Policy helpers pushed via remote settings must be real local executables; network paths and inline scripts are refused.
What's wrong with this entry?
A policy helper delivered through remote managed settings must now be a real local executable path. UNC paths, network automounts (/net, /Network/Servers) and kernel magic links (/proc, /dev/fd) are rejected, and inline scripts are refused outright.
- Any
claudeMdfield inside a remote-deliveredmanagedSettingspayload is deleted before the settings are used. - These checks apply only on the remote-delivery path; locally installed managed settings are validated as before.
path must not be a UNC, network-automount (/net, /Network/Servers) or kernel magic-link (/proc, /dev/fd) path when delivered via remote managed settings:
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.228
A policy helper is only honoured from an admin settings source
Both mention policy helper
-
v2.1.239
Policy-helper warnings say which platform they apply to
Both mention policy helper
-
v2.1.228
Managed settings accept per-OS
policyHelpersBoth mention policy helper