Changelog
All notable changes to Bayesian SSH will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[2.1.2] - 2026-07-15
Added
- Kerberos client detection: Desktop app reads
krb5.confto detect configured realms, infer default principals, and resolve credential cache paths even when no ticket is present. - Branded app icon sync: Tray, title bar, and favicon now use the custom Bayesian SSH icon consistently.
Fixed
- Kerberos Heimdal compatibility: Fixed false “no ticket” detection when valid tickets use
Credentials cache:output from Heimdal klist. - Modal accessibility: Resolved Svelte a11y warnings in Kerberos, Detached Sessions, and Onboarding modals; replaced deprecated
<svelte:component>in Sidebar. - Tray icon embedding: Use dedicated 32×32 compile-time icon asset for reliable Linux system tray display.
[2.1.1] - 2026-07-14
Added
- System Tray Support: Desktop app minimizes to the system tray instead of quitting on close; tray menu provides Open and Quit actions.
- Graceful Quit Flow: Dedicated quit button and confirmation dialog when active terminal sessions are open.
- Shared Terminal Utilities: Extracted xterm I/O, clipboard key handling, and Linux IME composition guard into reusable helpers.
Fixed
- PTY Terminal Rendering: Set
TERM=xterm-256colorfor spawned PTY sessions so vim, nano, and htop render correctly. - PTY Resize: Implemented
resize_ptyto propagate terminal dimensions to the backend PTY master. - Terminal Focus Handling: Global keyboard shortcuts no longer steal keys when the xterm terminal has focus; active tab auto-focuses on switch.
[2.1.0] - 2026-07-13
Added
- Core Modularization and Refactoring: Comprehensive codebase-wide refactoring of the CLI parser, TUI state management, and TUI keyboard input dispatcher. Splits monolithic modules into clear, domain-scoped files (
sftp.rs,tunnels.rs,tabs.rs,modals.rs). - Tauri Backend Commands Modularization: Restructured the monolithic
commands.rsinto a dedicated domain-scopedcommands/directory resolving connections, PTY terminal spawning, settings, env, ssh-agent, native file dialogues, and configuration imports. - Svelte 5 App State custom store: Extracted reactive UI states, properties, and async Tauri IPC invocations from the presentation page component (
+page.svelte) into a custom store (appState.svelte.ts). - Terminal UI/UX Improvements: Dynamic computed-style terminal themes matching Zinc/OLED/Slate/Cyberpunk backgrounds, auto-retheming on settings update using MutationObservers, keyboard and mouse-wheel font size zoom shortcuts (
Ctrl++/-/0), extra viewport padding, custom scrollbars, and active tab glows. - Detached GUI Subcommand: Added
bssh desktop(andbssh gui) command to spawn the Tauri desktop client detached in the background and release prompt control instantly.
Fixed
- Terminal Clipboard Handling: Custom event handlers intercepting copy/paste shortcuts to resolve character scrambling, duplicate pasting, and SIGINT conflicts when copying active selections.
[2.0.0] - 2026-07-13
Added
- Multi-host Split View and Session Management: Connect to multiple hosts concurrently without closing current terminal sessions. Features a sidebar for quickly searching and spawning terminal sessions in tabs.
- Popout Terminals & Detached Session Management:
- Move active terminal sessions into standalone windows with full drag-and-drop / tab reattachment support.
- Custom
DetachedSessionsModallists all background/popped-out terminal processes with close, reattach, and kill actions.
- Kerberos Ticket Management:
- Implemented real-time ticket checks, acquisition, and renewal scripts (
kerberos.rs). - Added warning thresholds on ticket expiry and a dedicated interactive
KerberosModalfor quick credential refreshes.
- Implemented real-time ticket checks, acquisition, and renewal scripts (
- App Onboarding Process: Guided start workflow using an
OnboardingModalsetting up default users, workspace profiles, paths, and themes on first run. - Session Logging: Capture and audit stdout/stderr terminal session logs securely in sqlite history database.
- SSH Agent & Configuration Defaults:
- Automatically detect and pre-fill the custom SSH agent socket from the live
SSH_AUTH_SOCKenvironment variable. - Option to set a default identity file (SSH private key) globally in Settings.
