Sandbox failures now name the stage that broke instead of a generic error.
What's wrong with this entry?
The sandbox layer raises named errors instead of generic ones, so a failure says which stage broke: init, an unavailable bridge, no sandbox for this shell, a command too long, or a policy refusal carrying its own reason.
- Ships with a schema for per-host network policy entries: an
actionof allow or deny plus optional HTTPmethods.
SandboxPolicyRefusalError
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox