← Back to arcshell.app

Changelog

Every release since v1.0. Newest first.

v2.2.8 Direct VNC & SPICE, securely connected 2026-07-27

New Dedicated VNC & SPICE hosts

  • Save VNC and SPICE servers as regular ArcShell hosts and open them directly in their own graphical console tabs
  • Configure the endpoint port and credentials, plus an optional SSH jump host; VNC supports VeNCrypt usernames and SPICE supports persistent TLS settings

Security Verified graphical connections

  • SPICE TLS and VNC VeNCrypt now verify the original server identity even when traffic passes through a loopback SSH tunnel
  • Secure certificate pinning replaces trust-all connections while preserving existing Proxmox VNC and SPICE consoles

Improved Reliability & tmux reclaim

  • Failed VNC and SPICE channels, sockets and tunnels are closed completely instead of leaving partial graphical connections behind
  • Reclaiming a tmux session after another client takes over now reveals the current screen atomically instead of visibly replaying redraw frames
v2.2.7 Remote Desktop, fully integrated 2026-07-26

New RDP connections

  • Connect to Windows and other RDP desktops directly from ArcShell, including Windows/NLA authentication, trusted TLS certificates and connections through an SSH jump host
  • The remote desktop follows the available screen size and can switch cleanly between its tab and full-screen presentation

New Desktop integration

  • Copy text in either direction, play remote audio on the device or remote computer, optionally redirect the microphone, and expose selected Android folders as Windows drives
  • Unicode input supports accents, symbols and CJK characters; server cursors, remote keys, keyboard controls and full-screen presentation make the desktop practical on touch devices

Improved Image quality & resilience

  • Configurable colour depth, compression and the RDP Graphics Pipeline provide sharper, smoother rendering with classic bitmap fallback
  • Adaptive quality, dynamic resolution and configurable automatic reconnect keep sessions usable as network and display conditions change
  • Display-size changes now rebuild the complete framebuffer in order, while the compact 48 dp toolbar leaves more room for the desktop

Fixed

  • SFTP through a jump host now opens the final target instead of the jump server
  • Proxmox reconnects after credentials or connection settings change, graphical consoles stay attached to the correct tabs, and active sessions survive Android configuration changes more reliably
v2.1.1 Move files between device and server 2026-07-05

New Device ↔ server file transfer

  • Send files straight from your device to a server: upload photos and files through the system picker, dropped right into the current server folder – no copying into an app folder first
  • "Save to device" writes any server file to a location you choose
  • Done the Play-compliant way – through the system picker, without any "all files" storage permission

Improved

  • A newly added Nextcloud account now shows up immediately, and the file listing is more reliable
  • Dashboard: a host's status no longer stays stuck after a reachability timeout

Security

  • Hardening around transfers: uploaded filenames are sanitised so they can't escape the target folder, clearer error messages, and no more empty 0-byte downloads on a dropped connection
v2.0.93 Two-level settings & keyboard polish 2026-07-02

New Settings, reorganised

  • Settings are now two-level: a category overview (Appearance, Terminal, Tabs & Toolbar, Input, Connection, tmux, Livestream, Security, Data, About) opens a focused sub-page – far easier to scan, with items grouped by topic

New Keyboard

  • Shift+Tab and modifier keys are more reliable: soft-/hardware-keyboard modifiers combine with the extra-keys bar, and the bar's own Shift + Tab sends a proper back-tab
  • Ctrl/Alt/⇧ in the extra-keys bar can be highlighted as modifiers (optional, in Input settings)

New More options

  • Keep screen on while connected, blinking-cursor toggle, copy-on-selection, auto-clear clipboard, default username for new hosts, and confirm-before-disconnect

Improved

  • More compact host list, tab restore after a disconnect, and a faster tmux reconnect
v2.0.80 MAC address input help 2026-06-29

New Wake-on-LAN MAC field

  • The MAC address field now adds colons automatically while you type, accepts any pasted format (colons, dashes, dots, spaces or none) and only allows valid hex characters – so a stray space or a missing separator can no longer slip in
v2.0.79 Jump-host file sharing & stable tab bar 2026-06-28

