Repository navigation
NetPilot 1.2.3 - Linux and macOS (release candidate)
Pre-releaseLinux and macOS
Built from the same tree as v1.2.3, which carries the command-injection fixes. Both artefacts
are headless-capable; the daemon runs without a display and the GUI needs one.
What is here
netpilot-daemon-*- the daemon for linux-x64, linux-arm64, osx-x64 and osx-arm64. This is
the headless build and the one with CI coverage on realubuntu-24.04andmacos-14
runners.netpilot-gui-*- the Avalonia GUI for linux-x64 and linux-arm64.
Please read this before reporting a problem
The GUI has never been rendered. No emulator or device was available on the machine that built
it, so it compiles, links and packages, and has not been seen on screen. That is why these are a
candidate rather than the main release. Everything testable is tested - the shared core, the
daemon's validation and argument handling, and the platform-independent screens - but the native
windowing layer is unverified. A first run may need a display server or a working session bus;
if it does not start, that is the untested part and it is worth saying so in an issue rather than
assuming a bug in the feature itself.
The daemon is a different matter: its blocking was measured with setpriv against a local
listener on real hardware, so the firewall and throttling paths are known to work.
What changed for these platforms
- Command injection, same as the main release. A resolver address or a proxy host arrived from
the HTTP API, which needs no authentication, and was interpolated into a command line the target
program then re-split. Every value is now validated as the kind of thing it must be, and passed
as one argument per element. - Linux DNS via
resolvectl, macOS vianetworksetup. Two of the macOS calls were also plain
broken: one built a single string holding fivegsettingscommands for one invocation, which
could only ever have failed; another passed the literal text{service}because it used an
ordinary string where an interpolated one was meant. - Every machine-rooted path removed, including the ones inside the release scripts, which is what
let the installer job fail on CI.
Checksums for all five files are in the main release's SHA256SUMS.txt; the values match the
ones computed here.