Skip to content

Runner health: Full Disk Access check reports "Not allowed" when ~/Library/.../com.apple.TCC/TCC.db doesn't exist - #93

Merged
danielehrhardt merged 1 commit into
mainfrom
godmode/16-runner-health-full-disk-access-check-rep
Oct 6, 2026
Merged

danielehrhardt merged 1 commit into
mainfrom
godmode/16-runner-health-full-disk-access-check-rep

Conversation

@danielehrhardt

Copy link
Copy Markdown
Contributor

The Full Disk Access check no longer says "Not allowed" on Macs that don't have the per-user privacy database (TCC.db). Unit tests (80) and typecheck pass. I did not run it on the "MacBook Pro von m" runner, where the bug showed up. The fix only takes effect there once this is merged and the runner is updated.

Runner health: Full Disk Access check no longer warns when the privacy database is missing

Problem: On some Macs, ~/Library/Application Support/com.apple.TCC/TCC.db doesn't exist. The runner health check only tried that one file and treated every error as a denial. A file-not-found therefore showed "Not allowed" even when Full Disk Access was granted and working. The permissions view had its own copy of the same check.

Changes

  • New shared check, packages/core/src/services/fullDiskAccess.ts. It tries several places that macOS only opens with Full Disk Access, in this order:
    1. the per-user TCC.db
    2. the system /Library/Application Support/com.apple.TCC/TCC.db
    3. ~/Library/Safari, ~/Library/Mail, ~/Library/Messages
  • Results:
    • If any of them opens, it reports allowed.
    • Only a permission error (EPERM/EACCES) on every one that exists counts as not allowed.
    • If none of them exist, the result is unknown instead of a warning.
  • packages/core/src/remote/health.ts uses the shared check. fullDiskAccess() now returns boolean | null. An unknown result shows "Couldn't check — none of the protected folders exist here". Before, it fell back to a message about the screen helper, which was wrong here.
  • packages/core/src/services/permissions.ts drops its private copy and uses the shared check too.

Tests (packages/core/test/remote-health.test.ts)

  • An unknown result from the check gives an unknown status, not warn.
  • No protected places exist: the result is null.
  • TCC.db is missing but a protected folder can be read: the result is allowed.
  • Every existing place refuses access: the result is not allowed. This one is skipped when running as root.
  • The order in which places are tried.

On this Mac the new check reports allowed. The branch has no conflicts with main.


Task #16 · done by Godmode with Godmode Bot

…en nothing protected exists

The runner check opened only the per-user TCC.db and called any error a denial, so a Mac without that file warned
"Not allowed" even with Full Disk Access granted. Both the runner health and the permissions view now use one probe
that tries the user and system TCC.db, then ~/Library/Safari, Mail and Messages.
@danielehrhardt
danielehrhardt merged commit 9ffae26 into main Oct 6, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant