Skip to content

fix(browserext): skip protected browser reads on macOS 27 - #226

Merged
ashishkurmi merged 2 commits into
step-security:mainfrom
raysubham:fix/tcc-protected-reads
Sep 23, 2026
Merged

ashishkurmi merged 2 commits into
step-security:mainfrom
raysubham:fix/tcc-protected-reads

Conversation

@raysubham

@raysubham raysubham commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Narrowed to browser-extension inventory only for v1.17.0. Other scanner work is preserved in draft PR #227 for team discussion.

Change

  • Preserve known browser-profile exemptions on macOS versions before 27.
  • On macOS 27 and unknown versions, honor the existing protected-directory policy before browser reads. Protected scanning stays off by default; explicit inclusion retains its existing meaning and does not grant OS access.
  • Pass the already collected OS version to browser detection in community and enterprise entry points.
  • Use existing refused_tcc and incomplete browser results; no Agent API or shared filesystem-reader changes.
  • Keep the changelog entry under 1.17.0.

Validation

  • Full race tests, go vet, formatting/module-drift checks, golangci-lint passed.
  • Darwin/arm64, Linux/amd64 and Windows/amd64 builds passed.
  • Gosec findings match the parent baseline.
  • macOS 26.5.1 VM: 45/45 CLI smoke checks; focused launchd browser check collected 16 extensions across Chrome, Edge and Firefox, complete=true.
  • macOS 27 host: focused launchd browser check returned refused_tcc for all three browsers, zero findings, complete=false. Temporary job removed.
  • The three review fixtures for relative paths, refused Python discovery and unrelated npm coverage now all pass with this narrowed change.
  • Developer MDM V1 run 35888879970 targets this exact commit using the updated integration harness; results pending.

Limits

This addresses the reproduced browser access notification. Other scanner permission gaps remain for the separate draft and are not covered by this fix. Protected browser inventory on macOS 27 is intentionally skipped. No permissions, customer policies, managed installation files or backend contracts are changed.

One signed commit. Do not merge without owner approval.

@raysubham
raysubham force-pushed the fix/tcc-protected-reads branch 2 times, most recently from 94b06e1 to debdf50 Compare September 23, 2026 16:25
@raysubham raysubham changed the title fix(tcc): guard protected scanner reads on macOS fix(browserext): skip protected browser reads on macOS 27 Sep 23, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Two unresolved moderate findings require changes and final human review.

Review effort: Lite
Findings: None

What changed in this PR

Updates browser-extension inventory to honor macOS 27 TCC protections while preserving pre-27 behavior.

Changes:

  • Passes OS versions into browser detection.
  • Adds version-aware TCC tests and live Darwin validation.
  • Documents the fix in the 1.17.0 changelog.
File Summary
internal/​telemetry/​telemetry.go Passes OS version to enterprise scanning.
internal/​scan/​scanner.go Passes OS version to community scanning.
internal/​detector/​browserext/​tcc_compat_test.go Tests version-dependent TCC behavior.
internal/​detector/​browserext/​live_darwin_test.go Adds live Darwin validation; moderate finding, 1 vote, regarding unbounded external command execution.
internal/​detector/​browserext/​detector.go Applies OS-version-aware protected-path handling; moderate finding, 1 vote, regarding malformed version validation.
internal/​detector/​browserext/​detector_test.go Updates macOS compatibility coverage.
CHANGELOG.md Records the macOS 27 fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ashishkurmi
ashishkurmi merged commit 0a985e6 into step-security:main Sep 23, 2026
12 checks passed
ashishkurmi pushed a commit that referenced this pull request Sep 24, 2026
#224 replaced the local delta switch with tenant authorization but left the
changelog claiming the protocol is "on by default" with use_legacy_package_scan
defaulting to false. Both halves are now wrong: the flag and the scan-state env
overrides are gone, and a run only sends deltas when the run-config check-in
returns package_scan.delta_enabled — missing, null and false all select legacy
full-snapshot reporting.

#225 also filed its two upload fixes under a fresh [Unreleased] while #218 and
#226 filed inside [1.17.0]. Nothing is tagged yet, so all of it ships in 1.17.0;
fold them in and drop the empty section.

Date moves to the 24th, the day the checks finished green.

Signed-off-by: Swarit Pandey <swarit@stepsecurity.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants