Changelog

Every release, newest first. Version numbers match what the app reports in Settings.

2.16.0 ·

Remote desktop

  • Connect in the connection list finally opens RDP and VNC. It used to send the connection over SSH to the desktop port, the server reset it, and connecting failed with "Connection reset by peer" — while the very same connection worked from the settings dialog.
  • While connecting, the screen says Connecting rather than Desktop Disconnected. The old wording appeared the moment you clicked and stayed for the whole handshake, so people pressed Reconnect again and opened a second session on top of the first.
  • Fit to Window now means the size of the window. That choice used to become 1024×768 regardless, leaving the desktop inside a frame of grey bars.

Editing remote files

  • Double-click opens a file in the application chosen in Settings. A file without an extension — an id_ed25519 key, say — no longer makes the system ask which application to use.
  • Edits are uploaded back from ANY editor. Only VS Code did that before; every other application received a detached copy, so you saved the file, saw that it saved, and never learned that nothing reached the server.
  • The first time you open a file, the app asks once how files should open. Choose nothing and the built-in editor is used.
  • Copies of remote files no longer stay in your home directory for ever: they live in a temporary directory for the length of the edit and are cleaned up afterwards.

Moving in from other clients

  • Servers can be imported from Bitvise: the app reads .tlp profile files and shows the list before writing anything. The address comes across — host, port, user name; passwords and keys are encrypted inside the profile, so authentication is set up again.
  • Duplicates and profiles with no user name are flagged and left unticked. You can tick them back, but that is a decision rather than an accident.

Connections and folders

  • A connection can be created inside a folder, and a server can be dragged into another folder — dragging simply did nothing before.
  • Servers that ask for the password in a login dialog (keyboard-interactive) no longer need it typed by hand: the password stored with the connection is used.
  • The port field can be cleared and retyped again. And it is no longer left empty when the dialog is opened the next time.

Small things that got in the way

  • The network graph shows real traffic: the scale follows it instead of sitting at a fixed ceiling next to which any real value looked like zero.
  • The expanded Advanced section in the connection dialog no longer scrolls into empty space.
  • A valid licence can no longer be refused because of a passing file-read error: such an error is no longer treated as the licence being absent.

Installing on Windows

  • The installer lets you choose between installing for yourself only or for the whole machine, in Program Files. There was no choice before.

2.15.1 ·

Bug fixes

  • Minor fixes and stability improvements.

2.15.0 ·

SSH keys are a list now

  • No more typing a path for every connection: the app finds keys in ~/.ssh and offers them in a list.
  • Settings gained a Keys section: your own label instead of a filename, the fingerprint, the algorithm, and how many connections use it.
  • A key can be kept in the vault, so it reaches your other devices and your phone, where there is no ~/.ssh at all. It is a per-key choice rather than a default: whether a private key goes into a folder that syncs belongs to its owner.
  • Existing connections can be pointed at a key in one press. The path stays as a fallback, so nothing that worked stops working.

The key passphrase is asked for when connecting

  • An encrypted key no longer needs its passphrase written down in advance: you are asked at connect time, with a Remember switch that is off by default.
  • A remembered passphrase belongs to the key, not to each connection: one key across ten servers means one phrase, not ten copies.
  • A wrong passphrase no longer loops for ever, and a broken key is no longer reported as a wrong passphrase.

Remote desktop

  • Pasting into RDP works properly: files and text arrive at once, with no floating button to click first.
  • Paste-as-typing (Cmd/Ctrl+Shift+V) types the clipboard into the session, bypassing the remote clipboard entirely.
  • You can see a paste has started, and mashing the shortcut no longer pastes a file several times.
  • The remote desktop wallpaper is no longer sent, which lightens the session.

Updates

  • The update prompt says what changed instead of linking to it.
  • The refresh button and full-frame request work — they previously did nothing.

Fixes

  • An encrypted PuTTY key is no longer written back to disk unencrypted on import.
  • A malformed .ppk no longer takes the whole app down.
  • The vault can be unlocked from settings — locking it used to be a one-way door.
  • Dialogs are centred, and the connection window's buttons no longer overlap.
  • Private keys are created with closed permissions from the start.

2.14.0 ·

Conchshell on Android

  • Conchshell is out on Android: connections, terminal, files, monitor and remote desktop — the same app as on the desktop, with screens built for a phone. The APK is served from the site.
  • The master password is not asked on every launch: the vault key lives in the Android Keystore. On a device with no keyboard that is the difference between a client people use and one that asks for a password every time.
  • The vault travels neither in a cloud backup nor through the phone-to-phone transfer wizard: the vault file, the server fingerprints and the connection list do not reach the new handset.

