Cupertino 1.10.0
Version 1.10.0 ·
Added
apple_mail_query, projection and aggregation over the Mail index. "Top ten senders" or "unread per account" is now aGROUP BYthe server runs, rather than a page of rows pulled into the context for the model to tally. It takes the same filters asapple_mail_search_messagesand shares its WHERE-clause builder, so a filter that narrows a listing cannot silently miss the aggregate.Aggregation always runs before
limit, never after.limitcaps the number of groups returned, and the envelope carriestotalRows— messages aggregated, never capped — alongsidetruncated, so a top-N answer cannot be mistaken for "top N among the page we happened to return." That distinction is the whole reason to have the tool: an aggregate computed over a truncated page is not a wrong number so much as a confidently wrong one.It registers on read-only servers only, for now. Not because it is unsafe with writes on — it reaches nothing but the index — but because every tool costs listing tokens on every connect, and this one has to prove it saves more than it costs before it goes on the surface most clients see. A Code-Mode-style single
executetool was considered and rejected first; it relocates the tool-surface cost rather than removing it, and collapses per-operation permissioning into one opaque call. See docs/mail-query.md.The site credits Magenta Creations with the mark, in the footer, the same form every mgcrea site uses. "Unofficial. Not affiliated with Apple" says who this is not, not who made it.
Changed
The Microphone row in a surface's Access card now says "Ask…" when the button raises the system prompt and "Allow…" when it opens the pane, matching the menu-bar popover — it had said "Allow…" in both states. Answering the prompt also updates the row now, instead of leaving it reading "Microphone needed" until something else triggered a refresh.
Fixed
The Microphone permission could not be granted at all. 1.9.0 shipped the
soundsurface withoutcom.apple.security.device.audio-inputin the app's entitlements. The app is unsandboxed, but the hardened runtime gates resource access too, and without that key macOS does not refuse the recording — it refuses to ask:AVCaptureDevice.requestAccessreturnedfalsewith no consent dialog, and wrote no TCC row. So Cupertino never appeared in Privacy & Security › Microphone, and that pane — unlike Full Disk Access, Screen Recording and Accessibility — has no "+" button to add it with. The "Allow…" button opened a window with nothing in it to switch on.Upgrading is the whole fix. There is no stale grant to clear and no
tccutil resetto run, because the refusal was never recorded.scripts/spike-app-tccmissed this because it signed its bundle without--options runtime; it now signs hardened with the app's own entitlements, so a lane that passes describes the app that ships.