Skip to content

feat: add macOS privileged proxy helper protocol - #60

Merged
kev1n77 merged 3 commits into
mainfrom
codex/macos-proxy-helper-protocol
Jul 18, 2026
Merged

kev1n77 merged 3 commits into
mainfrom
codex/macos-proxy-helper-protocol

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a versioned macOS privileged proxy helper control protocol
  • accept only explicit credential-free HTTP loopback endpoints
  • require a private owner directory, fixed journal name, matched helper artifacts, and root execution
  • expose a mode-0600 Unix socket and bind the only control connection to the requesting UID and PID
  • restore through an explicit command, owner disconnect, or the existing independent watchdog
  • add macOS integration coverage for PAC restoration on command and disconnect

Verification

  • cargo test -p codeischeap-proxy-recovery --all-targets -- --test-threads=1 (8 passed, 1 ignored real WinINet test)
  • cargo clippy -p codeischeap-proxy-recovery --all-targets -- -D warnings
  • cargo check -p codeischeap-proxy-recovery --all-targets --target aarch64-apple-darwin
  • cargo clippy -p codeischeap-proxy-recovery --all-targets --target aarch64-apple-darwin -- -D warnings
  • cargo fmt --all -- --check
  • git diff --check

Scope

This PR establishes the helper security and recovery core. Authorization launch and Tauri lifecycle wiring remain the next integration slice.

@kev1n77
kev1n77 merged commit 452700e into main Jul 18, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/macos-proxy-helper-protocol branch July 18, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant