Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
#!/bin/sh
|
||||
# Removes the BroV network core services (sudo sh scripts/netcore/uninstall.sh).
|
||||
# Keys stay in /Library/Application Support/BroV/netcore unless you pass --purge.
|
||||
# After this the Mac goes online by itself; turn AmneziaVPN back on if needed.
|
||||
set -e
|
||||
[ "$(id -u)" -eq 0 ] || { echo "Запусти через sudo: sudo sh $0"; exit 1; }
|
||||
for label in local.maksar.brov.netctl local.maksar.brov.netd; do
|
||||
launchctl bootout "system/$label" 2>/dev/null || true
|
||||
rm -f "/Library/LaunchDaemons/$label.plist"
|
||||
done
|
||||
rm -f /var/run/brov-netctl.sock
|
||||
if [ "$1" = "--purge" ]; then
|
||||
rm -rf "/Library/Application Support/BroV" /Library/Logs/BroV
|
||||
echo "✓ Службы, ядро и ключи удалены."
|
||||
else
|
||||
echo "✓ Службы ядра BroV остановлены и удалены. Ключи остались в /Library/Application Support/BroV/netcore (root)."
|
||||
fi
|
||||
Reference in New Issue
Block a user