upvote
If you try to ls / for example it's going to pop up a request to access your disk, multiple times. It's rather annoying.
reply
Why would ghostty try to access your disk when you run 'ls /'? ghostty isn't opening any files -- ls is.
reply
The TCC system attributes the access to Ghostty because that’s the thing the user understands as the app they are interacting with. Otherwise every `posix_spawn()` and `system()` call would result in a new TCC prompt attributed to an inscrutable name.
reply
macOS attributes shell commands to their parent app bundle.
reply
That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.
reply
Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.
reply
It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.
reply
That “just” is doing a LOT of work.
reply
It's already done on OpenBSD, and linux has the pieces to do it, though it's far more fragile and complicated. I'm not speaking hypothetically here, I've implemented code that works this way.
reply
You are minimizing the difference in scope between the audience and applications of OpenBSD and those of macOS.

macOS has had a capabilities model for over a decade called App Sandboxing. It would be entirely impractical to expect app authors to correctly declare their permissions up front and for users to audit them. Hence the permissions granted to sandboxed apps are pre-determined by the OS, and can be extended through explicit user interaction.

reply
This is really hard to do in general
reply
It's done on the majority of the OpenBSD base system, as well as important ports like Chrome and Firefox. Linux also has the parts to do this, though it's more fragile and complicated.
reply
Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file
reply