I don't know how to show the sandbox a running process is contained in, but it's easy enough to show that launchd runs ocspd directly, without sandbox-exec:
It's possible for a process to programmatically place itself in a sandbox (see /usr/include/sandbox.h), but a quick look at the source to ocspd and a quick disassembly of what actually ships with OS X 10.9.2 shows ocspd does not do that.
Comments
How can you tell if a process runs as root or is run within a sandbox?
"ps" will show the effective uid ocspd is running as:
I don't know how to show the sandbox a running process is contained in, but it's easy enough to show that launchd runs ocspd directly, without sandbox-exec: It's possible for a process to programmatically place itself in a sandbox (see /usr/include/sandbox.h), but a quick look at the source to ocspd and a quick disassembly of what actually ships with OS X 10.9.2 shows ocspd does not do that.On a mac Activity Monitor will show you that, also there are also things like top, ps aux and pgrep. These would work:
pgrep -lf -U root | grep processname
or:
ps aux | grep root | grep processname