Managed limits on which AWS credentials the sandbox may use survive settings merges now.
What's wrong with this entry?
Restrictions on which AWS credential forms the sandbox may use now survive merging of managed settings into child settings, instead of being dropped at the merge boundary.
- Inheritance now carries the
sandbox.credentials.sigv4deny list, whose values arestreaming,presignedandsigv4a. - A normalized
awsPairslist of allowed AWS key pairs is carried through the same merge.
sigv4a
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox