These entitlements are not easy to configure properly and most developers should not be using these services.
Also simplify how to opt into enabling sandboxing entitlements for the Downloader XPC Service.
They should not be bundle IDs because they may surface up in the UI.
Particularly, the Installer XPC Service may show up in the authorization prompt when authorization is required to install an update.
We now use XPC for communication between Sparkle.framework and Autoupdate.
Autoupdate is now ran as a launchd agaent/daemon. (Most of the time, it acts as an agent).
Using XPC can only be done from non-sandboxed processes, so a connection and status service had to be created.
Currently, the GUI progress tool doesn't work properly, but everything else should be behaving like before.