This commit is contained in:
@@ -47,7 +47,7 @@ struct PermissionsCommand: AsyncParsableCommand {
|
||||
Doctor.checkCodeSignature(),
|
||||
]))
|
||||
|
||||
let status = LocalNetworkPolicy.status()
|
||||
let status = LocalNetworkPermission.observedStatus()
|
||||
if !status.sourcePaths.isEmpty {
|
||||
print("")
|
||||
for path in status.sourcePaths {
|
||||
@@ -55,9 +55,19 @@ struct PermissionsCommand: AsyncParsableCommand {
|
||||
}
|
||||
}
|
||||
|
||||
if status.isIndeterminate {
|
||||
print("")
|
||||
print("The allowlist lives in root's preferences, which only root can read, so")
|
||||
print("this cannot tell whether it is already set. For a definitive answer:")
|
||||
print(" sudo gitea-macos-runner permissions status")
|
||||
}
|
||||
|
||||
guard !status.coversGuestRange else { return }
|
||||
print("")
|
||||
print("to fix:")
|
||||
// Not visible is not the same as not set, and an unconfigured host
|
||||
// looks identical to a configured one from an ordinary login — so
|
||||
// offer the commands without asserting anything is broken.
|
||||
print(status.isIndeterminate ? "if it is not set, either of these sets it:" : "to fix:")
|
||||
print(" gitea-macos-runner permissions grant # subnet allowlist, needs a reboot")
|
||||
print(" gitea-macos-runner permissions grant --method prompt # system prompt, takes effect at once")
|
||||
}
|
||||
@@ -185,7 +195,29 @@ enum LocalNetworkGrantFlow {
|
||||
// `defaults` reports success regardless of which preferences directory
|
||||
// the write landed in, so report what was read back rather than what
|
||||
// was asked for. See LocalNetworkPermission.grantViaAllowlist.
|
||||
guard result.verified else {
|
||||
if result.verified {
|
||||
print("granted: \(result.observed.allowlist.joined(separator: ", "))")
|
||||
for path in result.observed.sourcePaths {
|
||||
print("written to: \(path)")
|
||||
}
|
||||
if !result.observed.coversGuestRange {
|
||||
CLI.note("""
|
||||
warning: none of these cover the whole guest range (192.168.64.0/18), \
|
||||
so guests will still be blocked once the NAT subnet shifts
|
||||
""")
|
||||
}
|
||||
} else if result.observed.isIndeterminate {
|
||||
// The write succeeded but there is no way to look: the allowlist
|
||||
// lands in root's preferences, and this host does not keep sudo
|
||||
// credentials cached long enough for the read-back to use them.
|
||||
// Unknown is not failure — say so plainly rather than either
|
||||
// claiming success or crying wolf.
|
||||
CLI.note("""
|
||||
wrote \(subnets.joined(separator: ", ")), but could not read it back to \
|
||||
confirm — that needs administrator rights this process no longer holds. \
|
||||
Check it with: sudo defaults read \(LocalNetworkPolicy.domain)
|
||||
""")
|
||||
} else {
|
||||
CLI.error("""
|
||||
the write reported success but the values could not be read back. \
|
||||
Check by hand: sudo defaults read \(LocalNetworkPolicy.domain)
|
||||
@@ -193,17 +225,6 @@ enum LocalNetworkGrantFlow {
|
||||
throw ExitCode(1)
|
||||
}
|
||||
|
||||
print("granted: \(result.observed.allowlist.joined(separator: ", "))")
|
||||
for path in result.observed.sourcePaths {
|
||||
print("written to: \(path)")
|
||||
}
|
||||
if !result.observed.coversGuestRange {
|
||||
CLI.note("""
|
||||
warning: none of these cover the whole guest range (192.168.64.0/18), \
|
||||
so guests will still be blocked once the NAT subnet shifts
|
||||
""")
|
||||
}
|
||||
|
||||
print("")
|
||||
print("This is read at boot, so it does nothing until the host reboots.")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user