Skip to content

Releases: nobottomline/rctl

rctl 0.4.5

rctl 0.4.5 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:11
Immutable release. Only release title and notes can be modified.

This is an immutable pre-release for opt-in testing, excluded from latest and the default stable/APT update channel.

Relay candidate image: ghcr.io/nobottomline/rctl-relay@sha256:24cc8d2aba4755012469d57538b0cfc70303b7dcd6147b54c5142a79dc576043

Source commit: 0c636304da7d5169741a1f208cec9bf7affc10c3

SHA256SUMS SHA-256: 89bfc341847b0a37bb0fddc1b07f8f456bf3c837f700bf52dc0cda98c2380078

Verified artifacts

  • Exact-source CI: all six jobs passed, including both web clients, relay, container, tailnet and isolated iOS controller lifecycle tests. All three CodeQL analyses passed.
  • Tag-bound release build: Linux amd64/arm64 binaries, rootful/rootless packages, and signed device/host catalogs.
  • Independent verification passed all eleven asset sizes/checksums and tag/source/workflow-bound build attestations, both public-package audits, catalog signatures and immutable 0.4.4 rollback artifacts.
  • Anonymous candidate image access, linked amd64/arm64 SPDX SBOMs and repository/tag/source-bound OCI provenance passed. The embedded setup image remains digest-pinned.

Qualification limits

The owner deferred final physical rootless and clean-VPS acceptance for this preview. There is no all-passed schema-5 runtime qualification report. Earlier version-scoped tests do not qualify these new package bytes.

Physical guest touch/keyboard and held-input retirement, foreground live-camera/recording stop, Talk audibility, macro interruption and relay-partition recovery remain open. Fresh-host installation, renewal, upgrade/rollback and managed host-update lifecycle checks have not been repeated for this exact release. See guest acceptance and qualification requirements.

The device web build toolchain retains the unpatched braces advisory GHSA-vfj7-8cjw-p6xm through vite-plugin-singlefile. Its affected pattern matcher is not called with the current empty inlinePattern configuration; it is a build dependency and runtime dependency audit is clean. Protocol/admin toolchain advisories were patched.

This publication does not install packages or redeploy an existing relay. Native controller applications remain in development and are not package payloads. A later qualified stable release requires a new version and fresh evidence; this preview will not be promoted by changing its metadata.

Changes

Release candidate pending version-scoped device and fresh-host qualification.
Changes since stable 0.4.4:

Added

  • Temporary browser invitations for one device, with expiry, view-only presets,
    and 46 explicit permissions for input, audio, camera, files, media, terminal,
    and supported system operations. The relay and device enforce each operation.
  • Admin management of guest grants and sessions. Permission changes, revocation,
    and expiry retire device authority and guest-owned resources; the admin shows
    whether device retirement has been confirmed.
  • Automatic invitation entry into the themed device workspace, with compact
    permission-specific tools, responsive layouts, and clear reconnect, expiry,
    and owner-revocation states.
  • Separate experimental tailnet qualification probes with authenticated HTTPS
    browser enrollment and terminal transport. These are opt-in engineering tools.

Fixed

  • An arm64e SpringBoard crash during asynchronous guest-resource retirement.
  • Idle signaling disconnects, stale ICE events, and handling of rejected
    downloads and failed guest replies.
  • Guest tool state and focus across panel changes, plus accurate expiry and
    permission-change presentation after connection teardown.
  • Unmanaged TURN socket binding and deployment installation/log diagnostics.
  • GitHub Actions workflow lint for relay candidate release notes.
  • Vulnerable fast-uri and brace-expansion development dependencies in the
    protocol validator and admin lint toolchain.

Physical guest camera, input retirement, Talk audibility, partition recovery, and
rootless runtime qualification remain open; see docs/GUEST-ACCESS.md. Screen
video recording and guest package installation are not implemented product
features. Native controllers remain in development and are not distributed in
the device packages. Candidate builds do not advance stable catalogs or APT.

rctl 0.4.4

Choose a tag to compare

@github-actions github-actions released this 18 Sep 22:31
Immutable release. Only release title and notes can be modified.

Relay image: ghcr.io/nobottomline/rctl-relay@sha256:2d935a096ba6ae2b42f35c5eba439f687159bf93a1f54be12bca5969244004e8

Source commit: 672e4bb3793a05769a3ff05a287047f2045e240e

Release Status

Published as latest. The full schema-5 qualification matrix is not yet complete.
Artifact checksums, build provenance, public
package audits, and exact-commit CI passed. Both tested device lanes completed
the relay-admin update from 0.4.3 to 0.4.4 with relay identities preserved and
subsequent LAN/relay control checks.

Outstanding exact-candidate checks include forced-TURN device media, certificate
renewal, fault-injected host/device recovery, package-manager recovery, and parts
of the admin/scheduled host-update matrix. Earlier-version results do not
establish those checks for this release. There is no all-passed schema-5 report.
Back up before updating and retain independent recovery access.

This publication does not update the APT feed. Download the package matching
the jailbreak: iphoneos-arm for rootful, iphoneos-arm64 for ordinary Dopamine
rootless. Rootless testing covers iPadOS 15.5 with ElleKit; RootHide and other
untested device/iOS combinations are not qualified.

