Skip to content

kari v0.16.1

Latest

Choose a tag to compare

@github-actions github-actions released this 26 Sep 09:41
· 1 commit to main since this release
v0.16.1
b042b26

kari v0.16.1 — built from b042b26.

macOS no longer names kari in the dialog about access to the data of other
apps, when the request comes from a Claude session that kari did not ask for.

TL;DR

  • Stop macOS from blaming kari for what Claude sessions read (#55)

What changed

Stop macOS from blaming kari for what Claude sessions read (#55)

macOS asked whether "kari.app would like to access data from other apps",
also when kari was closed and the user only opened claude agents in a
terminal. The cause was the responsible process. macOS charges a privacy
request to the responsible process of the requester, and a child inherits it
from its parent. When a claude --bg call from kari started the Claude
daemon, kari became responsible for that daemon, and for every session that
the daemon started after that. Those sessions start the MCP servers of the
user. When one of them reads the data of another app, the dialog named kari.
The setting that turns off MCP servers in card runs did not help, because it
does not reach the sessions that the daemon starts in advance.

kari now starts every claude process with the responsibility disclaimed:
claude --bg, claude stop, claude agents and the summary call. The child
is then responsible for itself, the same as a daemon that a terminal starts,
and a dialog names claude and not kari. The call has no effect on Linux
and Windows.

Rust cannot give posix_spawn attributes to Command, so kari does not
replace Command. A pre_exec hook in the forked child calls posix_spawnp
with POSIX_SPAWN_SETEXEC and the disclaim flag, which turns the spawn into
an exec of that child. Pipes, the working directory, timeouts and kill
work as before. The flag comes from a private libSystem call that Chromium
and LLDB also use. kari looks it up at run time, so a macOS without it
starts the child as before.

Install

Download the .dmg for your Mac: aarch64 for Apple silicon, x64 for Intel.
The app is not signed. After you copy it to Applications, run:

xattr -dr com.apple.quarantine /Applications/kari.app

On Windows, run kari_0.16.1_x64-setup.exe. It installs for the current user,
because kari reads the Claude Code state of whoever is logged in. That installer is
not signed either, so SmartScreen asks once: More info, then Run anyway.

An installed kari updates itself to this release: it checks on start and every six hours,
writes the new version beside the running one and offers a restart. Settings, Updates has the switch.

Every host runs the headless node, so that its sessions stay on the board while no window is open.
A Mac takes kari-node-v0.16.1-aarch64-apple-darwin (or the x86_64 one),
a Linux host kari-node-v0.16.1-x86_64-unknown-linux-gnu.tar.gz,
a Windows host kari-node-v0.16.1-x86_64-pc-windows-msvc.zip.
Run kari-node service install to keep it running at login. One engine runs on a host at a time:
open the app and the node steps down, quit the app and it takes the host back.
A node updates itself only when asked: kari-node update, or serve --auto-update.

An Android phone installs kari-latest.apk. Add this repository to Obtainium: the asset name never
carries the version and the signing key never changes, so an update installs over the previous build.
The phone reaches the nodes over a private network, such as a VPN, and pairs with the code from
Settings, Nodes on the desktop. See TOUR.md.

See the README for requirements and setup.