Merge nucleic/vivid-glass-urchin-xoym into main
This commit is contained in:
@@ -351,12 +351,16 @@ enum SSHTransportError: Error {
|
||||
/// that errno is more often the privacy filter than a routing failure —
|
||||
/// worth naming rather than leaving the operator to guess.
|
||||
///
|
||||
/// It matters most right after a rebuild. Per
|
||||
/// On an **ad-hoc signed** build it matters most right after a rebuild. Per
|
||||
/// [TN3179](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy)
|
||||
/// the grant "uses your main executable UUID", and the linker mints a fresh
|
||||
/// `LC_UUID` on essentially every build — so `make install` can present a
|
||||
/// program macOS has never seen, whose permission is undetermined again,
|
||||
/// even though the previous binary worked minutes earlier.
|
||||
/// the grant "uses your main executable UUID" when there is no stable
|
||||
/// designated requirement to key on, and the linker mints a fresh `LC_UUID`
|
||||
/// on essentially every build — so `make install` can present a program
|
||||
/// macOS has never seen, whose permission is undetermined again, even
|
||||
/// though the previous binary worked minutes earlier. A Developer ID
|
||||
/// signature is anchored to the team instead and does not have this
|
||||
/// problem; the hint is unconditional because this layer cannot see which
|
||||
/// kind of signature it is running under.
|
||||
static func localNetworkHint(for underlying: any Error) -> String {
|
||||
let text = "\(underlying)".lowercased()
|
||||
guard text.contains("errno: 65") || text.contains("no route to host")
|
||||
@@ -365,11 +369,8 @@ enum SSHTransportError: Error {
|
||||
|
||||
return """
|
||||
(on macOS 15+ this is also what Local Network privacy returns when \
|
||||
it blocks an app — and the grant is keyed on the executable's UUID, \
|
||||
so every rebuild withdraws it. Pre-authorize the guest subnet \
|
||||
instead: sudo defaults write com.apple.network.local-network \
|
||||
AllowedEthernetLocalNetworkAddresses -array "192.168.64.0/18" — same \
|
||||
for AllowedWiFiLocalNetworkAddresses — then reboot. \
|
||||
it blocks an app. Check and fix it with `gitea-macos-runner \
|
||||
permissions status` / `permissions grant`. \
|
||||
See docs/troubleshooting.md)
|
||||
"""
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user