Releases: nobottomline/rctl
Release list
rctl 0.4.5
This is an immutable pre-release for opt-in testing, excluded from latest and the default stable/APT update channel.
Relay candidate image: ghcr.io/nobottomline/rctl-relay@sha256:24cc8d2aba4755012469d57538b0cfc70303b7dcd6147b54c5142a79dc576043
Source commit: 0c636304da7d5169741a1f208cec9bf7affc10c3
SHA256SUMS SHA-256: 89bfc341847b0a37bb0fddc1b07f8f456bf3c837f700bf52dc0cda98c2380078
Verified artifacts
- Exact-source CI: all six jobs passed, including both web clients, relay, container, tailnet and isolated iOS controller lifecycle tests. All three CodeQL analyses passed.
- Tag-bound release build: Linux amd64/arm64 binaries, rootful/rootless packages, and signed device/host catalogs.
- Independent verification passed all eleven asset sizes/checksums and tag/source/workflow-bound build attestations, both public-package audits, catalog signatures and immutable 0.4.4 rollback artifacts.
- Anonymous candidate image access, linked amd64/arm64 SPDX SBOMs and repository/tag/source-bound OCI provenance passed. The embedded setup image remains digest-pinned.
Qualification limits
The owner deferred final physical rootless and clean-VPS acceptance for this preview. There is no all-passed schema-5 runtime qualification report. Earlier version-scoped tests do not qualify these new package bytes.
Physical guest touch/keyboard and held-input retirement, foreground live-camera/recording stop, Talk audibility, macro interruption and relay-partition recovery remain open. Fresh-host installation, renewal, upgrade/rollback and managed host-update lifecycle checks have not been repeated for this exact release. See guest acceptance and qualification requirements.
The device web build toolchain retains the unpatched braces advisory GHSA-vfj7-8cjw-p6xm through vite-plugin-singlefile. Its affected pattern matcher is not called with the current empty inlinePattern configuration; it is a build dependency and runtime dependency audit is clean. Protocol/admin toolchain advisories were patched.
This publication does not install packages or redeploy an existing relay. Native controller applications remain in development and are not package payloads. A later qualified stable release requires a new version and fresh evidence; this preview will not be promoted by changing its metadata.
Changes
Release candidate pending version-scoped device and fresh-host qualification.
Changes since stable 0.4.4:
Added
- Temporary browser invitations for one device, with expiry, view-only presets,
and 46 explicit permissions for input, audio, camera, files, media, terminal,
and supported system operations. The relay and device enforce each operation. - Admin management of guest grants and sessions. Permission changes, revocation,
and expiry retire device authority and guest-owned resources; the admin shows
whether device retirement has been confirmed. - Automatic invitation entry into the themed device workspace, with compact
permission-specific tools, responsive layouts, and clear reconnect, expiry,
and owner-revocation states. - Separate experimental tailnet qualification probes with authenticated HTTPS
browser enrollment and terminal transport. These are opt-in engineering tools.
Fixed
- An arm64e SpringBoard crash during asynchronous guest-resource retirement.
- Idle signaling disconnects, stale ICE events, and handling of rejected
downloads and failed guest replies. - Guest tool state and focus across panel changes, plus accurate expiry and
permission-change presentation after connection teardown. - Unmanaged TURN socket binding and deployment installation/log diagnostics.
- GitHub Actions workflow lint for relay candidate release notes.
- Vulnerable
fast-uriandbrace-expansiondevelopment dependencies in the
protocol validator and admin lint toolchain.
Physical guest camera, input retirement, Talk audibility, partition recovery, and
rootless runtime qualification remain open; see docs/GUEST-ACCESS.md. Screen
video recording and guest package installation are not implemented product
features. Native controllers remain in development and are not distributed in
the device packages. Candidate builds do not advance stable catalogs or APT.
rctl 0.4.4
Relay image: ghcr.io/nobottomline/rctl-relay@sha256:2d935a096ba6ae2b42f35c5eba439f687159bf93a1f54be12bca5969244004e8
Source commit: 672e4bb3793a05769a3ff05a287047f2045e240e
Release Status
Published as latest. The full schema-5 qualification matrix is not yet complete.
Artifact checksums, build provenance, public
package audits, and exact-commit CI passed. Both tested device lanes completed
the relay-admin update from 0.4.3 to 0.4.4 with relay identities preserved and
subsequent LAN/relay control checks.
Outstanding exact-candidate checks include forced-TURN device media, certificate
renewal, fault-injected host/device recovery, package-manager recovery, and parts
of the admin/scheduled host-update matrix. Earlier-version results do not
establish those checks for this release. There is no all-passed schema-5 report.
Back up before updating and retain independent recovery access.
This publication does not update the APT feed. Download the package matching
the jailbreak: iphoneos-arm for rootful, iphoneos-arm64 for ordinary Dopamine
rootless. Rootless testing covers iPadOS 15.5 with ElleKit; RootHide and other
untested device/iOS combinations are not qualified.
Added
- Ordinary Dopamine rootless support with a separate
iphoneos-arm64package;
rootful devices continue to useiphoneos-arm. - Game Keyboard with held keys and WASD, plus captured mouse movement, buttons,
and scrolling. Session loss releases held input. - Device orientation locking, recorded-input playback pause/resume and JSON
export, screenshot previews, and device volume controls. - Personalized rootless packages and signed transactional device updates from
relay admin, with rollback and preservation of device identity. - Signed relay update discovery, installation from the admin page, and opt-in
scheduled server updates with backup, health verification, and recovery.
Device package installation still requires separate confirmation. - Installer domain selection, public-address inference, optional Docker
provisioning, clearer progress, and terminal-aware colors. - Controller permissions, presence, audit history, Bonjour discovery, and an
explicit LAN + Relay / Relay only access policy.
Fixed
- Rootless screen orientation and touch geometry, video thumbnails, microphone
recording, Talk playback, shell prompts, and duplicate tweak listings. - Duplicate keyboard input, stuck modifiers, inverted trackpad scrolling, and
input-session timeouts during mouse capture. - Installing a package for an additional relay now preserves existing relay
bindings and consumes the new enrollment instead of discarding it. - TURN/TCP negotiation and RTP packet sizing; stale web clients can no longer
survive package rebuilds. Experimental video pacing is not included. - Controller pairing now validates relay identity and origin; permission changes
invalidate stale sessions, and device updates reject downgrades. - Interrupted relay updates recover before new work starts, updater connections
survive service restarts, and failed scheduled releases are not retried in a loop. - Consistent dropdowns, stable hover feedback, device-neutral labels, and a
styled automatic-update checkbox. Unsupported HTTP-only sharing/copy actions
are hidden while downloads remain available.
The native iOS controller remains in development and is not distributed in
device packages. Sustained intermittent Listen noise testing remains open.
Rootful silent-session closures with delayed reconnects also remain under
investigation; always-online availability is not guaranteed.
rctl 0.4.3 - host updater qualification B
Test prerelease B for the signed 0.4.2 to 0.4.3 managed relay update path. Not a stable release, not promoted to APT, and not recommended for general installation.
Source: 6fcfb7e
Relay image: ghcr.io/nobottomline/rctl-relay@sha256:04f388c7f4b9d7058e76fc1e320d9b56a782b0f1f385f99ad69d5cf90c90662e
Versioned successor to qualification A with the same runtime code, used to test version discovery, admin-page installation, identity preservation, restart and recovery.
Build provenance, artifact checksums, catalog signatures and CI verified. Real VPS qualification is still in progress. Stable/latest is unchanged. Device installation remains separate.
rctl 0.4.2 - host updater qualification A
Test prerelease A for managed relay updater qualification. Not a stable release, not promoted to APT, and not recommended for general installation.
Source: 9775071
Relay image: ghcr.io/nobottomline/rctl-relay@sha256:11e66b135de6045580d9dad6ae32fbedb02461951a5f730f63591dcdd5cc0fb9
Includes signed host update catalogs, admin-managed relay updates, opt-in scheduling, durable job/recovery state, Debian-aware device version comparison, and terminal domain-picker cancellation fixes. Both package architectures are included for artifact validation; installing a device package is a separate action.
Build provenance, artifact checksums and catalog signatures verified. Real VPS upgrade and recovery qualification is still in progress. Stable/latest is unchanged.
rctl 0.3.2
Relay image: ghcr.io/nobottomline/rctl-relay:0.3.2
Relay digest: ghcr.io/nobottomline/rctl-relay@sha256:16c4f587b7377141e842ac970d283af620a63705b05e85999d8ea3479dc92317
Source commit: 38f210d59209910c9bdf753c283cf964659e76e4
Fresh-host qualification report SHA-256: 978f0866bf2b463511b1f35b1c4da5a5b2151e9504db9773a443cb705fbddb8d
- Fixed interactive
curl | sudo shsetup by reconnecting the verified wizard
to the controlling terminal and added visible lifecycle progress. - Added a release-gated, P-256 signed stable device-update catalog with exact
target and rollback package verification. - Added update target awareness so already-current devices are not offered a
redundant transaction. - Documented the intentional unauthenticated trusted-LAN/USB local-control
contract and added contributor navigation across runtime components. - Made release-signing key permission validation portable across GNU/Linux and
BSD/macOSstatimplementations.
rctl 0.3.0
Relay image: ghcr.io/nobottomline/rctl-relay:0.3.0
Relay digest: ghcr.io/nobottomline/rctl-relay@sha256:1d543eb4b0b16c7d17b1932cf39f3029963fd14b15daff7435440de1b891e600
Source commit: 13c8845c24599f3c78cf4e32958bb174c2bd92b8
Fresh-host qualification report SHA-256: 239c38745578264fd316502746fc07dda656041361c04f7bb87cbbc5a8904d31