Fix __darwinAllowLocalNetworking
sandbox
#10078
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation
The sandbox rule
(allow network* (local ip))
doesn't do what it implies. Using this rule permits all network traffic. We should be matching on(remote ip "localhost:*")
instead.Context
This is a first step towards fixing #6049
Similar issue experienced in Bazel bazelbuild/bazel#10068.
It's hard to tell because the sandbox is notoriously poorly documented by Apple, but it seems likely that this was working at some point and Apple made a breaking change. Either way, this has been a reported issue since at least 2019 (by other build systems), so I think it's safe to say that MacOS versions where this might still work are obsolete by now.
I tested the following scenarios with
netcat
on MacOS 14.3.1 (23D60) usingsandbox-exec -f sandbox-defaults.sb ...
:_ALLOW_LOCAL_NETWORKING=1
Priorities and Process
Add 👍 to pull requests you find important.
The Nix maintainer team uses a GitHub project board to schedule and track reviews.