Comment by saagarjha 2 hours ago macOS attributes shell commands to their parent app bundle. 5 comments saagarjha Reply 0c3ca83 26 minutes ago That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd. saagarjha 19 minutes ago Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process. 0c3ca83 17 minutes ago It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former. 1 reply → joshspankit 2 hours ago Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file
0c3ca83 26 minutes ago That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd. saagarjha 19 minutes ago Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process. 0c3ca83 17 minutes ago It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former. 1 reply →
saagarjha 19 minutes ago Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process. 0c3ca83 17 minutes ago It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former. 1 reply →
0c3ca83 17 minutes ago It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former. 1 reply →
joshspankit 2 hours ago Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file
That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.
Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.
It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.
1 reply →
Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file