| Age | Commit message (Collapse) | Author | Files | Lines |
|
Browsing restarted at the storage root on every configuration change.
The restored path goes through safeDirectory like a typed one, so it
still cannot escape the root.
A pinned remote wrote its index into both the instance state and the
intent. The instance state already survives recreation.
|
|
Every value the dashboard draws comes from an app-private file, and it
read all of them during layout, on every resume and at the end of every
sync. Scheduler.apply did the same at process start, where it also opens
WorkManager's database. Read on a worker thread and draw the result;
overlapping refreshes are settled by generation, the same way the log
viewer already settles its own.
|
|
The remote and folder counts and the serialized config size are enforced
only inside save, which throws. Every other rule an editor can break is
reported in the form, so a config that outgrew a limit crashed the
activity instead of saying so. overLimit answers before the entry is
added, and the editors report the answer.
hostKeyAllowed reconstructs the known_hosts address that rsh writes with
knownhosts.Normalize, and nothing recorded or tested that coupling.
Normalize leaves the host bare on port 22 for IPv6 literals too, so
bracketing them here looks right and would reject every IPv6 pin.
|
|
Support Alpine/musl and Debian/glibc hosts, lock downloaded and
Gradle artifacts, and verify native and APK security properties.
|
|
Validate persisted state and destination boundaries, make interruption
and mirror deletion explicit, and keep scheduled work singular.
|
|
Let each folder select a named SSH endpoint and migrate the published
0.1.x configuration without discarding its folders or host pin.
|
|
Persist config, key blob, and host pin via AtomicFile so an
interrupted write cannot corrupt state. Validate the port, clear the
host pin when the remote changes, cap imported key size, time out
native helpers, and escalate rsync termination to destroyForcibly.
Serialize manual and scheduled syncs behind a mutex.
Replace the chained one-time jobs with plain periodic work: it
survives reboots without a boot receiver and cannot silently die
like a broken chain. Costs the sub-15-minute interval, which photo
backup does not need. Document the floor and that syncs run on any
unmetered network, not only WiFi.
|
|
rsync forwards --mkpath to the remote side when sending, so a remote
rsync older than 3.2.3 (notably stock macOS, whose openrsync is
"rsync 2.6.9 compatible") rejects every sync with "unrecognized
option '--mkpath'".
rsync creates the final component of the destination path on its own,
so flat remote paths keep working everywhere, including the documented
rrsync setup whose root is pre-created. Only a nested remote path with
missing parents now needs a one-time mkdir -p on the server; the log
shows rsync's error when it is missing.
Reported-by: jsvk
Link: https://codeberg.org/0xlena/rsend/pulls/1
|
|
The containment check was a bare prefix match, so a sibling such as
/storage/emulated/0-evil passed for a root of /storage/emulated/0.
|
|
A crash mid-write corrupted config.json, and every later load then
threw on parse, crash-looping the app until its data was cleared,
losing the key and pinned host. Write to a temp file and rename.
|
|
A stopped worker (schedule replaced, constraints lost) left rsync
running detached until its own network timeout, including a window
where a WiFi-only sync kept pushing on another network. A watchdog
coroutine destroys the process on cancellation, which also closes its
pipes and unblocks the log reader; the worker rethrows cancellation
instead of logging it as a folder error.
|
|
The trailing-slash fix-up turns an empty local path into /, so a blank
folder row would rsync the entire filesystem; an empty remote path
pushes into the rrsync root. Reject both when saving a folder, skip and
log them at run time in case the config was edited by hand, and log why
a sync was skipped when the app is not configured yet.
|
|
rsh -keygen printed the pubkey but wrote the key pair into a directory,
so generating a key briefly left the plaintext private key on flash,
contradicting the documented invariant that it only ever exists in
memory. -keygen now emits the private key PEM on stdout and nothing
else; the app encrypts it immediately and derives the public key via
-pubkey, reusing the validated import path. Keygen failures now surface
as an error dialog instead of crashing the app from a bare thread.
|
|
Typing absolute paths is error-prone; let the user browse real
filesystem folders and pick one. Stays on real paths (no SAF) so
rsync keeps operating on POSIX paths.
|
|
A small Android app for one-way folder backup, a KISS alternative to
Syncthing. It bundles rsync (built from pinned source via the NDK) and
a pure-Go SSH transport, both shipped in the APK as lib*.so and run from
the native library directory.
rsend pins the host key, stores the ed25519 identity Keystore-encrypted,
pushes each folder additively or as a mirror, and runs on demand or on a
WiFi-only schedule. The build is self-contained and reproducible: make
setup provisions the toolchain, make builds rsync, rsh, and the APK.
|