Feedback ticket for the documentation: FB17345983
But as a third-party developer I’m not sure that’s a significant restriction. If you’re building your own daemon or agent, you can bake spawn constraint into its code signature.
This would protect the daemon or agent from being launched by an unexpected executable.
BUT this would not prevent the launchd plist from starting an executable at the path pointed by the plist but which is not the expected executable.
Topic:
Privacy & Security
SubTopic:
General
Tags: