There is a grant mode treating every app as allowed except ones on a denylist.
An all-apps-granted tier with a required denylist is defined within the host-dependent per-app control feature.
What's wrong with this entry?
Besides granting named applications, there is now a mode that treats every application as granted at the full tier except those a denylist excludes, and it skips the step that hides windows before acting.
- Constructing it with an empty denylist throws at runtime on purpose; the code calls that a wiring bug.
- It is only used where the host program supplies an every-app policy. The default behaviour, granting specific apps, is unchanged.
WildcardGrantSet: deniedBundleIds must be non-empty
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.248
Computer-use app blocklists extended on Windows
Both mention computer