Remix.run Logo
▲ brynet 6 hours ago

> sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided.

https://github.com/openssh/openssh-portable/commit/d4b4c304a...

▲kccqzy 5 hours ago | parent | next [-]

Deprecated since Mountain Lion. https://issuetracker.google.com/40474030

It’s what Apple experimented with before they came up with the current entitlements system.

▲djmdjm 3 hours ago | parent | next [-]

Entitlements are a great system for user applications, but pretty much unusable for OSS system applications as AIUI they need codesigned binaries

▲kccqzy an hour ago | parent [-]

They could have designed a system to put the code signature inside Mach-O but they chose not to.

▲ 5 hours ago | parent | prev | next [-]
[deleted]
▲saagarjha 3 hours ago | parent | prev [-]

I wouldn’t really say it compares to entitlements

▲mrpippy 4 hours ago | parent | prev | next [-]

I look forward to seeing if Apple makes any changes in the fork they ship with the OS: https://github.com/apple-oss-distributions/OpenSSH.

"Updated sandbox for privilege-separated pre-authorization sshd process" is listed as a modification to the open-source project, but I suspect this is out-of-date.

▲ 3 hours ago | parent [-]
[deleted]
▲saagarjha 3 hours ago | parent | prev [-]

I’m confused why they can’t just write a sandbox profile that does the equivalent

▲jmclnx 2 hours ago | parent [-]

Who is "they" ? AFAIK the OpenSSH team focuses on the OpenBSD version and others people/teams use the new releases to create/update a portable version.

So I think it would be up to the team that ports it to Apple, so I think the "Apple Team" is the ones who would worry about sandboxing.

▲brynet an hour ago | parent [-]

OpenSSH -portable is maintained by the OpenSSH developers, who are also OpenBSD developers.