The sandbox proxy only buffers request bodies when one exists, and tears down bad requests.
What's wrong with this entry?
The sandboxed network proxy now copies a request body only for methods that carry one, or when a content-length or transfer-encoding header is present, and tears down both streams when a request is malformed or denied. Deny messages were reworded and encrypted-tunnel requests are now filtered against a decoded command name.
denied by sandbox policy
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox