-
Notifications
You must be signed in to change notification settings - Fork 3
XPC Trust Boundary
ventaphobia edited this page Apr 23, 2026
·
1 revision
The trust boundary is the helper process, not SwiftUI. The app can request fan writes, but the helper must validate the client and input before performing privileged operations.
The helper validates fan IDs, RPMs, SMC key shape, and client authorization. The app manager validates state and user intent, but it cannot be the only protection layer because any XPC caller reaching the Mach service would otherwise be dangerous.
Entitlements, SMPrivilegedExecutables, SMAuthorizedClients, bundle IDs, Team IDs, helper labels, and signing requirements must remain aligned. The tests around privileged helper requirement strings exist because this alignment has broken before.
- Home
- Start Here
- Product Overview
- Runtime Architecture
- Monitoring Pipeline
- Fan Control
- Privileged Helper
- Touch Bar
- Release Automation
- Security Model
- File Index (279)
- Every Commit (401)
- Chronological Change Log
- Removed Parts
- All Deleted Paths
- Branches And Tags
- Wiki Manifest
- Start Here
- Product Overview
- Source Map
- Runtime Architecture
- App Startup And Lifecycle
- Dashboard Architecture
- Menu Bar Architecture
- Monitoring Pipeline
- Snapshot Trends And Freshness
- CPU GPU Memory Disk Network
- Battery Power And Thermals
- SMC And Apple Silicon
- Fan Control
- Custom Fan Curves
- Privileged Helper
- XPC Trust Boundary
- Helper Diagnostics
- Touch Bar Architecture
- Touch Bar Customization
- Weather And Location
- Privacy And Permissions
- Onboarding And Help
- Legacy Alerts
- Kernel Panic Weird Mode