<p>Thecompanionphoneapptookahugeleap(0.5.9).Yournodeanditsappsnowworkfromanywhere—on5Goranyinternetconnection,thephonereachesthenodeovertheencryptedmeshwithzeroportforwardingorVPNsetup.Startupawayfromhomeisinstant,appsonyournodeopeninsidetheapp,thephone's native camera handles QR scanning, and a branded full-screen loader shows while the mesh connects.</p>
<p>Mesh Party: two phones scan each other'sQRandinstantlygetadirectencryptedchatandappsharingbetweenthem—plusa"Share this app"QRthatanyonecanscanwithanormalcameratoinstallthecompanionapp.</p>
<p>Appskeeprunningwhenyouchangehowthey're displayed. Switching an app between windowed and fullscreen used to reload it from scratch (stopping any playing media); the app now stays live through the switch, and each app remembers its own preferred display mode.</p>
<p>A watchdog notices when the Lightning (LND) node wedges and revives it before you do; Fedi ecash gets its own send option with scannable token QR codes.</p>
<p>Your mesh messages now survive restarts. Chat history — channels and DMs alike — used to live only in memory, so a reboot or update wiped every conversation; worse, other nodes silently discarded the first messages you sent after a reboot. Everything is now saved on the node and restored on startup, and post-reboot messages deliver reliably.</p>
<p>Plug in any LoRa radio and the node walks you through it. A setup window appears every time a radio is connected, shows what firmware is already on it (MeshCore, Meshtastic, or Reticulum RNode — with its current name, region, and channels where available), and offers two honest choices: "Set Up with Archipelago Settings" (a preview screen shows exactly what will be written before anything touches the radio) or "Keep As Is" (the radio is used untouched, and you can hot-swap radios freely). Swapping sticks mid-session now just works — including Reticulum RNodes, which fresh installer images now support out of the box.</p>
<p>Incoming bitcoin appears in your wallet within seconds of being sent — balance and the yellow "unconfirmed" entry update live, no refresh, no waiting for the next poll.</p>
<p>The speaker now announces the very first mesh message a node ever receives, and DMs announce just like channel messages (a safety guard against announcement storms was quietly swallowing them). Announcements also react about twice as fast.</p>
<p>Opening a Lightning channel right after the node starts no longer fails with a scary red error. The node quietly retries while Lightning finishes waking up, and if it'sstillnotreadyyougetacalm"still finishing its startup — try again shortly"noticeinstead.</p>
<p>Viewingatransactionworksoneverynodenow,includingsmallones.Nodeswithprunedbitcoinstoragecan't run the Mempool explorer app; transaction links now open your choice of external explorer instead (tx1138.com by default) — after a clear one-time warning that a third-party server will see which transaction you looked up. Set your preferred explorer in Wallet Settings → the new On-chain tab.</p>
<p>Voice commands respond noticeably faster: speech recognition now transcribes in roughly half the time, with identical accuracy on short commands.</p>
<p>Scanning a Lightning invoice with your phone'scameraisfarmorereliable—denseinvoiceQRcodesthatthephotoscannermissedarenowreadbythephone's native barcode engine.</p>
<p>Peer requests sent from Nostr discovery now actually arrive: your node checks for incoming requests every five minutes by itself (previously they sat unseen until someone manually pressed "Poll"), requests publish to all your configured relays instead of two hardcoded ones, and a failed send tells you instead of pretending it worked.</p>
<p>The Connected Nodes list refreshes instantly. It previously froze for up to 30 seconds per offline peer while checking who'sreachable,onepeeratatime;thechecksnowrunallatonceinthebackgroundwhilethelistshowsimmediately.</p>
<p>Settings-stylewindowskeeptheirtabspinnedatthetopandtheirbuttonspinnedatthebottom;onlythemiddlescrolls.Thewallet's tabs are now Channels / Cashu / Fedi / Ark / On-chain so all five fit.</p>
<p>On the TV screen, menus no longer flash open and instantly close. And the interface never follows your computer'slight/darkpreferenceanymore—dropdownsandothernativecontrolsstaydarkoneverydevice.</p>
<p>Errormessagestellyouwhat's actually wrong: "Insufficient balance: need 80 sats, have 0 sats" now reaches your screen instead of "Operation failed. Check server logs."</p>
<p>Installing Mempool no longer refuses to start while ElectrumX is mid-resync (it connects by itself once ElectrumX is ready), and installs no longer fail just because the system was momentarily busy.</p>
<p>Much quieter logs: the node no longer tries to start containers that are already running (hundreds of harmless-but-alarming errors per day), and a node that'sofflinestopshammeringunreachableserversevery30secondswithrebuildattempts.</p>
<p>Phonespairingwiththecompanionappconnectoverthenode's embedded mesh for remote access, with instant QR pairing and per-device access tokens (contributed alongside this release).</p>
<p>Ask your node anything, out loud. Install Pine (the voice assistant app) alongside Home Assistant and everything wires itself automatically: speech recognition, the speaking voice, and a Claude-powered brain. Questions about your node — "what'stheblockheight?", "howmanypeersamIconnectedto?", "isbitcoinsynced?", "what's my Lightning balance?" — are answered instantly from the node itself without costing anything; anything else goes to Claude for a real conversation. New mesh radio messages are read out on your speaker as they arrive.</p>
<p>Pine now ships a wake-word listener, so a paired speaker can sit on standby and activate when it hears its wake word instead of needing a button press. (A custom "Yo Archy" wake word is in the works.)</p>
<p>Pine'slauncherpageshowsyournode's live status at a glance: software version, uptime, bitcoin sync progress, and mesh peers.</p>
<p>Fixed: installing Pine could send Home Assistant into a crash loop on startup (a record the installer wrote was missing a timestamp field Home Assistant requires). Two noisy warnings that repeated in Home Assistant'slogeveryhalfminutearesilencedtoo.</p>
<p>Turningonfederationdiscoverynowshowsyouexactlywhatyou're about to sign: a panel explains the announcement before your key signs it, you can review the signing details any time from the discoverability strip, and the panel fits and scrolls properly on small phones.</p>
<p>Fixed a bug on nodes using the newer app-management engine where Bitcoin'saccesscredentialswerewrittenoutincorrectly(aplaceholderleakedthroughastheliteraltext"/bin/bash"),whichbrokethenode's Bitcoin status display, Lightning'sconnectiontothechain,andanyappthatreadsBitcoindata.</p>
<p>Bitcoin's access credentials also moved out of the process command line into a protected file, so they'renolongervisibletoothersoftwareonthenode.</p>
<p>Pay by pointing your camera: the wallet has a new Scan button (on the wallet card and inside both the Send and Receive windows) that reads any payment QR code — Lightning invoices, Bitcoin addresses, Cashu tokens, and Fedimint invites — and takes you straight to the right send or redeem screen with everything filled in. It also understands the animated, multi-part QR codes some wallets show for long payloads. If your browser can'topenalivecamerapreview(commonwhenreachingthenodeoverplainhttp),a"Take photo of QR"buttonsnapsapicturewithyourphone's camera and reads the code from the photo instead.</p>
<p>The TV screen got a complete overhaul. A deep bug made the display freeze on the intro artwork on 4K TVs — that'sfixed,andalongtheway:theinterfacenowpicksacomfortable,sharpsizeforbigscreens(a4KTVgetsafulldesktoplayoutatdoublesharpness),theartworkbehindeverypageshowsagaininsteadofablackvoid,switchingbetweentabsanimatessmoothly,thebuilt-inAIassistantstaysinitsdarktheme,andtheCashuandArkwalleticonsnolongerrenderasemptysquares.</p>
<p>Youcannowchoosehowbigtheinterfacerendersonyournode's attached screen: Settings → Display offers Auto (recommended), Large UI, Balanced, and Native — changing it applies immediately.</p>
<p>The companion phone app can steer the TV again. Remote input from the phone was being silently ignored on kiosk displays; the remote-control relay now runs there like everywhere else.</p>
<p>The companion app is also ready to grant its built-in browser camera access, so the wallet scanner can work inside the app (ships with the next companion app build).</p>
<p>Zero-amount Lightning invoices can now be paid: the wallet asks you for the amount and sends it along, instead of failing on invoices that leave the amount up to the payer.</p>
<p>The Lightning setup guidance now reads the same everywhere: "Open a channel with Zeus Olympus node and start sending and receiving Lightning payments. Minimum 150,000 · maximum 1,500,000 on-chain sats required."</p>
<p>Installer images now bundle a color-emoji font, so emoji anywhere in the interface render properly on the TV screen.</p>
<p>Meet Pine, your node'svoiceassistant:anewappintheAppStorethatgivesyournodeearsandavoice—speech-to-textandtext-to-speechenginesthatrunentirelyonyourownhardware,readytowireintoHomeAssistantforprivate,offlinevoicecontrol.Installitlikeanyotherapp;nothingyousayleavesyournode.</p>
<p>YournodecannowprogramitsMeshCoreradio's RF settings — frequency, bandwidth, spreading factor, and coding rate — from Mesh → Device settings. Radios that were flashed with mismatched settings could hear that other radios exist but never decode their messages, and until now the only fix was a separate phone app. Set the values once and the node programs the radio automatically (it restarts once to apply); every radio on your mesh must use the same values to talk to each other.</p>
<p>The Device settings panel is tidier: values you can edit (name, region, channel) are no longer also shown as separate read-only rows.</p>
<p>Your node connects to the private mesh far more reliably. Nodes rely on a public rendezvous point to find each other, and the only one available was unreachable from many home and office networks — leaving some nodes unable to join the mesh at all. There is now a second, always-reachable rendezvous point, and your node tries every one it knows, so it joins the mesh in seconds instead of being stranded.</p>
<p>Wi-Fi setup now heals itself on older nodes. Some nodes set up before a mid-year fix couldn'tconnecttoaWi-Finetworkfromthescreen—itfailedwithapermissionserror—becausethepiecethatletsthenodemanagenetworkingonyourbehalfwasmissing.Nodesnowputthatpieceinplaceautomaticallyonstartup,so"scan, pick a network, type the password, connect"workswithoutreinstalling.</p>
<p>Onaphone,thepeerfilesscreentellsyouhowyou're connected again. The badge showing whether a peer'sfilesarearrivingoverthefastmeshoroverTorwasonlyvisibleondesktop—onnarrowscreensitdisappearedentirely.Itnowappearsnexttothepeernameonmobiletoo.</p>
<p>Yournode's mesh settings can no longer be written in a way that breaks the mesh. The configuration file used to be assembled as free-form text, where one wrong setting would stop the mesh service from starting and quietly drop your node off the network. It'snowgeneratedfromacheckeddescriptionofthefile,withteststhatverifytheexactoutput.</p>
<p>Whenyournodehastroublereachinganothernode,thelogsnowrecordtherealreasoninsteadofagenericsummary.Afailuretoopenapeer's files previously logged only "Failed to connect to peer" and threw away the actual cause, which made these problems very hard to diagnose. Nothing changes on screen, and no internal detail is exposed.</p>
<p>Behind the scenes: the installer image now builds its mesh component at a fixed, known version instead of whatever upstream had published that day, so two images built from the same source are identical.</p>
<p>Fixed a failure loop where a node that lost power or was moved could get stuck on a blank "can'treachyournode" screen forever: startup recovery no longer spends minutes retrying containers that no longer exist, and a genuinely large recovery is no longer cut off half-way and forced to start over. The node now reaches its login screen even after the messiest shutdown.</p>
<p>Phone tunnel setup (WireGuard) is now dependable: the QR screen automatically retries while a fresh install is still settling instead of dead-ending at "failedtofetch", and if your node has moved to a different network the QR and downloadable config now carry the node's current address instead of the old one.</p>
<p>Fixed the white screen some laptop displays showed right after the intro on v1.7.104.</p>
<p>The companion phone app no longer suggests installing the companion app from inside itself.</p>
<p>The Tor page now lists onion addresses only for apps you actually have installed — fresh installs no longer come with six pre-made addresses for apps that were never set up.</p>
<p>Running archipelago --version or --help on the command line now prints and exits instead of silently starting a second copy of the node, which could briefly disrupt running apps.</p>
<p>Behind the scenes: installer image builds now stop loudly if VPN components are missing instead of producing a broken image, and a background file-permission sweep runs far less often, reducing disk churn on busy nodes.</p>
<p>Software updates are now much safer to receive: the node will never install an update that isn't completely downloaded and verified byte-for-byte, closing a rare bug where an interrupted or cancelled download could leave a node unable to start.</p>
<p>If a freshly installed update does fail to start, the node now notices and automatically restores the previous working version by itself — no manual rescue needed.</p>
<p>The Electrum server now works with whichever Bitcoin you run: it finds Bitcoin Knots or Bitcoin Core automatically instead of assuming Knots.</p>
<p>While the Electrum server is first building its index, its waiting screen now shows the ElectrumX app icon and live progress.</p>
<p>Connecting from the phone app no longer replays the intro cinematic on a loop: signing in after scanning the pairing QR could accidentally trigger "ReplayIntro" instead of logging you in. The companion app now lands you straight on your dashboard, and the Android app waits for the login screen to be ready before it types your password.</p>
<p>Pressing Enter in any password box now does what you expect — it signs you in or moves to the next field, and can no longer "click" a nearby button by mistake when using a controller or the companion app.</p>
<p>The public demo no longer interrupts you with an "UpdateAvailable" popup that reset the site back to the intro — demo visitors simply get the newest version on their next visit.</p>
<p>The password you choose during setup is now truly your node's password: it also becomes the system login for console and SSH access, instead of leaving the factory default in place. If you ever renamed your node and the TV screen went black on the next boot, that's fixed too — renaming no longer breaks the kiosk display.</p>
<p>Setting up Lightning is now a guided journey: a fund-your-wallet step that shows a live countdown while Bitcoin syncs, suggested channels you can open straight into the Zeus mobile wallet with one tap, and a "finishsetup" prompt that walks you to the end — goals now complete when you've actually done the steps, not just when apps happen to be running.</p>
<p>Pair your phone by pointing it at the screen: the companion app now connects by scanning a QR code — scan, and it fills in your node's address and logs you in. The App Store has a banner to grab the Android app, and the pairing flow can now also set up secure remote access so your phone reaches home from anywhere.</p>
<p>First installs are far more dependable: app downloads that stall now retry instead of hanging forever (the old "firstinstallfails,thesecondworks" pattern), big multi-part apps show their real download progress instead of sitting at "Preparing", Lightning no longer fails its first install over temporary hiccups, and a brand-new node now comes up with its core apps — file cloud and ecash wallet — even with no internet connection.</p>
<p>The installer image is about 160MB smaller and gets to a working screen faster, because the apps bundled for offline setup are now compressed.</p>
<p>The first-run experience keeps its magic: the typing intro is back on fresh installs and can no longer be cut short by a mid-play refresh — updates now politely wait for the cinematic to finish — and dark backgrounds stay dark instead of flashing black or white.</p>
<p>Your backups now include your secrets — including the key that protects your Lightning wallet's recovery seed — and there's a Download button to take a copy off the node; the seed-backup reminder now actually opens the backup flow when you tap it.</p>
<p>Networking Profits grew into a full dashboard, network cards keep their action buttons in reach on every screen size, "ConnecttoMesh" goes to the right page instead of a dead end, and the identity pages got a round of mobile polish.</p>
<p>Behind the scenes: apps that report their own health are no longer second-guessed by a port probe (fewer false "restarting" states), and pressing arrow keys or a gamepad is once again the only thing that shows the controller focus ring.</p>
<p>The wallet speaks Ark: a new Ark tab shows your Ark balance and history, you can send and receive over the Ark protocol, pay Lightning invoices from your Ark balance, and Ark payments appear in the transactions view with their own filter chip.</p>
<p>Every app you install now automatically gets its own private .onion address — your apps are reachable over Tor a few seconds after install, with no manual "AddService" step.</p>
<p>"AddService" in the Tor panel now works for every app, not just a fixed list — the node reads the app's actual web port, so apps like Gitea, Jellyfin, Nextcloud, and Uptime Kuma no longer fail with "seeserverlogs".</p>
<p>Renaming your node now genuinely renames it everywhere: the machine's hostname, its .local network name (re-announced immediately), the local hosts file, and the HTTPS certificate all follow — so http and https links using your node's name keep working right after a rename.</p>
<p>The node no longer mistakes a VPN tunnel for its own address. On fresh installs with NetBird, apps could launch on an internal 10.x address instead of your LAN IP; the node now reads its address from the actual network route, fixing app launch links, generated app configs, and VPN setup.</p>
<p>Your cloud got a real layout: Apps-style tabs with categories for Folders, My Files, and Peer Files, readable file rows, a search that also finds files shared by your federated peer nodes — and music now opens in the bottom-bar player instead of a broken preview window.</p>
<p>The first-login experience flows again: the dashboard entrance animation is back — and you can actually hear it now (its sound was silently swallowed before, including on replays) — "ReplayIntro" in Settings actually replays it, opening a direct link to an inner page no longer detours through the splash screen, the login screen keeps the intro video until your first login (switching to rotating backgrounds after), and the intro video streams three times lighter so it starts instantly.</p>
<p>The public demo is richer and truer: the intro plays on every fresh visit, Ark wallet flows, working DNS and Tor service management, and a library of peer content with previews that never break.</p>
<p>Assorted fixes: failed installs clean up after themselves properly, and the transactions view fits mobile screens (capped at 60% of the visible viewport).</p>
<p>Bitcoin now supports multiple versions of both Bitcoin Core and Bitcoin Knots: install the version you want, switch between them, pin a version, or let it auto-update — and switching is designed to be safe, with no surprise resyncs.</p>
<p>Lightning grew up: your LND wallet's recovery seed is captured at setup and kept as an encrypted backup you can reveal from Settings, there's a new Channels tab with a fee control when opening channels, and on-chain and Lightning balances now show side by side.</p>
<p>Installing Lightning (and other Bitcoin-dependent apps) on a fresh node no longer fails repeatedly — the node now waits until Bitcoin is genuinely ready to answer before starting them, and Bitcoin sizes its storage to your actual disk and its memory cache to your RAM, so small machines stop swapping and stalling.</p>
<p>The wallet understands more money: Cashu v4 tokens are supported, you can pay for a peer's files from either your Cashu or Fedimint ecash, and the Transactions view now shows your Lightning, Cashu, and Fedimint activity together — with a payment confirmation screen and an automatic refund if a purchase fails.</p>
<p>Mesh radios got a major upgrade: Meshtastic direct messages are now true end-to-end-encrypted radio messages that interoperate with off-the-shelf Meshtastic phone apps, your radio's region and a shared channel are provisioned automatically, and a new setup window appears when a radio is plugged in — with board pictures, full radio settings, and signal-strength indicators.</p>
<p>Reticulum joins as a third mesh radio protocol with RNode LoRa hardware support, including sending images and voice messages over the radio — and every chat message now carries a small pill showing how it travelled (Mesh, FIPS, or Tor).</p>
<p>Your node can manage an OpenWrt router: set up its internet uplink from the UI with a Wi-Fi network scan, turn it into a TollGate pay-for-Wi-Fi hotspot with a real captive portal, and sweep the router's earnings into your node's wallet. The gateway's status appears on the Home screen's Network tile.</p>
<p>Peering is now trust-aware: "InviteaPeer" grants view-only Observer access while "LinkYourNodes" grants Trusted access, incoming requests ask for your confirmation with an optional message, Node Visibility is a single clear switch plus a list of discoverable nodes you can peer with, and the Fleet view shows your trusted nodes' health.</p>
<p>Updates and apps are verified end-to-end: release updates are cryptographically signed and checked against a key baked into your node, app definitions arrive via the signed catalog, and container images are checked against trusted sources before anything installs or runs.</p>
<p>Dozens of reliability fixes: failed installs no longer leave phantom app cards, uninstalling can't hang forever, apps you stopped stay stopped, crashed apps heal themselves (even "running" containers whose process actually died), the login page no longer refresh-loops, and the mobile layout fits real phone screens instead of hiding the last row behind the browser bar.</p>
<p>Ask your node things over the radio: send "!archy" for node status with no AI involved, or "!ai<yourquestion>" in a direct message for an AI answer that comes back on the same path it arrived — with a model dropdown (Haiku, Sonnet, or Opus) and an "alwaysallow" list in the Mesh AI Assistant panel.</p>
<p>The off-grid mesh radio no longer posts cryptic identity codes ("ARCHY:") to the shared public channel every minute, and mesh contacts take care of themselves: new radios you hear are added automatically, "ClearAll" really removes contacts (they return when in range), each contact shows a reachability dot, and the Peers list has a search box.</p>
<p>You can message standard meshcore phone apps and they can message you — readable text both ways, private replies instead of public-channel broadcasts. Federated Archipelago nodes now appear on the Mesh Map.</p>
<p>Apps open as an overlay on top of whatever page you're on, in every display mode, instead of yanking you to a different screen; the Services tab groups apps by category with proper icons.</p>
<p>BTCPay Server keeps its plugins across restarts, connects to your node's own LND out of the box, and its invoices stay payable over private Lightning channels.</p>
<p>Fedimint federations show up in Wallet Settings again (the client app's configuration error is fixed), and Wallet Settings has tabbed sections for Cashu and Fedimint.</p>
<p>The phone companion app can upload and download files, edit saved server entries, opens non-embeddable apps in an in-app browser, and got a proper round launcher icon.</p>
<p>Six placeholder "apps" that were just web bookmarks are gone from the store, the Bitcoin dashboard works fully offline, Gitea opens on the right port, and mempool, strfry, and Electrum stopped their restart loops.</p>
<p>Kiosk displays: HDMI audio no longer stutters, and a bad display-clone state no longer sticks after reboot.</p>
<p>Consistent dropdowns, toggles, tabs, and modal styling across the UI; in Mesh chat, scrolling the conversation no longer also scrolls the contact list; "AppUpdates" and "AppRegistry" sit directly under Account in Settings; and a fresh node no longer reinstalls apps just because their definition file exists on disk.</p>
<p>Your node can now hold Fedimint ecash as well as Cashu. Wallet Settings now has tabbed sections for each: keep your list of trusted Cashu mints, or paste a Fedimint invite code to join a federation, and the home wallet card shows both your Cashu and Fedimint balances side by side. A new "FedimintClient" app in the catalog powers the federation side.</p>
<p>You can now buy files shared by another node, right from their cloud. When you open a peer's paid file you get a simple "Buythisfile" picker with several ways to pay — instantly from this node's ecash balance, from your node's own Lightning wallet, on-chain from your node, or by scanning a Lightning QR code with any outside wallet. Once payment settles, the file downloads automatically.</p>
<p>Your node can now act as an AI assistant on the off-grid mesh radio network. If your node has a local AI model available (via Ollama), other people on the mesh can ask it a question by starting their message with "!ai" and get an answer back over the radio — handy where there's no internet. A new Mesh assistant panel lets you turn this on or off and shows whether a local AI model was detected.</p>
<p>You can now view your node's 24-word recovery phrase whenever you need it. Settings has a new "Recoveryphrase" option that, after you confirm your password (and 2FA code if you use one), reveals the words behind a tap-to-show blur with a copy button — so you can write them down and store them safely offline.</p>
<p>Setting up a brand-new node is smoother and less alarming. If the node is still starting up while you generate or confirm your recovery phrase, it now quietly waits and retries instead of flashing a scary error, and offers a clear "Tryagain" button only when something genuinely goes wrong. The final setup screen also shows a gentle "securingyourprivateconnection…" status that turns to "ready" on its own, so you can tell the encrypted transport is coming up rather than stuck.</p>
<p>The NetBird VPN app now actually logs in. It was failing to reach its sign-in screen because the dashboard needs a secure (HTTPS) connection that wasn't being provided; the node now serves it over HTTPS and opens it in a browser tab, so the login flow completes.</p>
<p>When you use your phone to remote-control a node's attached screen, two-finger scrolling now works inside apps and panels, not just the main page. And tapping an app that's meant to open in an external browser now hands the link to your phone to open there, instead of trying to open it on the (often unattended) attached display.</p>
<p>You can now choose whether your node shares Bitcoin block headers over the mesh. The Mesh Bitcoin panel has new switches to announce headers to peers and to accept headers from them, and your choices are remembered.</p>
<p>Version numbers now display cleanly everywhere. In a few places the interface was showing a doubled "v" (like "vv1.7.98"); it now always shows a single, tidy version label.</p>
<p>The "Back" buttons throughout the cloud and other detail screens now look and behave consistently on both desktop and mobile, including when browsing another node's files.</p>
<p>For advanced testing, Settings now includes an optional "update&appsource" choice between the usual trusted origin and an experimental peer-to-peer (DHT swarm) mode that pulls updates and app content from other nodes first, falling back to the origin automatically. The trusted origin remains the default.</p>
<p>Apps that crash now recover on their own. Multi-part apps like Immich and IndeedHub could have one of their pieces stop and stay stopped until the whole node was rebooted; the node now checks every couple of minutes and restarts any crashed piece automatically (while still leaving apps you deliberately stopped alone).</p>
<p>The on-screen kiosk display can no longer slow the whole node down. On machines without a graphics chip the kiosk browser could spin a CPU core at full tilt, starving everything else (including the wallet, which then timed out); it's now capped and uses lighter rendering on those machines.</p>
<p>If an update download fails, you're taken back to the Download button to retry, instead of being stranded on an Install button for an update that didn't actually finish downloading.</p>
<p>Your node's identity is clearer and always visible: Settings now shows your Node DID on every node (it previously only appeared if your browser had cached it) plus your node's npub, both with copy buttons. There's also a terminal tool to cryptographically prove all your node's keys come from your one seed phrase.</p>
<p>The "allnodesoverTor" group chat sends quickly now — the "sending" spinner clears as soon as the reachable nodes have the message, instead of hanging on a slow or offline node.</p>
<p>Message notifications now have a close button and open the relevant chat when tapped.</p>