Fix

  • File sharing over a jump host now uses the configured jump-host key instead of falling back to a password prompt
  • The terminal tab bar no longer disappears after a dialog (e.g. a cancelled SFTP password prompt) – it is now driven reactively from the live session list and stays reliably visible
v2.0.77 Browser live-stream works on every Android version 2026-06-27

Fix

  • Browser live-stream and terminal sharing work again, now on every Android version – the browser client was migrated to the current encryption protocol, and the on-device X25519 handshake that dropped some viewers right after the OTP is fixed
v2.0.76 VNC mouse control, SSH key import (PEM & PuTTY), faster reconnect 2026-06-27

New VNC console: mouse control

  • Full mouse control for the VNC guest console – three pointer modes (Trackpad, Grab-circle and Direct), switchable from the console menu and remembered
  • Mouse buttons (left/right/middle), scroll wheel via two-finger swipe, drag and drag-lock; the buttons can flee the cursor, auto-hide or stay visible
  • The console now shows the guest's real cursor shape, with a pan/scroll toggle when zoomed in

New SSH key import: PEM & PuTTY

  • Import classic PEM keys – BEGIN RSA/EC PRIVATE KEY and PKCS#8, encrypted (3DES/AES) or plain – alongside the modern OpenSSH format
  • Import PuTTY .ppk keys (v2 and v3, encrypted or plain) for RSA, ECDSA and Ed25519. Key import now covers practically every common key file, with a passphrase prompt for encrypted keys

New tmux & screen tabs

  • tmux and screen tabs now carry a small coloured marker icon (tmux = green grid, screen = teal bars) so you can tell at a glance which tab runs inside a multiplexer
  • More reliable tmux detach detection – the reclaim banner now also appears for external/manual detaches and on repeated detaches

New Proxmox console & faster reconnect

  • A Proxmox guest's graphical console (VNC/SPICE) now opens in its own tab – the dashboard stays usable and several consoles can stay open at once
  • Faster: a second session or tab to a host you're already connected to reuses the existing connection instead of logging in again

Fix

  • An SSH connection opened by expanding a host in the dashboard is now closed cleanly when you collapse it
  • Various stability and security hardening (incl. the auth token no longer appearing in error logs)
v2.0.60 Privacy: no broad storage permission 2026-06-23

Privacy Storage permission removed

  • ArcShell no longer requests the All-files-access permission. The FileCommander's local pane now uses the app-specific folder plus folders you explicitly grant via the Android folder picker – fewer permissions, more privacy.
  • SFTP and remote transfers work exactly as before; only unrestricted device-wide browsing is replaced by per-folder access.
v2.0.59 Proxmox VM Management, VNC Console Overhaul, Session Layouts 2026-06-22

New Proxmox VM Management

  • Create VMs with a full wizard – General · OS · System · Disks · CPU · Memory · Network · Confirm, with install ISO, OVMF/UEFI (+EFI disk), q35/i440fx, SCSI controller, QEMU agent and TPM 2.0
  • Full hardware editing in VM detail – CPU, memory + ballooning, disks, CD/DVD, EFI/TPM, network (incl. VLAN) and a real boot-order editor; add and remove devices
  • Set up a serial console from the app, and a console chooser (graphical noVNC vs. serial terminal) when a VM has both

New VNC Console Overhaul

  • Automatic keyboard layout – keys are sent as scancodes (QEMU Extended Key Event) so the guest decides the character; z/y, umlauts and path characters finally arrive correctly, with guest-keymap auto-detect
  • Control bar with Ctrl+Alt+Del, sticky Ctrl/Alt modifiers, Esc/Tab/Win and zoom; two-finger pan/zoom fixes

New Session Layouts

  • Save & restore your open tabs as named sessions – tab order, tmux/screen target and tab groups; rename/overwrite/delete, plus optional auto-restore on app start
  • Restored tabs and whole groups now open in parallel – one unreachable host no longer stalls the rest

New Host & Group Management

  • Move or remove hosts between groups via long-press, and rename groups in place
  • Reachability check now works behind a jumphost – probed through the tunnel instead of a dead direct socket
  • A single VPN prompt when opening many hosts at once, instead of one per host

Fix

  • Numerous stability fixes for connecting and restoring many hosts at once (parallel-connect thread safety)
  • Tab bar: scroll arrows on overflow, group-colored borders, and swipe order that follows the visible tabs
v2.0.35 Proxmox without SSH & security hardening 2026-06-14

New Proxmox without SSH

  • Sign in via API token or username & password – a Proxmox or PBS host now works entirely without SSH credentials, using a smart transport (direct HTTPS to :8006 with trust-on-first-use certificate pinning, SSH-tunnel fallback).
  • Node tools, web-UI parity: open a root shell on the node, manage services (start/stop/restart), review and install APT updates, and switch a node to the no-subscription community repositories in one tap.

New Backups & guest agent

  • Backup jobs – a dedicated Datacenter backup screen to create, edit, enable/disable and delete scheduled jobs, a working “Back up now”, and a list of guests that have no backup job yet.
  • QEMU guest agent – see a guest’s OS, IP addresses and filesystem usage, run a command, trim free space, or set a user password right from the guest detail.

New Tabs & languages

  • Groupable tabs – organise open sessions with three switchable layouts (flat, inline groups, workspaces, optionally two-row), plus a custom name when starting a new tmux session.
  • Korean is now available as an in-app language.

Security Shell-injection hardening

  • Codebase-wide audit – every server command that interpolates a user-, host- or server-controlled value (SSH jump-host wrappers, service control, file paths, the config wizard, the package manager and more) now routes through a single shell-escaping layer, so names with spaces, quotes or shell metacharacters can no longer break a command or inject.

Fix

  • Remote consoles now release their local port on close and can be opened several at once; the console back button reliably returns to the guest detail; and a background tab clearly highlights when it produces new output.
v2.0.13 Proxmox Backup Server, Clickable Links, Console Keyboard 2026-06-09

New Proxmox Backup Server

  • PBS as a first-class connection type – add a Proxmox Backup Server host directly, no PVE required
  • Three auth methods, your choice: API token, SSH bootstrap (mint a token over SSH), or user/password ticket
  • Datastores, backup groups, snapshots, verify, GC, and restore – also surfaced in the Proxmox dashboard for PVE-attached PBS

New Clickable Terminal Links

  • OSC 8 hyperlinks – apps that emit terminal hyperlinks (ls --hyperlink, gcc, many CLIs) are now tappable
  • Plain URLs are detected and followed across soft- and hard-wrapped lines, including indented continuations

New Terminal Key Bar

  • Shift modifier added – Shift+Tab plus Shift/Ctrl/Alt + arrow keys, using standard xterm modifier encoding

Fix

  • VM console: the on-screen keyboard now opens on tap – type directly into the noVNC console
  • Host list: collapse and re-expand re-runs a fresh service probe after a timeout instead of showing the stale error
  • Proxmox consoles run fully over the REST API – faster, more robust, with various fixes
v2.0.0 Proxmox Full Parity, Terminal Graphics, Fleet Heatmap 2026-05-20

New Proxmox VE – Full Web UI Parity

  • Cluster dashboard with PVE-style tree navigation (drawer sidebar), collapsible nodes, status pills
  • VM/CT detail view – 5 tabs: Summary (live metrics + graphs), Hardware (edit CPU/RAM/disk), Snapshots, Firewall, Cloud-Init
  • Node detail view – 7 tabs: Summary, Network, Storage (content browser), Disks, Syslog, Certificates, Replication
  • Create VM/CT – FAB dialog with OS type, CPU, RAM, disk, storage, template selection
  • Guest control: start, stop, reboot, pause, resume, migrate, clone, backup, delete
  • SPICE remote console (6 decoders, TLS) – direct VM display access
  • Snapshot management with tree view and rollback
  • Firewall management – cluster/node/VM rules, IP aliases, IP sets, security groups
  • User & access control – users, groups, roles, ACL, create/delete users
  • Task log with status filter (all/running/OK/error), auto-refresh, log detail
  • Resource pools with member browser
  • Monitoring graphs – CPU/RAM line charts from RRD data
  • Bulk operations – long-press multi-select, batch start/stop/snapshot
  • PBS integration: datastores, backup groups, snapshots, verify, GC, restore, backup jobs
  • VM/CT expand in host list – tap expand arrow to see VMs with status, CPU, RAM, uptime
  • 112 live API tests against PVE 8.3.0 – every Web UI endpoint verified

