Sandbox startup failure details are hidden from untrusted print-mode output.
What's wrong with this entry?
In print and stream-json modes, when a sandbox is required but cannot be started, the reason is only included in the visible error for trusted invocations. Otherwise you get the bare "Sandbox required but unavailable" and the detail goes to the debug log. The full reason is still written to stderr either way.
- Trust is decided at runtime from the entrypoint and session; there is no flag to change it.
Sandbox required but unavailable
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox