Root-outside-sandbox and container checks moved into one class with a hardcoded Linux platform.
What's wrong with this entry?
The check for running as root outside a deliberate sandbox, along with the related container and environment-gate checks, now lives in a single class with its inputs injected rather than read directly. The platform value passed in is the literal "linux", so the class's non-Windows guard is always satisfied here.
isRootOutsideDeliberateSandbox
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox