Darkelf Shadow v7.0.15
StableHighlights
- Show a link's destination in the bottom-left corner before clicking.
- Adjust the preview to the available width, shortening long URLs with an ellipsis.
- Correct preview sizing to prevent text clipping.
- Clear the preview when navigation starts or the active tab changes.
- Hide the preview during website video fullscreen.
- Remove control and bidirectional formatting characters from the displayed preview without changing the link destination.
Release Notes
# Darkelf Shadow CE 7.0.15
A navigation and usability update for the 7.x series, adding hovered-link previews and correcting Google Maps URL rewriting.
Hovered-link preview
Show a link's destination in the bottom-left corner before clicking.
Adjust the preview to the available width, shortening long URLs with an ellipsis.
Correct preview sizing to prevent text clipping.
Clear the preview when navigation starts or the active tab changes.
Hide the preview during website video fullscreen.
Remove control and bidirectional formatting characters from the displayed preview without changing the link destination.
The preview uses Qt's native link-hover signal.
Google Maps navigation
Restrict Google's forced language and region parameters to homepage and search paths.
Preserve Maps URLs, parameters and server-selected redirects.
Avoid applying Google Search locale rewriting to other Google applications.
Retain English request headers and YouTube language/region settings.
Developer testing confirmed that `https://www.google.com/maps?hl=en&gl=us` loaded after the interceptor correction.
Retained shutdown and session cleanup
Clean up inside the application without a detached background worker.
Destroy WebEngine pages and the profile before checking that storage files are closed.
Remove selected website-session stores during normal shutdown, including closing the last window, Cmd+Q and Delete & Quit.
Preserve native authentication configuration, the WebAuthn secret and macOS Keychain credentials.
Remove obsolete status files from the previous cleanup implementation.
Use a synchronous Qt process for the storage check.
Python/PyPI and ordinary source launches use an **off-the-record profile**. The native macOS ARM64 app retains its **named Darkelf profile** for native authentication. Both use web-content caching in memory and nonpersistent cookies.
Cleanup can fail if storage remains locked or access is denied. Crashes and forced termination cannot guarantee cleanup. Filter caches, saved snapshots and other intentionally saved files can remain. Historical profiles created by older builds are not automatically removed.
Retained browser reliability improvements
Restore browser controls when opening or switching tabs during video fullscreen.
Ignore stale fullscreen events from background or deleted pages.
Guard delayed keyboard-filter installation against deleted Qt views.
Validate HTTP/HTTPS URLs and redirects used by the View Source fallback.
Limit fallback source downloads to **8 MiB**, while preserving literal HTML display without executing it.
Guard WebAuthn handling against duplicate requests, reentrant polling and stale request cleanup.
The source-download limit does not restrict normal browsing or file downloads.
Privacy controls and filtering
Apply panic and lockdown checks before compatibility exceptions.
Recognize private IP addresses through address parsing.
Report **BLOCKED / PROTECTED / TRUSTED / COMPATIBLE** canvas states.
Show the active profile's off-the-record or named status in Settings.
Retain cached filter downloads, concurrent refreshes, direct matching for simple rules and regex compilation for complex patterns.
Skip unsupported cookie, scriptlet and page-action rules rather than treating them as network blockers.
Retain embedded Darkelf site-boundary rules without a separate `.dat` file.
Provide optional diagnostics through `DARKELF_DIAGNOSTICS=1`.
Earlier developer measurements reduced filter initialization from approximately **38 seconds to 6 seconds** with about 417,000 network rules. This measures filter loading and indexing, not total application startup; results vary by system and cache state.
CNN10 playback was confirmed in developer testing after the earlier parser correction. Site-boundary coverage remains curated rather than worldwide.
Automatic verification compatibility remains enabled. Console-based verification signals can be imitated by website scripts; TRUSTED status is not proof of completed human verification.
Authentication and media
The custom macOS ARM64 Qt WebEngine **6.11.2** retains native WebAuthn integration, H.264/AVC support, native WebGL modifications and disabled WebRTC.
Passkey compatibility depends on signing, keychain entitlements, provisioning, applicable Apple authorization, platform and website behavior.
**7.0.15 does not claim to resolve the pending Apple entitlement dependency.**
H.264 support does not provide DRM support. Widevine is not bundled. Custom engine patches are not included in standard PyPI dependencies.
Validation and release verification
Developer testing confirmed correct hovered-link preview sizing and successful navigation to the previously failing Google Maps URL.
Updated interceptor code passed syntax, Ruff and Bandit checks.
Targeted checks confirmed that Maps and other non-search Google paths are no longer rewritten by the locale rule.
Earlier developer testing confirmed website-session stores were removed after a native DMG shutdown.
Retain framework structure checks, final signing and ZIP verification before notarization.
Retain Developer ID signing, hardened runtime, notarization, stapling and embedded licensing notices.
These checks do not constitute an independent professional security audit.
Verify the DMG beside its matching checksum file:
```bash
shasum -a 256 -c Darkelf-Shadow-7.0.15.dmg.sha256
```
Acknowledgments
Thanks to the **Mecha Comet Team**, **Tim Burns**, and everyone testing and supporting Darkelf Shadow.
**Dr. Kevin Moore · Darkelf Project — Shadow Edition**