Finder is not lying at all. The permissions it shows in “Get Info” are the user/group permissions; not app permissions.
Maybe Apple could enhance the UX somehow to better what’s going on, but I wouldn’t go as far as to say Finder is lying.
Finder is not lying at all. The permissions it shows in “Get Info” are the user/group permissions; not app permissions.
Maybe Apple could enhance the UX somehow to better what’s going on, but I wouldn’t go as far as to say Finder is lying.
There’s missing nuance there. The “full disk access” and similar permissions apply even if an app is not using the traditional macOS Sandbox. Only software from the Mac App Store is required to use the traditional Sandbox, but the restrictions on disk access to certain directories apply to all processes not whitelisted (implicitly or explicitly), regardless of Sandboxing.
This nuance is somewhat important because an app listed “Sandbox: No” in e.g. Activity Monitor is still subject to disk access restrictions.
Nit: not every App Store app must be sandboxed.
> 2.4.5 Apps distributed via the Mac App Store have some additional requirements to keep in mind: (i) They must be appropriately sandboxed
[1] https://developer.apple.com/app-store/review/guidelines/
I'm not.
It’s just more sour grapes about SIP. Tough luck, it’s there to stay, if you don’t like it, turn it off.
The chattr/lsattr commands are used for accessing them.
The only time I've seen these come up are for secure locations that set log files to append-only. But I'm sure there are people out there that swear by extended attributes.