton mail bridge, so removing it would have taken three things with it. It's now built twice, and the Terminal download gets the copy without rclone. So the Terminal build loses **cloud storage** (rclone remotes) on top of the desktop and media features. Tunnels and mail are unaffected. The full build is unchanged. (#510, thanks @paour) 🔌 **Settings stopped offering what a build can't do.** The Terminal build still listed remote-desktop resolution, GPU stack, compositor shell command and media file extensions — settings for libraries it doesn't ship. They're hidden when the feature isn't there, and the connection screen no longer offers cloud storage in a build without it. Haven also stops claiming those features to a connected AI assistant. It answered from a fixed list before, whatever the build actually contained. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.87.0...v5.87.1
  • Aug 8, 2026 5.87.0
    - Fixes SSH connections failing with a NullPointerException on the alternative sshlib engine. 🔑 **SSH connections that died mid-handshake on the sshlib engine now work.** A reporter on a RedMagic 11 Air found that connecting failed with a `NullPointerException` during authentication — working on v5.86.50, broken from v5.86.51. Their log had everything needed, which is the only reason this was found and fixed the same day. The cause is a good illustration of why release builds break in ways debug builds never do. Haven's release build runs an optimiser that shrinks the app partly by flattening thousands of classes into one unnamed package. sshlib's Ed25519 component asks for its own package name while it starts up — and a class with no package has no name to give, so it got null and threw. It only happens on devices where Android's own Ed25519 support isn't usable and sshlib falls back to its own, which is why it hit one reporter and not everyone. The fix keeps that one class's name intact, and it has been added to the check that runs on every release build and asserts these classes survive — so a future change to the optimiser rules can't quietly bring it back. Debug builds don't run the optimiser at all, which is exactly why a check tied to the release build is the only thing that would catch it. (#513, thanks @Slayerx96)
    More…
    📦 **A round number for the two-download split.** The lighter *Haven Terminal* build arrived in v5.86.53 as an ordinary patch release, which undersold it. This version number marks it. Nothing about the split changes here — the full build and the terminal build are both on the [releases page](https://github.com/GlassHaven/Haven/releases), F-Droid carries the full one, and 6.0.0 stays reserved for when the alternative SSH engine becomes the default (#58). **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.53...v5.87.0
  • Aug 7, 2026 5.86.52
    - The download is 9.3 MB smaller — 84.4 MB to 75.0 MB on arm64. - Release notes now start with a summary like this one, so there is something short to read. 📦 **The same app, 9.3 MB less to download.** A reporter pointed out that an 80 MB download every few days adds up, and asked for a stripped-down build. Measuring the APK first turned up something better: two of its largest files were nearly the same file twice. Haven ships `ffmpeg` and `ffprobe`, the two programs behind media conversion, previews and streaming. They were 23.7 MB and 23.6 MB — and almost all of that was one shared body of codec, format and filter code, compiled into each of them separately. Building that code once as a library both programs link against leaves 345 KB and 167 KB of actual program. Nothing about what the app can do changes. Every codec, filter and container is still there, and the conversion path was exercised on a phone — x264, x265, MP3, Opus, scaling and media probing all encode and read as before. That is 11% off the download for everyone, including people who use the desktop features. The stripped-down build the reporter asked for is a bigger change and is still being looked at; this was the part worth doing first. (#510)
    More…
    📄 **Release notes you can read in ten seconds.** The same reporter noted the notes are long enough that nobody reads them. They now open with a few bullets, and F-Droid's "What's New" shows those instead of the first 500 characters of an essay. The reasoning stays underneath for anyone who wants it — several bug threads link back to it. (#510) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.51...v5.86.52
  • Aug 7, 2026 5.86.51
    💥 **Fixed: Haven crashed after saving in `crontab -e`** (#509, thanks @ash-945). The crash was a native one — the C++ terminal being freed by the garbage collector's finalizer while a call into it was still running. Reproduced and fixed in termlib: every native call now holds the lock for its whole duration, and taking the lock away makes the crash come back, which is the evidence that it is the right fix. Terminals whose session has ended are now closed rather than left to the finalizer, so the race has less to happen in. 🔑 **Authenticator entries can be renamed.** Enrol one client on several routers and you get entries identical down to the issuer, identifiable only by trying a code somewhere. SSH keys have had rename since #231; TOTP now does too. 📂 **The Keys screen starts collapsed, except the codes.** Authenticator codes are what you open that screen to read; the rest is reference material. If you deliberately expand everything, that is remembered. 🐚 **"New plain shell" now works on SSH tabs, not just local ones.** It opens a shell with your session-manager preference bypassed — the point being to escape a multiplexer, so it belongs where the multiplexer is: an SSH profile wrapped in tmux.
