Loading...
Loading...
Compare original and translation side by side
lsfindcatgrepfindgreprgcatReadlsfilePatholdStringnewStringreplaceAllEditEdit.entitlementsls.xcodeproj.xcworkspaceXcodeGlob "**/*.xcodeproj"lsfindXcodeReadXcodeUpdate.entitlementsXcodeReadfindplutillsfindcatgrepfindgreprgcatReadlsfilePatholdStringnewStringreplaceAllEditEdit.entitlementsls.xcodeproj.xcworkspaceXcodeGlob "**/*.xcodeproj"lsfindXcodeReadXcodeUpdate.entitlementsXcodeReadfindplutil| Symptom | Cause | Correct Response |
|---|---|---|
| The | Use the project name from system context; do not fall back to |
| Some on-disk artifacts aren't navigable via project paths | Translate to filesystem absolute path using the project root from system context, then use |
| 症状 | 原因 | 正确处理方式 |
|---|---|---|
| | 使用系统上下文里的项目名称;不要退回到 |
| 某些磁盘工件无法通过项目路径访问 | 使用系统上下文里的项目根目录转换为文件系统绝对路径,然后使用 |
Primary working directoryIs a git repositoryPrimary working directoryIs a git repositoryAudit <target><project-root>/xcode-security-audit-scratchpad.mdWriteRead## Plan SelectionApply Enhanced Security to <target>Apply Basic Clang Safety WarningsApply Hardware Memory TaggingApply Additional Diagnostic SettingsEmit Bounds Safety Adoption guidanceInquire about <MACRO> on <target>Report and update decision documentRemove scratchpadPrompt to remove plan filein_progresscompletedAudit <target>Write<project-root>/xcode-security-audit-scratchpad.mdRead## Plan SelectionApply Enhanced Security to <target>Apply Basic Clang Safety WarningsApply Hardware Memory TaggingApply Additional Diagnostic SettingsEmit Bounds Safety Adoption guidanceInquire about <MACRO> on <target>Report and update decision documentRemove scratchpadPrompt to remove plan filein_progresscompletedXcodeGlob '**/xcode-security-settings.md'XcodeReadXcodeGlob '**/xcode-security-settings.md'XcodeReadXcodeGlob**/*.c**/*.cpp**/*.cxx**/*.cc**/*.m**/*.mm**/*.swiftXcodeGlob**/*.c**/*.cpp**/*.cxx**/*.cc**/*.m**/*.mm**/*.swiftreferences/reading-build-settings.mdTaskCreate "Audit <target>"GetTargetBuildSettingsscripts/filter_build_settings.pyevaluatedValuesetAtTargetLevelyestargetValueXcodeGrep*.xcconfig**/project.pbxprojnumMatchesInXCConfigsnumMatchesInPbxprojGetTargetBuildSettingsreferences/reading-build-settings.mdTaskCreate "Audit <target>"in_progressGetTargetBuildSettingsscripts/filter_build_settings.pyevaluatedValuesetAtTargetLeveltargetValueyesin_progress*.xcconfig**/project.pbxprojXcodeGrepnumMatchesInXCConfigsnumMatchesInPbxprojGetTargetBuildSettingsreferences/reading-build-settings.mdreferences/enhanced-security.mdCODE_SIGN_ENTITLEMENTSreferences/universal-binaries-for-libraries.mdARCHSTaskUpdate "Audit <target>".entitlementsreferences/reading-build-settings.mdreferences/enhanced-security.mdCODE_SIGN_ENTITLEMENTSreferences/universal-binaries-for-libraries.mdARCHSTaskUpdate "Audit <target>"completed.entitlements<project-root>/xcode-security-audit-scratchpad.mdWriteXcodeWrite<project-root>Primary working directory## Audit Table## Enhanced-Security BucketsFoo: Partial — missing hardened-heap, has deprecated platform-restrictions## Plan SelectionEditRemove scratchpadBash rmWriteXcodeWrite<project-root>/xcode-security-audit-scratchpad.mdPrimary working directory<project-root>## Audit Table## Enhanced-Security BucketsFoo: Partial — missing hardened-heap, has deprecated platform-restrictionsEdit## Plan SelectionRemove scratchpadBash rmIs a git repositorytrue.git.hg.svn.bzr.fslckout_FOSSIL_CVSIs a git repositorytrue.git.hg.svn.bzr.fslckout_FOSSIL_CVSalready hardeneddeliberately disabledalready hardeneddeliberately disabledxcode-security-audit-plan.mdXcodeWritexcode-security-audit-plan.mdXcodeWrite<project-root>/<…>undefinedXcodeWritexcode-security-audit-plan.mdxcode-security-audit-plan.mdXcodeWrite<project-root>/<…>undefined⚠️ No version control detected. This skill modifies build settings and entitlements. Without Version Control System (e.g., Git), rollback requires manual undo. Consider runningor copying the project before picking Run. Edit the items below — set what steps to perform now, or leave them unchecked to defer them.git init
⚠️ 未检测到版本控制。 此技能会修改构建设置和权限。 没有版本控制系统(如Git),回滚需要手动操作。建议在选择运行前执行或复制项目。 编辑以下项——设置现在要执行的步骤,或者取消勾选以推迟执行。git init
ENABLE_ENHANCED_SECURITY=YES<setting>=NO<target>references/additional-settings.mdENABLE_ENHANCED_SECURITY=YES<target><setting>=NOreferences/additional-settings.mdxcode-security-settings.mdxcode-security-settings.md
Include the ⚠️ blockquote only when the project is **not version-controlled**; omit it otherwise.