Added

  • Ordinary Dopamine rootless support with a separate iphoneos-arm64 package;
    rootful devices continue to use iphoneos-arm.
  • Game Keyboard with held keys and WASD, plus captured mouse movement, buttons,
    and scrolling. Session loss releases held input.
  • Device orientation locking, recorded-input playback pause/resume and JSON
    export, screenshot previews, and device volume controls.
  • Personalized rootless packages and signed transactional device updates from
    relay admin, with rollback and preservation of device identity.
  • Signed relay update discovery, installation from the admin page, and opt-in
    scheduled server updates with backup, health verification, and recovery.
    Device package installation still requires separate confirmation.
  • Installer domain selection, public-address inference, optional Docker
    provisioning, clearer progress, and terminal-aware colors.
  • Controller permissions, presence, audit history, Bonjour discovery, and an
    explicit LAN + Relay / Relay only access policy.

Fixed

  • Rootless screen orientation and touch geometry, video thumbnails, microphone
    recording, Talk playback, shell prompts, and duplicate tweak listings.
  • Duplicate keyboard input, stuck modifiers, inverted trackpad scrolling, and
    input-session timeouts during mouse capture.
  • Installing a package for an additional relay now preserves existing relay
    bindings and consumes the new enrollment instead of discarding it.
  • TURN/TCP negotiation and RTP packet sizing; stale web clients can no longer
    survive package rebuilds. Experimental video pacing is not included.
  • Controller pairing now validates relay identity and origin; permission changes
    invalidate stale sessions, and device updates reject downgrades.
  • Interrupted relay updates recover before new work starts, updater connections
    survive service restarts, and failed scheduled releases are not retried in a loop.
  • Consistent dropdowns, stable hover feedback, device-neutral labels, and a
    styled automatic-update checkbox. Unsupported HTTP-only sharing/copy actions
    are hidden while downloads remain available.

The native iOS controller remains in development and is not distributed in
device packages. Sustained intermittent Listen noise testing remains open.
Rootful silent-session closures with delayed reconnects also remain under
investigation; always-online availability is not guaranteed.

rctl 0.4.3 - host updater qualification B

Choose a tag to compare

@github-actions github-actions released this 16 Sep 18:55
Immutable release. Only release title and notes can be modified.

Test prerelease B for the signed 0.4.2 to 0.4.3 managed relay update path. Not a stable release, not promoted to APT, and not recommended for general installation.

Source: 6fcfb7e
Relay image: ghcr.io/nobottomline/rctl-relay@sha256:04f388c7f4b9d7058e76fc1e320d9b56a782b0f1f385f99ad69d5cf90c90662e

Versioned successor to qualification A with the same runtime code, used to test version discovery, admin-page installation, identity preservation, restart and recovery.

Build provenance, artifact checksums, catalog signatures and CI verified. Real VPS qualification is still in progress. Stable/latest is unchanged. Device installation remains separate.

rctl 0.4.2 - host updater qualification A

Choose a tag to compare

@github-actions github-actions released this 16 Sep 18:55
Immutable release. Only release title and notes can be modified.

Test prerelease A for managed relay updater qualification. Not a stable release, not promoted to APT, and not recommended for general installation.

Source: 9775071
Relay image: ghcr.io/nobottomline/rctl-relay@sha256:11e66b135de6045580d9dad6ae32fbedb02461951a5f730f63591dcdd5cc0fb9

Includes signed host update catalogs, admin-managed relay updates, opt-in scheduling, durable job/recovery state, Debian-aware device version comparison, and terminal domain-picker cancellation fixes. Both package architectures are included for artifact validation; installing a device package is a separate action.

Build provenance, artifact checksums and catalog signatures verified. Real VPS upgrade and recovery qualification is still in progress. Stable/latest is unchanged.

rctl 0.3.2

Choose a tag to compare

@github-actions github-actions released this 23 Aug 22:14
Immutable release. Only release title and notes can be modified.

Relay image: ghcr.io/nobottomline/rctl-relay:0.3.2

Relay digest: ghcr.io/nobottomline/rctl-relay@sha256:16c4f587b7377141e842ac970d283af620a63705b05e85999d8ea3479dc92317

Source commit: 38f210d59209910c9bdf753c283cf964659e76e4

Fresh-host qualification report SHA-256: 978f0866bf2b463511b1f35b1c4da5a5b2151e9504db9773a443cb705fbddb8d

  • Fixed interactive curl | sudo sh setup by reconnecting the verified wizard
    to the controlling terminal and added visible lifecycle progress.
  • Added a release-gated, P-256 signed stable device-update catalog with exact
    target and rollback package verification.
  • Added update target awareness so already-current devices are not offered a
    redundant transaction.
  • Documented the intentional unauthenticated trusted-LAN/USB local-control
    contract and added contributor navigation across runtime components.
  • Made release-signing key permission validation portable across GNU/Linux and
    BSD/macOS stat implementations.

rctl 0.3.0

Choose a tag to compare

@github-actions github-actions released this 23 Aug 12:18
Immutable release. Only release title and notes can be modified.

Relay image: ghcr.io/nobottomline/rctl-relay:0.3.0

Relay digest: ghcr.io/nobottomline/rctl-relay@sha256:1d543eb4b0b16c7d17b1932cf39f3029963fd14b15daff7435440de1b891e600

Source commit: 13c8845c24599f3c78cf4e32958bb174c2bd92b8

Fresh-host qualification report SHA-256: 239c38745578264fd316502746fc07dda656041361c04f7bb87cbbc5a8904d31