Signature
Team ID plus Signing ID. An ad-hoc signature has no Team ID, so it misses a rule that names one.
Match
The allow key is Team ID, Signing ID, cdhash, domain, and port. A full path may be added, and then it must match together with the cdhash.
Team ID plus Signing ID. An ad-hoc signature has no Team ID, so it misses a rule that names one.
Read from this flow's audit token at decision time. Replacing the file at the same path changes the hash.
Segment by segment. Not the file name, not a prefix. The same name in another directory does not match.
A domain with no port allows every port on that name. Switching to another address after DNS is not a match. The access point dials the upstream in the snapshot, not an IP the client resolved later.
Swift does not compare these fields. The comparison is Go. The Go runtime is not embedded in the extension process.