- Automatically detect and pre-fill the custom SSH agent socket from the live
- Premium Custom Modals: Beautiful dialog overlays replacing ugly browser native
confirm()prompts for connection or profile deletions. Features high-fidelity pulsing warning animations and full dark mode compatibility. - Frictionless Connection Cloning:
- Fixed arguments parsing issue with
add_connectionon duplicate. - Automatically highlights newly duplicated connections using a brief cyan flash animation.
- Immediately opens the Connection edit drawer upon duplication to prompt for value updates.
- Fixed arguments parsing issue with
- Aesthetics & Accessibility: Enhanced sidebar toggle navigation, custom titlebar controls, responsive grid/list styling, and refactored overall project component modularity.
Fixed
- PTY Session Isolation: Kept master PTY descriptor alive in
PtySessionstate to prevent closing one tab from triggering EOF and closing all active SSH connections. - Manual Close Race: Suppressed duplicate exit signals when manually closing terminal windows or PTY processes via
close_pty.
[1.6.0] - 2026-07-12
Added
- Tauri Desktop Application: A beautiful, performance-oriented standalone desktop GUI built using SvelteKit, TypeScript, and Rust. Features:
- Vercel/Linear-inspired sleek dark mode layout with Grid and List views.
- Collapsible drawer sidebar with tags and profiles selection.
- Interactive tabbed inline terminals powered by Xterm.js and a backend PTY process broker.
- Connection logs audit table and system metrics monitoring.
- Global keyboard shortcuts and search bar navigation.
- Agnostic build and installation system integrated via Makefile and install.sh scripts.
- Refactored core shared library: Modularized
bayesian-sshinto a reusable Rust library target. doctorcommand: Diagnose the active environment, configuration, SQLite database, SSH client, SSH config, ssh-agent socket, and Kerberos helper tools from the CLI.
Changed
- Actionable CLI errors: Command failures now print a stable
Error:line and targetedSuggestion:hints for common recovery paths.
[1.5.0] - 2026-04-18
Added
- Native russh SSH transport: Pure-Rust SSH transport layer (
SshTransporttrait) withrusshbackend, known-hosts verification, and multi-method authentication — replaces subprocess-based SSH for supported operations - SFTP via russh-sftp: Full SFTP session implementation (
RusshSftpSession) built on the native transport for file operations without shelling out exec,upload,downloadcommands: New CLI commands backed byTransferServicefor remote command execution and file transfers- Recursive upload and download: SFTP upload and download now support entire directory trees recursively
- Local port-forward tunnel:
bssh forward -Lestablishes SSH local port-forwarding tunnels - SOCKS5 dynamic proxy:
bssh proxy -Dcreates a SOCKS5 dynamic forwarding proxy through the SSH connection - TUI SFTP file browser: New Files tab for browsing remote file systems, uploading, deleting, creating directories, and renaming files interactively
- TUI Tunnels tab: Start, list, and stop port-forward tunnels directly from the TUI
Changed
- Transport architecture refactored: Extracted
SshTransporttrait withSubprocessTransportandRusshTransportimplementations behind a dispatcher for flexible backend selection
Fixed
- CLI argument short flags: Corrected conflicting short flags for SSH commands
[1.4.1] - 2026-03-05
Added
- TUI tab-based navigation: Three tabs — Connections (
1), History (2), Config (3) — switchable with number keys orTab/Shift+Tab - Add new connection form: Press
ain the Connections tab to create a connection directly from the TUI with a 9-field overlay (Name, Host, User, Port, Bastion, Bastion User, Key Path, Kerberos, Tags) and validation - Session history view: History tab with sortable columns (Date, Name, Duration, Status), connection name filter (
/), failed-only toggle (f), and reconnect onEnter - Environment management: Config tab listing all environments with the active one highlighted; switch (
Enter), create (a), or delete (d) environments without leaving the TUI - Connection grouping by tag: Toggle grouped view with
f— connections are organized under collapsible tag headers - Quick-connect bar: Press
:and type[user@]host[:port]to connect to an ad-hoc host without saving it - Multi-select and batch operations:
Spaceto toggle selection,Ctrl+Ato select all,xto batch-delete selected connections with a confirmation dialog - SSH command preview: Press
pto see the full SSH command that would be executed, broken down by component (host, port, user, bastion, kerberos flags, key path) - Async TCP ping with status indicators: Press
Pto ping the selected connection in the background; results appear as colored indicators — green●with round-trip time for reachable, red●for unreachable, yellow◌while checking - Shared ping service (
services/ping.rs): Lightweight TCP-level reachability check usingtokio::net::TcpStreamwith timeout — no external process spawning; pings bastion host on port 22 for bastion connections
Changed
- TUI modular architecture: Split monolithic
tui/app.rs(721 lines) andtui/ui.rs(572 lines) into focused modules:models.rs— enums and small types (Tab,AppMode,EditState,PingStatus, etc.)state.rs—Appstruct and state management withtokio::sync::mpscping channelinput.rs— keyboard handlers dispatched per tab and modeevent_loop.rs— terminal setup/teardown and main loop with async ping result drainingui/mod.rs— draw dispatcher routing to tab views and overlaysui/header.rs,ui/list.rs,ui/detail.rs,ui/status.rs,ui/overlays.rs,ui/history.rs,ui/config.rs,ui/helpers.rs
- Edit overlay extended: Now supports 9 fields (added Key Path);
EditStateincludesis_newflag andvalidate()for required-field checks - Ping indicators use distinct colors: Reachable (green), unreachable (red), checking (yellow) — previously all rendered identically
Fixed
- Unreachable key binding patterns:
Ctrl+Aselect-all now correctly takes precedence over plainaadd-connection; removed deadggrouping arm that was shadowed by go-to-top
[1.4.0] - 2026-03-05
Added
- New commands:
bssh backup,bssh restore,bssh duplicate,bssh env,bssh export,bssh groups,bssh ping— expand the CLI with backup/restore, connection cloning, environment management, export, grouping, and latency checks - Multi-environment configuration: Manage separate configs per environment with the
--envflag; environment name shown in TUI header and logs - TUI detail pane: Side panel (toggled with
Enter/d) displaying all connection fields, full SSH command preview, and contextual hints - TUI inline editing: Edit any connection directly from the TUI with
e— 8-field overlay with cursor navigation, written back to the database on save - TUI sorting: Cycle sort field with
s(Name → Host → Last Used → Created) and toggle direction withS; indicator shown in header - TUI compact view: Toggle single-line vs two-line row display with
v - Optimized release profile:
opt-level=3, thin LTO, single codegen unit, stripped symbols,panic=abort
Changed
- Database module split:
database/refactored into separate submodules (connection,alias,session,search) for better organisation - Core error handling: Internal refactoring of error types and propagation across modules
- TUI visual refresh: Alternating row backgrounds,
[B]/[K]bastion/Kerberos badges, mode-coloured status bar badge, improved help overlay (50-col popup)
Fixed
- TUI log corruption: Tracing output is now routed to
~/.local/share/bayesian-ssh/tui.logwhen the TUI is active, preventing log lines from corrupting the alternate-screen display
Removed
- SCP command: Removed
bssh scpand the associated config fieldsbastion_scp_modeandbastion_scp_wrapper
[1.3.2] - 2025-12-31
Fixed
- Log level configuration ignored: The
log_levelsetting in config file was not being applied because logging was initialized before loading the configuration. Now the config is loaded first and the tracing subscriber respects the configured log level (trace,debug,info,warn,error,off/none).
