macOS local sandbox: expose an exact Mach/XPC lookup allowlist
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- macos
- Área
- cli, operating-systems, security
Línea de trabajo
Start by tracing the sandbox.userPolicy.seatbelt schema, especially SandboxConfigUserPolicySeatbelt, to the MXC seatbelt.extraMachLookups option. Check the /sandbox policy output and the supplied bootstrap_look_up probe while preserving the separation from keychainAccess. Done means exact configured names are passed through, visible in the effective policy, and unrelated Mach services remain denied.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the feature or problem you'd like to solve
GitHub Copilot CLI's macOS local sandbox does not expose a way to allow a specific third-party Mach/XPC service.
A concrete example is 1Password CLI desktop app integration, which needs to look up:
2BUA8C4S2C.com.1password.browser-helper
This blocks credential-helper chains such as:
aws
-> credential_process
-> credential helper script
-> op CLI
-> NSXPCConnection / mach-lookup
-> 2BUA8C4S2C.com.1password.browser-helper
Granting access to the executables, configuration files, 1Password Unix socket, and network destinations is not enough. Seatbelt treats Mach service discovery as the separate mach-lookup capability.
Copilot CLI 1.0.86-0 exposes only keychainAccess under sandbox.userPolicy.seatbelt. Its installed API schema defines SandboxConfigUserPolicySeatbelt with only that property and additionalProperties: false. Adding extraMachLookups to user settings produces no validation error, but the setting is inert and does not change the effective Seatbelt policy.
keychainAccess is not a substitute for an XPC allowlist. It grants a broad set of Apple Keychain and trust services plus Keychain-related filesystem paths, but it does not allow the third-party 1Password browser-helper service. The remaining workaround is to bypass the sandbox for the command, removing substantially more isolation than this workflow requires.
The underlying Microsoft MXC Seatbelt backend already supports exact-name lookups through seatbelt.extraMachLookups. The missing layer appears to be Copilot CLI's settings/API pass-through to MXC rather than a macOS Seatbelt limitation.
Proposed solution
Expose MXC's exact-name Mach lookup list in Copilot's sandbox policy:
{
"sandbox": {
"userPolicy": {
"seatbelt": {
"extraMachLookups": [
"2BUA8C4S2C.com.1password.browser-helper"
]
}
}
}
}
The minimum implementation could pass each configured value to MXC's existing seatbelt.extraMachLookups field, producing a narrow rule equivalent to:
(allow mach-lookup
(global-name "2BUA8C4S2C.com.1password.browser-helper"))
Suggested security properties and acceptance criteria:
- Accept exact Mach service names only. Reject empty values, glob patterns, regular expressions, and prefix wildcards.
- Keep the setting independent from
keychainAccess. - Include the effective lookup list in
/sandbox policyso the grant is visible and auditable. - Confirm that the configured 1Password helper lookup succeeds while an unrelated Mach service remains denied.
- Do not implicitly grant
mach-register, all Mach lookups, GUI access, Apple Events, or a raw Seatbelt profile override.
Example prompts or workflows
With an AWS profile whose credential_process refreshes through 1Password desktop integration:
List the caller identity for this AWS profile.
The AWS CLI invokes its credential helper, which invokes op. The helper should reach the configured 1Password XPC service without the entire command running outside the sandbox.
Additional context
Environment:
- GitHub Copilot CLI
1.0.86-0 - macOS
26.6.2(25G83) - Apple silicon (
arm64) - 1Password CLI
2.38.1
To isolate the blocked capability from credentials and the rest of the AWS helper chain, I compiled a small probe whose only relevant operation is:
bootstrap_look_up(
bootstrap_port,
"2BUA8C4S2C.com.1password.browser-helper",
&port
);
The probe does not call op, retrieve a credential, access a Unix socket, or make a network request. I ran the identical binary in each context:
| Context | Copilot Seatbelt setting | Result |
|---|---|---|
| Host, outside Copilot's sandbox | Not applicable | Exit 0: mach-lookup allowed |
| Copilot Bash tool in the local sandbox | keychainAccess: true |
Exit 1: mach-lookup failed: 1100 (Permission denied) |
| Copilot Bash tool using an isolated settings directory | Proposed extraMachLookups value |
Exit 1: mach-lookup failed: 1100 (Permission denied) |
The host result confirms that the service is registered. The sandbox result isolates the failure to mach-lookup; unrelated socket, filesystem, network, and Keychain grants cannot satisfy that operation. The isolated-settings result confirms that extraMachLookups is silently ineffective in Copilot 1.0.86-0.
This diagnostic does not reproduce the full credential chain. A sandboxed AWS command can succeed while credentials are cached; the user-visible failure occurs when the helper must refresh through 1Password desktop integration.
Relevant references:
- MXC macOS Seatbelt backend documents
extraMachLookupsas exact service names and describes the broaderkeychainAccessandguiAccessgrants. - anthropics/sandbox-runtime#83 reported the same 1Password XPC limitation; Anthropic subsequently exposed
allowMachLookup. - microsoft/mxc#887 tracks exposure of backend-specific configuration through shared SDK layers.
- Copilot CLI sandbox configuration documentation documents Keychain support but no narrow third-party Mach/XPC allowlist.
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 14 h 16 min
- PR fusionados (30 d)
- 6
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/copilot-cli
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
github/copilot-cli#4932 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/copilot-cli#4909 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/copilot-cli#4906 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4848 ·
-
area:agents area:mcp
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4729 ·
Todos los issues de github/copilot-cli
Issues similares
-
Issue-Enhancement Needs-Triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 86/100
PowerShell/PowerShell#28061 · 2 reacciones ·
-
Feature Request: Add ability to load custom environment variables in linux-exec-server-installer.sh Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
microsoft/vscode-remote-release#11867 ·
-
AuTest Bug Tests
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
apache/trafficserver#13714 ·
-
Update to NCCL 2.32 Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
conda-forge/nccl-feedstock#166 ·
-
Fix codex-seed-model-cache.sh Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
vllm-project/agentic-api#358 · 1 comentario ·