Can you please confirm if my findings are accurate and sandboxed apps fail to read the com.apple.system.Security EA by design? No, I don't think that's correct. You can see the code here but I believe that xattr was set up as the fallback storage mechanism which the VFS system uses if the can't retrieve the data through ATTR_CMN_EXTENDED_SECURITY. As far as directly reading the xattr, the vfs layer is what blocks that, not the sandbox, through this check. However, my bigger question here is what you mean by read. ACL enforcement and validation happens in the kernel, not user space, so a process doesn't really read its ACL, whether or not it's stored in an xattr. I don't know what's going on here, but the general theory you're describing doesn't really make sense to me. Have you tried starting with a minimal test app that's sandboxed and directly access the file? I'd start with our basic app template with the sandbox enabled, then use the File Access Entitlement to hard code
Topic:
App & System Services
SubTopic:
Core OS
Tags: