OS X -> macOS

(cherry picked from commit c20641ce56)
This commit is contained in:
Eelco Dolstra 2017-06-12 14:04:52 +02:00
parent 1dcadadf74
commit a10951de08
No known key found for this signature in database
GPG Key ID: 8170B4726D7198DE

View File

@ -19,7 +19,7 @@ filter. Note that this imposes a small performance penalty (e.g. 1%
when building GNU Hello). Using seccomp, we now also prevent the when building GNU Hello). Using seccomp, we now also prevent the
creation of extended attributes and POSIX ACLs since these cannot be creation of extended attributes and POSIX ACLs since these cannot be
represented in the NAR format and (in the case of POSIX ACLs) allow represented in the NAR format and (in the case of POSIX ACLs) allow
bypassing regular Nix store permissions. On OS X, the restriction is bypassing regular Nix store permissions. On macOS, the restriction is
implemented using the existing sandbox mechanism, which now uses a implemented using the existing sandbox mechanism, which now uses a
minimal “allow all except the creation of setuid/setgid binaries” minimal “allow all except the creation of setuid/setgid binaries”
profile when regular sandboxing is disabled. On other platforms, the profile when regular sandboxing is disabled. On other platforms, the