Catch-all gateway policies merge desktop overlays key by key, so a strict base can't be loosened accidentally.
What's wrong with this entry?
A gateway policy that inherits from the catch-all entry (match: {}) now merges its desktop overlay semantically instead of overwriting keys wholesale, so a stricter base cannot be loosened by accident.
disabledBuiltinToolsfrom the base and the role entry are unioned rather than replaced.builtinToolPolicyis merged so a base value other thanallowsurvives a looser role value.- The merged result is diffed and the changed keys are logged, matching what the
clihalf of a policy already did.
desktop overlay after merge with catch-all base
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
Managed-settings review prompt dropped from the main UI
Both mention managed
-
v2.1.242
Startup can wait on a remote managed-settings refresh, with a deadline
Both mention managed
-
v2.1.246
Remote managed settings can defer their consent prompt to the next interactive session
Both mention managed