4 ms·
> Are the capabilities of Apple's user-level APIs sufficient to replace most legitimate uses of kernel extensions? From what I remember reading from some macOS
by webmobdev 5y ago
> Are the capabilities of Apple's user-level APIs sufficient to replace most legitimate uses of kernel extensions?
From what I remember reading from some macOS Application Firewall makers, no. (And that's ofcourse, intentional.)
While it is true that poorly coded Kernel extensions can make an OS unstable, this is just another example of Apple taking away more control from its users and further crippling macOS to make it more like ios.
- least 5y agoAfter feedback from aforementioned firewall developers, changes were made to network extensions that allowed them to do what they wanted with their applications (for the most part, at least). I still think that it’s a worse in-practice system than kexts but they are responding to feedback at least. You can still load kernel extensions in Big Sur by disabling SIP, though.
- no_time 5y agoI wonder how far away are we from governments mandating SIP and equivalents to be turned on to connect to the internet.
- IfOnlyYouKnew 5y agoWell, I'm glad to see even the cynics can't find an evil motive here, and has to resort to just assuming stupidity. That, however, isn't easy to do, considering Apple has a rather impressive track record of creating products people enjoy and buy. And to jump two replies ahead: them trying to make it "easy" and "save" doesn't imply their users are idiots. Quite a few developers and scientists use Macs, and the lawyers aren't exactly dumb either. Spending hours trying to somehow get both sound and bluetooth to work at the same time, a favourite pastime on Linux, means lifetime wasted for something that shouldn't need doing. And considering nobody reads the source, there is no reason to believe some "expert" has some ability to avoid installing that one extension that soon starts encrypting their files. At least they tend to have better backups...
- Hackbraten 5y agoIronically, kexts allow me to have better backups in the first place. APFS won’t check for bit rot, nor does it allow to make snapshots. OpenZFS enables both, and works with a kext. I don’t know whether Apple will allow that use case in the future. I don’t like the way this is going.
- yehaaa 5y agoYou can definitely make snapshots on APFS. It also use checksums for filesystem integrity.
- Hackbraten 5y ago> You can definitely make snapshots on APFS. Apple can. I can’t. Making APFS snapshots requires special entitlements, which they’re not going to give me. > It also use checksums for filesystem integrity. It doesn’t check integrity of the actual data though. But I care about my data.
- yehaaa 5y agoYou can use tmutil to create a snapshot. Or do you want to create an app that performs a snapshot via some API.
- Hackbraten 5y agoOne does not simply create an APFS snapshot using tmutil. Using tmutil means Time Machine creates a snapshot for me. It also conveniently earmarks the snapshot for later removal at Time Machine’s own discretion. That’s not what I want. I want to have a say in snapshot retention, not have some tool make the decision for me. Specifically, I need precise control over snapshot retention so I can maintain several off-site replicas of my backup.
- CharlesW 5y ago> Apple can. I can’t. Making APFS snapshots requires special entitlements, which they’re not going to give me. What makes you think that? Carbon Copy Cloner does this, and is made by a small independent developer. https://bombich.com/kb/ccc6/leveraging-snapshots-on-apfs-volumes https://bombich.com/kb/ccc6/leveraging-snapshots-on-apfs-vol...
- leokennis 5y ago> While it is true that poorly coded Kernel extensions can make an OS unstable, this is just another example of Apple taking away more control from its users and further crippling macOS to make it more like ios. It isn't. They are making it (very) less likely for average simpleton users like myself to expose or fuck up their system. And for the more elite hackers such as yourself who absolutely want to load third party kernel extensions, they require you to disable SIP. The knowledge and work it takes to do that is a very nice "I hereby declare I know what I'm doing and I alone bear the responsibility if things go wrong" entry barrier.