<p>The encrypted mesh transport (FIPS) turns itself on automatically after setup — no button to press — and connects to peers more reliably (it retries and keeps connections warm), so node-to-node features use the fast path more often instead of falling back to Tor.</p>
<p>Your chat history with other nodes is saved reliably and now encrypted on disk, so it survives restarts and updates and can't be read from a stolen drive (only clearing chat removes it).</p>
<p>Peer media shows a "connecting" loader before a video or audio file plays, and audio errors are accurate instead of blaming File Browser.</p>
<p>The Fedimint app now displays with its proper styling, and the Connected Nodes screen stays compact — it shows a few nodes and scrolls, you can tap a node to jump to it in Federation, or tap Message to open its chat.</p>
<p>App updates can now arrive on their own without waiting for a full system release, so individual apps can be improved and shipped faster.</p>
<p>The Bitcoin sync status on the home screen no longer disappears for a moment when it refreshes. If the node was briefly busy, the panel used to vanish and pop back; it now stays put and simply shows "Updating…" until the next reading arrives, while a genuinely stopped node still correctly shows as not running.</p>
<p>Bitcoin sync progress on the home screen now updates more promptly, so the percentage and block height keep pace with the node instead of lagging behind.</p>
<p>The Lightning wallet "connectyourwallet" screen loads its details and QR code again across all nodes, instead of failing to fetch them.</p>
<p>Your list of trusted nodes is now clean: the same node no longer appears several times under different names, and removed nodes stay removed. In chat, a node that previously showed up as two separate contacts now appears just once.</p>
<p>Browsing another node's cloud is smoother: music and video files from a peer now preview and play properly (including seeking partway through), and the connection now shows a small badge telling you whether it's using the fast encrypted mesh or the slower Tor network.</p>
<p>Opening "MyFolders" in the cloud now shows a clear, friendly message when the file app isn't running, instead of a confusing error.</p>
<p>The Electrum server app opens on its own once it's ready, instead of sometimes leaving a loading spinner stuck on top of the screen.</p>
<p>The Fedimint app now displays with its proper styling and icons, instead of appearing unstyled with a missing image.</p>
<p>The Mempool app now connects to your Bitcoin node whether the node is Bitcoin Core or Bitcoin Knots, instead of only working with one of them.</p>
<p>Nodes start up cleanly after a reboot. On some boots the node's main service was trying to start before its data drive had finished mounting, so it failed and retried about twenty times over roughly five minutes — showing a wall of "Failedtostart" messages — before finally coming up. It now waits for the data drive to be ready first, so it starts on the first try.</p>
<p>The background images throughout the interface now load faster — they've been made significantly smaller with no loss of quality.</p>
<p>The screen attached to your node now shows the normal Archipelago interface and your dashboard after you sign in, instead of a separate, stripped-down grid of app icons that could appear in its place. That extra screen has been removed so the attached display matches what you see everywhere else.</p>
<p>On a brand-new node, the attached screen now walks through the same welcome and setup steps you'd see on a phone or laptop, and shows the normal sign-in screen once the node is set up — so the on-device display always matches the rest of the interface.</p>
<p>When adding a FIPS network anchor, you can now choose whether it connects over TCP (for a public anchor reached across the internet) or UDP (for one on your local network), instead of it always assuming the local-network option.</p>
<p>Behind the scenes, a new automated two-node test now exercises real node-to-node features — browsing another node's shared files and handling a removed node — against live nodes before each release, so node-to-node problems are caught earlier.</p>
<p>Browsing another node's shared files now works over the fast encrypted mesh. Opening a peer's cloud could fail with a generic "Operationfailed" message because the request for their file list wasn't permitted over the mesh and came back as "notfound" — and it never retried over Tor. The mesh now serves the file list directly, and if a peer can't answer over the mesh the node automatically falls back to Tor instead of giving up.</p>
<p>Nodes you remove from your federation now stay removed. Previously a deleted node could quietly come back the next time you synced with another node that still listed it. Removed nodes are now remembered as removed and won't reappear on their own — only if you add them back yourself.</p>
<p>The app credentials pop-up now appears as a normal centred box with a dimmed background over the whole screen, instead of stretching to fill the entire screen.</p>
<p>Your node now joins the private encrypted mesh network on its own. A wrong built-in setting meant nodes were quietly never reaching the shared mesh meeting point, so everything between nodes fell back to the slower Tor network. Every node now connects to the mesh automatically on startup, so node-to-node features like file sharing use the faster encrypted mesh first and only fall back to Tor when a peer is genuinely offline. (Confirmed live: a node with its mesh setting wiped re-connected to the mesh by itself within a second of starting.)</p>
<p>You can now bring the mesh networking software up to the latest stable version straight from the node, with one action — it fetches the new version, checks it's genuine before installing, and restarts the mesh on its own. (Confirmed live end to end: a node on an older build was upgraded to the current stable release and rejoined the mesh automatically.)</p>
<p>The Lightning wallet screen connects again on nodes where it was showing a "failedtofetch" error instead of your balance and channels. The wallet app and the node now talk to each other correctly, and the connection quietly repairs itself if its details drift after a restart.</p>
<p>Receiving Bitcoin and Lightning works again on nodes where the Lightning wallet was stuck locked. After some updates the wallet could come back locked with a password the node no longer had, so "generateareceiveaddress" kept failing with a "walletislocked" message that nothing could clear. The node now detects this and repairs itself automatically.</p>
<p>Each node now secures its Lightning wallet with its own unique, randomly generated password instead of a shared built-in one, and remembers it safely so the wallet unlocks on its own after every restart or update — no more getting stuck locked.</p>
<p>If a wallet is found locked with an unrecoverable password, the node rebuilds it cleanly so Bitcoin and Lightning start working again. (On these early-access nodes the wallet holds no funds, so nothing is lost — a wallet locked with an unknown password was already inaccessible.)</p>
<p>The self-repair was validated end to end on live nodes: a stuck, locked wallet was detected, rebuilt, and came back unlocked on its own, and stayed unlocked across restarts.</p>
<p>The Electrum server app no longer flashes a "can't connect, try again" error over its loading screen while it'sstillcatchingup.IfElectrumXisbuildingitsindexorwaitingontheBitcoinnode,younowjustseethesyncprogress,andtheappopensonitsownonceit's ready.</p>
<p>Behind the scenes, the reboot-survival test now confirms the whole system is genuinely healthy after a restart — every app reachable, updates not stuck, core services answering — instead of only checking that containers came back, so update-related problems are caught before shipping.</p>
<p>Settings → What'sNewnowliststhenotesforeveryrecentreleaseagain.Thescreenhadquietlyfallenseveralversionsbehind,sothelasteightreleasesofchangesweren't showing up there — they'reallbacknow,andareleasecheckkeepsitfromdriftingagain.</p>
<p>Appsyou've installed now reliably show their "Open" button again. Some apps — including Jellyfin, BTCPay Server, Fedimint, Gitea and Portainer — were running fine but their launch link sometimes went missing, so there was no way to open them from the home screen. They now open correctly.</p>
<p>Receiving Bitcoin is more dependable: if the wallet'sinternalconnectiondetailsdriftafterarestart,itnowrepairsthemonitsown,andanyerroritdoeshitisreportedclearlyinsteadofasagenericfailureoramisleading"wallet locked"message.</p>
<p>"Open in a new tab"fromthecompanionappnowopenstheappinyourphone's browser, instead of doing nothing. The normal mobile browser keeps working as before.</p>
<p>The login/credentials pop-up on phones is once again a centered, properly sized window rather than stretching the full height of the screen.</p>
<p>The Electrum server now recovers on its own if its index ever gets corrupted, and shows a clear progress screen (with percent complete and block height) while it builds its index, instead of a blank or broken page.</p>
<p>Software updates are more reliable on slow internet connections — downloads are given much more time to finish before giving up.</p>
<p>The AI assistant looks the way it always did again: no extra back button or close button on phones, and the desktop view fills the whole screen without a gap at the bottom.</p>
<p>System updates are much more reliable: updates that previously got stuck partway or failed to install now complete cleanly, and a failed update can no longer block all future updates.</p>
<p>After an update, the system now checks itself correctly on every node type, so working updates are no longer mistakenly undone.</p>
<p>Generating a Bitcoin receive address works again on nodes where a network proxy previously got in the way.</p>
<p>The Lightning wallet now recovers and unlocks itself properly after restarts.</p>
