(subpath "/Library/Managed\ Preferences")
(subpath "/Library/Preferences")
(subpath "/private/var/root")
- (literal "/private/var/db/mds/messages/se_SecurityMessages"))
+ (literal "/private/var/mobile/Library/Caches/com.apple.MobileGestalt.plist")
+ (literal "/private/var/db/mds/messages/se_SecurityMessages")
+ (literal "/private/var/db/icu"))
(allow file-write*
(literal "/private/var/run/racoon.sock")
(allow mach-lookup
(global-name "com.apple.SecurityServer")
(global-name "com.apple.SystemConfiguration.configd")
- (global-name "com.apple.ocspd"))
+ (global-name "com.apple.ocspd")
+ (global-name "com.apple.commcenter.xpc")
+ (global-name "com.apple.aggregated")
+ (global-name "com.apple.cfprefsd.daemon")
+ (global-name "com.apple.cfprefsd.agent")
+ (local-name "com.apple.cfprefsd.agent")
+ (global-name "com.apple.nehelper"))
+
+(allow ipc-posix-shm-read*
+ (ipc-posix-name-regex #"^apple\.shm\.cfprefsd\."))
;;;;;; Common system sandbox rules
;;;;;;