202
edits
Haftandilian (talk | contribs) (Comments on system.sb) |
Haftandilian (talk | contribs) (system.sb) |
||
| Line 45: | Line 45: | ||
| | | | ||
<pre style="border:none;">(import \"/System/Library/Sandbox/Profiles/system.sb\")</pre> | <pre style="border:none;">(import \"/System/Library/Sandbox/Profiles/system.sb\")</pre> | ||
This excerpt it what is enabled for us. | This excerpt it what is enabled for us. The file also defines some macros, but they're not used in the file or by our rules. Namely "(define (system-network) ...)" and "(define (system-graphics) ...)". | ||
<small> | |||
<pre style="border:none;"> | <pre style="border:none;"> | ||
... | ... | ||
| Line 121: | Line 123: | ||
(allow sysctl-read) | (allow sysctl-read) | ||
</pre> | </pre> | ||
</small> | |||
|| | || | ||
This imports all the sandbox policy directives in the file /System/Library/Sandbox/Profiles/system.sb which ships with OS X. | This imports all the sandbox policy directives in the file /System/Library/Sandbox/Profiles/system.sb which ships with OS X. | ||
|- | |- | ||
| | | | ||
edits