The decision document should live in the same directory as the rest of the documentation, or at the project level.xcode-security-settings.mdxcode-security-settings.md
仅当项目**未进行版本控制**时,才包含⚠️块引用;否则省略。
决策文档应与其他文档放在同一目录,或放在项目根目录。already hardeneddeliberately disabledENABLE_POINTER_AUTHENTICATION = NOSUPPORTED_PLATFORMSSDKROOTmacosxiphoneosiphonesimulatorxrosxrsimulatoralready hardeneddeliberately disabledENABLE_POINTER_AUTHENTICATION = NOSUPPORTED_PLATFORMSSDKROOTmacosxiphoneosiphonesimulatorxrosxrsimulator[x][ ][x][ ]"Plan written toand added to the Xcode project — open it to review. Edit it as needed — uncheck or delete items to skip them; edit the decision document path to relocate. When ready, pick Run. Pick Cancel to abort without changes. Nothing is modified until you pick Run."xcode-security-audit-plan.md
AskUserQuestion"计划已写入并添加到Xcode项目中——请打开它进行审阅。根据需要进行编辑——取消勾选或删除项以跳过;编辑决策文档路径进行迁移。准备就绪后,选择“运行”。选择“取消”则中止操作,不进行任何更改。在你选择“运行”前,不会修改任何内容。"xcode-security-audit-plan.md
AskUserQuestionRemove scratchpadPrompt to remove plan filePrompt to remove plan fileRemove scratchpadXcodeRead xcode-security-audit-plan.md- [x]- [X]**…**- [ ]Path:## Plan SelectionEditReadRemove scratchpadPrompt to remove plan filePrompt to remove plan fileRemove scratchpadXcodeRead xcode-security-audit-plan.md- [x]- [X]**…**- [ ]Path:Edit## Plan SelectionRead.xcconfig.pbxprojUpdateTargetBuildSettingUpdateProjectBuildSetting.xcconfigENABLE_ENHANCED_SECURITY.xcconfig.pbxprojUpdateTargetBuildSettingUpdateProjectBuildSetting.xcconfigENABLE_ENHANCED_SECURITYApply Enhanced Security to <target>references/enhanced-security.mdreferences/pointer-authentication.mdreferences/typed-allocators.mdreferences/stack-zero-init.mdreferences/readonly-platform-memory.mdreferences/runtime-restrictions.mdreferences/security-compiler-warnings.mdreferences/cpp-hardening.mdreferences/hardware-memory-tagging.mdarm64eENABLE_ENHANCED_SECURITY = YESarm64eENABLE_POINTER_AUTHENTICATION = NOarm64eARCHS = "arm64 arm64e"ONLY_ACTIVE_ARCH = NOreferences/universal-binaries-for-libraries.md.entitlementsCODE_SIGN_ENTITLEMENTSENABLE_ENHANCED_SECURITY = YESUpdateProjectBuildSettingENABLE_ENHANCED_SECURITY = YESENABLE_POINTER_AUTHENTICATION = YESENABLE_POINTER_AUTHENTICATION = NOSDKROOTSUPPORTED_PLATFORMSarm64eENABLE_POINTER_AUTHENTICATION = NOARCHS = "arm64 arm64e"ONLY_ACTIVE_ARCH = NOUpdateTargetBuildSettingARCHS.entitlementsApply Enhanced Security.entitlementsApply Enhanced Security to <target>references/enhanced-security.mdreferences/pointer-authentication.mdreferences/typed-allocators.mdreferences/stack-zero-init.mdreferences/readonly-platform-memory.mdreferences/runtime-restrictions.mdreferences/security-compiler-warnings.mdreferences/cpp-hardening.mdreferences/hardware-memory-tagging.mdarm64eENABLE_ENHANCED_SECURITY = YESarm64eENABLE_POINTER_AUTHENTICATION = NOarm64eARCHS = "arm64 arm64e"ONLY_ACTIVE_ARCH = NOreferences/universal-binaries-for-libraries.md.entitlementsCODE_SIGN_ENTITLEMENTSENABLE_ENHANCED_SECURITY = YESUpdateProjectBuildSettingENABLE_ENHANCED_SECURITY = YESENABLE_POINTER_AUTHENTICATION = YESENABLE_POINTER_AUTHENTICATION = NOSDKROOTSUPPORTED_PLATFORMSarm64eENABLE_POINTER_AUTHENTICATION = NOARCHS = "arm64 arm64e"ONLY_ACTIVE_ARCH = NOUpdateTargetBuildSettingARCHS.entitlementsApply Enhanced Security.entitlementsalready hardenedGCC_WARN_ABOUT_RETURN_TYPE = YES_ERRORGCC_WARN_UNINITIALIZED_AUTOS = YES_AGGRESSIVECLANG_WARN_IMPLICIT_FALLTHROUGH = YESGCC_WARN_64_TO_32_BIT_CONVERSION = YESGCC_TREAT_IMPLICIT_FUNCTION_DECLARATIONS_AS_ERRORS = YESCLANG_ANALYZER_SECURITY_FLOATLOOPCOUNTER = YESCLANG_ANALYZER_SECURITY_INSECUREAPI_RAND = YESCLANG_ANALYZER_SECURITY_INSECUREAPI_STRCPY = YESalready hardenedGCC_WARN_ABOUT_RETURN_TYPE = YES_ERRORGCC_WARN_UNINITIALIZED_AUTOS = YES_AGGRESSIVECLANG_WARN_IMPLICIT_FALLTHROUGH = YESGCC_WARN_64_TO_32_BIT_CONVERSION = YESGCC_TREAT_IMPLICIT_FUNCTION_DECLARATIONS_AS_ERRORS = YESCLANG_ANALYZER_SECURITY_FLOATLOOPCOUNTER = YESCLANG_ANALYZER_SECURITY_INSECUREAPI_RAND = YESCLANG_ANALYZER_SECURITY_INSECUREAPI_STRCPY = YESSUPPORTED_PLATFORMSSDKROOTmacosxiphoneosiphonesimulatorxrosxrsimulatorreferences/hardware-memory-tagging.mdSUPPORTED_PLATFORMSSDKROOTmacosxiphoneosiphonesimulatorxrosxrsimulatorreferences/hardware-memory-tagging.mdreferences/additional-settings.mdreferences/additional-settings.md"To adopt(annotation-based bounds safety for C), invoke theENABLE_C_BOUNDS_SAFETYskill."adopt-c-bounds-safety
"To adopt(C++ bounds-safe buffer patterns), read the documentation at https://clang.llvm.org/docs/SafeBuffers.html"ENABLE_CPLUSPLUS_BOUNDS_SAFE_BUFFERS
"要采用(基于注解的C语言边界安全),请调用ENABLE_C_BOUNDS_SAFETY技能。"adopt-c-bounds-safety
"要采用(C++边界安全缓冲区模式),请参阅文档:https://clang.llvm.org/docs/SafeBuffers.html"ENABLE_CPLUSPLUS_BOUNDS_SAFE_BUFFERS
deliberately disabledreferences/reading-build-settings.mdENABLE_POINTER_AUTHENTICATION = NOreferences/settings-and-entitlements-catalog.mdInquire about <MACRO> on <target>DisabledAskUserQuestion<MACRO>NOdeliberately disabledENABLE_ENHANCED_SECURITY = NOdeliberately disabledreferences/reading-build-settings.mdENABLE_POINTER_AUTHENTICATION = NOreferences/settings-and-entitlements-catalog.mdInquire about <MACRO> on <target>DisabledAskUserQuestion<MACRO>NOdeliberately disabledENABLE_ENHANCED_SECURITY = NOreferences/decision-document.mdRemove scratchpadBash rm <project-root>/xcode-security-audit-scratchpad.mdPrompt to remove plan fileAskUserQuestionxcode-security-audit-plan.mdXcodeRM xcode-security-audit-plan.md deleteFiles:truereferences/decision-document.mdRemove scratchpadBash rm <project-root>/xcode-security-audit-scratchpad.mdPrompt to remove plan fileAskUserQuestionxcode-security-audit-plan.mdXcodeRM xcode-security-audit-plan.md deleteFiles:true= NOAskUserQuestion= NOAskUserQuestion