;;; Copyright (c) 2020 Apple Inc.  All Rights reserved.
;;;
;;; WARNING: The sandbox rules in this file currently constitute
;;; Apple System Private Interface and are subject to change at any time and
;;; without notice.
;;;
(version 1)

;;; Training wheels ON...
(allow (with report) default)
(allow (with report) file-map-executable iokit-get-properties process-info* nvram*)
(allow (with report) dynamic-code-generation)

;;; Training wheels OFF...
;;; (deny default)
;;; (deny file-map-executable iokit-get-properties process-info* nvram*)
;;; (deny dynamic-code-generation)

(deny mach-priv-host-port)

(import "system.sb")
(import "com.apple.corefoundation.sb")
(corefoundation)

(define (home-regex home-relative-regex)
	(regex (string-append "^" (regex-quote (param "HOME")) home-relative-regex)))

(define (home-subpath home-relative-subpath)
	(subpath (string-append (param "HOME") home-relative-subpath)))

(define (home-prefix home-relative-prefix)
	(prefix (string-append (param "HOME") home-relative-prefix)))

(define (home-literal home-relative-literal)
	(literal (string-append (param "HOME") home-relative-literal)))

(allow process-info* (target self))

(allow file-read-metadata)

(allow process-info-codesignature)

(allow user-preference-read user-preference-write
	(preference-domain "com.apple.MobileAccessoryUpdater.GenericKextUpdaterService"))

(allow file-read* file-write*
	(subpath (param "TMPDIR"))
)

(let ((cache-path-filter (home-subpath "/Library/Caches/com.apple.MobileAccessoryUpdater.GenericKextUpdaterService")))
  (allow file-read* file-write* cache-path-filter)
  (allow file-issue-extension
	(require-all
	  (extension-class "com.apple.app-sandbox.read" "com.apple.app-sandbox.read-write")
	  cache-path-filter)))

(allow system-info
    (info-type "net.link.addr")
)

(allow file-read-data
    (subpath "/private/preboot/")
)

(allow file-read*
    (subpath "/private/var/hardware/FactoryData/")
)

(allow iokit-open
    (iokit-user-client-class "AppleFirmwareUpdateUserClient")
)

(allow iokit-get-properties
    (iokit-property "Content")
    (iokit-property "IOClassNameOverride")
    (iokit-property "Protocol Characteristics")
    (iokit-property "boot-objects-path")
    (iokit-property "IOUserClientClass")
    (iokit-property "AIDStartMs")
    (iokit-property "AHTLoaderName")
    (iokit-property "Image Tag")
    (iokit-property "Need FUD Download")
    (iokit-property "FDR Classes")
)
