A build Cordial was pointed at is now verified
Cordial has always verified an engine build it downloaded itself. It did not check one it was merely pointed at — throughCORDIAL_APK, the APK you choose
in Settings, an engine directory beside it, or Sober’s package directory. Those
went into the same store the Version page lists, sitting beside builds that had
been checked, with nothing to tell them apart.
They are checked now, once, against Roblox’s signing certificate. The
fingerprint is recorded next to the extracted engine, so later launches read it
back rather than digesting a hundred-megabyte archive again. A refusal says
which kind of failure it was, because a tampered archive and an intact one that
simply is not Roblox’s are different problems.
What changes for you: if you point Cordial at an APK that did not come from
Roblox, it now refuses rather than running it. cordial-run --apk is
deliberately unchanged — naming a file on your own command line is the
documented loader switch, and it stays one.
Reported by @kanqz.
The package repositories follow releases again
If you installed from the apt, dnf or pacman repositories, you have been receiving every commit to main. The publishers fired on any successful build, and that workflow runs on every push, soapt upgrade could hand you an
unreleased tree that no notes had been written for.
They now publish only from a tag. This release is the first one to go out that
way.
The Flatpak remote is unchanged and still follows main. Moving it needs a
settings change on the Pages environment rather than a change to the workflow,
so it is not in this release.
Every binary says what it is and under what licence
cordial --help, cordial-run’s usage text and the diagnostics block now carry
the version, the licence and the project URL, so a stray binary can be
identified with strings alone. Nothing reads it back and removing it breaks
nothing — Cordial does not ship integrity marks, and anything that behaved
differently when the string was missing would be one.
What is still broken
Nothing in this release fixes a crash. It is a packaging and verification release, and the faults people are hitting are still here:- The second launch fails for some people, with
Can't initialize the TaskScheduler before flags have been loaded. Clearing the cache buys exactly one more working run. This is the most-reported problem in the tracker and is being worked on now — #44, #28. - Fullscreen freezes the client, and leaving fullscreen crashes it — #39.
- No window appears on COSMIC, KWin or wlroots compositors — #38. Mutter and X11 are unaffected.
- A touchscreen crashes the client on the first touch — #36.
- On X11 the camera can spin a full 180 degrees, and inputs can stick for a few seconds — #41.
- Join in a game’s Servers list does nothing — #40. Play on the home page and the game page still work.