Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -108,7 +108,9 @@ final class ClaudeCodeCLI {
|
||||
"--append-system-prompt", Self.notchPrompt]
|
||||
if let sessionID { args += ["--resume", sessionID] }
|
||||
if !model.isEmpty { args += ["--model", model] }
|
||||
if !permissionMode.isEmpty, permissionMode != "default" { args += ["--permission-mode", permissionMode] }
|
||||
// Never bypass: the chat gets untrusted input (dropped files, window titles, URLs).
|
||||
let allowedModes: Set<String> = ["acceptEdits", "plan"]
|
||||
if allowedModes.contains(permissionMode) { args += ["--permission-mode", permissionMode] }
|
||||
|
||||
let p = Process()
|
||||
p.executableURL = URL(fileURLWithPath: binary)
|
||||
|
||||
Reference in New Issue
Block a user