Sandbox allow and deny rules can now target a specific port instead of the whole host.
What's wrong with this entry?
Domain allow and deny rules in the sandbox now parse a host pattern plus an optional port, so a rule can target a single port rather than the whole host.
- Matching fails closed on both sides: a port-qualified rule matches a request with an unknown port when denying, and does not match when allowing.
- Otherwise the port must match exactly.
- Deny rules still come from
sandbox.network.deniedDomainsplus WebFetch-styledomain:permission rules.
sandbox.network.allowManagedDomainsOnly is set and
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox