Updates of Shellaro
Shellaro updates itself with the official Tauri updater plugin.
For users
- Official builds know Shellaro's update server (built in at release time). Settings > Updates shows it; a different server can be entered there (empty the field to go back). Development and unofficial builds have no server and never check.
- Channels: Stable, or Preview (release candidates first). A release candidate always follows Preview, so it receives the next candidate and the final release; after that, the channel chosen in Settings applies again.
- Automatic checks (default on): a minute after start, then every six hours. If a newer version exists it is downloaded and its signature verified in the background; the status bar then shows Update ready · Restart to Update. If there is nothing new, nothing is shown. If a check fails (offline, server down, bad metadata, refused signature), Shellaro carries on: the reason is in Settings > Updates and in the log, and the next check runs as usual.
- Restart to Update saves the workspace (tabs, splits, panels; never credentials), closes Shellaro, runs the installer with a small progress window (no wizard, no clicks, no administrator rights) and starts the new version, which restores the workspace with SSH tabs disconnected and one Reconnect N sessions button. Unsaved editor changes are mentioned first. Getting Started is not shown after an update; the data folder is not touched.
- Shellaro never restarts by itself.
Verification
Each update must be signed with the private key whose public key is built into Shellaro (Ed25519, minisign format). Shellaro refuses, and logs:
- a missing, broken or different signature ("its signature does not match Shellaro's update key");
- an update server, or an installer address in its metadata, that is not https (plain http is accepted only for
127.0.0.1/localhost, for testing); - metadata that does not parse.
Nothing is installed in any of these cases.