    More…
    The terminal changes are not yet exercised on a device; the unit tests for the modules they touch pass. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.50...v5.86.51
  • Aug 7, 2026 5.86.50
    🔒 **Your Windows account name and your server's address are out of the remote-desktop logs.** A reporter has now redacted his own account name by hand from three separate log attachments, and asked for the address and port to go too. Haven had been redacting the username since v5.86.46 — at its own log lines. The ones that kept leaking belong to the RDP library underneath, which prints whole protocol messages when logging is turned up, and two of those messages carry the logon name and the server address verbatim. Redacting each place a name might appear is a game you lose eventually, so this does it at the other end: every line the RDP engine writes now passes through a filter that removes the values Haven already knows — your username, domain, password, the host you typed, any proxy host, and the address it resolved to. Anything the library starts printing later is covered without anyone having to notice it. What survives is shape rather than substance: `<ipv4>` or `<hostname>`, and a port only as "non-default". That is deliberate — a name that had to resolve versus an address that did not is the difference between a DNS failure and a routing one, and that distinction is what these logs are read for. The reporter's log is the test. The two lines he flagged are now fixtures in the test suite, and removing the filter makes them fail. His remaining 8,407 lines were swept for anything else identifying and came back clean. Still in the clear, and worth saying rather than leaving to be found: non-RDP connections log their host and port unredacted. Same leak, different part of the app.
    More…
    🔍 **A remote-desktop log line that read like a measurement when nothing had been measured.** The performance probe added last release printed `alloc+copy of 0KB took 0us` when it had not run at all — which reads as "copying is free", the exact opposite of what it means. Against a Windows 11 server it never runs, because Windows sends ordinary desktop updates as progressive images rather than H.264 even with AVC420 switched on. It now omits the clause instead of printing zeros. The test that was supposed to catch this only checked the path where the probe *does* fire, so it could never have failed — that is fixed too. 🔊 **Guest audio latency is now measured rather than argued about.** A reporter proposed three progressively larger rewrites of the audio path to cut delay. Before building any of them, this release logs the two numbers that decide which one is even worth building: the size of the playback buffer in milliseconds, and whether the loop spends its time waiting for the guest to produce audio or waiting for the phone to play it. Reading the code first already turned up one number worth knowing: the playback buffer's floor is 341 ms at CD-quality stereo. No change of transport can get underneath that. No behaviour changes here — this is the measurement that picks the fix. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.49...v5.86.50
  • Aug 6, 2026 5.86.48
    ⚡ **Remote desktop colour conversion is roughly three times faster, and the next log will say where the rest of the time goes.** A reporter's KDE session at 2560x1440 was running at 6.6 fps, and his log carried the timings that split the frame up. 68 ms of every frame was going into converting the decoded picture to screen pixels — a step that had already been moved out of Kotlin and into Rust, and was still the second largest cost in the frame. The reason turned out to be the shape of the loop rather than the arithmetic: it appended the result one byte at a time, which at his resolution is 14.7 million append operations per frame, each one re-checking whether the buffer needed to grow. Writing into the buffer directly instead measured **24.5 ms → 7.9 ms** on a desktop, built the same size-optimised way the shipped library is. The output is byte-for-byte identical — the colour tests pass unchanged. Those are desktop numbers, and a ratio rather than a promise. What it is worth on a phone has to be measured on a phone. 🔍 **A measurement, not a fix, for the largest remaining cost.** The same log showed the hardware decoder taking 6–8 ms and the frame packing 2–5 ms, inside a round trip that Haven measured at 83 ms. So around 72 ms per frame is spent handing the frame between Haven's Kotlin and Rust halves rather than doing anything with it.
