Core safeguards
- Plan before change
- Per-item Update, Options, and Update All build the same immutable, expiring Safe Update Plan. Detection-only Options authorize no download, external open, quit, privilege, or mutation.
- Exact source
- HTTPS scheme, host, path, redirect, response type, and size are constrained per adapter. Generic vendor download discovery is not authorized.
- Independent identity
- Where direct installation exists, checksums and Apple-anchored signing identity are both required; TLS alone is not treated as artifact trust.
- Path safety
- Bounded no-follow file operations, private staging, exact destinations, same-volume replacement, and race rechecks reduce traversal and path-replacement risk.
- Least privilege
- Chronologix 1.0 has no sudo path, root helper, arbitrary shell command runner, private API, or Gatekeeper/SIP weakening.
- Verified outcome
- Success requires the expected version and local identity to be observed after the in-app transaction. Process exit alone is never enough.
Current direct-install scope
Chronologix 1.0 authorizes one exact Firefox stable-channel contract plus eligible official Homebrew formula and safe-cask transactions. Firefox is bound to Mozilla’s fixed metadata/checksum locations, en-US macOS DMG, org.mozilla.firefox, Mozilla’s Team ID, arm64 support, and /Applications/Firefox.app. Homebrew is bound to one current official token, live receipt, conventional Apple-silicon executable, and fixed formula/cask argument vector. Neither authority extends to a generic vendor, package, path, option, or command.
Recovery boundary
The Firefox transaction checks the current app, available space, destination access, source evidence, signing identity, and recovery state before download and again before replacement. It stages on the destination volume, retains the prior verified bundle, journals mutation, post-verifies, and recovers after interruption where the exact state permits. Chronologix does not promise universal rollback.
Homebrew owns its package and dependency transaction. Chronologix revalidates the plan, executable, and live receipt, journals the operation, hides bounded raw output, and reports success only when a fresh receipt matches the proposed version. Update All runs entries serially and stops at the first drift or unverified result.
For an eligible signed application-owned feed, Options keeps the confirmed version and evidence visible but opens no app, updater, Store page, Settings surface, browser, or Terminal. It never inherits install or batch authority.
Reporting a vulnerability
Do not publish a suspected vulnerability in a public issue. Use GitHub private vulnerability reporting in the source-free public release repository.
Version 1.0 passed Developer ID signing, Apple notarization, staple validation, Gatekeeper assessment, and clean macOS 14 standard-account smoke testing before publication.