Devices sync directly

  • Linked devices exchange the vault directly over your own network while the app is open. A shared folder is no longer needed for it — and a phone never had access to one.
  • The licence travels to the second device with the vault: there is nothing to enter there, and the app says so.
  • A computer can now join a vault from a code shown on a phone. The phone could always show its code; there was nothing on the computer to accept it, while the hint under the button promised exactly that.

Screens made for a phone

  • "New connection" and "Settings" are no longer desktop windows squeezed into a phone: they are full-screen sheets. Settings also open on a fresh install — the door used to be locked until something was connected, and the licence key is entered right there.
  • The terminal key row no longer disappears under the keyboard. Ctrl, Esc, Tab and the arrows are needed exactly while typing, and that is exactly when they vanished.
  • Buttons, fields and list rows grew to the size of a finger, a dialog’s main button no longer sits under the system navigation bar, and the system Back goes one level up instead of closing the app.

Connection window and settings

  • An ordinary connection is one screen instead of four tabs: three fields, all eight protocols in a row, Enter connects. Rare settings are folded away and labelled with their current value — "Proxy: direct", not just "Proxy".
  • An edit can be saved without connecting. A record was only written after a successful connection, so a host with a typo in its address could not be fixed: the very address being fixed stood in the way.
  • Settings sections are a list down the side instead of a tab strip with scroll arrows; Devices and Conflicts are sections of their own, and the number of unresolved conflicts shows in the list.
  • The first screen offers hosts from ~/.ssh/config that you do not already have. Reading the config worked before, but lived in Settings → Advanced, where it was found by people who already knew to look.

Licence and buying

  • A licence can be entered as a twelve-character activation code rather than only a 250-character key: typing it from a phone into a laptop is finally realistic. The long key still works, and still needs no network.
  • The grey "conchshell.app" line is now a "Buy a licence" button that opens the purchase page in the language the settings are being read in.
  • After an update the app shows once what changed, and the update dialog now speaks the interface language — two of its fourteen translated strings were actually read. A "Check for updates" menu item was added: automatic checking can be turned off, and after that there was no way to check at all.

Messages in your language

  • Refusals the core sends while linking devices and syncing are translated. A Russian interface showed "Connection timed out after 3 seconds", and sometimes an internal marker instead of the text.
  • A refusal by your own system is no longer presented as a network problem: linking a phone to a computer failed with "both devices must be on the same network" while they were.

Security

  • A stolen device can be revoked without a working licence. Serving the vault to linked devices asked for no licence at all, while the Revoke button refused — the paid line was drawn the wrong way round.
  • A revoked device no longer comes back by reinstalling the app. Revocation was looked up by an id the device declares about itself, and a clean install mints a new one; it now goes by the key the device proves with a signature.
  • A recovery code is no longer handed out on "the vault is open" alone — the current passphrase or the previous code is required. By default the vault opens silently through the system keychain, so a permanent second key to it was issued without a single keystroke.
  • One failed write to disk no longer switches syncing off for good, and deleting a password no longer loses the merge to a counter overflow: the deleted password stayed alive on every other device while the deletion looked successful here.

Fixes

  • Dragging a top-level folder onto "All Connections" deleted everything inside it — connections, subfolders and their passwords in the vault — and reported success.
  • "The remote host replaced your clipboard" no longer appears on every copy: `yy` in vim over SSH is the same sequence of bytes as a replacement.
  • A local terminal tab opens on Windows: the shell was chosen the same way on every system, and Windows tried to run /bin/sh.
  • The editor font list is no longer the terminal one — on a phone the field showed a truncated raw stack with nothing selected; bracket matching can actually be switched off; and "Open with an external application" on Windows and Linux no longer stays disabled for as long as the editor is open.
  • The "what gets sent" screen showed zeroes in the counters — the very fields it exists for.

2.13.0 ·

The connection list, rebuilt

  • The panel header carries a total, and every folder carries its own. A collapsed folder now stays collapsed — it used to spring back open at the first click on any connection.
  • Each row has a status dot and an address on the right: the address itself for SSH, and the protocol plus a short mark of the machine for everything else — `ftps · nas`, `rdp · .46`. One host can be three rows with the same name, and the protocol is what tells them apart.
  • A selected row is shown three ways at once: a fill, a rail and the weight of the text. Hovering no longer paints a row the same as selecting it — the list used to show two selected rows whenever the mouse was over it.
  • The buttons are labelled, and the second collapses to an icon in a narrow panel. The panel goes down to 12% of the window, where no label fits.
  • Connection state is now the real one. The panel only knew whether a tab existed, so connecting and connected looked identical, and a second window onto the same host darkened the first when it closed.