    More…
    There are two plausible reasons for that, and they call for opposite fixes. Rather than guess, this release measures the one thing that separates them — what it costs *your* device to allocate and copy that many bytes — and prints it alongside. If you have been sending remote-desktop logs, the next one answers it. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.47...v5.86.48
  • Aug 6, 2026 5.86.47
    ⌨️ **Two keyboard and mouse bugs in remote desktop, both found by one reporter's measurements rather than his symptoms.** **Keys repeating forever, and buttons needing twenty presses.** Every discrete input — key down, key up, button press, button release — was dispatched on its own background task from a *pool* of threads. Nothing guaranteed the order they ran in, so a key release could reach the guest ahead of its own press. A guest that receives release-then-press is left holding the key down: it auto-repeats until some other key arrives, which is why pressing Tab appeared to "fix" it. The same inversion on a mouse button gives a click the guest never sees. Pointer *movement* was unaffected — it is a stream of positions where a swapped pair is invisible — which is exactly what the reporter observed and what identified the cause. Input now goes out in the order it was made. **AltGr typed nothing on non-English layouts.** All four right-hand modifiers — Alt, Ctrl, Shift and Win — were being sent as their left-hand twins. A reporter ran `showkey` on his guest's console and read back scancode 56 for AltGr; 56 is 0x38, which is *left* Alt. On a Polish layout that meant AltGr+o produced nothing instead of ó, because the guest had been told he pressed a modifier that composes nothing. Right Ctrl, Alt and Win are now sent E0-prefixed as the separate keys they are, and right Shift as its own code. This fixes what Haven sends. Whether an accented character then appears still depends on the guest having that keyboard layout loaded. **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.46...v5.86.47
  • Aug 5, 2026 5.86.44
    🎞️ **The slow remote desktops: the biggest cost is gone from where it was** — a reporter's logs finally showed where a frame's quarter-second actually went, on a 1920×1080 H.264 session: | | | |---|---| | the phone's video decoder | 9–25 ms — the real work | | converting its output to screen colours | 27–109 ms | | handing the finished frame from Java to the native side | 87–112 ms | | drawing it | 1–3 ms | About 25 ms of a ~250 ms frame was doing anything useful. The two biggest items sit on the same path and shrink for the same reason, so this is one change rather than two: the colour conversion now happens on the native side, and what crosses between the two is the video decoder's own output rather than the finished picture — **3.11 MB instead of 8.29 MB per frame**, so there is 2.67× less to allocate and copy every time.