New Terminal Graphics

  • Sixel inline graphics – display images from gnuplot, matplotlib, etc. directly in the terminal
  • TN3270 mainframe terminal emulation – EBCDIC, field-based screen, IBM 3270 data stream

New Fleet Management

  • Heatmap dashboard: CPU/RAM/disk usage as color-coded grid, auto-refresh
  • Batch VM operations: start/stop/restart across host groups
  • Alert enhancements: disk >90%, host offline >5min with push notifications
  • Fleet export: JSON, CSV, and TXT formats
  • Cancel button for running fleet executions
  • Variable substitution in command templates: {{HOST}}, {{USER}}, {{PORT}}

New Remote Log

  • Stream terminal output to a second device via NSD/MyClerk
  • Severity color coding (ERROR, WARN, DEBUG), regex filter, pause/resume

New Docker Compose

  • Projects tab: docker compose ls, up/down/restart entire projects
  • Health status per container

New ArcHub Integration

  • Upload/download config profiles to community server
  • Provisioning wizard: connect → detect services → apply profile

New Dual Proxy Mode

  • SSH Hop (default): runs ssh target on the jumphost – uses jumphost keys and known_hosts
  • Direct Tunnel: end-to-end encrypted DirectTcp tunnel – uses app keys
  • Selectable per host in the connection dialog

New URL Highlighting

  • URLs in the terminal are now visually highlighted – blue color + underline
  • Single-tap opens the link in the browser

New Universal Edge-to-Edge

  • EdgeToEdge.applyToFragment() – one-line call handles all insets automatically
  • All 41 fragments now respond to keyboard show/hide and system bars

Fix Bugfixes

  • Agent forwarding crash through jumphost – race condition resolved
  • Jumphost DirectTcp crash on DNS failure – graceful error instead of crash
  • DNS resolution completely eliminated for IP addresses – zero DNS calls for IPs
  • SSH-Hop mode for jumphost connections – uses jumphost keys naturally
  • Duplicate code elimination – centralized FormatUtils, SshExecutorImpl, EdgeToEdge
  • Proxmox tool SSH context through jumphost – ProxyConnectionManager cache
  • tmux/screen "new session" buttons only shown when installed
  • Dashboard probe uses SSH-Hop for hosts behind jumphosts

Security

  • Passphrase-protected SSH keys: OpenSSH bcrypt_pbkdf import, AES-256-GCM agent cache
v1.5 Privilege Escalation, Collaboration & Mosh 2026-05-15

New

  • Mosh protocol – pure Kotlin implementation with SSH bootstrap, UDP transport, SSP
  • sudo/su integration – auto-fills password prompts via Expect Engine. Supports sudo, su, doas, pfexec, prun
  • GNU screen support – attach, detach, list sessions. Dashboard integration alongside tmux
  • Shared terminal sessions – server-side (tmux/screen) + device-to-device via MyClerk Tier 3 with R/W permissions
  • VNC tunneling – auto-detect installed VNC viewer, SSH local forward, per-host VNC port config
  • VPN auto-start – WireGuard, OpenVPN, Tailscale, NordVPN, strongSwan detection and launch before connect
v1.4 Certificates, Agent Forwarding, Crypto, PTY 2026-05-15

