TetherBay 0.2.381
· Updated 2026-08-02
TetherBay 0.2.381 packages the latest documented beta improvements across relay resilience, storage, and encrypted sync.
Highlights
- Windows upgrades now retire the legacy beta auto-updater.
Setup removes the old scheduled updater and its LocalAppData application copy before launching the Program Files build, preventing obsolete beta clients from reappearing after a successful installation while preserving settings and synced folders.
- Windows one-line upgrades now complete cleanly over running beta clients.
The PowerShell flow downloads a recognisably named installer, closes existing launcher and agent processes, waits for setup to finish, and cleans up afterward. The Windows installer no longer lets Restart Manager reopen a legacy client behind the setup wizard.
- Sync server no longer slows down as the total number of synced files grows.
The relay's metadata store became database-authoritative: per-write work is now proportional to what actually changed (indexed point/range queries) instead of the whole dataset, and the server no longer loads all records into memory at startup — so boot time and memory stay flat as the service grows.
Fixes
- Windows upgrades now retire the legacy beta auto-updater. Setup removes the old scheduled updater and its LocalAppData application copy before launching the Program Files build, preventing obsolete beta clients from reappearing after a successful installation while preserving settings and synced folders.
- Windows one-line upgrades now complete cleanly over running beta clients. The PowerShell flow downloads a recognisably named installer, closes existing launcher and agent processes, waits for setup to finish, and cleans up afterward. The Windows installer no longer lets Restart Manager reopen a legacy client behind the setup wizard.
- Sync server no longer slows down as the total number of synced files grows. The relay's metadata store became database-authoritative: per-write work is now proportional to what actually changed (indexed point/range queries) instead of the whole dataset, and the server no longer loads all records into memory at startup — so boot time and memory stay flat as the service grows.
- One busy account can no longer degrade everyone else. Write contention is now keyed per folder/account behind a new lock manager (opt-in sharded mode), with a fair-share soft throttle that *slows* an over-active tenant rather than blocking it, and per-tenant lock metrics on /metrics. Closes the single-account denial-of-service path that could previously wedge the whole relay.
- PostgreSQL is now a supported metadata backend for the relay (selectable by configuration), alongside the existing SQLite store which remains the default for local and self-hosted use. Includes a one-shot SQLite→Postgres data migration tool with row-count reconciliation.
- Cloudflare R2 (S3-compatible) blob storage is production-ready. The relay can store encrypted blobs in R2 with presigned zero-egress downloads, a live storage health/deep-probe check, and a global storage-cap safety valve; switching is a configuration change. Verified end-to-end against a real S3 server.
- Server startup no longer waits on the boot-time storage maintenance pass. The audit that repairs/cleans staged and orphaned blobs now runs after the server is listening instead of before it binds, so health checks come up immediately even on an object-store backend where that pass can take minutes. Controlled by TETHERBAY_STARTUP_AUDIT_MODE (background default, off to skip at boot, blocking for the legacy pre-bind behavior).
- End-to-end encryption for synced folders and clipboard. File contents are encrypted on the sending device with AES-256-GCM (framed streaming AEAD) before upload; folder keys are shared device-to-device via sealed ECDH envelopes and never reach the relay. Clipboard items are sealed per-event with the account key. The relay stores ciphertext only and has no decryption path. Rollout is fail-closed — uploads are held rather than sent in the clear if any device in a folder cannot yet support E2E, so every device in a folder must be updated before content flows again. Clipboard E2E defaults ON since 2026-06-15.
- Remote file access hardened alongside folder encryption.
Known issues
- macOS beta packages are unsigned and not notarized; follow the documented Gatekeeper first-launch steps.
Availability
- win-x64 — Download
3ccabd4077def563b0a952b3f37bfa00dc68559f9ae6b3ed8b979747d8c24f1a - osx-arm64 — Download
306cad332f1d2fa860b9c23d966c2197351db7ea3ce00298fd935df372f98d8f - osx-x64 — Download
c93283b83baaefe769ee73f0ec23d2a2a476a046f1477d91986e6bede98f80dc - linux-x64 — Download
f571db55a1b7fb7f04ac3f18e49e238bc5f9253185f59ac141f25f2b983f3ac5 - linux-arm64 — Download
fe550755fedbdf347a7fa07364853947d90d4b8f193ad91dd356d9f6a98fd5f2 - android — pending
- ios — pending