    More…
    The drawing step is untouched. At 1–3 ms it was the other suspect, and measuring it is what ruled it out — worth saying, because it is the one that could have been "optimised" for no gain at all. The bar for the change was **identical pixels**, not similar ones, so the new conversion is checked against output captured from the old one — including a full-brightness-range frame compared by digest, because the first check turned out to be too small to notice a one-off rounding difference. **What is not established: whether this makes it faster on a phone.** It cannot be measured here — the only server that speaks this codec needs a desktop session this machine does not have. The per-frame report now breaks the conversion out separately, so the next log will say plainly whether the move paid off. If it did not, that will be visible immediately rather than assumed. (#466, #477) 🔌 **A USB drive that fails instantly no longer claims it waited seven minutes** — a reporter on GrapheneOS got "the VM didn't reach a login prompt in 420s" **1.7 seconds** after plugging a flash drive in, which sent them looking for a slow boot instead of a crash. The wait behind that message ends for two unrelated reasons — the deadline passing, or the helper VM dying — and reported the deadline either way. Meanwhile the VM's own output, the one thing that would identify the crash, was being captured and shown to nobody. It now says which of the two happened, how long it actually took, and quotes the VM's last words. This does not fix the underlying failure; it makes the next report able to say what the failure is. (#506) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.43...v5.86.44
  • Aug 5, 2026 5.86.42
    🖥️ **The stop button on a VNC desktop actually stops it now** — stopping a desktop kills the launcher and then sweeps up the VNC server, which survives on its own. That sweep looked for the server by asking the system for a process list and filtering on the display number — but that listing prints process *names* and no arguments, and the display number is only ever an argument. So it matched nothing, on every device, on every run, since the day it was written. It found nothing to kill and killed nothing, which is exactly the "I press terminate and nothing happens" reported. The equivalent sweep for the other desktop type had already been moved off process names for a related reason; the same reasoning had simply never been carried across. Both now look in the same place. Stopping display 1 also no longer risks taking 10 and 11 with it. Raised by @sugerpersion on #501. (#501) 🐧 **A shell in the Linux guest is bash, if the guest has bash** — it was always the minimal shell, which on Debian is dash and on Alpine is busybox, even on a guest with bash sitting right there. Haven now asks the guest which it has. Distros without bash are unaffected and behave exactly as before. Raised by @sugerpersion on #501. (#501) 🖥️ **Starting one Linux desktop no longer makes all the others look like they started too** — the install progress said which *step* was running but not which desktop it belonged to, so every row in the list showed the same spinner and it read as all of them having been launched at once. Each row now answers for itself. Install buttons still go inactive across the board while any install runs, because there is only one package database and a second install would collide with the first — but that is now a separate thing from the spinner rather than the same flag doing both jobs. Raised by @sugerpersion on #502. (#502) ⏱️ **A desktop install can no longer wedge forever** — one step compiles a VNC server from source in the guest, and it waited for that with no limit of any kind. Worse, it waited for the *output pipe* to close rather than for the command to finish, so a stray background process still holding that pipe kept Haven waiting long after the work itself was over — which matches the report exactly: the install sat there while nothing at all was running inside the guest.
    More…
    It now waits on the command, with a 20-minute limit. Long, deliberately: on a phone this genuinely is a multi-minute compile and cutting a working build short would be worse than the bug. Every other step is untouched and still waits as long as it takes — putting a limit on a package install would turn a slow connection into a failure. This step was always best-effort, so a limit costs nothing. Raised by @sugerpersion on #503. (#503) 🔑 **A key held in OpenKeychain is no longer offered where it cannot be used** — its stored bytes point at a key inside OpenKeychain rather than being key material, so handing them to the SSH library could only ever fail, and did, once per connection. The rule that should have caught it existed and was right; a second copy of it elsewhere had lost half its meaning. Found by @onatio22 on #487, whose log showed the rejection sitting between two connection attempts. The reconnect problem reported alongside it is not fixed. (#487) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.41...v5.86.42
  • Aug 4, 2026 5.86.40
    🖥️ **Windows remote desktops look right at last — the haloing around text is gone** — with H.264 turned off, a Windows desktop sends each part of the picture roughly first and then sharpens it over the next few messages. Haven drew the rough version and threw every sharpening pass away, so text kept a dark halo around every letter and smooth areas came out blotchy. That is the "lots of artifacts" reported on #496. Haven now decodes the sharpening passes, and this is on by default. It was off because nobody had ever checked it against a real Windows desktop, and the fear was that decoding it wrongly would look worse than not decoding it at all. So it was checked: connected to a Windows 11 machine, an *idle* desktop turned out to send more than a thousand sharpening messages in thirty seconds, and dropping them is exactly what produced the haloing. Decoding them gives clean text, no errors, and a picture that matches what the desktop actually looks like. The cost was measured rather than hoped for: about twice the decoding work — from a small base — and roughly 12 MB more memory at this screen size. Along the way this also fixed a leak that would have arrived with it, where that memory was never released when a remote desktop changed resolution. (#496, #418) ⌨️ **Haven no longer pretends to send characters a server won't take** — VirtualBox's remote desktop accepts only ordinary key presses, not the separate mechanism Haven used for characters with no key of their own, like accented letters and emoji. It was discarding them, and Haven had no idea: nothing failed, nothing was logged, the characters simply vanished.
