Blocked network requests are now recorded with the command that made them, not just dropped.
What's wrong with this entry?
A network request blocked by the sandbox is now recorded as a violation with its method, sanitized URL, reason and the command that made it, instead of only being dropped. Filesystem violations on Linux and macOS also gained command text.
- Applies only while the sandbox proxy and platform monitors are running.
deny http-request
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox