Skip to content

16.3.5

Choose a tag to compare

@voipnorm voipnorm released this 22 Aug 01:31
0ff1a69

CE-Deploy 16.3.5

This is a major reliability and defect-remediation release containing 70 numbered fixes completed since 16.3.4 was published on August 14, 2026 (Pacific time), plus additional lifecycle, analytics, IPC, and build-process corrections.

Highlights

  • More truthful progress, partial-success, stale-data, and failure feedback across deployments, inventories, diagnostics, notifications, and Environmental Intelligence.
  • Stronger organization, token, OAuth, IPC, proxy, credential, and request-lifecycle handling.
  • Safer scheduled execution, cancellation, gateway-timeout verification, and organization-bound state.
  • Extensive Environmental Intelligence reliability, organization-isolation, reporting, theme, and layout improvements.
  • Macro Inventory, Macro Factory, Macro Drift, Dashboard, xAPI Forge, and QR workflow corrections.
  • The release gate passed 1,796 automated tests, with each remediation also held for its documented smoke-test gate.

Fixes

Organizations, authentication, and credentials

  • D-023: Deployments retain the submitted deployment type instead of reading later mutable UI state.
  • D-041: Active-token resolution now follows one organization-first contract.
  • D-050: Commercial and FedRAMP API domains are request-scoped instead of mutating shared state.
  • D-051: Organization changes reset hidden deployment-route state.
  • D-057: Webex 401 responses refresh the active organization token before retrying.
  • D-060: Transient OAuth refresh failures receive bounded retry handling.
  • D-061: Reused OAuth providers can move correctly between Commercial and FedRAMP environments.
  • D-125: Main-process window messages use destroyed-window-safe delivery.
  • D-126: Shared HTTP-client exceptions are explicitly bounded and documented.
  • D-211: Cancelling Add Organization now closes and settles the matching OAuth attempt without stale replies.
  • D-226: On-premise Device Groups can be populated and edited safely while preserving protected credentials.
  • D-233: On-premise Device Group usernames and passwords are no longer written to application logs.
  • D-236: Organization Test Connection uses acknowledged IPC and visible pending/success/failure feedback instead of recursive reply handling.

Deployment, scheduling, and operation lifecycle

  • D-014: Closing the progress modal now releases its handlers, state subscription, Bootstrap instance, and modal artifacts.
  • D-016: Stalled download streams are destroyed and cleaned up.
  • D-018: Web-server control replies are correlated to the initiating request.
  • D-028: Persisted scheduled chains fail closed with a clear unsupported message.
  • D-038: Scheduled UI update failures are reported instead of disappearing into logs.
  • D-042: Application-update progress no longer collides with device download and backup progress.
  • D-045: PhonePilot connections and sessions close with their window.
  • D-054: Persistent device-session failures propagate across IPC instead of appearing successful.
  • D-055: Command-output CSV save failures produce an accurate partial-completion result.
  • D-062: Preflight results belong to one deployment attempt instead of shared window state.
  • D-063: Scheduled on-premise jobs resolve the Device Group's current membership on every run.
  • D-064: Gateway-timeout verification is cancelled and drained at the shared deadline without resending commands.
  • D-068: TFTP start and stop operations are serialized and their controls remain locked during transitions.
  • D-069: Transient backup-download failures receive one bounded retry.
  • D-216: Cancelling the scheduler fully clears modal state so later deployment summaries continue to appear.
  • Active-operation quit protection now uses the shared themed in-app confirmation instead of a native Electron dialog (D-058).

Proxy, networking, and diagnostics

  • D-029: Proxy discovery continues polling after transient failures.
  • D-056: Proxy configuration failures are presented to the user.
  • D-067: System proxy rules are parsed safely.
  • D-177: Webex Network Diagnostics uses concrete, reachable Webex services and Copy Report provides verified clipboard feedback.
  • D-178: Connectivity Check identifies local HTTP/HTTPS service purpose, ports, health, and actionable failures without irrelevant transfer metrics.
  • D-215: Custom file-server ports now control listener binding, generated URLs, status, and diagnostics through one validated contract.
  • D-237: Unused Traceroute IPC, dependency, and attack surface were removed while active DNS, HTTP, and TCP diagnostics remain.

Environmental Intelligence

  • D-012: Environmental health reports calculate trend data from score history.
  • D-066: Overlapping metric windows are deduplicated by timestamp.
  • D-070: Workspace, device, and location discovery follows all Webex pagination links instead of stopping at 2,000 records.
  • D-205 / D-227: Organization and target changes atomically reset EI context, reject late data, update existing windows, and prevent previous-organization results from leaking into the new view.
  • D-208: Manual Refresh shows pending, completion, cancellation, already-running, and failure states.
  • D-209: Environmental Intelligence report generation loads correctly and provides truthful download/failure feedback.
  • D-228: Poll, analytics, and cache failures identify stale data, organization context, severity, and last successful refresh.
  • D-229: Settings, lobby, clipboard, retry, and Reset Data actions await acknowledgement and restore rejected state.
  • D-230: Environmental Intelligence charts, controls, and semantic colors follow the shared light, dark, and system theme architecture.
  • D-231: Reports are bound to the active organization and include authoritative organization identity in metadata and filenames.
  • D-232: The non-durable Auto-report control was removed; manual report generation remains available.
  • D-234: Environmental Intelligence is hidden for on-premise organizations and remains guarded at launch.
  • D-235: Device cards reserve consistent content regions so optional rank, anomaly, and confidence data no longer shifts the layout.

Macro Inventory, Macro Factory, and Macro Drift

  • D-217: Drift notification preferences use readable shared theme tokens.
  • D-218: Macro Inventory initialization failures settle progress and display an actionable error.
  • D-219: Macro Factory preserves per-endpoint success, failure, and skipped outcomes.
  • D-220: Drift persistence failures are acknowledged and rejected preference changes are reverted.
  • D-221: Action feedback and opt-in automatic scanning now honor their exposed preferences.
  • D-222: Drift indicators are reconciled with current results and badge settings instead of remaining stale.
  • D-223: Partial drift scans and bulk-push failures no longer appear as successful completion.
  • D-224: Local Macro Drift content reads close endpoint connections on failure.
  • D-225: Removing a drift exception completes persistence, history attribution, and UI reconciliation without the prior scope error.

Dashboard, inventory, xAPI, and user feedback

  • D-006: Workspace CSV exports preserve hybrid-calling email data.
  • D-174: Inventory, Macro Factory, Button Factory, and Environmental Intelligence visibly reject empty location targets.
  • D-176: Test Notifications shows pending and per-channel success, partial-success, failure, or missing-configuration results.
  • D-179: Dashboard validates Org, Tags, and Location targets before opening and no longer launches an empty dashboard.
  • D-212: xAPI command-import validation is readable in dark themes.
  • D-213: xAPI Forge normalizes local, cloud, and IPC macro-log response shapes.
  • D-214: Dashboard refresh failures retain the last snapshot with a visible stale state, retry action, last-success time, and configurable refresh cadence.
  • D-238: Remaining application messages and notifications use themed in-app UI; bounded file Open/Save pickers remain available.

QR Code generation

  • D-239: Public center-logo URLs are validated and fetched through a bounded main-process capability, converted to CSP-safe PNG data, and accompanied by visible loading and failure feedback without weakening renderer security policy.

Analytics and development process

  • D-206: Native boolean analytics properties are validated and encoded correctly for Aptabase.
  • D-207: Renderer and main-process analytics now use one validated event/property schema and centralized collection path.
  • Anonymous analytics collection was hardened and full payload logging was reduced.
  • Generated application bundles are no longer tracked in source control.
  • Development guidance now requires feature/remediation branches and one reversible commit per defect.
  • CE-Deploy support links were updated.

Upgrade recommendation

16.3.5 is recommended for all users. The release contains broad correctness, security-boundary, state-isolation, and failure-reporting improvements across core CE-Deploy workflows.