Documentation Start Updated

Updates

How each program finds a new release of itself, how it decides to trust it, and what it does when you agree to install it.

What happens

Twenty seconds after it starts, and every six hours after that, each program reads its own update channel on this site: Quikap reads the Quikap channel, QuikapStudio the QuikapStudio channel. You can ask at any time with Help › Check for Updates.

When a newer release exists, the program says so. Nothing is downloaded and nothing is installed until you choose to. You can also skip a version: the program will not mention it again, and will tell you about the next one.

The two programs are updated independently. A new QuikapStudio does not require a new Quikap, and the other way round; the versions of the contracts they share are negotiated when they connect.

How a release is trusted

A program uses a release only when all of these hold:

  1. The manifest's signature is valid, and was made with a key that is compiled into the program you are running.
  2. The manifest is well formed, and is for this program, for your channel and for your platform. A manifest for the other program of the family, however genuine, is not applicable.
  3. Its version is strictly newer than yours. An old release, however genuine, is never offered, so nobody can take you backwards to a version with a known fault.
  4. A pre-release is offered only to an installation that follows the preview channel.

Then, when you choose to update:

  1. The installer is downloaded, and checked against the size and the SHA-256 in the signed manifest. A file that does not match is deleted.
  2. The file is held open against changes from that check until the installer has started.

Where the files came from is no part of this. The channel is read over HTTPS, and this site requires an entitlement to read it, but the release would be refused just the same if a genuine server handed out a forged file. The signature is what is trusted.

Installing

Install closes the program, runs the installer without questions, and starts the new version. No administrator rights are needed.

Channels

Channel What it carries
stable Releases. This is what every installation follows unless you change it.
preview Releases and pre-releases, whichever is newest. Less tested. Your license must include it.

To follow the preview channel, choose Help › Check for Updates and tick Include pre-releases. The choice is made per program.

If updates do not arrive

What the program says What it means
Updates come to installations that are activated… Activate it: Help › License. See Licenses and seats.
This installation's entitlement does not include that channel of releases Your license does not include the preview channel. Untick Include pre-releases.
Could not reach quikap.exprezoe.com: … The computer cannot reach this site. The program will try again later.
The update information from quikap.exprezoe.com was ignored: … The manifest's signature was not valid. Nothing was installed. Please tell us.
The download does not match the release's SHA-256; it was discarded. (or: ended early, is larger than the release's installer) The installer was not the one the release names. The file was deleted. Try again, and tell us if it repeats.

You can always install a release by hand: download it from the downloads page, verify it, and run it over the version you have. Your captures, documents and settings are kept.

For administrators

An installation can be pointed at a mirror of its channel with the QUIKAP_UPDATE_FEED environment variable. It must be an HTTPS address. A mirror changes where releases are read from, never whose releases are accepted: the signature is checked just the same.