Relmio installer reliability
SkillWeb & browsingDiagnose, fix, and release-test Relmio installer or browser-wizard failures, especially Windows CMD, PowerShell, portable Node/npm, browser handoff, and ChatGPT OAuth regressions. Use when an installer screenshot, failed bootstrap, expired sign-in, Windows-only report, or installer CI gap needs an evidence-first fix.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Relmio installer reliability skill
What this skill tells your AI
The instructions your AI receives, as published by demonbane18/relmio in .agents/skills/installer-reliability/SKILL.md and read by ahel’s review.
Treat installer failures as release blockers. Preserve user work and secrets while reproducing the exact runtime path.
Establish a safe baseline
- Read the repository
AGENTS.mdand current release metadata. - Record
git status, branch,HEAD, and upstream divergence before fetching. - Fetch
origin/main. Never overwrite a dirty checkout. Use an isolated branch or checkout when upstream changes overlap local work. - Inspect screenshots and reports for the first failing boundary: bootstrap, Node/npm selection, ACL protection, browser launch, OAuth callback, credential promotion, or UI polling.
- Run the narrow existing tests before editing. A green baseline is evidence of a coverage gap, not proof that the report is invalid.
Reproduce Windows behavior faithfully
- Start from a clean-user fixture with no
.relmiodirectory and no local n8n Docker stack. Missing prerequisites must be reported inside the browser wizard, not terminate the CLI before the browser opens. - Verify bare
relmio, bare NPX, and repositorynpm startlaunches use the foreground wizard without initializing persistent local state. Exercisestart,status,open, andstopseparately when testing the opt-in persistent dashboard. - Exercise both
install.cmdandinstall.ps1with installed Node 24 and the checksum-verified portable fallback. - Keep
RELMIO_FOREGROUND_WIZARD=1scoped to the child invocation and verify restoration afterward. - Invoke npm on Windows through the current Node runtime or
npx.cmd; never rely on shell execution of a POSIX shim. - Test with inherited or extra profile ACL entries. Foreground browser handoff must use a fresh, owner-only temporary root and must not require the persistent
.relmioroot to be healthy. - Treat a successful Windows
explorer.exespawn as the browser-dispatch boundary. Its later exit status does not prove the browser failed and must not trigger deletion of the handoff file; keep direct-launcher nonzero-exit checks for macOS and Linux. - Verify false and thrown default-browser launches produce an actionable, secret-free error and close the server plus temporary handoff root.
- Run real Windows ACL read-back tests on native Windows, not only mocked platform branches.
Fix sign-in without exposing credentials
- Check the current official OpenAI Codex authentication and CLI documentation before changing the login contract.
- Prefer a pinned official Codex CLI browser login over parsing undocumented third-party authorization output.
- Give each attempt an isolated protected
CODEX_HOMEand force file credential storage. - Capture helper output only with a strict byte bound. Never return it to the browser or logs.
- Validate the credential file, protect it before reading or copying, stage it, and atomically promote it only after the official helper exits successfully.
- Preserve the previous credential on cancellation or failure. Bound process-tree termination and block retries when termination or final commit cannot be confirmed.
- Return only a random attempt identifier and a fixed launch mode to browser JavaScript. Poll server-owned status and reject stale attempts.
Work test-first
For each root cause:
- Add one focused regression that fails for the observed reason.
- Make the smallest production change that passes it.
- Run the focused module tests.
- Run neighboring server, UI, installer, ACL, and cancellation tests.
- Keep security invariants explicit: loopback only, no capability or OAuth URL in logs, no credential contents in responses, and exact cleanup only.
Harden CI and release evidence
Windows CI must cover:
- the complete repository check under the pinned npm version;
- Windows PowerShell 5.1 parsing;
- native PowerShell and CMD bootstrap tests;
- installed and portable Node/npm handoffs;
- browser launcher failure handling;
- real owner-only handoff ACL verification;
- the pinned official Codex Windows login binary;
- OAuth credential promotion and sanitized errors;
npm audit --audit-level=highandnpm pack --dry-run.
Before handoff, run npm run check, the focused native Windows tests, npm audit --audit-level=high, npm pack --dry-run, and git diff --check. Report exact pass/skip counts, any environment-limited checks, the upstream commit used, and whether the user's original checkout was left untouched.
Do not deploy, publish, alter the existing n8n Compose/container, expose port 10531, or perform remote writes without the required human confirmation.
Signals
- GitHub stars
- 56
- Forks
- 6
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
installer-reliability- Source
- github.com/demonbane18/relmio