New issue
Advanced search Search tips

Issue 799149 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Feature



Sign in to add a comment

10.13 has additional sandbox enforcement policies available

Project Member Reported by kerrnel@chromium.org, Jan 4 2018

Issue description

Thanks to Alex Gaynor from Mozilla for pointing this out. macOS 10.13 has additional enforcement policies that we should investigate:

(deny default)
(deny file-map-executable iokit-get-properties process-info* nvram*)
(deny dynamic-code-generation)


Note that if we use deny file-map-executable, we need an allow file-map-executable for the component flash location.


 

Sign in to add a comment