The hosts screen on the phone

  • Its own list rather than the desktop panel: rows sized for a thumb, a status ring, `user@host` beneath the name, and the protocol on the right.
  • Folders became flat sections with a count. Expanding needs a second meaning for a tap, and here a row means exactly one thing — connect.
  • One tap connects; a long press opens edit, duplicate and delete.

Fixes

  • A terminal background image now reaches terminals that are already open. It used to arrive only in tabs created after saving — that is, remote ones, which are rebuilt on every connect, and never the local shell, which lives for the whole session.
  • An oversized image is no longer lost in silence: it did not fit in storage and took the rest of the appearance settings with it without a word. Images are now scaled down, and a failure is visible.
  • Line height and letter spacing apply at once rather than after a restart.
  • A file dropped on a terminal inserts its path. The terminal accepted no drops at all, and on Retina displays a near miss handed the file to the file panel below — an upload where a path was meant.
  • The application's name is visible in full screen, where the system title bar is hidden and the name appeared nowhere.
  • About opens the application's own screen, with links to the site, the privacy policy and the third-party licences, instead of the system panel. On Windows and Linux the item did not exist at all.
  • Duplicating a connection no longer loses its settings. A copy of an FTPS host looked identical to the original but connected without TLS, sending the password in clear text. The VNC password, the domain and the RDP resolution were lost with it.
  • Dragging a folder that contains folders no longer loses them. The inner ones stayed in storage under a parent that no longer existed and disappeared from the application for good.
  • A long address no longer eats the connection's name in a narrow panel.
  • Changing appearance settings no longer damages background tabs. It used to shrink them to about 10x5 cells and report that size to the remote shell, leaving htop or vim redrawn as an unreadable column.

Security

  • A filename can no longer run a command. A file whose name contained terminal control sequences could execute arbitrary commands when dropped on a terminal — with no Enter pressed, locally or on the server of an open session. Such a name is created with ordinary tools and travels in an archive or on a memory stick. Control characters are now stripped from a path before it is inserted.

2.12.0 ·

Syncing connections between machines

  • Connections sync through a folder you already sync yourself — iCloud Drive, Dropbox, a git working copy, a mounted WebDAV share. The app puts one encrypted file there and reads what your other machines put there. There is no server in the middle and nothing is sent to us.
  • A second computer joins an existing vault: point it at the same folder and open it with the master password. Before this the only option on a second machine was to create a new vault — which overwrote the shared folder with an empty copy, and the cloud client replicated that deletion to every device.
  • When two machines change the same connection, or one deletes what the other edited, a "needs your decision" list appears. The losing copy is kept until you answer. Deciding automatically is wrong in both directions: one way it restores a password you retired as compromised, the other it silently loses one you believe you saved.
  • A pass that found nothing writes nothing: the app does not hand your cloud a fresh file every few minutes just because it is running.

Who is allowed to write to your vault

  • Settings now lists the machines that have touched this vault, with "That's mine" and "Stop trusting". Changes from a machine you have not vouched for are refused, and you vouch on each of your machines separately.
  • The decision is local precisely because one carried inside the file could be granted by anyone holding the key. Without that, revoking a device would mean nothing: a lost laptop still holds the key.
  • The app remembers how far the vault has got and refuses an older copy pushed at it. Last year's file passes every check — it is honestly signed and honestly encrypted — and would otherwise hand you back a changed password, a deleted connection, or a revoked device.

Linking a phone to your vault

  • On the computer that has the vault: "Link a device" and a code on screen. On the phone: the camera. The copy travels straight between the two over your local network.
  • The code never carries your master passphrase. The phone gets a key of its own that opens this vault and nothing else, and that can be removed later without touching any other device's way in — a photograph of the screen does not become a permanent key to everything.
  • The phone gets a copy as of the moment it linked. It cannot keep syncing yet: that needs a folder both devices can see, and iOS has none.

Conchshell on iPhone

  • The app builds and runs on an iPhone, with an icon of its own: commands, an interactive shell, SFTP files, monitoring and remote desktop.
  • The layout is built for a phone rather than squeezed down from a desktop: one section at a time — Connections, Terminal, Files, Monitor, Settings — and a key row above the keyboard for what an iOS keyboard has no keys for: Ctrl, Esc, Tab, the arrows and the combinations readline expects.
  • A remote desktop takes the whole screen and is driven like a trackpad: the cursor is drawn and stays where you left it, one finger is the mouse, two pan and zoom. A forty-point fingertip cannot hit a target a few pixels across that it is also covering.
  • Tapping a file opens it in the built-in editor and writes it back over SSH.
  • What a phone cannot do: open a shell on the phone itself — iOS does not let one program start another. The local-terminal card is simply absent there rather than offering something that will not happen.

