[MacPorts] #66358: sip-workaround no longer works on arm64 macOS 13 Ventura due to new security features

MacPorts noreply at macports.org
Sat Dec 16 01:22:37 UTC 2023


#66358: sip-workaround no longer works on arm64 macOS 13 Ventura due to new
security features
-------------------------+-----------------------------------------
  Reporter:  reneeotten  |      Owner:  Clemens Lang <neverpanic@…>
      Type:  defect      |     Status:  reopened
  Priority:  Normal      |  Milestone:
 Component:  base        |    Version:
Resolution:              |   Keywords:  ventura
      Port:              |
-------------------------+-----------------------------------------

Comment (by kencu):

 I was hoping that instead of needing to modify the now-unavailable
 binaries, there might instead be a way to put  a file system trace on
 ${prefix}, and only allowing access to files that have been allowed to be
 accessed.

 picture the equivalent of making a virtual /opt/local populated by
 symlinks to the contents of ports that have been allowed prior to the
 build.

 then you would have the equivalent of trace mode, leaving the binaries
 alone.

 But I don't know enough about how this is done.  chroot, etc ... and I
 haven't explored any of the trace mode code.

-- 
Ticket URL: <https://trac.macports.org/ticket/66358#comment:53>
MacPorts <https://www.macports.org/>
Ports system for macOS


More information about the macports-tickets mailing list