[1.3.1] - 2025-12-30
Added
- Bayesian-ranked search: Smart connection ranking combining:
- Prior probability (usage frequency with Laplace smoothing)
- Likelihood (match quality: exact, prefix, word-boundary, contains)
- Recency (exponential decay based on last use)
- Success rate (connections that work get boosted)- Configurable search mode (
bssh config --search-mode bayesian|fuzzy) bayesian: Smart ranking based on usage patterns (default)fuzzy: Simple pattern matching
- Assets: SVG icons, banner, architecture and workflow diagrams
Changed
- Default search mode is now “bayesian” for smarter results
[1.3.0] - 2025-12-30
Added- Interactive TUI mode (bssh tui): Full-screen terminal interface with ratatui
- Browse, search, and connect to servers
- Keyboard navigation (vim-style j/k, arrows, PgUp/PgDn)
- Tag filtering, help overlay, confirmation dialogs
- Session history command (
bssh history): View connection history with statistics- Success/failure rates, average duration
- Filter by connection, days, failed-only
- Connection aliases (
bssh alias): Create shortcuts for connectionsbssh alias add db prod-database→bssh connect db- Aliases work transparently with connect command
- Close/kill sessions (
bssh close): Manage active SSH sessions- List active sessions with PID and stale detection
- Close specific sessions or all at once
--cleanupto remove stale sessions (PIDs no longer running)
- Configurable search mode (
bssh config --search-mode bayesian|fuzzy)bayesian: Smart ranking based on usage patterns (default)fuzzy: Simple pattern matching
Changed
- Connect command now checks aliases before fuzzy search
- Session tracking improved with accurate active/stale detection
- Default search mode is now “bayesian” for smarter results
Dependencies
- Added
ratatuiandcrosstermfor TUI - Enabled
signalfeature innixfor process management
[1.2.0] - 2025-12-22
Added
--forceflag for remove command: Skip confirmation prompt with-for--force--clear-bastionflag for config command: Clear default bastion settings- Shared CLI utilities module: New
src/cli/utils.rsfor consistent UX across commands - Working “search again” feature: The ‘s’ option in interactive selection now performs actual recursive search
- Contextual help messages: Suggestions like “Use ‘bssh list’ to see all connections” when no matches found
Changed
- Single-match auto-connect: Connect and show commands now auto-select when only one fuzzy match is found (improved UX)
- Default yes for non-destructive operations: Confirmation prompts now default to Yes
[Y/n]for show/connect - Simplified remove confirmation: Changed from typing full connection name to simple y/n prompt (use
--forceto skip)
Fixed
- Config update bug: Fixed double-wrapping of
Option<Option<String>>for bastion settings that prevented clearing values - DateTime parsing panic: Graceful handling of malformed dates in database instead of crashing
- Home directory panic: Better error message when
$HOMEis not set during SSH config import
Technical
- Major code deduplication: Extracted ~300 lines of duplicated code from connect.rs, edit.rs, remove.rs, show.rs into shared utilities
- Reduced file sizes: connect.rs (257→65 lines), edit.rs (360→70 lines), remove.rs (235→70 lines), show.rs (246→35 lines)
[1.1.1] - 2025-08-29
Fixed
- Configuration defaults: Changed default user from hardcoded “admin” to current system user
- Kerberos default: Disabled Kerberos by default (changed from
truetofalse) - Documentation: Updated all examples to reflect new sensible defaults
Changed
- Default configuration: Application now uses current Linux username instead of “admin”
- Kerberos behavior: Kerberos authentication is now opt-in rather than default
- Documentation examples: Updated configuration commands and JSON examples across all docs
Technical
- Dependencies: Added
whoamicrate for system user detection - Configuration: Updated
AppConfig::default()implementation - Documentation: Updated README.md, docs/README.md, and docs/advanced-usage.md
[1.1.0] - 2025-08-28
Added
- Intelligent fuzzy search across all commands - Find connections by partial names, tags, or patterns
- Enhanced
connectcommand with fuzzy search and interactive selection - Enhanced
editcommand with fuzzy search for connection management - Enhanced
showcommand with fuzzy search for connection details - Enhanced
removecommand with fuzzy search and extra confirmation
- Enhanced
Fuzzy Search Features
- Smart pattern matching: Handles hyphens, underscores, and separators (
webprod→web-prod-server) - Tag-based search: Search within connection tags
- Recent connections fallback: Shows recently used connections when no matches found
- Interactive selection: Numbered menus for multiple matches with user-friendly prompts
- Relevance ranking: Prioritizes recently used and exact matches
Enhanced Safety
- Extra confirmation for destructive operations:
removecommand requires typing full connection name - Graceful error handling: Clear messages and helpful suggestions
- Backwards compatibility: All existing functionality preserved
Documentation
- Updated README with fuzzy search examples across all commands
- Enhanced user guide with practical usage scenarios
- Improved feature descriptions and examples
Technical Improvements
- Enhanced database layer with fuzzy search algorithms
- Improved error handling and user feedback
- Better code organization and maintainability
[1.0.0] - 2024-08-23
Added
- Initial release of Bayesian SSH
- Basic SSH connection management
- Kerberos authentication support
- Bastion host routing
- Tag-based organization
- SQLite database persistence
- Connection history and statistics
Core Features
- One-click connections to servers
- Automatic Kerberos ticket management
- Smart bastion host routing
- Tag-based organization for easy management
- Complete connection history with statistics
- SQLite database for persistence
Types of changes
Addedfor new featuresChangedfor changes in existing functionalityFixedfor any bug fixesRemovedfor now removed featuresSecurityin case of vulnerabilities