Sandbox-blocked hosts can now tell you the specific reason they were denied.
What's wrong with this entry?
The generated sandbox network policy now includes a per-domain reason for each blocked host. The enforcement side already looked for these and fell back to a generic message, so blocked requests can now say something more specific than "host is on the deny list".
host is on the deny list
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox