Skip to content

fix(shared): install the T3 Connect relay client on Windows ARM64 - #14840

Closed
zachspartofaday wants to merge 1 commit into
pingdotgg:mainfrom
zachspartofaday:fix/relay-client-win32-arm64
Closed

zachspartofaday wants to merge 1 commit into
pingdotgg:mainfrom
zachspartofaday:fix/relay-client-win32-arm64

Conversation

@zachspartofaday

Copy link
Copy Markdown

Problem

T3 Connect cannot be enabled on the Windows ARM64 desktop build. CLOUDFLARED_RELEASE_ASSETS has no win32-arm64 entry, so resolve reports the relay client as unsupported and install fails with unsupported_platform. Cloudflare publishes no Windows ARM64 cloudflared: 2026.5.2 and the current 2026.9.3 ship only windows-386 and windows-amd64 Windows assets.

Fixes #14836

Change

Map win32-arm64 to the existing pinned windows-amd64 asset, with the same URL and SHA-256. Windows 11 on ARM runs x64 binaries under its built-in emulation. The managed path already keys on ${platform}-${arch}, and download, checksum verification, version validation and atomic activation are unchanged.

Scope and approval

This is a very small, focused fix for an obvious bug. A platform T3 Code ships a desktop build for has no relay client, and the fix adds one manifest entry plus a focused test. It changes no product defaults or workflows.

Verification

  • Focused test: vp test run --config ../../vite.config.ts --dir . src/relayClient.test.ts in packages/shared → 6/6 pass. The new test runs the client as win32/arm64 and asserts two things: resolve returns missing rather than unsupported, and install requests the pinned cloudflared-windows-amd64.exe URL. With the manifest change reverted, the new test fails with expected { status: 'unsupported', … } to deeply equal { status: 'missing', … }.
  • Targeted checks: tsc --noEmit in packages/shared, vp lint on both files, and vp fmt --check all pass.
  • Manual check on a Windows 11 ARM64 machine (build 26200) running 0.0.45-nightly.20261002.2584. This used the same layout this change produces:
    • I placed the pinned cloudflared-windows-amd64.exe 2026.5.2 at <T3 home>\tools\cloudflared\2026.5.2\win32-arm64\cloudflared.exe. Its SHA-256 matched the pinned value, and cloudflared version exited 0 under emulation.
    • T3 Connect then enabled and the tunnel started.
    • The iOS app connected through the relay: /.well-known/t3/environment, /oauth/token, /api/auth/websocket-ticket, /ws and /api/orchestration/shell all succeeded.
  • Not checked:
    • the in-app automatic download on ARM64 with this build, since I did not build a desktop artifact;
    • Windows 10 on ARM, which cannot run x64 binaries.

Claude Opus 5.5, Claude Code harness

Cloudflare publishes no Windows ARM64 cloudflared, so win32-arm64 had no
managed release asset and T3 Connect reported the relay as unsupported.
Map win32-arm64 to the pinned x64 Windows asset, which Windows 11 on ARM
runs under emulation.

Fixes #14836
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 2, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 2, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 7bcde59

Macroscope's review found this PR approvable — This is a narrowly scoped fix that maps Windows ARM64 to the existing verified cloudflared Windows x64 asset while leaving all existing platform paths unchanged. Focused tests cover resolution and download selection, and the PR introduces no product-default or static-analysis changes.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 2, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 2, 2026 16:27

Dismissing prior approval to re-evaluate 7bcde59

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 4c9ca4d9-0a1d-4a8c-b1ff-3c872935d03e

📥 Commits

Reviewing files that changed from the base of the PR and between 54084ae and 7bcde59.

📒 Files selected for processing (2)
  • packages/shared/src/relayClient.test.ts
  • packages/shared/src/relayClient.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The relay client maps Windows ARM64 to the pinned Windows AMD64 release asset. A new test checks that installation requests this asset and rejects an empty response with invalid_checksum.

Changes

Windows ARM64 relay client support

Layer / File(s) Summary
Map and test the Windows AMD64 asset
packages/shared/src/relayClient.ts, packages/shared/src/relayClient.test.ts
The release asset map uses one pinned Windows AMD64 asset for both Windows x64 and ARM64. The ARM64 installation test checks the requested URL and verifies that an empty response fails checksum validation with invalid_checksum.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 7bcde

Windows 11 ARM64 users can now get the managed relay client through the existing verified download flow. Nothing found blocks merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7bcde

The change reuses the pinned Windows binary, checksum verification, and validation-before-activation flow. No concrete security regression was identified. Successful automatic installation and recovery on Windows ARM64 are not fully demonstrated.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated exposure expansion is managed binary installation and execution on Windows ARM64 within the configured local tool directory. The changed code does not introduce a privileged execution mechanism; downstream relay identity and service exposure are outside the hydrated scope.

Trust Boundaries and Controls

  • observed — Network-supplied bytes must match the pinned SHA-256 before reaching the managed executable path. Validation invokes the downloaded executable with a fixed version argument and shell execution disabled; the ARM64 mapping does not bypass these controls.

Resilience and Maintainability Implications

  • observed — The existing installer uses an in-process semaphore, an exclusive filesystem lock, a post-lock availability check, scoped temporary storage, and lock cleanup. Stale-lock recovery is age-based; these mechanisms do not establish cleanup after process death or prove all Windows rename races.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the primary change: enabling installation of the T3 Connect relay client on Windows ARM64. It uses a valid conventional commit format.
Description check ✅ Passed The description includes all required sections. It explains the problem, fix, scope, linked issue, focused verification, manual verification, and unverified cases. It also identifies the agent and har…
Linked Issues check ✅ Passed Issue [#14836] requires managed relay installation on Windows 11 ARM64. The PR maps win32-arm64 to the existing pinned windows-amd64 asset and preserves the download, checksum, version validation,…
Out of Scope Changes check ✅ Passed The changes are limited to the relay asset map and a focused test for the requested Windows ARM64 behavior. The test supports the issue objective. No unrelated product defaults or workflow changes are…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@juliusmarminge

Copy link
Copy Markdown
Member

Closing in favour of #17275, which reworks how T3 Connect picks and updates cloudflared and covers this fix as part of that. Thank you for the diagnosis and the patch, it shaped the approach there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: T3 Connect relay client cannot be installed on Windows ARM64 (no win32-arm64 cloudflared asset)

2 participants