OpenCapX 0.4.0
macOS 用户请先看这里 / macOS users read this first
macOS 构建未做代码签名与公证(购买 Apple Developer 会员已推迟到有商业需求时),首次打开会弹出「Apple 无法验证"OpenCapX"是否包含恶意软件」。这是预期行为,不是木马。 新版 macOS 上"右键 → 打开"已无法绕过;把应用拷入「应用程序」后,任选其一:
- 终端执行:
/usr/bin/xattr -cr /Applications/OpenCapX.app(用全路径,部分环境的PATH里xattr缺-r) - 系统设置 → 隐私与安全性 → 页面底部 → 仍要打开
The macOS build is not code-signed or notarized, so Gatekeeper shows "Apple cannot check 'OpenCapX' for malicious software" on first launch. This is expected, not malware. The right-click → Open bypass no longer works on recent macOS; after copying the app to /Applications, run /usr/bin/xattr -cr /Applications/OpenCapX.app, or System Settings → Privacy & Security → Open Anyway. See INSTALL.md.
What's new
- Windows sandbox — AppContainer.
opencapx sandboxgains a third OS backend: the kernel isolation primitive Edge/Chrome use — a lowbox token with no user SID, granted per-run through ACLs and revoked when the run ends. No admin rights, no virtualization.--checkreportsbackend: appcontainer;--requirefinally has a real backend to require on Windows. Network fenced by the capability list (no capabilities = no sockets); timeouts kill a Job Object. Windows previously ran everything unguarded with a warning. - OS-permission preflight on every platform. The probes that tell you whether screen / camera / microphone built-ins can actually work now run on Windows and Linux too, with a new
unavailablestatus ("this machine cannot do this at all" vs "grant something first"), Linux session classification (X11 / Wayland / headless), and RDP monitor enumeration on Windows.
Full changelog: CHANGELOG.md
🤖 Generated with Claude Code