Sandboxed commands now carry an id into the sandbox config so activity traces back to its command.
What's wrong with this entry?
Commands run in the sandbox now pass an identifier through to the sandbox wrapper, where it appears as a command id in the macOS and Linux sandbox configuration, so sandbox activity can be traced back to the command that caused it.
- A new sandbox attribution id option is threaded through the bash and PowerShell exec path into both sandbox wrapper entry points.
- The macOS sandbox log watcher was reworked to decode its command marker through a caller-supplied resolver, defaulting to identity, instead of a pre-built ignore map.
sandboxAttributionId
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox