Darkelf Shadow v7.0.14
StableHighlights
- Replace the detached cleanup worker with cleanup inside the application.
- Destroy WebEngine pages and the profile before checking that storage files are closed and removing selected website-session stores.
- Remove history, website storage and caches during normal shutdown, including closing the last window, Cmd+Q and Delete & Quit.
- Preserve native authentication configuration, the WebAuthn secret and macOS Keychain credentials.
- Remove obsolete status files from the previous cleanup implementation.
- Use a synchronous Qt process for the storage check, without launching a detached background task.
Release Notes
# Darkelf Shadow CE 7.0.14
A shutdown-cleanup and WebAuthn request-handling update for the 7.x series.
Normal shutdown and session cleanup
Replace the detached cleanup worker with cleanup inside the application.
Destroy WebEngine pages and the profile before checking that storage files are closed and removing selected website-session stores.
Remove history, website storage and caches during normal shutdown, including closing the last window, Cmd+Q and Delete & Quit.
Preserve native authentication configuration, the WebAuthn secret and macOS Keychain credentials.
Remove obsolete status files from the previous cleanup implementation.
Use a synchronous Qt process for the storage check, without launching a detached background task.
Python/PyPI and ordinary source launches use an **off-the-record profile**. The native macOS ARM64 app retains its **named Darkelf profile** for native authentication. Both use web-content caching in memory and nonpersistent cookies.
Cleanup can fail if storage remains locked or access is denied. Crashes and forced termination cannot guarantee cleanup. Filter caches, saved snapshots and other intentionally saved files can remain.
WebAuthn request handling
Guard against duplicate requests and reentrant state polling.
Defer replacement requests instead of processing them recursively.
Prevent stale request cleanup from closing a newer request's interface.
Check that requests remain active after authentication dialogs return.
These changes address request handling; they do not guarantee successful passkey authentication. Apple-specific compatibility still depends on signing, keychain entitlements, provisioning, applicable Apple authorization and website behavior.
**7.0.14 does not claim to resolve the pending Apple entitlement dependency.**
Retained browser improvements
Restore browser controls when opening or switching tabs during video fullscreen.
Ignore stale fullscreen events from background or deleted pages.
Guard delayed keyboard-filter installation against deleted Qt views.
Validate HTTP/HTTPS URLs and redirects used by the View Source fallback.
Limit fallback source downloads to **8 MiB**, while preserving literal HTML display without executing it.
The source-download limit does not restrict normal browsing or file downloads.
Privacy controls and filtering
Apply panic and lockdown checks before compatibility exceptions.
Recognize private IP addresses through address parsing.
Report **BLOCKED / PROTECTED / TRUSTED / COMPATIBLE** canvas states.
Show the active profile's off-the-record or named status in Settings.
Retain cached filter downloads, concurrent refreshes, direct matching for simple rules and regex compilation for complex patterns.
Skip unsupported cookie, scriptlet and page-action rules rather than treating them as network blockers.
Retain embedded Darkelf site-boundary rules without a separate `.dat` file.
Provide optional diagnostics through `DARKELF_DIAGNOSTICS=1`.
Earlier developer measurements reduced filter initialization from approximately **38 seconds to 6 seconds** with about 417,000 network rules. Results vary by system and cache state.
CNN10 playback was confirmed in developer testing after the parser correction. Site-boundary coverage remains curated rather than worldwide.
Automatic verification compatibility remains enabled. Console-based verification signals can be imitated by website scripts; TRUSTED status is not proof of completed human verification.
Engine and media
The custom macOS ARM64 Qt WebEngine **6.11.2** retains native WebAuthn integration, H.264/AVC support, native WebGL modifications and disabled WebRTC.
H.264 support does not provide DRM support. Widevine is not bundled. Custom engine patches are not included in standard PyPI dependencies.
Validation and release verification
Updated browser features passed syntax, Ruff and Bandit checks.
The developer's local `shadow/` Bandit scan reported **zero findings, zero suppressions and zero skipped files**.
Developer testing confirmed website-session stores were removed after a native DMG shutdown.
Retain framework structure checks, final signing and ZIP verification before notarization.
Retain Developer ID signing, hardened runtime, notarization, stapling and embedded licensing notices.
These checks do not constitute an independent professional security audit.
Verify the DMG beside its matching checksum file:
```bash
shasum -a 256 -c Darkelf-Shadow-7.0.14.dmg.sha256
```
Acknowledgments
Thanks to the **Mecha Comet Team**, **Tim Burns**, and everyone testing and supporting Darkelf Shadow.
**Dr. Kevin Moore · Darkelf Project — Shadow Edition**