Updates
How PluggedDesk finds a new release, how it decides to trust it, and what it does when you agree to install it.
What happens
Twenty seconds after it starts, and every six hours after that, PluggedDesk reads the update channel on this site. You can ask at any time with Help › Check for Updates.
When a newer release exists, a pill appears in the title bar. Nothing is downloaded and nothing is installed until you choose to. You can also skip a version: PluggedDesk will not mention it again, and will tell you about the next one.
How a release is trusted
PluggedDesk uses a release only when all of these hold:
- The manifest's signature is valid, and was made with a key that is compiled into the PluggedDesk you are running.
- The manifest is well formed, and is for PluggedDesk, for your channel and for your platform.
- Its version is strictly newer than yours. An old release, however genuine, is never offered, so nobody can take you backwards to a version with a known fault.
- A pre-release is offered only to an installation that follows the preview channel.
Then, when you choose to update:
- The installer is downloaded, and checked against the size and the SHA-256 in the signed manifest. A file that does not match is deleted.
- The file is held open against changes from that check until the installer has started.
Where the files came from is no part of this. The channel is read over HTTPS, and this site requires an entitlement to read it, but the release would be refused just the same if a genuine server handed out a forged file. The signature is what is trusted.
Installing
Install closes PluggedDesk, runs the installer without questions, and starts the new version. The button says how many sessions that will end, so that you can choose your moment. No administrator rights are needed.
The new version says once, in the status bar, that it was updated. Installers and their logs are kept under
%LOCALAPPDATA%\PluggedDesk\updates and removed once they are no newer than what is running.
Channels
| Channel | What it carries |
|---|---|
| stable | Releases. This is what every installation follows unless you change it. |
| preview | Releases and pre-releases, whichever is newest. Less tested. Your license must include it. |
To follow the preview channel, choose Help › Check for Updates and tick Include pre-releases.
If updates do not arrive
| What PluggedDesk says | What it means |
|---|---|
| Updates come to installations that are activated… | Activate it: Help › License. See Licenses and seats. |
| This installation's entitlement does not include that channel of releases | Your license does not include the preview channel. Untick Include pre-releases. |
| Could not reach pluggeddesk.exprezoe.com: … | The computer cannot reach this site. PluggedDesk will try again later. |
| The update information from pluggeddesk.exprezoe.com was ignored: … | The manifest's signature was not valid. Nothing was installed. Please tell us. |
| The download does not match the release's SHA-256; it was discarded. (or: ended early, is larger than the release's installer) | The installer was not the one the release names. The file was deleted. Try again, and tell us if it repeats. |
You can always install a release by hand: download it from the downloads page, verify it, and run it over the version you have. Your workspace and settings are kept.
Version 0.4.0
PluggedDesk 0.4.0 reads a different update channel and cannot sign in to this one. To move from 0.4.0 to a later version, install the later version by hand, once. From then on, updates arrive by themselves.
For administrators
An installation can be pointed at a mirror of the channel with the PLUGGEDDESK_UPDATE_FEED environment variable, or
the updates.feed setting. It must be an HTTPS address. A mirror changes where releases are read from, never whose
releases are accepted: the signature is checked just the same.