Merge nucleic/vivid-glass-urchin-xoym into main
build / build (push) Successful in 2m30s

This commit is contained in:
2026-08-08 17:39:40 -07:00
parent de3fc45777
commit b682cfd0ba
8 changed files with 281 additions and 42 deletions
+19 -3
View File
@@ -771,7 +771,7 @@ public enum Doctor {
/// does not apply (Apple, TN3179).
public static func localNetworkNote() -> DoctorCheck {
let name = "local network access"
let status = LocalNetworkPolicy.status()
let status = LocalNetworkPermission.observedStatus()
if status.isConfigured {
if status.coversGuestRange {
@@ -796,10 +796,26 @@ public enum Doctor {
)
}
// Nothing found. On all but an unusual host that means *not visible*
// rather than *not set*: the allowlist is written as root and lands in
// /var/root, which is mode 700. Say which of the two this is, because
// "no allowlist" would otherwise be asserted on a host that has one.
let caveat =
status.isIndeterminate
? """
This cannot see the setting itself — it lives in \
\(status.unreadablePaths[0]), which only root can read — so treat the above as \
"not visible", not "not set". `sudo gitea-macos-runner permissions status` \
answers definitively, and `permissions grant` verifies its own write.
"""
: ""
return DoctorCheck(
name: name,
result: .info,
detail: "guests are reached over the host-private NAT link",
detail: status.isIndeterminate
? "no allowlist visible; guests are reached over the host-private NAT link"
: "guests are reached over the host-private NAT link",
remediation: """
on macOS 15+ the first connection to a guest can be blocked by the Local Network \
privacy prompt, and frequently there is nothing able to answer it. A LaunchAgent \
@@ -810,7 +826,7 @@ public enum Doctor {
`gitea-macos-runner permissions grant`, which writes a subnet allowlist that \
needs no prompt, covers every process, and survives rebuilds — then reboot. \
`permissions status` explains both routes. See docs/setup.md §2.6.
"""
""" + caveat
)
}