Merge nucleic/vivid-glass-urchin-xoym into main
build / build (push) Successful in 2m30s

This commit is contained in:
2026-08-08 17:39:40 -07:00
parent de3fc45777
commit b682cfd0ba
8 changed files with 281 additions and 42 deletions
@@ -47,7 +47,7 @@ struct PermissionsCommand: AsyncParsableCommand {
Doctor.checkCodeSignature(),
]))
let status = LocalNetworkPolicy.status()
let status = LocalNetworkPermission.observedStatus()
if !status.sourcePaths.isEmpty {
print("")
for path in status.sourcePaths {
@@ -55,9 +55,19 @@ struct PermissionsCommand: AsyncParsableCommand {
}
}
if status.isIndeterminate {
print("")
print("The allowlist lives in root's preferences, which only root can read, so")
print("this cannot tell whether it is already set. For a definitive answer:")
print(" sudo gitea-macos-runner permissions status")
}
guard !status.coversGuestRange else { return }
print("")
print("to fix:")
// Not visible is not the same as not set, and an unconfigured host
// looks identical to a configured one from an ordinary login — so
// offer the commands without asserting anything is broken.
print(status.isIndeterminate ? "if it is not set, either of these sets it:" : "to fix:")
print(" gitea-macos-runner permissions grant # subnet allowlist, needs a reboot")
print(" gitea-macos-runner permissions grant --method prompt # system prompt, takes effect at once")
}
@@ -185,7 +195,29 @@ enum LocalNetworkGrantFlow {
// `defaults` reports success regardless of which preferences directory
// the write landed in, so report what was read back rather than what
// was asked for. See LocalNetworkPermission.grantViaAllowlist.
guard result.verified else {
if result.verified {
print("granted: \(result.observed.allowlist.joined(separator: ", "))")
for path in result.observed.sourcePaths {
print("written to: \(path)")
}
if !result.observed.coversGuestRange {
CLI.note("""
warning: none of these cover the whole guest range (192.168.64.0/18), \
so guests will still be blocked once the NAT subnet shifts
""")
}
} else if result.observed.isIndeterminate {
// The write succeeded but there is no way to look: the allowlist
// lands in root's preferences, and this host does not keep sudo
// credentials cached long enough for the read-back to use them.
// Unknown is not failure — say so plainly rather than either
// claiming success or crying wolf.
CLI.note("""
wrote \(subnets.joined(separator: ", ")), but could not read it back to \
confirm — that needs administrator rights this process no longer holds. \
Check it with: sudo defaults read \(LocalNetworkPolicy.domain)
""")
} else {
CLI.error("""
the write reported success but the values could not be read back. \
Check by hand: sudo defaults read \(LocalNetworkPolicy.domain)
@@ -193,17 +225,6 @@ enum LocalNetworkGrantFlow {
throw ExitCode(1)
}
print("granted: \(result.observed.allowlist.joined(separator: ", "))")
for path in result.observed.sourcePaths {
print("written to: \(path)")
}
if !result.observed.coversGuestRange {
CLI.note("""
warning: none of these cover the whole guest range (192.168.64.0/18), \
so guests will still be blocked once the NAT subnet shifts
""")
}
print("")
print("This is read at boot, so it does nothing until the host reboots.")