macOS attributes shell commands to their parent app bundle.
That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.
Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file
That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.