Sandbox status can be emitted as a JSON object covering availability, enablement, strict mode and filesystem policy.
What's wrong with this entry?
A new sandbox status path emits a JSON object stamped statusVersion: 2 covering whether sandboxing is available, installed, policy-locked and supported, whether it is enabled, whether strict mode is on, and the filesystem policy, with reasons attached.
- Two provenance fields say where the settings came from: one for enablement and one for strict mode, each reported as
forced,policy,settingsoroff. - Nothing carrying a status version existed in the previous build.
- Which command surfaces this output is not wired up anywhere visible in the bundle.
strictModeSource
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox