This commit is contained in:
@@ -108,10 +108,14 @@ prompt**: a LaunchAgent that was never granted permission (or was denied) cannot
|
||||
2. No entry at all: check and fix the permission.
|
||||
|
||||
```sh
|
||||
gitea-macos-runner permissions status
|
||||
gitea-macos-runner permissions grant # then reboot when it offers
|
||||
sudo gitea-macos-runner permissions status # sudo: the allowlist lives in root's preferences
|
||||
gitea-macos-runner permissions grant # then reboot when it offers
|
||||
```
|
||||
|
||||
Without `sudo`, `status` reports `no allowlist visible` on every host — it is written as root into
|
||||
`/var/root/Library/Preferences/`, which an ordinary login cannot read. That is not evidence the
|
||||
grant is missing. `grant` itself does not have the problem: it verifies its own write.
|
||||
|
||||
`grant` pre-authorizes the VM subnets and offers to reboot, which is required — the allowlist is
|
||||
read at boot. It grants all of RFC 1918 by default; `--subnet` narrows it, but nothing narrower
|
||||
than `192.168.64.0/18` is safe, because the NAT subnet is chosen at runtime and slides to the next
|
||||
|
||||
Reference in New Issue
Block a user