The vault and the master password

  • A connection is now stored encrypted in full — name, host, user, port, folder — not just its password. Before this your servers' addresses and account names sat on disk in the clear next to the encrypted secrets.
  • Turning on "Ask for the master password at launch" is now two steps: the app mints a recovery code, shows it, and asks you to confirm you have written it down. Before, a password typed twice into unmasked-free fields instantly became the only thing that opens all your credentials — and there is no reset. The same typo in both fields meant losing them for good.
  • The pre-0.7 copy of your sessions — passwords and key passphrases written out in the clear — is now removed when they move into the vault. For some people it had been sitting there since before the vault existed.
  • macOS stops asking for your keychain password over and over: "Always allow" now lasts longer than a single save.

What syncing used to lose, and no longer does

  • Merging two copies was tested on two real machines with a folder between them. That found several ways saved work failed to arrive: a change that did not move the shared counter was never sent at all, and a copy carrying the same counter was rejected wholesale as "older" — along with everything new in it.
  • One resolved conflict no longer breeds. Two machines that settled it independently produced results neither recognised as the other's, and settled those too: one saved connection became sixty-four copies of itself in six syncs.
  • A computer on an older version no longer wipes connection fields it does not know about. While not every machine is updated — which is what every update looks like — a setting added in the newer version would vanish on both sides, silently.
  • Deleting a connection now also removes its saved password, its remembered window size and its file-browser history. Session restore actually runs at launch, for every tab rather than only the visible ones.

Security

  • The separate window showing a remote desktop can no longer open a shell on your own computer. It displays another machine's screen and was held to seven permitted actions for that reason — and one of them handed out a key that went around the whole list.
  • A record's signature now covers everything the merge looks at. Someone holding the key could change the fields left outside it on somebody else's record — and a connection would disappear from the list on every machine, under its owner's own signature.
  • Joining somebody else's folder no longer grants write authority automatically. The device list inside a file is a claim by whoever wrote that file; machines named in it now wait for your confirmation instead of being trusted silently.

Terminal and tabs

  • Opening a session no longer prints seven lines of our own text before the shell. The terminal starts with what the machine actually said.
  • A tab takes its name from the shell's title, the way a terminal window's title changes as you work. Three tabs on one server stop being "server", "server (2)", "server (3)".
  • You can also name a tab yourself: double-click it, or use the menu. A name you gave is never overwritten by the automatic one; clearing the field gives the automatic name back.

Appearance

  • The desktop has a new palette. The terminal is now darker than the pane holding it and in the same colour family, rather than a lighter grey rectangle on a blue ground — which is why it read as pasted on instead of cut in.
  • A coloured dot next to a server means one thing. Protocol has its own colour — a shell, files, or a screen — and connection status has another. Green used to mean either "connected" or "this is SSH", with no way to tell which.
  • Dialogs always fit the window: a tall one clamps to the screen and scrolls its middle while the header and buttons stay put, and the margin around it is proportional to the window again.

Licence, updates and builds

  • Syncing connections between machines is a paid feature. Everything else in Conchshell stays free. The key is asked for only where something changes: choosing a folder, syncing, linking a device, answering a conflict.
  • If a key stops being valid you are not locked out of your own data: the device list, the conflict list and the settings stay available — only syncing itself closes.
  • Downloads and updates come from conchshell.app.
  • Settings has an About tab listing every open-source component Conchshell is built on, with each licence's full text.
  • This release is for macOS and Linux. The Windows build was delayed and follows separately; Windows stays on 2.11.0 for now.

2.11.0 ·

Importing connections from ~/.ssh/config

  • Settings can now read your OpenSSH client configuration and offer its hosts for import.
  • Inheritance follows OpenSSH's own rules: a host takes settings from every pattern it matches, and the first value wins rather than the last. Reading it naively gives you a connection with no user, or with somebody else's port, and says nothing.
  • ProxyJump is resolved through the jump host's own block, along with its user, port and key.
  • Nothing is saved until you choose. Rows carrying a warning — a duplicate, no user, a shortened jump chain — start unchecked.

macOS build signing

  • macOS builds now carry a signature and are built with the hardened runtime. Before this there was no signature at all, and anyone downloading from the site was told the app was damaged and could not be opened — a message with no way out.
  • Notarisation is not in place yet, so the first launch still needs confirming through Privacy & Security.

Updates

  • Fixed update signature verification. Four consecutive releases downloaded and then failed the check on the user's machine.
  • The signing key is now checked against the public key in the configuration before a build runs. If the two disagree, the release does not go out.