Skip to main content
v0.9.1

Changelog

v0.9.1 adds Bifrost Setup Check, an optional standalone utility for administrators on macOS, Windows, and Linux. It shows a consolidated Setup Status and walks through a Setup Guide that exports a complete, MDM-ready deployment bundle with pinned release packages, deployment scripts, and platform profiles. Direct vendor relays no longer share a per-domain concurrency cap, so bursts of parallel requests are no longer shed with 503. The background service now verifies interception readiness on its own and automatically reconnects temporary pass-through connections for every application once policy requires inspection. Every captured request carries its original destination address to the gateway, Cursor turns no longer fail on signature-only reasoning events, and support reports redact personal identifiers inside check text.

✨ Features

  • Bifrost Setup Check Utility - A new optional standalone application, installed from the same installer as Edge, owns the Setup Status and Setup Guide pages. It runs without Edge or the tray, so an administrator can inspect a device or prepare a deployment before Edge is installed. On macOS it is a third installer choice next to Edge and the Network Extension, on Windows an independent MSI feature, and on Linux a separate DEB/RPM package selected with install-linux.sh --setup-check. Removing it never touches Edge or its configuration.
  • Setup Status - One page consolidates background service health and privileges, trust status, sign-in, gateway connectivity, configuration sync, applied application routing, capture readiness, MCP observation, and possible VPN and network-extension conflicts. Missing evidence is shown as Unknown instead of hidden, Refresh analysis is read-only and repairs nothing, Run interception check remains an explicit action, and Copy report includes the analysis using the existing redacted report path.
  • Setup Guide with MDM Deployment Export - An ordered native wizard follows the Edge setup template through dashboard settings, trust, release package, configuration, endpoint coexistence, platform prerequisites, signing and export, then deployment, activation, sign-in, and pilot verification, with branches for MDM-managed TRP, standalone TRP, and TUN. Each completed guide exports a private bifrost-edge-setup-* folder containing config.json, a deploy-edge.sh or deploy-edge.ps1 script with the selected release’s SHA-256 and architecture pinned, a DEPLOYMENT.md pilot and rollback checklist, MDM validation notes, and on macOS the trust, extension approval, TRP service, and managed-uninstall profiles. The script installs the chosen components, backs up and merges existing gateway and capture configuration without losing credentials or unknown fields, and stops on any package or script failure. Jamf Pro exports also include a deploy-jamf.sh policy wrapper.
  • MDM Product Guidance and Existing Profile Import - The guide provides upload instructions for common MDM products plus a capability-based Other path, without vendor API credentials or automatic uploads. An existing device-scoped transparent proxy profile from any vendor can be imported: profile identity, unknown vendor settings, and unrelated payloads are retained, Bifrost takes order 1 and existing providers keep their relative order at 2, 3, and so on, and the exact values are recorded in trp-ordering.json. Ambiguous orders, duplicate providers, and legacy VPN shapes are flagged for review, and JumpCloud managed TRP exports are review-only because JumpCloud rewrites profile identifiers.
  • Profile Signing with an Existing Keychain Identity (macOS) - When the selected MDM workflow requires signed profiles, the guide lists installed identities in the keychain, validates the chosen one with a temporary signing and decode check, and signs the exported profiles. No private key enters an export, and the format is selected per product (for example Jamf Pro receives signed profiles and Jamf Now receives unsigned XML).
  • Headless Setup Helpers - Both the Edge and Setup Check executables accept --setup-status, --apply-setup-config GENERATED_CONFIG, and --check-setup-profiles REQUIRED_PROFILES_JSON for system-context scripts. They do not start capture, register services, or loosen local IPC access.
  • Endpoint Coexistence Discovery - Read-only inventory now includes macOS endpoint-security extensions and Windows Security Center registered endpoint protection products, alongside VPNs, network extensions, and filter bindings. The inventory is shown in Setup Status and on the Diagnostics interception page with its own timestamp, and discovery never disables or modifies any product.
  • Direct Relay Concurrency Cap Removed - Direct vendor relays no longer share a limit of 20 active requests per registrable domain, so a burst of parallel requests from one application is no longer answered with 503 and shed. Connection pooling and HTTP/2 multiplexing still apply, and the TUN bypass guard still returns 503 only when a routing loop is detected.
  • Interception Readiness Verification - The background service now verifies on its own that trust is active, the signing service answers with a fresh credential, and the current routing and sign-in configuration is applied before it reports interception as ready, instead of depending on tray polling. Pending checks retry from 5 seconds up to 60 seconds and healthy checks repeat every 15 minutes. The tray shows a new verifying state, and Diagnostics separates a running service from a verified interception path with a new Interception readiness check.
  • Automatic Reconnect of Temporary Pass-Through Connections - Temporary vendor connections opened while trust was pending, an application was disabled, logs-only mode was on, or the fleet kill switch was engaged are now tracked for every browser and CLI, not only Cursor. When policy changes to require inspection, Edge closes those connections so the client reconnects through governed routes. Long-lived SSE and WebSocket streams can be interrupted, requests are never replayed, and connections that never passed through Edge are left alone and may still need an application restart.
  • ChatGPT Routing Diagnostics - Diagnostics now includes a bounded history of recent ChatGPT routing decisions with Edge-generated correlation IDs, fixed route labels, capture mode, protocol, and outcome, plus the last observed policy inspection, the number of active pass-through connections, and the reconnect count. Records contain no prompts, cookies, query strings, or conversation IDs, and the daemon log is included in support ZIPs.
  • Original Destination Address Forwarded to the Gateway - Every captured request now carries the original destination IP in the X-Forwarded-For header, replacing any client-supplied value, for HTTP/1.1, HTTP/2, and WebSocket traffic in both TUN and TRP capture modes. In TRP mode the relay’s loopback address is never mistaken for the provider address.

🐞 Fixed

  • Cursor Turns Failed on Signature-Only Reasoning Events - A reasoning event without text caused invalid Cursor text delta: unexpected end of JSON input; such events are now retained as opaque replay data and never treated as visible text or tool completion.
  • Support Reports Exposed Identifiers Inside Check Text - Copy report now redacts the user name, email local part, hostname, and home paths inside check details, remedies, and routing reconciliation errors, matching whole words only so short names cannot rewrite parts of longer words.
  • Fail-Open Bypassed Applications That Require Governance - When signing was unavailable, a domain rule allowing fail-open could pass through traffic for an application that requires governance; that traffic now fails closed.
  • TRP Pass-Through Ignored the System Proxy - Raw pass-through relays in TRP capture mode now follow the operating system proxy and PAC configuration, the same as inspected traffic.
  • Expired Session Failed Signing Requests - A signing request rejected with 401 now shares the service’s session refresh and is retried once instead of failing the connection.
  • Signing Errors and WebSocket Logs Retained Sensitive Data - Signing service error bodies are no longer kept in error messages, and routine ChatGPT WebSocket log lines no longer include signed URLs or payload previews.
  • Cursor BYOK Helper Retried Failures Continuously - Failed helper launches are now limited to one attempt per minute per profile and policy; a policy change still reconciles immediately.
  • Elevated Windows Service Launched User Helpers with the Wrong Token - When running elevated in the user’s own session, the helper now uses the desktop shell’s unelevated primary token and refuses a shell that belongs to another user, another session, or an elevated desktop.
  • UID and GID Parsing Hardened - Unix user and group IDs are parsed with a 32-bit bound, and out-of-range IDs are refused before privileges are dropped for Cursor storage access.
  • Empty Diagnostics Fields Showed a Bare Dash - Empty values now read “Not available”.