Repository navigation
Releases: gmoddev/DeskLink
Release list
DeskLink 0.1.2 Beta 3 Development Secure
DeskLink 0.1.2 Beta 3 Development Secure
Windows 11 experimental prerelease built from 9c0b7f54970b04369a2b14eaa2125a1893c3dab0. The installer version is 0.1.2. This uses the same private development signing identity as Beta 2; it is not publicly trusted or production-signed.
Changes since Beta 2
- Automatically discover IPv4 and IPv6 paths over the available PC network interfaces, including direct fiber links.
- Keep multiple paths under one trusted PC identity, prefer eligible faster links, and bind the connection to the selected interface and address.
- Disable connection migration. Ordinary network failures reconnect through fresh authentication in Local; identity and protocol failures remain terminal.
- Reconcile stable monitor identities and connected-display inventory.
- Build the Displays canvas from Windows' current desktop monitor positions instead of enumeration order or stale saved ordering. Move each PC's monitors together, and refresh current geometry when reopening Displays.
- Fix WinUI audio endpoint enumeration.
Existing explicit roaming links, pairing, certificate pins, and permissions remain authoritative. Canvas movement does not change Windows display settings or silently approve a new roaming link.
Download and trust
Use DeskLink-0.1.2-beta.3-development-secure.exe. The public certificate and trust bundle are unchanged from Beta 2. The bundle includes explicit install, status, and removal commands; it contains no private key.
Before trusting the development certificate, verify its DER SHA-256 fingerprint out of band:
A4E64875A7043221A9A7CC3C7B9244E9D543CB3DAD964C375C8DB37C21A5D6C0
Installing this private development root in Local Machine Trusted Root Certification Authorities and Trusted Publishers broadens Windows' code-trust boundary. Use it only on controlled test PCs, and remove it after testing. DeskLink's authenticated pairing, certificate pinning, capability grants, and focus leases remain required. DeskLink never approves a UAC prompt automatically.
Installer SHA-256:
7E290E0BE8C38579F9BF6C65527DB45B960E29178E35C37980189AE42B174979
Validation and limitations
- The exact merged source passed GitHub CI, including Windows and Linux builds, sanitizers, MsQuic, optional driver build, and Server 2022 product/installer qualification.
- The release build passed 20 selected CTest checks, including secure-input self-tests and console/probe rejection checks. The WinUI Release build and packaging signature, timestamp, runtime-hash, and payload checks passed.
- A live two-PC probe selected the 10 Gbps fiber path and selected the 2.5 Gbps LAN after cooling down fiber candidates. Bound IPv4/IPv6 transport reconnect tests passed.
- Physical cable removal during an active session was not tested. Elevated/UAC input remains experimental; if focus remains blocked after dismissing UAC, pause and resume DeskLink to re-arm the managed session.
- Windows 10 support and extended-display/video transport are not included in this Development Secure package.
- Use
Ctrl+Alt+Pauseto return input locally when needed.
DeskLink 0.1.0 Beta 2 Development Secure — experimental private-signing build
DeskLink 0.1.0 Beta 2 Development Secure
This is an experimental, privately signed prerelease built from commit
3e048efda2c02640e9dbfb31e6a61c165e03f371 (PR #74). It is intended for
controlled testing of DeskLink's elevated-application and visible-UAC input
path. It is not publicly trusted or production-signed.
Changes since Beta 1
- Improves privileged focus handoff and pointer landing across PC boundaries.
- Reduces secure-input service lease renewal and event-delivery latency.
- Coalesces high-rate pointer datagrams to prevent stale input from building up.
- Improves roaming observation, directional activation, and rapid return trips.
- Keeps privileged control opt-in and bound to an authenticated, pinned peer.
Development Secure trust warning
Elevated application and visible UAC control requires the exact public
DeskLink Development Secure certificate to be installed separately in the
controlled PC's Local Machine Trusted Root Certification Authorities and
Trusted Publishers stores. Verify this DER SHA-256 fingerprint out of band
before installing it:
A4E64875A7043221A9A7CC3C7B9244E9D543CB3DAD964C375C8DB37C21A5D6C0
Trusting this private development root broadens the PC's Windows code-trust
boundary and therefore lowers security relative to leaving it untrusted. Use
it only on controlled test PCs where that tradeoff is acceptable. The trust
bundle contains an explicit install/status/remove script. Remove the
certificate after testing. The private key and any PFX are not included and
must never be distributed.
