TetherBay 0.2.377
· Updated 2026-08-02
TetherBay 0.2.377 packages the latest documented beta improvements across relay resilience, storage, and encrypted sync.
Highlights
- Windows upgrades now retire the legacy beta auto-updater.
Setup removes the old scheduled updater and its LocalAppData application copy before launching the Program Files build, preventing obsolete beta clients from reappearing after a successful installation while preserving settings and synced folders.
- Windows one-line upgrades now complete cleanly over running beta clients.
The PowerShell flow downloads a recognisably named installer, closes existing launcher and agent processes, waits for setup to finish, and cleans up afterward. The Windows installer no longer lets Restart Manager reopen a legacy client behind the setup wizard.
- Sync server no longer slows down as the total number of synced files grows.
The relay's metadata store became database-authoritative: per-write work is now proportional to what actually changed (indexed point/range queries) instead of the whole dataset, and the server no longer loads all records into memory at startup — so boot time and memory stay flat as the service grows.
Fixes
- Windows upgrades now retire the legacy beta auto-updater. Setup removes the old scheduled updater and its LocalAppData application copy before launching the Program Files build, preventing obsolete beta clients from reappearing after a successful installation while preserving settings and synced folders.
- Windows one-line upgrades now complete cleanly over running beta clients. The PowerShell flow downloads a recognisably named installer, closes existing launcher and agent processes, waits for setup to finish, and cleans up afterward. The Windows installer no longer lets Restart Manager reopen a legacy client behind the setup wizard.
- Sync server no longer slows down as the total number of synced files grows. The relay's metadata store became database-authoritative: per-write work is now proportional to what actually changed (indexed point/range queries) instead of the whole dataset, and the server no longer loads all records into memory at startup — so boot time and memory stay flat as the service grows.
- One busy account can no longer degrade everyone else. Write contention is now keyed per folder/account behind a new lock manager (opt-in sharded mode), with a fair-share soft throttle that *slows* an over-active tenant rather than blocking it, and per-tenant lock metrics on /metrics. Closes the single-account denial-of-service path that could previously wedge the whole relay.
- PostgreSQL is now a supported metadata backend for the relay (selectable by configuration), alongside the existing SQLite store which remains the default for local and self-hosted use. Includes a one-shot SQLite→Postgres data migration tool with row-count reconciliation.
- Cloudflare R2 (S3-compatible) blob storage is production-ready. The relay can store encrypted blobs in R2 with presigned zero-egress downloads, a live storage health/deep-probe check, and a global storage-cap safety valve; switching is a configuration change. Verified end-to-end against a real S3 server.
- Server startup no longer waits on the boot-time storage maintenance pass. The audit that repairs/cleans staged and orphaned blobs now runs after the server is listening instead of before it binds, so health checks come up immediately even on an object-store backend where that pass can take minutes. Controlled by TETHERBAY_STARTUP_AUDIT_MODE (background default, off to skip at boot, blocking for the legacy pre-bind behavior).
- End-to-end encryption for synced folders and clipboard. File contents are encrypted on the sending device with AES-256-GCM (framed streaming AEAD) before upload; folder keys are shared device-to-device via sealed ECDH envelopes and never reach the relay. Clipboard items are sealed per-event with the account key. The relay stores ciphertext only and has no decryption path. Rollout is fail-closed — uploads are held rather than sent in the clear if any device in a folder cannot yet support E2E, so every device in a folder must be updated before content flows again. Clipboard E2E defaults ON since 2026-06-15.
- Remote file access hardened alongside folder encryption.
Known issues
- macOS beta packages are unsigned and not notarized; follow the documented Gatekeeper first-launch steps.
Availability
- win-x64 — Download
342fe77b32d8f25cdd37b8f4c011f37d8af543e5908171978488b5e96e876421 - osx-arm64 — Download
e307e082a559c34e2c7328c0184baebc03c403b247112be7347374f30475ecdd - osx-x64 — Download
1193f89bdaf14e0d494dd115bf9781dcf572513113c976cb431faddb584c43a7 - linux-x64 — Download
a69abf5bb2f9a9dbfc8b1f59b6727196a3f3870bab075373712cf4360a7b62b4 - linux-arm64 — Download
dd350d99c8aba826118f97c12d3d9f1735011226d4de2e9cb3bb8b8a56f1de69 - android — Download
be37e8ebc6127c11ec55a84f8d36e9c200446ce920f8e2bc951f7df6cf0b77f8 - ios — pending