Bug 1388360 - remove access to the com.apple.iconservices mach service from content processes; r?haik
MozReview-Commit-ID: D20alO2PKR0
--- a/security/sandbox/mac/SandboxPolicies.h
+++ b/security/sandbox/mac/SandboxPolicies.h
@@ -181,18 +181,17 @@ static const char contentSandboxRules[]
(ipc-posix-name-regex "^AudioIO"))
(allow signal (target self))
(allow mach-lookup
(global-name "com.apple.coreservices.launchservicesd")
(global-name "com.apple.pasteboard.1")
(global-name "com.apple.audio.coreaudiod")
- (global-name "com.apple.audio.audiohald")
- (global-name "com.apple.iconservices"))
+ (global-name "com.apple.audio.audiohald"))
; bug 1376163
(if (>= macosMinorVersion 13)
(allow mach-lookup (global-name "com.apple.audio.AudioComponentRegistrar")))
; bug 1312273
(if (= macosMinorVersion 9)
(allow mach-lookup (global-name "com.apple.xpcd")))