<p>AIUI now loads immediately again instead of waiting on a production availability probe and cache-busted iframe URL, restoring the lighter launch behavior from before the regression.</p>
<p>Bitcoin receive now uses LND'sGET-basednewaddressflowwiththenativeSegWitaddresstype,fixingthe501MethodNotAllowedresponsefromthepreviousPOSTattempt.</p>
<p>BitcoinreceivenowcallsLND's on-chain address endpoint with the correct REST method, and backend failures keep the specific address-generation error instead of collapsing into the generic operation-failed message.</p>
<p>App launch credential interstitials now render as true full-screen overlays, and the launcher loading indicator uses the neutral brand palette instead of a blue spinner.</p>
<p>Fleet now preserves the last known node list, alerts, and selection locally while telemetry refreshes in the background, so the dashboard no longer blanks on tab switches or update scans.</p>
<p>Connected nodes and identities now reuse their last loaded data instead of reloading the visible list every time the user revisits the tab.</p>
<p>The Fleet matrix and detail views now show actual node names and host information instead of raw node id prefixes.</p>
<p>The network map only redraws when its graph data actually changes, which stops the D3 scene from visually resetting on every refresh tick.</p>
<p>Mobile federation and system-update actions now stack full width, and the ElectrumX app health check allows a long startup window so slow sync nodes do not restart mid-index.</p>
<p>ElectrumX now runs with less cache pressure and more memory headroom, reducing the restart loop seen during sync catch-up.</p>
<p>Portainer is pinned to 2.19.4 instead of latest, avoiding schema-drift restarts from surprise image updates.</p>
<p>LND receive-address creation now asks for a native SegWit address and returns clearer wallet/readiness failures when an address is not available.</p>
<p>Fleet telemetry now carries server name, hostname, and server URL, and the Fleet dashboard shows those names instead of hashed node ids.</p>
<p>Trusted federation peers are still auto-added transitively, but the local node no longer imports itself back into the fleet list.</p>
<p>Bitcoin trusted-node relay approvals now generate restricted txrelay credentials and restart the active Bitcoin backend so the new RPC whitelist is live.</p>
<p>Bitcoin Core now matches Bitcoin Knots for restricted relay RPC support, including txrelay secret injection and sendrawtransaction-focused permissions.</p>
<p>The Bitcoin UI companion image is pinned for OTA updates, and container scanning now avoids getting stuck busy after timeout or error paths.</p>
<p>App launch metadata now follows typed manifest launch interfaces more consistently, keeping catalog entries aligned with their runtime ports and launch surfaces.</p>
<p>Unsupported app surfaces were removed from the release path, including revoked OnlyOffice metadata and the unvalidated Saleor surface.</p>
<p>Mobile and desktop app surfaces received release polish: stricter production build typing, safer mesh desktop/tablet scrolling, improved mobile app layout, and a Home system card link that goes directly to Monitoring.</p>
<p>The Bitcoin UI avoids false stale/reconnecting messages when fresh block snapshots advance, and deploy tooling now skips local scratch/upload artifacts while bounding optional IndeedHub fixups.</p>
<p>Saleor storefront proxying forwarded the correct external host and media paths, fixing Server Actions origin checks and product image optimizer failures.</p>
<p>The storefront received an internal media origin so rewritten media URLs resolve inside the Podman network without exposing private API ports to browsers.</p>
<p>Saleor storefront installs switched to the prebuilt registry image instead of building Next.js on-device, avoiding build failures during stack installation.</p>
<p>Existing Saleor stacks were repaired on adoption by recreating missing storefront containers, forcing the app to bind on all interfaces, and resolving nginx upstreams after restarts.</p>
<p>Saleor storefront proxying falls back to the direct request scheme when forwarded protocol headers are absent, fixing direct local launches on port 9011.</p>
<p>Public proxy support remains intact by still honoring forwarded HTTPS headers for Nginx Proxy Manager domains.</p>
<p>Saleor was published as a recommended commerce stack with storefront, dashboard, API, worker, database, cache, Mailpit, and Jaeger services.</p>
<p>Saleor launches opened the storefront while dashboard credentials stayed visible in Archipelago, and public storefront domains received same-origin GraphQL proxying.</p>
<p>NetBird launches now stay on the unified dashboard/proxy origin at port 8087 instead of following stale server URLs on 8086.</p>
<p>NetBird proxy routing no longer depends on a hard-coded rootless Podman gateway IP and now includes the upstream management proxy gRPC path.</p>
<p>Mobile credential prompts keep long credential lists scrollable and the Cancel/Continue buttons reachable in both My Apps and the mobile icon grid.</p>
<p>Android app-session popups hand external login/signup windows to the system browser instead of dropping them inside the WebView.</p>
<p>Saleor first-use credentials are shown in Archipelago before launch and in App Details, instead of leaving users at an unexplained dashboard login.</p>
<p>NetBird embedded login now uses upstream-compatible signing-key behavior and sends ID tokens to the management API, fixing post-signup Unauthenticated states.</p>
<p>Transient unnamed Podman helper containers are hidden from My Apps so generated names no longer appear as user applications.</p>
<p>NetBird API and OAuth routes now proxy through the stable host-published server port, and the embedded IdP keeps upstream-compatible signing-key refresh settings while the dashboard sends ID tokens to the API so signup no longer lands in an Unauthenticated dashboard state.</p>
<p>Transient unnamed Podman helper containers created during app installs are hidden from My Apps, so random generated names like eager_keldysh no longer appear as applications.</p>
<p>Mobile App Store categories are now visible as horizontal chips above the tab bar, Discover is reachable on mobile, category choices update the actual view, and apps that require a real tab open directly from the icon tap.</p>
<p>NetBird repair now rewrites the unified-origin config and recreates the browser-facing proxy/dashboard while preserving existing control-plane data.</p>
<p>Desktop dashboard scrolling hands focus back from the sidebar to the main content when the pointer or wheel moves over the main pane.</p>
<p>App-session right panels now re-focus the iframe after load and when the frame area is activated, so scrolling works immediately after selecting an app or switching tabs on shorter screens.</p>
<p>NetBird now uses a unified local launch origin on port 8087 that serves the dashboard and proxies auth/API routes to the server, fixing the Unauthenticated and 404 logout/login loop.</p>
<p>Existing NetBird installs are repaired during adopt/start by rewriting the config files and creating the missing dashboard/proxy containers while preserving data.</p>
<p>Mobile apps that block iframe embedding now open directly in a browser tab instead of first landing in a broken in-shell webview.</p>
<p>App Store search covers all apps while searching, My Apps search can surface matching installable App Store entries, and mobile My Apps/Websites tab switching updates the view reliably.</p>
<p>NetBird installs prefer a 100.x tailnet address when available, and app sessions gained iframe auto-focus plus a scroll host for right-frame scrolling.</p>
<p>Home status cards are calmer and more honest now. System, VPN, Bitcoin, and FIPS values keep their last known good state while route changes or short RPC failures are in flight, so the dashboard no longer flashes false "not configured" or "not running" states during normal refreshes.</p>
<p>Home, Web5 Monitoring, and the full Monitoring page now agree on the headline CPU, memory, disk, uptime, and load numbers. The UI uses one live system-stat snapshot for the visible cards while keeping the Monitoring page'shistoricalstoreforcharts,alerts,andcontainerhistory.</p>
<p>ThemissingWhat's New history is filled in through this release, including every curated entry from v1.7.44-alpha through v1.7.66-alpha.</p>
<p>Bitcoin lifecycle specs are aligned again across Rust, first boot, and reconcile. Bitcoin Core/Knots get the intended memory headroom on normal hosts, and pruned Knots uses a larger dbcache when the node has enough RAM, improving IBD throughput without raising pressure on low-memory machines.</p>
<p>ElectrumX/electrs lifecycle specs now use the same memory policy everywhere, reducing drift between fresh installs, app lifecycle actions, and reconciliation.</p>
<p>Nginx Proxy Manager stale-port repair now catches stopped or Created Podman records that still remember old port mappings. That means a stuck record can be removed and recreated before it blocks the current NPM ports.</p>
<p>Live recovery on the field node preserved the existing Nginx Proxy Manager data directory while recreating only the stale container metadata with the current 8081, 8084, and 8444 host ports.</p>
<p>Orchestrator-backed app starts now run the same pre-start repair path as the legacy Podman start flow. Nginx Proxy Manager can clean up stale port metadata before the orchestrator tries to bring it online.</p>
<p>Diagnostics confirmed host nginx was healthy while Nginx Proxy Manager itself had no listeners on its expected ports, narrowing the outage to NPM container lifecycle repair instead of the system proxy.</p>
<p>Authenticated update applies are no longer throttled so aggressively during troubleshooting. The System Update page now allows legitimate retry flows without immediately running into 429 Too Many Requests.</p>
<p>The release still includes the corrected backend rebuild protection, so OTA artifacts are built from the fresh Rust binary instead of an older compiled version.</p>
