If the sandbox fails to start, a later attempt can now succeed instead of failing forever.
What's wrong with this entry?
When sandbox initialization fails, it now clears its recorded state and returns instead of caching a rejected promise, so a later attempt can succeed. A successful init clears the previous failure reason.
- The reset covers both whether the sandbox was started with TLS termination and a new flag recording whether the installed network filter actually enforces the allowlist.
- The settings-change subscription now also re-subscribes to the stream of denied plugin producer directories.
- A new helper answers whether the sandbox is currently usable without re-running the dependency probe.
Sandbox configuration updated from settings change
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox