Sandbox credential host entries written with a port or scheme now still match.
What's wrong with this entry?
Host entries controlling which credentials get injected into a sandbox are now normalized to a bare host pattern and de-duplicated before matching, so an entry written with a port or scheme still matches, and repeated entries collapse.
- Applies to the environment variable, AWS key-pair and masked-file credential resolution paths.
- Only affects the sandbox credential configuration path.
degradeToUnsetNames
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox