> sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided.

https://github.com/openssh/openssh-portable/commit/d4b4c304a...

Deprecated since Mountain Lion. https://issuetracker.google.com/40474030

It’s what Apple experimented with before they came up with the current entitlements system.

Entitlements are a great system for user applications, but pretty much unusable for OSS system applications as AIUI they need codesigned binaries

They could have designed a system to put the code signature inside Mach-O but they chose not to.

I wouldn’t really say it compares to entitlements

[deleted]

I look forward to seeing if Apple makes any changes in the fork they ship with the OS: https://github.com/apple-oss-distributions/OpenSSH.

"Updated sandbox for privilege-separated pre-authorization sshd process" is listed as a modification to the open-source project, but I suspect this is out-of-date.

[deleted]

I’m confused why they can’t just write a sandbox profile that does the equivalent

Who is "they" ? AFAIK the OpenSSH team focuses on the OpenBSD version and others people/teams use the new releases to create/update a portable version.

So I think it would be up to the team that ports it to Apple, so I think the "Apple Team" is the ones who would worry about sandboxing.

OpenSSH -portable is maintained by the OpenSSH developers, who are also OpenBSD developers.