New

  • SSH certificates – openssh-cert-v01@openssh.com support
  • Agent forwarding – forward SSH keys to remote hosts
  • sntrup761x25519-sha512 – OpenSSH default post-quantum KEX
  • Own crypto library – BouncyCastle removed, replaced with arcshell-crypto
  • X/Z-Modem – file transfer + serial USB transport
  • OTP/TOTP generator – one-time passwords for keyboard-interactive auth
  • Biometric auth – fingerprint/face unlock for the app
  • Expect engine – pattern-matching scripting and automation
  • IPv6 support
  • Local shell PTY – real PTY via JNI/NDK (forkpty), TERM=xterm-256color, readline, job control
  • LogFile viewer – remote log search, regex filter, severity colors, tail -f

Fix

  • FileCommander/Tools SSH guard, tunnel NPE fix, advanced options for LOCAL connections
v1.3 Server Management Platform 2026-05-15

New Config GUI

  • Visual config editor for nginx (500+ directives), sshd (120 params), systemd, UFW, Docker Compose, OS basics
  • Schema-driven with tooltips, validation, undo, color-coded diffs
  • Service dashboard: status cards, quick actions, start/stop/restart, journalctl logs
  • nginx sites management: enable/disable, SSL certificate status and expiry

New Profiles & Compliance

  • Config profiles: export/import .arcprofile, built-in templates (nginx, sshd, linux-os, systemd)
  • Fleet profiles: apply to multiple hosts with dry-run and rollback
  • Compliance checking via profile diff

New Enterprise

  • MyClerk integration for encrypted vault
  • SSO/LDAP host import
  • MDM compliance checks
  • Audit log with export

New Documentation

  • Online handbook in 10 languages at arcshell.app
v1.2 Package Manager & Wake on LAN 2026-05-15

New

  • Package manager UI – 28+ distros, 5 adapters (apt, dnf, pacman, apk, zypper). Install, remove, upgrade, search, manage repos
  • Fleet update check – parallel package checks across hosts, "Upgrade All Hosts" button
  • Wake on LAN – MAC auto-discover, magic packet, WOL through jumphost
  • Jumphost crypto badge – progressive updates during proxy chain connect
  • Quick actions – all visible by default, icon mode, disconnect icon

Fix

  • tmux: black screen, freeze, background probe, tab handling, reconnect
  • Android 10: local shell + FileCommander storage access
v1.1 tmux Dashboard, Projects & Recording 2026-05-15

New

  • tmux dashboard – expand icon shows active sessions as sub-items. Create, attach, or kill sessions directly from the host list
  • tmux groups – group tmux sessions across hosts, connect all at once
  • tmux templates – reusable scripts with variable substitution (${SESSION_NAME}, ${HOST})
  • Projects – temporary host groups for work contexts with auto-connect
  • Session recording – capture terminal sessions, export as GIF, MP4, or .cast
  • Edge-to-edge – full WindowInsets support for all screens
  • Connect All – progress indicator, parallel auth, per-host error handling
v1.0 Play Store Launch 2026-05-15

New

  • SSH terminal – own SSH library with ChaCha20-Poly1305, AES-GCM, ML-KEM-768 post-quantum key exchange
  • Own terminal emulation – xterm-256color, TrueColor, scrollback, selection, search
  • Host management – groups, folders, favorites, search overlay
  • SSH key management – Ed25519, RSA, ECDSA generation. Install key on server with duplicate detection
  • SFTP file commander – dual-pane browser, upload/download, directory compare, multi-source share basket
  • Port forwarding – local, remote, dynamic (SOCKS5)
  • Jumphost / proxy chains – multi-hop SSH with progressive crypto badge
  • Fleet management – multi-host command execution, host groups, health monitoring
  • Snippets – command library with categories and startup snippets
  • Backup/restore – .asb format with selective import
  • Plugin system – themes, tools, connectors, snippet packs
  • Docker tools – container list, start/stop, logs, images, volumes, networks, stats
  • Server info – OS, CPU, memory, disk, SSH details
  • Crypto info badge – tap for KEX, cipher, MAC, host key details

Security

  • SQLCipher encrypted database
  • No telemetry, no tracking, no analytics
  • ASCR + TSU export compliance