<p>The release script now rebuilds the backend after bumping the version and before hashing artifacts. OTA manifests no longer point at a stale backend binary.</p>
<p>This corrected the previous stale-artifact issue and carries the Nginx Proxy Manager stale-port repair in a backend binary that nodes can actually install and run.</p>
<p>Nginx Proxy Manager start and restart now repair stale Podman containers that still publish the admin UI on host port 81, which conflicts with host nginx on updated nodes.</p>
<p>The repair recreates only NPM container metadata while preserving its persistent data and using the current 8081, 8084, and 8444 host mappings.</p>
<p>Multi-container stack installs stay in Installing for up to 20 minutes while dependency containers are being pulled and prepared. BTCPay no longer appears to vanish after two minutes while Postgres and NBXplorer are still being created.</p>
<p>Lifecycle stale-state recovery remains short for start, stop, restart, update, and removal actions, so genuinely wedged operations still clear quickly.</p>
<p>Meshtastic serial detection now rejects malformed handshakes and skips known non-mesh serial devices such as Sierra Wireless LTE modems and Zooz/Z-Wave sticks.</p>
<p>Meshtastic config sync sends the correct protobuf wire type, allowing node-info and contact ingestion to work reliably. The mesh udev rule also stops claiming every ttyACM device and now targets known mesh adapters/vendors.</p>
<p>MeshtastictextpacketsaretranslatedintoArchipelago's existing mesh frame pipeline, and Meshtastic node information appears as normal mesh contacts using stable synthetic public keys.</p>
<p>Frontend OTA behavior improved: hashed assets no longer fall back to index.html, the HTML shell revalidates on every load, and runtime promotion installs the bundled nginx config on update.</p>
<p>Nginx Proxy Manager now avoids privileged rootless Podman host port 81, preferring 8081 for its admin UI while host nginx keeps a compatibility proxy on :81 for stale launch buttons.</p>
<p>App installs allocate ports by checking live host bind availability, falling back to a free high port when preferred ports are occupied. Portainer-created launchable containers now appear in a Websites tab through their discovered host ports.</p>
<p>Fresh installs include the full Wi-Fi userspace stack and grant the Archipelago service user NetworkManager PolicyKit access, so Intel Wi-Fi scanning and connection changes work from the web UI.</p>
<p>Container health and reconciliation are more honest and resilient: stale alerts clear, Stopping containers can be recreated, health states come from Podman, and drifted Quadlet settings trigger proper restarts.</p>
<p>Bitcoin Knots and ElectrumX get more CPU and memory headroom, LND helpers tolerate container-owned files better, and the screensaver stays out of media-heavy app sessions.</p>
<p>Container reconcile can force-recreate Podman records stuck in Stopping while preserving bind-mounted app data, recovering wedged containers automatically.</p>
<p>Lifecycle audits on the hardened container layer passed on the validation node, with direct app probes returning healthy responses.</p>
<p>Existing installs now self-repair nginx backend proxy locations for Bitcoin status and app catalog calls, including hosts where the active config is a copied file rather than a symlink.</p>
<p>LND UI is consistently served on port 18083 across first boot, Tor config, Quadlet reconciliation, OTA runtime payloads, and ISO scripts. OTA frontend tarballs also carry a cleaner runtime payload so startup promotion does not reintroduce stale host assets.</p>
<p>Bitcoin Knots/Core config generation no longer duplicates RPC bind and port settings between bitcoin.conf and container command arguments, fixing startup failures from RPC endpoint binding conflicts.</p>
<p>Legacy Bitcoin healthchecks no longer depend on bitcoin-cli being present in current images. Update checks now prefer manifest OTA releases over stale git remotes unless git updates are explicitly enabled.</p>
<p>Tailscale now launches its local installed web UI on port 8240 and starts tailscaled before tailscale web, fixing unreachable installs after container creation.</p>
<p>Grafana lifecycle actions repair missing rootless host listeners on port 3000, and Debian 13 install paths pull security updates from trixie-security during image/install creation.</p>
<p>Bitcoin Knots/Core UI now reports connection, reconnecting, syncing, and error states from a backend status bridge instead of showing stale connection failures while the node warms up.</p>
<p>ElectrumX exposes indexed height, local Bitcoin height, known headers, status, and progress source, making long initial indexing states readable. Bitcoin Core and Bitcoin Knots are now mutually exclusive variants with corrected install conflict handling.</p>
<p>IndeeHub launches only on its direct web UI port, and BTCPay/NBXplorer Postgres environment formatting was fixed to avoid malformed connection strings.</p>
<p>archipelago.service now creates /run/containers before startup, fixing systemd mount-namespace failures on nodes where that runtime directory did not already exist.</p>
<p>Bitcoin Knots/Core sync is significantly faster: containers now use every available core for script verification and have 8 GB of memory so the 4 GB UTXO cache has headroom.</p>
<p>ElectrumX initial indexing is faster too, with CPU caps removed, 4 GB of container memory, and a 3 GB internal cache.</p>
<p>Health monitoring no longer pages auto-restart failures for orphaned containers left behind after Bitcoin variant switches.</p>
<p>Apps no longer disappear from My Apps when an install fails, and multi-image stack pull progress now advances during the download phase instead of sticking at 20%.</p>
<p>Several docker.io images were mirrored into Archipelago registries, reducing first-boot install dependency on Docker Hub.</p>
<p>Bitcoin RPC auth is durable across container restart, image update, and reboot. The dashboard no longer fails because registry-pulled images shipped stale baked-in credentials.</p>
<p>Multi-container apps show real install progress, app cards stay visible while containers are being created, IndeedHub installs cleanly on fresh nodes, and Tailscale install no longer fails from a malformed command.</p>
<p>The installer now allocates swap on the encrypted data partition, capped at 8 GB, so image builds and memory spikes are less likely to OOM the system.</p>
<p>Container orchestration migration and release hardening continued, including OTA synchronization for rebuilt UI containers and aligned LND UI port handling across runtime specs.</p>
<p>Release packaging moved toward tarball-only artifacts with archived ISO build recipes, keeping update payloads focused on the files existing nodes need.</p>
<p>Installing, updating, and removing apps no longer freezes the UI. The backend now spawns the actual work in the background and returns immediately, so the progress bar starts moving right away instead of the whole page locking up for 30+ seconds while podman pulls an image.</p>
<p>Install progress bar actually reflects reality now. It previously stayed at 0% until the very end because podman doesn'temitparseableprogresswhenrunwithoutaTTY.Replacedbyte-countingwithsevenclearly-labelledphases—Preparing,Pullingimage,Creatingcontainer,Starting,Waitingforhealth,Finalizing,Done—eachmappedtoafixedpercentagesothebaronlymovesforward.</p>
<p>Thecontainer-installauditlogisnowactuallywrittentodisk.Thebackendrunsasanunprivilegeduserandwastryingtoappendeveryinstall,update,andlifecycleeventto/var/log/archipelago-container-installs.log — a path only root can create. Every write failed silently, so the log stayed empty on every node. Logs now land at /var/log/archipelago/container-installs.log, a directory pre-created at boot and on self-update with the right ownership, and they rotate daily under the existing logrotate rule.</p>
<p>TheAIAssistanttabnolongerdisappearsafterupdates.Self-updatesrebuiltthefrontendfromsourceandthenusedrsync--deletetoswapitintoplacewhilepassing--excludeaiuitopreservetheexistingbundle;thatworkedonlyaslongasapreviousinstallhadalreadyputAIUIondisk.AnynodewhosewebUIdirectorygotreplacedwholesale(includingbyamanualredeployofjustthedisttarball)lostAIUIentirelyandtheAIAssistanttabfellthroughtoa"needs to be enabled"placeholder.EveryupdateandeveryISObuildnowshipsthecanonicalAIUIbundlefromdemo/aiuiintherepo,soAIUIisafirst-classversionedpartofeachreleaseandcannotbewipedbyaswap.</p>
<p>Updatesnowself-check.Afteranupdatelands,thenodeprobesitsownwebUIthroughnginx—ifthefrontendisn't answering cleanly within 90 seconds, the node automatically rolls back to the previous version and restarts. A bad release can no longer leave the fleet stranded on an unreachable node.</p>
<p>Proper fix for the 500 / Internal Server Error after update. The v1.7.38 and v1.7.39 frontend archives had the wrong permissions baked into the archive itself — the tarball'srootdirectoryentrywasprivate,soeverynodethatextracteditendedupwithawebUIdirectorynginxcouldn't read. v1.7.40 packages the archive with correct world-readable permissions from the start, so no node ever sees the 500 again.</p>
<p>Hotfix for v1.7.38 — on some nodes the update landed with the web UI directory set to private file permissions, so nginx returned a 500 / "Internal Server Error" on every page. This release fixes the updater to set world-readable permissions on the new frontend, and the node also now self-heals on boot if it ever finds the UI directory in that state again.</p>
<p>Signing in is quiet now. The intro music, welcome voice, and transition sounds belong to the first-boot cinematic and only play before you'vefinishedonboarding—everyloginafterthatissilent.Typingsoundsinthesearchbarandonthedashboardareunaffected.</p>
<p>Fixedabugwhereclearingyourbrowsercache,updatingthenode,orrebootingcouldbounceyoubackthroughtheonboardingwizardeventhoughyournodewasalreadyfullysetup.Thenodenowself-heals:ifyourpasswordisset,itknowsyou've been through onboarding and takes you straight to the login screen. No more starting over.</p>
<p>Trimmed the App Store. FIPS, Nostr Relay, Nostr VPN, Routstr, and Penpot have been removed from the catalog and their container images deleted from our registries. Your node'snativeFIPStransportisuntouched—thisisjusttheapp-storeentriesgoingaway.</p>
<p>BitcoinCore(thereferenceimplementation)nowinstallsfromtheAppStoreandrunscleanlyalongsideBitcoinKnotsasafirst-classoption.Theinstallflowpullstheofficialdocker.io/bitcoinimagedirectlyifyourinternalmirrorsdon't carry it, and the node UI auto-detects which implementation is running so the logo, title, and version line all reflect Core vs. Knots without any manual config.</p>
<p>The node dashboard now shows a Storage indicator (Full Archive · X GB or Pruned · X GB) right next to Network, so you can tell at a glance whether your node is carrying the full chain history or the last ~550 MB. The Node Settings modal was stripped of its hardcoded Regtest/port-18443 placeholders and now shows real values — network mode, storage mode, transaction index, ZMQ publishing, and RPC port — all read from the running node.</p>
<p>Fresh installs no longer default to pruned mode. Previously, a new install would write <code>prune=550</code> into bitcoin.conf even on boxes with 2 TB of free space; now the default is full archive and you can opt into pruning by editing the conf yourself.</p>
<p>Bitcoin Core joins the App Store as its own entry, with the Umbrel community icon and a description that frames it as a reference alternative to Bitcoin Knots rather than a replacement. A Sovereignty Stack tile on the Discover page now groups your node options together so the choice is obvious.</p>
<p>The App Store catalog fetch now follows whichever container registries you'vesetasprimaryinSettings.PreviouslythecatalogURLwashardcodedtotwoservers;nowtheoperator's own mirror priority drives where the App Store pulls its listings from, so switching primary actually moves the catalog too.</p>
<p>Rootless-netns self-heal: if the container network loses its outbound tap (symptom: Bitcoin Knots and other outbound containers can'treachtheinterneteventhoughcontainer-to-containerstillworks),thenodenowdetectsitandrestartsthenetworkfromscratchonitsown.NomorehavingtoSSHinandbouncepodman.</p>
<p>Yournode's Web5 DID, Identities list, and peer-to-peer pubkey now all resolve to the same seed-derived identity instead of drifting apart after onboarding. The Node identity on fresh installs is mirrored from the onboarding seed rather than generated as a separate random keypair.</p>
<p>Bitcoin Knots (and the new Bitcoin Core slot) now run on bitcoin/bitcoin 28.4 with a realistic 4 GiB memory cap and uncapped CPUs so bitcoind can run -par=auto across every core on your box.</p>
<p>The login background now rotates through six atmospheric images, advancing one each time you land on the login screen, so returning to your node doesn'tkeepshowingthesamewallpaper.Thechosenindexisrememberedacrosslogouts.</p>
<p>Re-logginginisnoticeablysnappier.Thedashboardentryanimationusedtoreplaythefull1.2-secondzoomrevealoneverylogin;that's now reserved for the first entry after onboarding. Subsequent logins fade in with just the welcome typing in about 300 ms.</p>
<p>If you clear site data on a node you'vealreadyonboarded,theintrovideonolongerfiresagainontheloginscreen.Theonboardingcacheisre-seededfromthebackendautomatically,so/loginstaysquietinsteadofreplayingthewholeintrosequence.</p>
<p>Theonboardingwizardnolongergetsskippedongenuinely-freshnodeswhenyouconnectfromabrowserthatonboardedadifferentnodeearlier.Thebackendisnowthesourceoftruthfor"has this node been onboarded yet?"—thebrowser's local flag is the offline fallback, not the primary answer.</p>
<p>Already-onboarded nodes no longer show the "boot loader" or "server starting up" screens during an OTA update blip. The health check polls quietly for up to a minute before showing the boot screen, so a 10-second restart no longer looks like a catastrophic failure.</p>
<p>Logging out and returning to <code>/login</code> no longer replays the full intro video — you get a quiet lock-screen background instead. The full welcome sequence is reserved for genuine first-time entries.</p>
<p>Upgrading nodes now pick up this release'sUIcleanlywithoutastalecachehangingon.Acache-versionbumptellsyourbrowser's service worker to ditch the old bundle on first load.</p>
<p>Updatesnowfinalizecleanlyinsteadofbeingforce-killedbysystemd.Previouslythenodelogged"shut down cleanly"duringanupdate,thensystemdwaited15secondsandSIGKILL'd the service because one of the internal threads wasn'treleasing.That's been tracked down and fixed, so the service exits promptly and the restart path is snappier.</p>
<p>IndeedHub install is now idempotent — re-running it after a failed first attempt no longer leaves orphaned containers blocking the retry with a "name already in use" error. The installer force-cleans leftover containers and the dedicated network before starting a fresh stack.</p>
<p>Server 3 (OVH) is now an automatic tertiary mirror for both system updates and app registries. Existing nodes pick it up on next restart without any manual config — another independent network path, so a single-provider outage can'tstalldownloads.</p>
<p>Appinstallsnowshowarealdownloadprogressbar—sameaccuracyasthesystemupdatebar.You'll see "Downloading: 50.5 / 200.0 MB (25%)" with a live percentage instead of a generic spinner. The bar keeps streaming even when the install falls back from one registry to another, so you'llneverseea"stuck at 0%"again.</p>
<p>Uninstallsnowshowwhat's actually happening: "Stopping containers (2/5)", "Cleaning up volumes", "Removing app data" — labelled per app so you can fire off multiple uninstalls in parallel and watch each one'sstageonitsowncard.</p>
<p>TheOVHmirrorisnowbakedinasServer3bydefaultforbothupdatesandtheappregistry—extramirror,completelyindependentnetworkpathsoasingle-provideroutagecan't take everything down.</p>
<p>New App registries page in Settings — same experience as Update mirrors, but for the container registries your node pulls app images from. Add a mirror, test reachability with one click, pick the primary.</p>
<p>New nodes default to the VPS registry as the primary for both app installs and the app catalog, with tx1138 as the automatic fallback if the VPS is slow or unreachable. Existing nodes keep whatever registry order they'vealreadyset.</p>
<p>Rebootscreennowshowstheanimated"a"logointhecenterofthering—matchingthescreensaver's look so you get something nice to watch while the node comes back up.</p>
<p>Reboot now shows a proper progress screen. Click Reboot and you'llseeafull-screenoverlaywiththefamiliarpulsingringanimation,arebooting/reconnecting/back-onlinestatus,andanelapsedcounter—nomoreblackscreenofmysterywhileyouwait.</p>
<p>NewnodesnowdefaulttotheVPSmirrorasServer1(primary)andtx1138asServer2(fallback).Existingnodeskeepwhatevermirrororderthey've already set — use Set Primary on the System Update page to change it.</p>
<p>The Update page now shows which mirror delivered your update — a small "Served by" line under the new version tells you whether Server 1, Server 2, or a custom mirror was the one your node actually reached. Great for spot-checking that mirror fallback is doing its job.</p>
<p>Every mirror row has a new lightning-bolt button that pings the mirror and shows whether it'sreachable,plustheround-triplatencyinmilliseconds.Nomoreguessingifamirroryoujustaddedisresponding.</p>
<p>Downloadsautomaticallyfollowthemirrorthatservedthemanifest.Previouslyeverymirrorservedthesamemanifest,andthemanifest's download URLs were hardcoded to a single server — so even picking a faster mirror couldn'tspeeduptheactualdownload.NowthebackendrewritesdownloadURLstomatchwhichevermirrorsucceeded.</p>
<p>Shipswithtwodefaults:Server1(tx1138)andServer2(VPS).AddtheURLformat<code>https://host/.../releases/manifest.json</code> for custom mirrors.</p>
<p>YournodecannowreachthebroaderFIPSpublicmesh,notjustyourownfederatedcluster.TheFIPSdaemonnowbindsbothUDP(fastmeshforwarding)andTCP(NAT-friendlybootstrap)transports—matchingtheupstreamfactorydefault.ThepublicanchorcurrentlyanswersonTCP,soUDP-onlynodescouldn't reach it; this fixes that without any action needed on your end.</p>
<p>Upgrading the config happens automatically. On next startup, if the installed FIPS yaml doesn'tmatchthenewtwo-transportschema,thenodereinstallsandrestartsthedaemonsotheTCPtransportcomesonline.NomanualReconnectrequired.</p>
<p>Frontendupdatesnowactuallyship.Sinceroughlyv1.7.17thereleasepipelinehadbeenrebuildingthebackendeveryversionbutsilentlyskippingthefrontendbundle—apermissionsissueonthebuildservermeantvue-tscfailedbeforeviteeverran,andnobodynoticedbecausethepublishedtarballsstillextractedcleanly.TheresultwasthebackendmovingforwardwhiletheUIstayedfrozenatitsv1.7.9-erastate,whichiswhytheFIPSgeariconandtheWhat's New entries for every release since then had been missing on your node.</p>
<p>Once this update applies, your node gets the real v1.7.24 frontend: the FIPS Seed Anchors modal (gear icon on the FIPS Mesh card), the current What'sNewhistory,thecancel-downloadbutton,andeveryotherUItouchfromthereleasesinbetween.</p>
<p>TheFIPSanchorstatusnolongershowsredjustbecauseonespecificpublicanchorisunreachable.Itnowlightsgreenwheneveranyauthenticatedpeerisarecognisedanchor—that's either the public anchor or something you added under Seed Anchors. A federated cluster that routes through its own seed anchor finally reports the truth.</p>
<p>Reconnect also re-pushes your seed anchors after the restart, so you don'thavetowaitfiveminutesforthebackgroundapplylooptore-dialthem.</p>
