Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -23,6 +23,7 @@ final class AppDelegate: NSObject, NSApplicationDelegate {
|
||||
exit(0)
|
||||
}
|
||||
BroVLaunchAgent.ensure()
|
||||
Self.pruneInbox()
|
||||
setupMenuBarItem()
|
||||
CodexUsageMonitor.shared.start()
|
||||
AgentWatch.shared.start()
|
||||
@@ -33,6 +34,24 @@ final class AppDelegate: NSObject, NSApplicationDelegate {
|
||||
#endif
|
||||
}
|
||||
|
||||
func applicationShouldHandleReopen(_ sender: NSApplication, hasVisibleWindows flag: Bool) -> Bool {
|
||||
openIsland()
|
||||
return true
|
||||
}
|
||||
|
||||
/// Copies of dropped files (HookServer.supportDir/inbox) are kept 7 days, then removed.
|
||||
private static func pruneInbox() {
|
||||
let inbox = HookServer.supportDir.appendingPathComponent("inbox")
|
||||
let fm = FileManager.default
|
||||
guard let files = try? fm.contentsOfDirectory(at: inbox, includingPropertiesForKeys: [.contentModificationDateKey]) else { return }
|
||||
let cutoff = Date().addingTimeInterval(-7 * 86400)
|
||||
for f in files {
|
||||
let d = (try? f.resourceValues(forKeys: [.contentModificationDateKey]))?.contentModificationDate ?? .distantFuture
|
||||
if d < cutoff { try? fm.removeItem(at: f) }
|
||||
}
|
||||
try? fm.setAttributes([.posixPermissions: 0o700], ofItemAtPath: inbox.path)
|
||||
}
|
||||
|
||||
// MARK: - Menu bar
|
||||
|
||||
private func setupMenuBarItem() {
|
||||
@@ -56,6 +75,7 @@ final class AppDelegate: NSObject, NSApplicationDelegate {
|
||||
// MARK: - Actions
|
||||
|
||||
@objc private func openIsland() {
|
||||
islandController?.fsm.openedExternally()
|
||||
islandController?.expand(to: .overview)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user