Skip to content

rctl 0.4.5

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:11
· 1 commit to main since this release
Immutable release. Only release title and notes can be modified.

This is an immutable pre-release for opt-in testing, excluded from latest and the default stable/APT update channel.

Relay candidate image: ghcr.io/nobottomline/rctl-relay@sha256:24cc8d2aba4755012469d57538b0cfc70303b7dcd6147b54c5142a79dc576043

Source commit: 0c636304da7d5169741a1f208cec9bf7affc10c3

SHA256SUMS SHA-256: 89bfc341847b0a37bb0fddc1b07f8f456bf3c837f700bf52dc0cda98c2380078

Verified artifacts

  • Exact-source CI: all six jobs passed, including both web clients, relay, container, tailnet and isolated iOS controller lifecycle tests. All three CodeQL analyses passed.
  • Tag-bound release build: Linux amd64/arm64 binaries, rootful/rootless packages, and signed device/host catalogs.
  • Independent verification passed all eleven asset sizes/checksums and tag/source/workflow-bound build attestations, both public-package audits, catalog signatures and immutable 0.4.4 rollback artifacts.
  • Anonymous candidate image access, linked amd64/arm64 SPDX SBOMs and repository/tag/source-bound OCI provenance passed. The embedded setup image remains digest-pinned.

Qualification limits

The owner deferred final physical rootless and clean-VPS acceptance for this preview. There is no all-passed schema-5 runtime qualification report. Earlier version-scoped tests do not qualify these new package bytes.

Physical guest touch/keyboard and held-input retirement, foreground live-camera/recording stop, Talk audibility, macro interruption and relay-partition recovery remain open. Fresh-host installation, renewal, upgrade/rollback and managed host-update lifecycle checks have not been repeated for this exact release. See guest acceptance and qualification requirements.

The device web build toolchain retains the unpatched braces advisory GHSA-vfj7-8cjw-p6xm through vite-plugin-singlefile. Its affected pattern matcher is not called with the current empty inlinePattern configuration; it is a build dependency and runtime dependency audit is clean. Protocol/admin toolchain advisories were patched.

This publication does not install packages or redeploy an existing relay. Native controller applications remain in development and are not package payloads. A later qualified stable release requires a new version and fresh evidence; this preview will not be promoted by changing its metadata.

Changes

Release candidate pending version-scoped device and fresh-host qualification.
Changes since stable 0.4.4:

Added

  • Temporary browser invitations for one device, with expiry, view-only presets,
    and 46 explicit permissions for input, audio, camera, files, media, terminal,
    and supported system operations. The relay and device enforce each operation.
  • Admin management of guest grants and sessions. Permission changes, revocation,
    and expiry retire device authority and guest-owned resources; the admin shows
    whether device retirement has been confirmed.
  • Automatic invitation entry into the themed device workspace, with compact
    permission-specific tools, responsive layouts, and clear reconnect, expiry,
    and owner-revocation states.
  • Separate experimental tailnet qualification probes with authenticated HTTPS
    browser enrollment and terminal transport. These are opt-in engineering tools.

Fixed

  • An arm64e SpringBoard crash during asynchronous guest-resource retirement.
  • Idle signaling disconnects, stale ICE events, and handling of rejected
    downloads and failed guest replies.
  • Guest tool state and focus across panel changes, plus accurate expiry and
    permission-change presentation after connection teardown.
  • Unmanaged TURN socket binding and deployment installation/log diagnostics.
  • GitHub Actions workflow lint for relay candidate release notes.
  • Vulnerable fast-uri and brace-expansion development dependencies in the
    protocol validator and admin lint toolchain.

Physical guest camera, input retirement, Talk audibility, partition recovery, and
rootless runtime qualification remain open; see docs/GUEST-ACCESS.md. Screen
video recording and guest package installation are not implemented product
features. Native controllers remain in development and are not distributed in
the device packages. Candidate builds do not advance stable catalogs or APT.