Skip to content

v2.1.5

Choose a tag to compare

@github-actions github-actions released this 09 Sep 20:31
· 9 commits to master since this release
a071f4b

RemoteAppClient 2.1.5 — minor fixes

A device could be online, green and reporting every minute while silently discarding every command sent to it — and nothing, anywhere, said so. That is exactly what a live machine did: its clock ran 88 seconds fast, the agent correctly refused every command as a replay, the console showed a healthy device, and the server logged each command as delivered. It cost an afternoon to find. This release makes the fleet admit it in under a minute, and then repair itself. All components are 2.1.5.0.

Database schema change. Two nullable columns are added to Devices. Apply the idempotent upgrade-2.1.5-device-problem.sql (see Upgrading); a fresh install gets them from schema.sql.

A device that admits what is broken

  • A new error state, with the reason. Devices carry a Problem, and the console shows a red badge and the concrete fault instead of a reassuring green one. The first fault it knows is clock skew, because that is what bit us: an agent refuses any command whose timestamp is more than 60s from its own clock, so a machine running 88 seconds fast is completely unreachable while looking perfectly healthy.
  • The server detects it on its own, with no agent update at all. It compares the telemetry's own CollectedAtUtc against arrival. Telemetry is not signed, so it still arrives from a device whose every command is being thrown away — which makes it the only channel that can report this fault. The threshold is 30s, half the command window: it warns while there is still time to act. Verified in production against a machine running the previous agent.
  • The problem is stored as a language-neutral code and rendered by each console in its own language. An unrecognised code is shown raw rather than hidden, so an older console cannot swallow a fault whose name it has not learnt yet. Transitions land in the device history like any other state change.

An agent that fixes its own clock

  • Time sync runs at startup, periodically, and — the part that matters — whenever the skew is demonstrated. Two independent signals trigger it: a command carrying a valid server signature but an out-of-window timestamp (proof the fault is ours, not a forgery), and the Date header on every telemetry response, which catches it within one 60-second cycle without any command needing to arrive.
  • Neither signal is ever trusted as a time source; both only prompt the agent to consult a real one. A domain-joined machine is left alone — its time comes from the domain hierarchy, and overriding that fights the DC — and an existing NTP configuration is never overwritten; only a machine with no source at all is given one.
  • The correction is measured and logged ("the clock was stepped by −180s"). A system that quietly moves a machine's clock by three minutes should leave a record that it did.

Fewer confident wrong answers

  • The console no longer puts up "waiting for the user at the device to approve" when nobody was asked. It could not tell before: it sees only the device's own tri-state consent setting, while the effective value comes from group inheritance — so the server now returns it. When consent really was requested the wait is unchanged; when it was not, a silent device is reported as a silent device.
  • Show VNC password (admin-only, right-click). The console hands the secret straight to the viewer and never displays it, so reading one previously meant decrypting the database by hand. Every read is written to the audit log — that record is the point, which is why it re-fetches rather than using the copy already in the device list.
  • "nem vezérelhető" is now "csak jelent", which fits the badge.
  • build.ps1 -Deploy replaces a live installation in one step: stops the services, kills the console, swaps the binaries while everything is down, verifies each copy by hash, and only then restarts. The script is now in English.

Upgrading

Server first, with upgrade-2.1.5-device-problem.sql (attached below, also in src/RemoteServer/Data/Migrations/) — through the in-app Server update → choose SQL upload, or manually. It is idempotent (ADD COLUMN IF NOT EXISTS), so running it twice is harmless.

The wire contract is additive, so nothing breaks in either direction. Most importantly, the fault reporting works across the whole fleet without updating a single agent — that is the point of deriving it from unsigned telemetry. The 2.1.5 agent adds the prevention (self time sync) on top; roll it out at your own pace.

Artifacts

  • RemoteAgent.exe, RemoteAgent.Updater.exe, RemoteClient.exe, RemoteClient.Lite.exe — Windows x64, self-contained single-file
  • RemoteServer-linux-x64.tar.gz — server
  • remoteclient_2.1.5_amd64.deb — Linux operator console
  • upgrade-2.1.5-device-problem.sql — the schema upgrade, idempotent