- Preserved unread session and forwarding output through automatic connection teardown after remote channel close, including exec stderr and buffered SFTP responses (#317).
- Released retained delivery workers and buffers on explicit session close or client disconnect, including when the network has already shut down.
Changes for library users since 0.4.2.
- Added support for reading OpenSSH private keys encrypted with
aes128-gcm@openssh.comandaes256-gcm@openssh.com. - Added
SshClientConfig.sessionWindowSizeandSshClientConfig.sftpWindowSizeto configure receive windows for session channels and channels opened bySshClient.openSftpindependently.
- Increased default receive windows from 64 KiB to 2 MiB for session channels and 8 MiB for SFTP channels to improve throughput on higher-latency connections.
- Improved SSH and SFTP transfer performance by batching channel writes and receive-window updates, pipelining SFTP frames, and reducing buffer copies and allocations.
- Serialized protocol decisions independently of transport writes, keeping incoming packet processing and shutdown responsive under backpressure.
- Prevented valid packets arriving during suspended writes from causing spurious disconnects by serializing complete connection state transitions.
- Preserved reply ordering when requests are cancelled after being admitted for transmission.
- Released SFTP lifecycle locks before waiting for writes to prevent deadlocks under transport or channel-window backpressure.
- Cancelled pending remote forwarding handlers and released sockets and selector resources when forwarding ends or fails.
- Improved Android key compatibility by falling back to JVM Base64 operations when Android calls fail and accepting Ed25519 private keys with PKCS#8 encodings regardless of their implementation class name.
Changes for library users since 0.4.1.
- Deprecated
SshKeys.ensureEd25519Support()because Ed25519 support is now selected automatically without modifying the global JCE provider list.
- Preserved unread session output, error output, extended data, and forwarded channel data when the remote peer closes a channel.
- Validated JCE providers with raw-key operations before selecting them for Ed25519, Ed448, ECDSA, RSA, and X25519, avoiding failures from providers such as AndroidKeyStore that advertise algorithms but reject non-keystore keys.
Changes for library users since 0.4.0.
- Bound TLA+ Terrapin model to implementation and tightened up the SFTP model.
- Ensured channels are unregistered and old channels are closed in the registry.
Changes for library users since 0.3.1.
- Added
SshSession.exitInfo(Deferred<SessionExit>) to expose remote execution exit status (SessionExit.Status) and exit signal (SessionExit.Signal) details sent viaSSH_MSG_CHANNEL_REQUESTexit-statusandexit-signalmessages. - Added formal TLA+ specifications and model checking for verifying state machine transitions, channel isolation, and Terrapin attack mitigation.
- Converted channel lifecycle management to explicit state machines using
KStateMachineto support formal modeling and strict state separation. - Updated default algorithm preference lists to prioritize modern cryptographic ciphers, key exchanges, and MACs.
- Enforced strict session binding (session ID and host key verification) for forwarded SSH agent signing requests.
- Implemented receive-window backpressure across channel types (session, port forwarding, and agent) to prevent window overflows.
- Bounded nested field sizes and entry counts during SFTP response decoding to prevent excessive memory allocation from malformed responses.
- Verified host-key proof signatures prior to trusting host keys during key exchange.
- Validated parameter boundaries and key lengths during Diffie-Hellman group exchange.
- Directionally isolated rekeying state transitions to handle inbound and outbound key exchange independently.
- Decoupled SSH agent response handling from the main packet loop to prevent connection deadlocks.
- Hardened connection tear-down to ensure transport closure occurs cleanly and only once under concurrent close requests.
- Ensured
ssh-rsaalgorithm wishlist selections are honored when explicitly specified. - Switched outbound SSH packet padding generation to cryptographically secure random values.
- Fixed passphrase encryption when exporting Ed25519 private keys to PKCS#8 format.
Changes for library users since 0.3.0.
- Restricted maximum length constraints on SSH agent messages and packet payload fields to prevent excessive memory allocation when processing untrusted wire data (GHSA-ch3q-cw5r-f4hg).
- Hardened DER length and integer parsing for ASN.1 private keys to prevent integer overflow and excessive memory allocation (GHSA-vc8p-8pxg-rfwg).
Changes for library users since 0.2.1.
- Added FIDO2 / Security Key authentication helpers for
sk-ssh-ed25519@openssh.comandsk-ecdsa-sha2-nistp256@openssh.comkeys in the neworg.connectbot.sshlib.skpackage. The library handles the SSH wire-format pieces while callers provide their own CTAP2 transport. - Added
AuthHandler.onBanner(message)so applications can displaySSH_MSG_USERAUTH_BANNERmessages during authentication. - Added
KtorTcpTransport.getLocalAddress()to expose the local socket address assigned to a connected TCP transport. - Added
docs/ALGORITHMS.mdwith the complete supported algorithm list anddocs/SK_AUTH.mdwith Security Key authentication guidance.
SshClient(...)andBlockingSshClient(...)convenience constructors now require an explicitHostKeyVerifier. This makes host-key verification a required caller decision instead of allowing a convenience constructor that could not build a validSshClientConfig.AuthHandler.onSignatureRequest()is documented as a verbatim signature extension point for local private keys, SSH agents, and FIDO2 authenticators.
- Authentication banners are now delivered to callers during every authentication step instead of only being logged.
SshSigning.sign()now rejectssk-*algorithms with an actionable error, since Security Key private material lives on the authenticator and must be signed throughAuthHandler.onSignatureRequest().- Hardened host-key signature verification by requiring the signature algorithm to match the negotiated host-key algorithm.
- Hardened agent session-binding signature verification by requiring the signature algorithm to be compatible with the key type.
- Hardened key exchange and channel handling by rejecting all-zero ECDH shared secrets, invalid DH group-exchange parameters, channel-window overflows, and incoming channel data that exceeds the local receive window.
- Limited zlib decompression output per packet to reduce decompression-bomb denial-of-service risk.