Flip 1.5.1
Flip could refuse to launch at all, and then refuse to stay gone. It reads a
private accessibility symbol to put a window server id on a window — the only
reliable way to line the two lists up. That symbol was linked strongly, so on a
system that does not export it the process was killed by the dynamic linker
before any Flip code ran: no log, no menu bar, nothing to read but a system
dialog. The check inside the app that was supposed to catch this could never fire,
because there was no app yet.
It is weakly imported now. Where the symbol is missing Flip starts, says so in
the menu bar and in Copy Diagnostics, and does the rest of its job.
And the login item no longer resurrects a broken copy. The launch agent asked
launchd to restart Flip after any unsuccessful exit, which turns "cannot start"
into a loop: a new process every few seconds, and quitting or force-quitting it
brings it straight back. Measured on a deliberately failing job — three starts in
twenty-five seconds with that setting, one without. It is gone. Starting at login
still works; a crash now leaves Flip closed until you open it.
Installing
brew install --cask mxwnk/tap/flipOr take the disk image below. Flip is signed with its own certificate
rather than notarised, so a copy installed by hand has to be allowed once
under System Settings › Privacy & Security. Homebrew does that for you.
Accessibility is asked for on first run, Screen Recording only if you
want thumbnails. Both survive updates: the signature is pinned to the same
certificate every release, and the pipeline refuses to publish one where
it has drifted.