This is a repository of profiles for Apple's sandbox-exec
for usage with different Applications.
All profiles have been somewhat reverese-engineered by using the following boilerplate for a
file. And after creation of the first profile with which the app actually starts the output of executed as root via sudo.
(version 1)
(deny default)
(trace "")
What these three lines do is to do two things.
First: ignore (deny default)
and allow everything to enable execution as usual
Second: Log everything that would otherwise have been denied into
This might look like this:
(version 1) ; Sun Aug 13 14:26:31 2017
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow ipc-posix-shm-read-data (ipc-posix-name "/tmp/"))
(allow iokit-open (iokit-registry-entry-class "RootDomainUserClient"))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow mach-lookup (global-name ""))
(allow file-read-data (path "/Library/Application Support/CrashReporter/"))