<p>Fixedacriticalbugwherenodesontheautomaticdaily-updateschedulecouldendupofflineaftertheirnightlyupdate.Theschedulerwaskillingtheserviceamomenttooearly,beforethebuilt-inrestarthandlerhadachancetobringthenewversionbackup—leavingthenodedeaduntilsomeoneSSH'd in and started it manually. The scheduler now hands off cleanly to the same restart path the 'InstallUpdate' button uses, so auto-applied updates come back online on their own.</p>
<p>Applies to any node configured for 'Check&ApplyDaily' — no change required on your end, the fix ships with this update.</p>
<p>Your node no longer offers a version you'vealreadypassedasan"available update".Ifyousideloadorskiparelease,anystoredpointertoanearlierversionisdroppedonnextrestart,andtheSystemUpdatepageoffersonlythegenuinelynewerrelease—nomoreseeinganolderversionlistedassomethingtoinstall.</p>
<p>Versioncomparisonisnownumeric,notalphabetic.1.7.10correctlyoutranks1.7.9(earliernaivestring-orderwouldhavegotthisbackwardsoncethepatchnumberhitsdoubledigits),soupdatepromptsand"up to date"checksstayaccuratepastthenines.</p>
<p>Astalemanifestfromaslowcacheorproxycannolongerdowngradeyournode.Ifthemanifestreportsaversionequaltoorbehindwhat's running, your node treats that as "up to date" rather than offering the older version as an update.</p>
<p>Nodes discovered through a trusted peer now land as Trusted instead of Observer. When your federated peer shares its own peer list with you, those nodes get the same trust level as a direct invite — the link they came through is already one you vetted, so you no longer need to promote them by hand before they can be used normally.</p>
<p>The update flow now writes clearer logs at every step. Start of download, cancel, and apply each emit a one-line entry to the system journal with the staging path and the affected files, so if a download misbehaves on your node it'seasytoseeexactlywhereitgotto.</p>
<p>Downloadsthatstallfor30secondsormorenowsayso.Theprogressbarturnsamberandshows'Download appears stuck — try Cancel and start again'insteadofjustsittingsilentlyatwhateverpercentitreached.</p>
<p>Cancelingisfast.Itnolongerhastowaitouttheretrytimer—thedownloadbailswithinhalfasecond,soyou're not stuck watching a stuck screen while you wait to unstick it.</p>
<p>Federation is now bidirectional and instant. When someone joins using your invite code, their node appears on your Federation page automatically — no need for the inviter to click Sync or wait for the next poll. Names and node details populate within seconds of the handshake finishing.</p>
<p>New nodes can no longer federate with themselves. Accepting an invite that points back at the local node (by DID, public key, or onion address) is rejected up front, so self-peering no longer clutters the node list with a duplicate card.</p>
<p>Transitive discovery: if nodes A and B are already federated and node C joins A, all three nodes now learn about each other. The new peer is pulled in as an Observer entry on existing federation members, so you can promote to Trusted with one click instead of trading a second invite code.</p>
<p>The Federation page auto-refreshes every five seconds while it'sopen.Statuschanges,newpeers,andincomingjoinrequestssurfaceontheirown—clickingSyncremainsavailableforanon-demandpull.</p>
<p>Updatecheckitselfretriesonslowresponses.Ifthereleaseserverismomentarilyoverloaded,thenodetriesthreetimeswithafive-secondwaitbetweenattemptsbeforeconcludingyou're up to date.</p>
<p>Installing an update now shows a full-screen progress overlay with the Archipelago logo, a status message, and an animated bar. The page reloads itself automatically once the new version is up — no manual refresh. If something stalls, a 'Reloadnow' button appears after a few minutes.</p>
<p>Download progress no longer looks frozen near the end. The bar pauses at 95% with a 'Finishingdownload—verifyingchecksum…' message and spinner while the last bytes arrive and are hashed.</p>
<p>FIPS Reconnect now genuinely tries to fix the anchor. It runs a proper recovery sequence (stop → start → wait for the bootstrap window → check peers) and tells you the likely reason it'sstillunreachable—corruptidentitykey,seednotunlocked,networkblockingUDP,ortheanchorserverbeingdown—insteadofageneric'try again'.</p>
<p>HealedalatentFIPSidentitybug:thepublic-keyfilewasbeingwrittenintextform(an'npub1…'string)onsomenodes,whichthedaemoncouldn't parse and silently authenticated with a garbage key. The Reconnect button now rewrites the file in the correct binary format and re-installs the config before restarting — nodes stuck with no peers for 'noreason' should come back online.</p>
<p>AIUI (Claude sidebar) is back. The installer now ships AIUI in the frontend bundle and preserves it across future updates — it was being wiped on every OTA because it lived outside the Vue build.</p>
<p>Installing a big app (IndeedHub, Bitcoin, Penpot) no longer gives up early and shows 'didn't work'whilethedownloadisstillrunninginthebackground.Theclientwaitsupto45minutesfortheinstallpipelinetofinish.</p>
<p>'Rollback to Previous'isnowlabelled'Rollback Available'—clearerthatit's a choice you have, not a status you'restuckwith.</p>
<p>Appcatalognowloadsreliably.Before,theMarketplace/Discoverpagecouldn't fetch the catalog of apps because the upstream host wasn'tsendingtherightCORSheadersandthenode's security policy didn'tallowthefallbackURLeither.Thenodenowfetchesthecatalogserver-sideandservesitsame-origintothebrowser—nomoreblankapplists.</p>
<p>InstallUpdateactuallyappliesnow.Theinstallerhadtowriteintosystemfoldersthatthebackendservicewassandboxedoutof—everyearlier'Failed to apply update'wasalayerofthatonion.Fixedbyrunningthefileswapsinaseparatesystemcontext.</p>
<p>FIPSstatusontheHomeandServerpagesnowreflectswhetherthepublicanchorisreachable.You'll see 'Active·Npeers' (green) when healthy or 'Noanchor' (orange) when the network is blocking the bootstrap — same signal as the full FIPS card.</p>
<p>Pasting an https://… URL into the profile picture or banner now previews correctly. Before, if the URL failed to load, the UI would silently blank out instead of showing your initial as a placeholder.</p>
<p>Uploaded profile pictures under 64 KB are now embedded directly in your Nostr profile (as a data URL), so any Nostr client can see them — not just ones routing over Tor. Larger uploads keep the onion URL for now, with a hint to paste a public URL for wider visibility.</p>
<p>OTA verification release — nothing new to see. Click Install Update, grab a coffee, and watch the sidebar flip to 1.7.9-alpha on its own. If this one works end to end, the pipeline is solid and future updates will flow the same way.</p>
<p>Install Update finally works end-to-end over the air. The installer was trying to overwrite the running backend binary with a tool that fails on in-use files (ETXTBSY) — swapped it for an atomic rename, which the kernel allows on a live executable. Every previous 'Failedtoapplyupdate' attempt was this one root cause.</p>
<p>Over-the-air update test — no feature changes, just a version bump so your node can walk through the whole update flow end-to-end using the new robust installer. Safe to apply; nothing to do afterwards.</p>
<p>Install Update is now more robust. Each install gets its own uniquely-named staging folder and then moves files into place — the previous version had a small cleanup step that could hit a transient filesystem hiccup and bail out halfway. You'llalsostillseearollbackfolderafterasuccessfulinstall.</p>
<p>InstallUpdateactuallyinstallsnow.Before,thefinalstepextractedthenewUIintothewrongfolderandbailedwith'Failed to apply update'—yournodeendedupbackingupcleanlybutneverswappinginthenewfiles.Fixed.</p>
<p>Downloadprogressnolongerovershoots100%.You'll see the bar climb smoothly to 95% and then jump to 100% when the download actually finishes.</p>
<p>The version number in the sidebar now always matches the actual running version — no more lying to you about being on an older release after an update.</p>
<p>FIPS Mesh card on the server page: cleaner layout on desktop (no more awkward gaps), and a one-click Reconnect button when the public anchor is unreachable — it restarts the FIPS daemon so it can re-bootstrap from the anchor.</p>
<p>Profile pictures now show correctly in the identity list and editor. Before, uploaded images silently failed to render because the URL was only reachable over Tor; the UI now rewrites them to a local path while keeping the external URL for other Nostr clients.</p>
<p>Identity rows now show your Display Name first (from your Nostr profile) with the internal identity name beside it in parentheses, so you see the name other people will see — not just the one you picked when creating it.</p>
<p>Install Update now actually installs. Before, the button would back up your current version then fail with 'Failedtoapplyupdate' because the installer couldn'twriteintosystemfolders.</p>
<p>Thebutton's also been renamed to 'InstallUpdate' (previously 'ApplyUpdate') and the node restarts itself a moment after you click it — no more manual restart step.</p>
<p>Your existing identities now show the generated avatar instead of just their initials — same look as freshly created ones.</p>
<p>Everything from 1.7.0-alpha and 1.7.1-alpha carries over (default avatars on creation, one-click Save publishes to Nostr relays, public blob URLs for profile pictures, 30-minute download window, VPN peer restore on reboot, reconciler-only-repairs, filebrowser fix).</p>
<p>Over-the-air update test — same features as 1.7.0, just a fresh version number so your node can try the new download-and-apply flow end-to-end. Safe to apply; nothing to do afterwards.</p>
<p>Every identity now gets a personal avatar the moment it'screated.Yourmainnodeidentitygetsadistinctivehexagonal-networkicon;otheridentitiesgetacolourfulgeneratedpatternuniquetoeachone.</p>
<p>Profileeditor:uploadaprofilepictureandabanner,thentapSave—yourNostrprofilenowgoesouttotherelaysinonestep.Nomore'Save'vs'Save & Publish'confusion.</p>
<p>NostrVPN is now a native system service. Peer discovery via Nostr relays, WireGuard tunnels. Auto-configured with your node'sidentityduringonboarding—nosetuprequired.</p>