This certificate trust does not weaken DeskLink's network authentication:
certificate pinning, peer validation, permissions, leases, and manual UAC
approval remain required. DeskLink never approves a UAC prompt automatically.
Known limitations
- Elevated/UAC control remains experimental.
- Physical Windows 11-to-Windows 11 coverage is still incomplete.
- Extended-display/video transport is not included.
- Use
Ctrl+Alt+Pauseto return input locally if necessary.
Report issues at https://github.com/gmoddev/DeskLink/issues.
DeskLink 0.1.0 Beta 1 - unsigned development build
DeskLink 0.1.0 Beta 1
DeskLink Beta 1 is the first public beta of the product-shell experience for
secure keyboard and mouse roaming across trusted Windows PCs.
Highlights
- Guided pairing with independently approved per-PC permissions.
- Authenticated edge roaming, reciprocal focus, monitor mapping, and display
identification. - Text clipboard sharing and per-peer audio routing with gain and mute.
- Persistent background broker, tray controls, reconnect, suspend/resume, and
fail-local emergency return. - Stock MsQuic/Schannel on Windows 11 and Server 2022 or newer.
- Experimental equal-security Windows 10 22H2 compatibility through the
reviewed OpenSSL 3.5 provider and the same non-exportable CNG identity.
Audio qualification
The Windows 10-to-Windows 11 voice run accepted and submitted 4,412 five-ms
blocks with no concealment or rejection. Median emit-to-WASAPI-submit latency
was 7.152 ms; p95 was 14.914 ms and p99 was 16.018 ms. These figures end at
software submission and exclude device, DAC, speaker, room, and microphone
delay.
Important beta limitations
- This build and installer are unsigned; Windows SmartScreen may warn.
- Windows 10 transport is experimental and unsupported.
- Physical two-PC Windows 11-to-Windows 11 qualification is deferred because a
second Windows 11 PC is not currently available. - Hands-on accessibility, high-DPI, sleep/network interruption, and wider audio
endpoint coverage remain ongoing beta work. - Extended-display/video transport is not part of this release.
Use Ctrl+Alt+Pause to return input locally if necessary. Report issues at
https://github.com/gmoddev/DeskLink/issues.
DeskLink 0.1.0 Alpha 2 — unsigned development build
Unsigned development Alpha build; it is not production-signed. This release fixes false Offline state, keeps paired PCs visible when discovery is empty, reconciles safely stored permission grants after fail-local cleanup, and reduces the oversized status badge. Existing non-exportable CNG device identities are preserved; there is no TLS downgrade and peer/session validation remains fail-closed. Windows 11 and Windows Server 2022+ remain the production baseline. Windows 10 OpenSSL/CNG compatibility remains experimental and unsupported. Known limitations: physical Windows 11 two-PC validation is deferred, and LAN discovery can fail while Windows classifies the LAN as Public. Installer SHA-256: BAFB8DCE603AD2F61EEAB98E5532A14922B1F87CFD7BF242E59F21895FB75A18.
DeskLink 0.1.0 Development Alpha 1
Unsigned Development Alpha build for easy two-PC testing. This is not a production-signed release; Windows SmartScreen may warn.
Provider policy:
- Windows 11 / Server 2022+ uses MsQuic + Schannel.
- Windows 10 build 19045 uses MsQuic + OpenSSL 3.5 with the existing opaque, non-exportable CNG identity.
- There is no provider fallback after credential, signing, certificate, authentication, or handshake failure.
Security status:
- Exact commit-diff security review completed with zero findings.
- Linux, Windows, sanitizers, MsQuic, installer, Server 2022, and Windows 10 opaque-CNG CI gates passed.
- Windows 10 remains experimental/unsupported pending the remaining physical sleep, network-loss, held-input termination, and accessibility qualification.
SHA-256: 240FC0DC708B7059C073EF43BE3FD6F6C7D11E3B106870AFA16C562B5F82FC19