← Back to context

Comment by dcrazy

1 hour ago

That “just” is doing a LOT of work.

It's already done on OpenBSD, and linux has the pieces to do it, though it's far more fragile and complicated. I'm not speaking hypothetically here, I've implemented code that works this way.

  • You are minimizing the difference in scope between the audience and applications of OpenBSD and those of macOS.

    macOS has had a capabilities model for over a decade called App Sandboxing. It would be entirely impractical to expect app authors to correctly declare their permissions up front and for users to audit them. Hence the permissions granted to sandboxed apps are pre-determined by the OS, and can be extended through explicit user interaction.