Skip to content

ApolloVibe 2026.6.1-ms5

Latest

Choose a tag to compare

@vibesoftwarecoder vibesoftwarecoder released this 28 Sep 18:00
5fbe014

This release fixes a permission bypass, a display-mode remapping bug, and rounds out the test suite and docs. Everything from ms4 is included.

Security fix

A client paired with only view permission — the default for every device paired after the first — could terminate the app another user was running. launch()'s permission-downgrade check was meant to exclude terminate requests, but its exclusion clause missed two paths into the terminate branch. A single predicate now covers both, and terminating always requires launch, the same requirement /cancel already had.

Filed upstream as ClassicOldSong/Apollo#1606, since the same code exists there unchanged.

Behaviour change: a view-only client can no longer terminate an app it had joined, by any route.

Display mode remapping fix

A remapping entry with a Requested FPS never matched, so it was silently skipped. Apollo stores the session refresh rate in millihertz, and the comparison used exact struct equality against the entry's plain fps value, which could never match. Remapping now compares by value.

Behaviour change: entries with a Requested FPS that were silently skipped will now apply. An earlier entry can win over a later one, since the first match is used. Clients streaming at a fractional rate such as 59.94 still will not match an integer entry.

Documentation

16 config options that Apollo added over 2024-2025 had no entry in docs/configuration.md, because upstream Apollo never documented them. They are documented now: global_state_cmd, hide_tray_controls, enable_pairing, enable_discovery, enable_input_only_mode, forward_rumble, keep_sink_default, auto_capture_sink, fallback_mode, headless_mode, double_refreshrate, limit_framerate, envvar_compatibility_mode, legacy_ordering, ignore_encoder_probe_failure and nvenc_intra_refresh.

Also from ms4

Early config failures write sunshine-startup-error.log next to the executable and exit with code 2 instead of 0. See the ms4 notes.

How this was checked

The full unit test suite passes: 237 tests, 233 passed, 4 skipped (the Windows-only mouse tests), 0 failed, with audio, encoder, download and external-command tests excluded.

The security and remapping fixes were confirmed in the binary: both changed source files (src/nvhttp.cpp, src/display_device.cpp) were recompiled and linked into this build, checked by object and link timestamps.

Not tested by execution. The permission fix has no existing test harness for launch(); it was verified by hand-tracing every branch, not by running a live server. Nobody has run this build against a real client or display.

Install

apollovibe-windows-x64.zip is the complete portable build: sunshine.exe, assets/ and tools/. MultiSeat's installer pulls it from releases/latest/download/ and needs no change.

SHA-256 of sunshine.exe:
95083822664BCA479C895B935B5A83EFE0D2960986360CB773E8794CD02CCCDF