    More…
    Normal typing was never affected — letters, digits and punctuation go the other way and always worked. But now the unusable ones are recognised and reported instead of disappearing silently. They still cannot be delivered to that kind of server; Haven just stops pretending otherwise. (#422) 🔎 **Groundwork for the slow remote desktops** — a reporter's measurements finally showed where the time goes on a laggy 1080p connection: decoding each frame, not drawing it. Drawing takes under 3 milliseconds; decoding takes 120 to 240. So the drawing-speed work of the last few releases was never going to help them, which is worth saying plainly. This release adds the measurement that narrows it further — separating the video decoder's own time from the colour conversion afterwards — so the next fix can be the right one rather than a guess. No change you will notice yet. (#466, #477) 🖥️ **A remote-desktop compatibility fix, corrected** — v5.86.38 taught Haven to accept a message whose stated length is smaller than the message itself, which is what VirtualBox sends. Review of the same change upstream found it was too permissive: it also accepted a message claiming *zero* length, which is malformed rather than merely miscounted. Narrowed. VirtualBox is unaffected. (#422) 🖥️ **Linux desktop graphics keep working after a system update** — Haven builds a patched graphics driver inside the Linux guest for GPU acceleration. A guest system update cannot delete it, but it could leave it stale — silently paired with a newer driver it no longer matches — and nothing rebuilt it. Now the version is recorded and a mismatch rebuilds. Raised by @sugerpersion on #441, whose objection was half right and found a real bug. (#441) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.39...v5.86.40
  • Aug 4, 2026 5.86.39
    🔑 **Keys from OpenKeychain can be imported again** — a reporter with a YubiKey could not add one: "The key provider refused the request", a couple of seconds after the prompt opened, and nothing in the message to act on. Nothing was wrong with their key, their card, or their permissions — they had already checked all three, which is what made this findable. Two faults, both Haven's. **Haven was throwing away the answer.** When OpenKeychain needs to ask you something, it hands Haven a prompt to show, and when you have answered it, it hands back Haven's own request *with what it learned added to it* — the key you picked, or the result of unlocking the card. That returned request is the answer, and it is what the next call has to carry. Haven kept only "did that come back OK?" and dropped the rest. So it asked again with the same empty request, and OpenKeychain, quite correctly, asked the same question again. **And Haven only ever answered one question.** It handled a single prompt and treated the next one as a refusal — though OpenKeychain routinely asks more than once, and asks something different each time: permission to talk to Haven, then which key you want, then the PIN and a tap on the card. Together those made the import impossible to complete, and made the failure look like a flat refusal with no explanation: a "please ask the user" reply carries no error with it, so once Haven had decided it was a failure there was nothing to report and it fell back to a generic sentence.
