Skip to content

DefenseClawMac 1.1.23

Choose a tag to compare

@keitheobrien keitheobrien released this 22 Sep 15:03
a324c1b

DefenseClawMac 1.1.23 adds native macOS administrator authorization for gateway Start, Stop, and Restart, and preserves the runtime already installed on your Mac. It also fixes the authorization handoff that previously reported an immediate denial after preauthorization.

Changes

  • Enable Run gateway as administrator in Overview or Settings → Connection. macOS approves the signed background helper and requests administrator authorization for each operation. Passwords are handled by macOS.
  • Administrator operations use a validated, private copy of your existing installed gateway, isolated to your macOS account. The app does not replace it with the runtime bundled for fresh installations. Use Restart Gateway as Administrator after updating the runtime.
  • The app checks the latest published DefenseClaw release and prompts when the installed runtime is older. Equal or newer runtimes remain in place. Source-managed, custom, partial, and unknown installations remain protected from replacement; eligible release installations use the authenticated runtime updater.
  • Runtime version detection ignores Go/Sonic warnings and refreshes release availability on launch. The command catalog now tracks 235 upstream entries, with Kiro setup shown only when supported by the selected runtime.

See the administrator setup guide for background-service approval and Full Disk Access. Full Disk Access is separate from administrator authorization.

Downloads and compatibility

  • DefenseClawMac-1.1.23.zip — app only, including the signed administrator helper; suitable for the app updater and Macs with an existing runtime.
  • DefenseClawMac-1.1.23.dmg — unified app with the authenticated, published DefenseClaw 0.8.10 payload for fresh Apple Silicon runtime installations.

The published 0.8.10 payload predates the new Runtime monitoring planes and support for an administrator gateway using operator-owned configuration. Those features require a compatible newer/source runtime. The app preserves existing runtimes, including source builds that carry the same version number. Fresh-install packaging rejects unsupported ACP-bearing payloads; runtime updates remain managed independently.

The Runtime panel displays risk findings above the reporting floor, not all observed processes or activity. Zero findings is possible while sensors are running. Read-only investigation of the installed source runtime also found missing HOME-default file-watch coverage and a static DNS-capture label when DNS capture was disabled. These runtime issues are documented in the verification report; this Mac app release does not modify the installed runtime to conceal them.

Verification

Built from merged mainline commit a324c1be664fd00d8c06000b6c0d765a625688cf, incorporating PR #23 and PR #24.

All 35 standalone test suites passed, including 110 administrator-helper security checks. Debug compilation and a clean signed Release archive passed, with script sandboxing enabled. A native-authorized restart was verified live: the gateway ran from the account-specific private copy, all three selected Runtime planes started, and the installed gateway digest was unchanged. Native cancellation has regression coverage but was not separately exercised in the live release check.

Compatibility was reviewed against upstream mainline f05a9d3cb115c18f2c7903590a82dadf8835f2ae, runtime 0.8.10, and schema 8. The full audit retains one failure because the intentionally preserved installed source runtime differs from current mainline in 76 contract files. Source parity is not claimed. The fresh-install payload has separately authenticated published source provenance bf45995c7fa691f34ffa89b6f0468c93a6207dea.

Both downloads are Developer ID signed and Apple-notarized. The app bundles and disk image are stapled. Local checks passed for Gatekeeper, strict app/helper signatures, updater ZIP extraction, and the unified runtime payload and its manifest digests. After publication, an independent verification freshly downloaded both GitHub assets and confirmed byte-for-byte SHA-256 matches. Both downloads passed signature, notarization/stapling, Gatekeeper, helper-layout, and strict unified-payload checks. All six payload manifest digests matched, and the helper was identical in both distributions.

Apple notarization accepted the app-only build (f679f699-e33a-4d9c-b23c-c359e7309011), unified app (8e5546fa-0443-4593-bb5d-e789d346b2ed), and disk image (237fdb2d-d7b4-4049-96d3-0901a4657781).

SHA-256:

03551061abb23261f58bb495036ddf432d8c7a0a10f8b7d1d41bf17c50f08dac  DefenseClawMac-1.1.23.zip
c04498fba3f19485dda09f5553ae0557072f27d574fdc171e37e585931f6036b  DefenseClawMac-1.1.23.dmg