Windows: automatic updates by default, following the user's channel (stable or testing) #55

Open
opened 2026-10-06 03:50:53 +00:00 by robocub · 0 comments
Member

Goal: non-technical testers on Windows always run the newest build of their channel without ever checking for updates. On by default for Windows builds, with an off switch in Settings.

Where we are

  • There is no Windows build yet. Our CI (.forgejo/workflows) makes Linux, Flatpak and Android. Flutter can't build Windows apps from Linux; upstream uses GitHub's windows-2022 runners in .github/workflows/release.yml. So step 0 is a Windows runner: for example a Windows VM on cubuntu running forgejo-runner in host mode, with Flutter, VS Build Tools and Rust (for rust_lib_commet).
  • Upstream's updater (lib/utils/update_checker.dart) reads the latest version from a Matrix profile on data.commet.chat and, on Windows, runs a bundled installer/commet-installer.exe after a confirmation prompt. Vommet disables it (hasReleaseFeed = false), since that feed would "update" people to Commet. Nothing in it is channel-aware or silent.

Proposal

  1. Channel baked into the build: BuildConfig.CHANNEL = stable | testing, set by CI. The app follows the channel it was installed from; switching channels is a setting (or a different installer).
  2. Release feed from our own releases, no new service: the Forgejo releases API on nether/vommet (/releases?limit=…). For stable, the latest non-pre-release; for testing, the latest pre-release tagged testing-*. Compare by build date or a monotonic build number, not the label (CI labels like testing.76 differ per workflow; see #50).
  3. Silent update mechanism. Candidates:
    • Velopack (recommended to evaluate first): installer + background download + apply on next start + delta packages. It ships a Rust crate, which fits our existing rust_lib_commet FFI, and needs no admin rights (per-user install).
    • Inno Setup installer run with /VERYSILENT after download: simple, but full downloads and a brief UAC-free relaunch dance.
    • MSIX + .appinstaller with UpdateSettings (we already have msix_config in pubspec): Windows itself checks for updates, but it needs a trusted signing certificate, and sideloading MSIX is fiddly for exactly the users this is for.
  4. Behaviour: check on start and every few hours, download in the background, apply on next launch (or offer "Restart now"). Show the "What's new" list (#50) after the update. Never interrupt a call.
  5. Code signing: without it, every new download triggers SmartScreen ("Windows protected your PC"), which defeats the non-technical audience. Options: SignPath Foundation (free for open source, needs approval) or Azure Trusted Signing (paid, ~$10/month). This is an operator decision.
  6. Setting: Settings › General › "Install updates automatically" (default on for Windows), plus "Check now".

Open decisions (operator)

  • Windows runner: where it runs (VM on cubuntu?), and who maintains it.
  • Signing route (SignPath vs Trusted Signing vs none for now).
  • Whether testing-channel users get every CI build or only tagged testing-YYYY-MM-DD pre-releases (recommendation: tagged pre-releases, so a broken nightly can't auto-ship).
  • #50 "What's new" dialog (same version-ordering problem, shown after an auto-update)
  • Android and Flatpak update separately (APK self-update / Flathub), out of scope here.

Upstream (searched 2026-10-06): no issue, PR or branch for channel-aware or silent auto-update.

Goal: non-technical testers on Windows always run the newest build of their channel without ever checking for updates. **On by default** for Windows builds, with an off switch in Settings. ## Where we are - **There is no Windows build yet.** Our CI (`.forgejo/workflows`) makes Linux, Flatpak and Android. Flutter can't build Windows apps from Linux; upstream uses GitHub's `windows-2022` runners in `.github/workflows/release.yml`. So step 0 is a Windows runner: for example a Windows VM on cubuntu running forgejo-runner in host mode, with Flutter, VS Build Tools and Rust (for `rust_lib_commet`). - Upstream's updater (`lib/utils/update_checker.dart`) reads the latest version from a Matrix profile on `data.commet.chat` and, on Windows, runs a bundled `installer/commet-installer.exe` after a confirmation prompt. Vommet disables it (`hasReleaseFeed = false`), since that feed would "update" people to Commet. Nothing in it is channel-aware or silent. ## Proposal 1. **Channel baked into the build:** `BuildConfig.CHANNEL` = `stable` | `testing`, set by CI. The app follows the channel it was installed from; switching channels is a setting (or a different installer). 2. **Release feed from our own releases**, no new service: the Forgejo releases API on nether/vommet (`/releases?limit=…`). For stable, the latest non-pre-release; for testing, the latest pre-release tagged `testing-*`. Compare by build date or a monotonic build number, not the label (CI labels like `testing.76` differ per workflow; see #50). 3. **Silent update mechanism.** Candidates: - **Velopack** (recommended to evaluate first): installer + background download + apply on next start + delta packages. It ships a Rust crate, which fits our existing `rust_lib_commet` FFI, and needs no admin rights (per-user install). - Inno Setup installer run with `/VERYSILENT` after download: simple, but full downloads and a brief UAC-free relaunch dance. - MSIX + `.appinstaller` with `UpdateSettings` (we already have `msix_config` in pubspec): Windows itself checks for updates, but it needs a trusted signing certificate, and sideloading MSIX is fiddly for exactly the users this is for. 4. **Behaviour:** check on start and every few hours, download in the background, apply on next launch (or offer "Restart now"). Show the "What's new" list (#50) after the update. Never interrupt a call. 5. **Code signing:** without it, every new download triggers SmartScreen ("Windows protected your PC"), which defeats the non-technical audience. Options: SignPath Foundation (free for open source, needs approval) or Azure Trusted Signing (paid, ~$10/month). This is an operator decision. 6. **Setting:** Settings › General › "Install updates automatically" (default on for Windows), plus "Check now". ## Open decisions (operator) - Windows runner: where it runs (VM on cubuntu?), and who maintains it. - Signing route (SignPath vs Trusted Signing vs none for now). - Whether testing-channel users get every CI build or only tagged `testing-YYYY-MM-DD` pre-releases (recommendation: tagged pre-releases, so a broken nightly can't auto-ship). ## Related - #50 "What's new" dialog (same version-ordering problem, shown after an auto-update) - Android and Flatpak update separately (APK self-update / Flathub), out of scope here. Upstream (searched 2026-10-06): no issue, PR or branch for channel-aware or silent auto-update.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nether/vommet#55
No description provided.