02-Oct-2026
- Fixed
DailyReminderTimesvalues that mix valid and invalid entries (for example,8:00,17:00) resolving to no baseline reminder slots. The invalid-entry warning text was captured into the resolved value instead of the log, so the valid17:00entry was dropped, the08:00,12:00,16:00default was not applied, and Remind Me Later fell through to the first pre-deadline threshold (Issue #139; thanks, @TechTrekkie!)- Invalid entries are now logged as
[WARNING] Ignoring invalid DailyReminderTimes entry '…'and skipped, valid entries are kept, and a fully invalid value still falls back to the default with the existingdefaulting to '…'warning. - Affected standalone and deployed runs alike; deployed
dor.zshadditionally lost the warning line entirely because it logs through the LaunchDaemon's standard output. HH:MMstill requires zero-padded hours;8:00is rejected (and now logged), not normalized.
- Invalid entries are now logged as
- Applied the same fix to
MinutesBeforeDeadlineReminderSchedule, where mixed input such as45,abcpreviously disabled all pre-deadline threshold reminders. - Applied the same fix to
Resources/reminderDialogPreferenceTest.zsh. - Hardened language-code handling for localized dialog text and deadline date formats. Unrecognized language values now fall back to English and the global
DateFormatDeadlineHumanReadable, and log a[WARNING]. - Validated localized preference key names before applying them; keys with an unrecognized language code are skipped and logged at
[WARNING]. - Applied the same hardening to
Resources/reminderDialogPreferenceTest.zsh. - Hardened runtime temporary-file handling. Each reminder run now creates a private, root-owned
/var/tmp/dorm.XXXXXXdirectory (named after the runtime'sorganizationScriptName), mode0755so swiftDialog can read it as the console user. Downloaded icons, the swiftDialog command file (passed with--commandfile), and the threshold-refresh marker live in that directory, and quitting removes it.- The runtime no longer writes fixed names such as
/var/tmp/icon.png,/var/tmp/overlayicon.png, or/var/tmp/dialog.log. - The runtime no longer deletes the default swiftDialog command file used by other swiftDialog workflows.
- Concurrent root runs no longer share icon or command files.
- The runtime no longer writes fixed names such as
- swiftDialog now runs from its root-owned app bundle (
/Library/Application Support/Dialog/Dialog.app/Contents/MacOS/dialogcli) instead of/usr/local/bin/dialog./usr/localand/usr/local/binwere removed from thePATHof the runtime, the deployer,dor-starter.zsh, and the LaunchDaemon. - Hardened DDM declaration trust. When
/var/db/softwareupdate/SoftwareUpdateDDMStatePersistence.plistis readable,install.logdeclaration candidates must match a persisted active declaration'sTargetOSVersionandTargetLocalDateTime.- Declarations that do not match are ignored and logged as
[WARNING] Ignoring N install.log DDM declaration(s) absent from softwareupdate DDM state. - When no corroborated candidate remains, the resolver reports
missing, which stays eligible for DDM Emergency Fallback. - When the plist is missing or has an unrecognized structure, a
[NOTICE]is logged and resolution works as before. Resources/JamfEA-Pending_OS_Update_Date.zshandResources/JamfEA-Pending_OS_Update_Version.zshapply the same corroboration.
- Declarations that do not match are ignored and logged as
- Update Tonight suppression now accepts only
SUOSUInstallTonightManager: QueuedandSUOSUScheduler: ARMEDevidence logged bysoftwareupdated. Evidence from other senders is skipped and logged at[NOTICE], and invalidating lines from any sender still fail closed. - Bounded the wait for System Settings after Open Software Update to 30 seconds, so a blocked or crashed System Settings can no longer hold
dor.pidand stop all later reminders until reboot. Added a 10-second--max-timeto the macOS icon download. - Opened the Info button URL and the System Settings activation in the console user's session with
launchctl asuser, instead ofsu -with an interpolated shell command. - Deployment writes
dor.zshanddor-starter.zshto adjacent temporary files, validates them withzsh -n, and moves them into place atomically, so the heartbeat can never launch a partially written script. - Deployment now changes ownership only of the organization directory and DDM OS Reminder's own runtime assets, instead of recursively running
chownacross/Library/Management/<rdnn>. - swiftDialog validation now reinstalls when the installed version cannot be read, instead of treating an empty version as current.
- A swiftDialog Team ID verification failure is now logged as
[FATAL ERROR]with the expected and received Team IDs, and the error dialog appears in the console user's session. - Upgrade note:
AllandScriptredeployments now keep the aggressive-mode support kill switch/Library/Management/<rdnn>/dor-aggressive-killand log a[NOTICE]; onlyUninstallremoves it. Script Parameter 4 still defaults toAllwhen blank; the in-script comment now says so. Resources/createSelfExtracting.zsh(2.4.0) generated wrappers have three changes:- They extract into a private
mktemp -ddirectory. - They forward all MDM script parameters, so Parameters 4–6 now reach the deployer: reset mode, DDM Emergency Fallback, and
Uninstall. - They remove the extracted payload on exit.
- They extract into a private
Resources/Jamf-getDDMstatusFromCSV.zsh(1.4.0) has four changes:- API credentials and bearer tokens reach
curlthrough stdin configuration instead of process arguments. - Debug logs no longer include token responses.
- Entered passwords are no longer stripped of quote characters.
- Supplying the password as a positional argument now prints a warning.
- API credentials and bearer tokens reach
assemble.zshnow re-prompts on an invalid deployment-mode selection instead of defaulting to production, and exits when no selection can be read.Resources/monitorRemoteSession.zsh(1.1.1) also recognizes swiftDialog processes launched from the app bundle path.- No preference keys, defaults, or precedence rules changed.