Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -14,7 +14,11 @@ configs:
|
||||
settings:
|
||||
base:
|
||||
SWIFT_VERSION: "6.0"
|
||||
ENABLE_HARDENED_RUNTIME: NO
|
||||
# Hardened runtime, no get-task-allow: other processes can't inject code into BroV
|
||||
# and borrow its Accessibility / Apple Events permissions.
|
||||
ENABLE_HARDENED_RUNTIME: YES
|
||||
CODE_SIGN_INJECT_BASE_ENTITLEMENTS: NO
|
||||
CODE_SIGN_ENTITLEMENTS: Resources/BroV.entitlements
|
||||
OTHER_SWIFT_FLAGS: "-strict-concurrency=complete"
|
||||
# Ad-hoc signature: runs locally, no Apple Developer account needed.
|
||||
CODE_SIGN_STYLE: Manual
|
||||
|
||||
Reference in New Issue
Block a user