6 ms·
> a degraded user experience, as the first time a user runs a new executable, Apple delays execution while waiting for a reply from their server. The way to av
by davidvartan 6y ago
> a degraded user experience, as the first time a user runs a new executable, Apple delays execution while waiting for a reply from their server.
The way to avoid this behavior is to staple the notarization ticket to your bundle (or dmg/pkg), i.e. "/usr/bin/stapler staple <path>." Otherwise, Gatekeeper will fetch the ticket and staple it for the user on the first run.
(I'm the author of xcnotary [1], a tool to make notarization way less painful, including uploading to Apple/polling for completion/stapling/troubleshooting various code signing issues.)
[1] https://github.com/akeru-inc/xcnotary https://github.com/akeru-inc/xcnotary
- oefrha 6y agoI mean, when I’m developing in a compiled language with the workflow edit code -> compile -> run (with forced stapling), changing it to edit code -> compile -> staple -> run doesn’t make it any less slow...
- davidvartan 6y agoNotarization/stapling/etc. is for distribution only, not generally part of your dev workflow.
- oefrha 6y agoBut TFA and my personal experience do point to a noticeable delay after each recompile in dev workflows, and TFA claims this is due to notarization checks... So I guess I’m confused and you’re talking about something else?
- rgrs 6y agoHow does mac identify a dev workflow and normal workflow?
- jmercouris 6y agoWhen you use XCode you have different compilation options.
- oefrha 6y agoAn update: flat out denying network access to syspolicyd using Little Snitch could cut down on the delay. (Yes, syspolicyd does send a network request to apple-cloudkit.com for every single new executable. Denying its access to apple-cloudkit.com only isn't sufficient either since it falls back to IP address directly.) Note that this might not be a great idea, and it still has nonzero cost — a network request has to be made and denied by Little Snitch. Here's my benchmarking script: #!/bin/zsh tmpfile=$(mktemp) cat >$tmpfile <<EOF #!/bin/sh echo $RANDOM # Use a different script each time in case it makes a difference. EOF chmod +x $tmpfile setopt xtrace time ( $tmpfile ) time ( $tmpfile ) unsetopt xtrace rm -f $tmpfile If your local terminal emulator is immune with "Developer Tools" access (interestingly, toggling it off doesn't bring back the delay for some reason), you should be able to reproduce the delay over ssh.
- davidvartan 6y agoI can repro this locally as well. Interesting if it's inconsistent with Apple docs and when Gatekeeper should be firing, as running stuff locally without distributing/downloading is somewhat out of scope for notarization. Reached out about this to Apple dev support, hope to get more insight.
- abathur 6y ago> interestingly, toggling it off doesn't bring back the delay for some reason Noticed the same; it should come back if you disable it and reboot.
- xenadu02 6y agoXcode (the UI) is able to bypass GateKeeper checks for things it builds. The "Developer Tool" pane in System Prefs, Security, Privacy is the same power. Drag anything into that list you'd like to grant the same privilege (such as xcodebuild). This is inherited by child processes as well. The point of this is to avoid malware packing bits of Xcode with itself and silently compiling itself on the target machine, thus bypassing system security policy.
- closeparen 6y agoThis is life-changing. Thank you!
- pindab0ter 6y agoWhat did you notice?
- LeoPanthera 6y agoPutting Terminal (and your favorite text editor) in this category and in "Full Disk Access" will change your life.
- sneak 6y agoYes, falling victim to ransomware is definitely lifechanging if you don’t have good backups.
- LeoPanthera 6y agoThat is a non-sequitur.
- mperham 6y agoIt's not; they are stating that if you bypass these security checks, you open the machine up to ransomware.
- scottlamb 6y ago> The way to avoid this behavior is to staple the notarization ticket to your bundle (or dmg/pkg) Maybe in some cases, but the article says "even if you write a one line shell script and run it in a terminal, you will get a delay!" Shell scripts don't come in bundles. I don't think this kind of stapling is possible for them? I don't think it'd be reasonable to expect users to do this anyway.
- davidvartan 6y agoThe Gatekeeper behavior is specific to running things from Finder (not Terminal), and only if you downloaded it via a browser that sets the com.apple.quarantine xattr. Two posts from Apple dev support (Cmd+F "eskimo") describe this in more detail. https://forums.developer.apple.com/thread/127709 https://forums.developer.apple.com/thread/127709 https://forums.developer.apple.com/thread/127694 https://forums.developer.apple.com/thread/127694
- nemosaltat 6y agoI recently learned that `xattr -cr path/to/my.app` solves the “this App is damaged would you like to move it to the trash” you get when you copy an app from one Mac to another.
- rhizome 6y agoThat might be the Windows-iest feature of OSX I've ever heard of.
- cosmojg 6y agoIt seems macOS is going downhill fast these days.
- withinboredom 6y agoNo, it’s just that they’re becoming more popular. When you become a popular desktop OS, governments and militaries want to start using it which comes with some strange requirements. It also means that you can’t rely on “obscurity” to provide any sort of security, where before you could overlook some things.
- ihiulll 6y agoI'm confused. does macbook send executable to apple servers or just the hash?
- saagarjha 6y agoJust the hash.
- dahfizz 6y agoThe way to avoid this behavior is to not buy a machine from a company that actively hates it's users.