    More…
    Both are fixed, and not just for picking a key — the passphrase and card-unlock prompts answer by the same route, so signing needed it too. Separately, when a provider does refuse for a real reason, Haven now says what it was — "that key has no authentication subkey", "no key with that id", "incompatible API version" — instead of the same generic sentence every time, and an unrecognised reason prints its code rather than disappearing. Honest limit: **not verified on a device.** The sequence is read off OpenKeychain's own source rather than guessed, which is better than it was, but nobody here has run it against a real card. (#487) 🖥️ **A remote-desktop warning pointed at a settings screen that does not exist** — when Haven skips picture-refinement data it cannot decode, it says so, and tells you which setting turns that decoding on. It named "Settings → RDP". There is no RDP section — the switch lives under Diagnostics. Anyone who hit the warning and went looking would not have found it. (#496, #418) 📊 **Verbose connection logging now admits it covers RDP** — the setting's description listed SSH, Mosh and ET. It has covered RDP since March, and RDP is now where it matters most, because that is where the frame timings for a slow remote desktop turn up. (#477) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.38...v5.86.39
  • Aug 3, 2026 5.86.35
    🖥️ **App windows on a Debian 13 guest stop crashing** — opening an app in its own window failed roughly one time in three, and when it failed there was nothing on screen to say why. The cause was not in Haven: Debian 13 ships wayvnc 0.9.1, the piece that turns the guest's screen into something Haven can show, and that version crashes. Upstream declined to fix a version that old, and 0.10.1 does not crash. Debian 13 will not move to 0.10, and the newer version is packaged only in Debian's testing archive — which is a moving target, so pulling one package out of it onto a stable guest can leave that guest unusable later. Haven now compiles wayvnc 0.10.1 from source inside the guest instead, when it sets up a nested-Wayland desktop and finds the installed version too old. It touches no distro package, so there is no way for it to damage a guest. This costs a few minutes and a compiler the first time, on guests that need it — and nothing at all on guests that already have a new enough wayvnc, where the check takes under a second. Measured on a phone: eight app-window launches, eight connected, no crashes, against roughly one failure in three before. Two limits worth stating. **An existing desktop keeps its old wayvnc** until you reinstall it — or run `sh /usr/local/share/haven/wayvnc-build/build.sh` in the guest terminal yourself. And this fixes the crash; the freeze some people saw on the first frame was never reproduced here, so if video still freezes without a crash, that is a separate problem and worth reporting. (#473) 🤖 **The agent endpoint repairs itself without you switching back to Haven** — if the MCP endpoint's listener died, Haven only noticed when you returned to the app or the network changed. For an AI app running on the same phone that is exactly backwards: switching to that app *is* what puts Haven in the background, and a connection over the phone's own loopback never causes a network change. So the one setup that needed the repair most could never trigger it. Haven now re-checks on a timer for as long as the connection notification is showing.
    More…
    Being straight about the limit: this recovers an endpoint whose listener has died. It cannot help when the phone's system has frozen Haven outright, because the timer is frozen with it. (#494) 🔒 **An approval you gave after the agent gave up waiting is no longer wasted** — when a tool needs your approval every time, and the AI app's own timeout is shorter than the time you take to answer, the approval was meant to be held so the app's retry of the *same* action goes through instead of asking again. It never was: the approval was filed under one key and looked up under another, so it never matched, and every retry asked again. This has been broken since it was added. It matters most with an agent on the phone itself, where the approval cannot even be shown until you switch back, so the app is always the one to give up first. (#494) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.34...v5.86.35
  • Aug 2, 2026 5.86.34
    🖱️ **RDP: the pointer moves on the server the way it moves under your finger** — while the remote screen was busy, a drag reached the server as a handful of jumps rather than a continuous movement. Input was sent once per pass of the session loop, and every pass also decoded a frame, so input left only as often as frames arrived. Measured against a test server, sixty pointer positions a second were arriving in three and a half bursts — about seventeen at once, then a quarter-second of nothing. Sending input no longer waits for decoding. On the same measurement, all sixty positions a second now leave as they are made, and the picture arrives no more slowly for it. The effect is largest exactly where it was worst: the heavier the remote screen is to decode, the more this was costing you, which is why it was more noticeable with H.264/AVC420 switched on. Worth being straight about what was checked: this was measured against a FreeRDP test server on a desktop, not on a phone against Windows or KDE, and not through the phone's hardware video decoder. If pointer movement still differs between AVC420 on and off for you, that is worth reporting — it would mean some of the coupling remains. (#477) 🖥️ **RDP: a fix for sessions dropping on VirtualBox now also covers reconnection** — Haven already knew how to rejoin a large message that VirtualBox had split across two network reads, but only during a settled session. The same split during a *reconnection* — which is what happens when the remote desktop changes size or 3D acceleration is switched on — still ended the session. That path is now handled too. This one is reasoned from the crash reports rather than reproduced here, since it needs a VirtualBox host to trigger. (#422) **Full Changelog**: https://github.com/GlassHaven/Haven/compare/v5.86.33...v5.86.34
  • Jul 31, 2026 5.85.0