Docker, bubblewrap and root-outside-sandbox checks share one cached prober that answers false until ready.
What's wrong with this entry?
Docker, bubblewrap, running as root outside a deliberate sandbox, and "contained with no internet" checks now live in a single class that caches each probe. One gate additionally requires an internal-network probe to come back empty. Its synchronous accessor reports false until the asynchronous checks have settled, so very early callers see the negative answer. The bubblewrap and IS_SANDBOX=1 signals are Linux-only.
passesAntDspEnvGateSync
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox