4 ms·
You can `sandbox-exec`. But that probably wouldn’t be useful for a program like little-snitch, which needs rather broad permissions normally.
by Kejistan 6y ago
You can `sandbox-exec`. But that probably wouldn’t be useful for a program like little-snitch, which needs rather broad permissions normally.
- jldugger 6y agoThe sandbox-exec command is DEPRECATED. Developers who wish to sandbox an app should instead adopt the App Sandbox feature described in the App Sandbox Design Guide. The sandbox-exec command enters a sandbox
- Wowfunhappy 6y agoDoes it work though?
- comex 6y agoIt works, but you have to supply your own sandbox profile (list of allowed/denied operations) and it won’t create a virtual home directory for you like App Sandbox does. I’m not sure whether there’s an easy way to forcibly enable App Sandbox, but one possibility is to compile your own sandboxed app that simply execs the untrusted one. (Sandboxes are inherited by child processes, as they must be for security.)
- oefrha 6y agoIt works, and Homebrew is a high profile example of software that uses sandbox-exec extensively (bottling CI and brew install from source build formulae in sandboxes so that build scripts can’t read/write whatever they feel like; so do tests).
- saagarjha 6y agoAll of sandboxing (including sandbox-exec, which is like 10 lines of code to just call the sandboxing functions) is considered deprecated/Apple private. As it’s the way to do such things on macOS, however, some very popular software depends on it in addition to Apple’s: Chrome, Firefox, MacPorts, Homebrew, …