The sandbox proxy now tells refused connections why, including SSH ones, instead of dropping them.
What's wrong with this entry?
When the sandbox proxy requires an auth token, a client that offers no authentication method now gets an explanation rather than a silently dropped connection. On port 22 the proxy writes an SSH-shaped banner and disconnect message saying why the connection was refused, including the policy reason when the destination is on the deny list.
This proxy requires authentication, and this client did not offer an authentication method, so the connection was refused.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox