19 ms·
macOS Sonoma 14.4 might break Java on your machine
- vbezhenar 3y agohttps://blogs.oracle.com/java/post/java-on-macos-14-4 https://blogs.oracle.com/java/post/java-on-macos-14-4
- self_awareness 3y agoI find this hard to accept. Doesn't Apple do pre-release testing of their updates? How the release process looks like? News like these are the major reason why I apply updates only after long periods of waiting if anything blows up for others. Why companies use their userbase as testers?
- jbverschoor 3y ago[flagged]
- agsnu 3y agoFTFA: > The issue was not present in the early access releases for macOS 14.4, so it was discovered only after Apple released the update. There were some security fixes that were marked as under active exploitation in macOS 14.4, so my money is on those landing very steep close to the release date and this being fallout from that.
- jbverschoor 3y agoPlease read the actual bugreport instead of an article written my Oracle's PM who really does not want the crap on his account.
- jbverschoor 3y agoFTBR: "It is also successful on the previous versions of Sonoma" (no mention of EA) "It could not be reproduced on 23-ea+13, 22+36-2370" (EA versions of Java)
- agsnu 3y agoRight so it’s present in all shipping versions of Java back to at least 8, and the reproduction case works fine on Sonoma pre-14.4. Ergo, Apple changed something in 14.4 (a minor patch release), and it broke something in Java. I’m not sure what point you’re trying to make. It’s possible that Java was doing something very weird, maybe undocumented/unsupported; but it’s not clear how this is anything other than Apple making a change (which I don’t see documented in their release notes) and breaking users.
- jbverschoor 3y agoYes, pre 14.4 (14.3.1 to be exact) but NOT early access of macos. The whole thread and Oracle's blogpost is about that it "suddenly broke but it was still working in a preview release of macos". Java DOES work with an EA version of Java according to the bugtrackers. Oracle's PM doesn't know what's going on and is mixing things up.
- bingbingbing777 3y agoSo I can release breaking changes to my API and expect consumers (who are software suppliers themselves) and it's their fault for not instantly updating their code? How is this not Apple when they were the ones that broke it?
- fractalb 3y agoApple should not be at fault! As simple as that.
- dboreham 3y agoDefinitely Apple.
- daghamm 3y agoDid you read Oracles post? "The issue was not present in the early access releases for macOS 14.4, so it was discovered only after Apple released the update." JVM generates code on the fly, which normal applications are not allowed to do. So java by definition receives special treatment from the OS, which OSX seem to have broken now.
- self_awareness 3y agoIt's not that Java has a special treatment, but all applications who "request it" are allowed (for example also JavaScript engines in browsers). https://developer.apple.com/documentation/bundleresources/entitlements/com_apple_security_cs_allow-jit https://developer.apple.com/documentation/bundleresources/en...
- jbverschoor 3y agoI did and also the bugreport. https://bugs.java.com/bugdatabase/view_bug?bug_id=8327860 https://bugs.java.com/bugdatabase/view_bug?bug_id=8327860 It says that "It is also successful on the previous versions of Sonoma", no mention of EA. In the bug report it says it's actually not reproducable with an eary access version of Java "It could not be reproduced on 23-ea+13, 22+36-2370" TBF I'd rather not take Oracle's Product Managment's word for granted.
- grodriguez100 3y agoThere is no “special treatment for Java”. This is a well known technique that has been used for ages in the implementation of JITs. The behavior it relies on is specified by POSIX.
- qwertimus 3y agoStrangely, the issue wasn't present in pre-release builds. I agree though, Apple's internal testing before final release should have picked this up.
- angulardragon03 3y agoThere is some sample C code to test with, and the issue is actually in the pre-releases. It’s just not in the first couple.
- t-sauer 3y ago> News like these are the major reason why I apply updates only after long periods of waiting if anything blows up for others. But then you are accepting that you are running an exploitable OS since you are lacking the latest security fixes. Not sure if that‘s an acceptable tradeoff.
- tchbnl 3y agoApple doesn't EOL the last OS version when the latest comes out. I think they mean they wait a few months to make sure all the issues have been worked out.
- t-sauer 3y agoBut that only works if you stick to old majors. At this point Sonoma is out for almost 6 months, so even if you waited a few months to upgrade to Sonoma you are out of luck now. You are either stuck on 14.3 without security fixes or you upgrade to 14.4.
- xcv123 3y agoWhat's the difference? Wait a month (or whatever) before upgrading to the next major or minor release. My work laptop is stuck on 14.3 for a few weeks until they fix this issue. So what? Actual security risk is practically zero. Whereas if I update to 14.4 today the risk is that I can't do my job.
- usrusr 3y agoThe difference, if I read gp correctly, is that an older major release would still get new security updates when necessary, but if you already are on the current major, which had been out without this problem for quite a while, you will only see security updates bundled with minor feature changes like the one that introduced the JVM incompatibility. Not really an Apple-specific problem, it could hit anyone who supports multiple versions without opening that can of worms of allowing completely free mix&match of fixes and updates.
- yedpodtrzitko 3y agoprevious discussion: https://news.ycombinator.com/item?id=39726292 https://news.ycombinator.com/item?id=39726292
- Symbiote 3y agoMaybe the Oracle blog post [1] would be a better link than the Apple Insider article, which says "The problem does not affect most typical Mac users, as Java was deprecated for the Mac back in 2012." [1] https://blogs.oracle.com/java/post/java-on-macos-14-4 https://blogs.oracle.com/java/post/java-on-macos-14-4
- mikiobraun 3y agoYeah, but all developers who are working with Java or JVM related languages or using JVM based tools like jetbrain's IDEs are affected. That's not "typical" but still many people.
- cataphract 3y agoI think they're confusing the Java plugin for websites with the normal Java runtime.
- mort96 3y agoI can't find that quote in your link. I can't find any mention of the word "deprecated" or "2012". Did you send the wrong link?
- Symbiote 3y agoMy quote is from the 5th paragraph of the posted article. I suggest the Oracle blog as an alternative. I thought it was clear, but I have replaced the "this" in my comment anyway.
- karolist 3y ago> As a normal part of the just-in-time compile and execute cycle, processes running on macOS may access memory in protected memory regions. Prior to the macOS 14.4 update, in certain circumstances, the macOS kernel would respond to these protected memory accesses by sending a signal, SIGBUS or SIGSEGV, to the process. > With macOS 14.4, when a thread is operating in the write mode, if a memory access to a protected memory region is attempted, macOS will send the signal SIGKILL instead. What is bizarre to me is that Oracle relied on receiving SIGSEGV as normal mode of operation. That should have been a hint where things are going, no?
- deleted 3y ago[deleted]
- cataphract 3y ago> What is bizarre to me is that Oracle relied on receiving SIGSEGV as normal mode of operation. That should have been a hint where things are going, no? Not bizarre at all, this how the runtime has always operated, as anyone one who's ever attached a debugger to a Java process knows. The SIGSEGV handler is also responsible to handling NullPointerExceptions IIRC.
- fniephaus 3y agoCorrect: > ... the JVM can intercept the resulting SIGSEGV ("Signal: Segmentation Fault"), look at the return address for that signal, and figure out where that access was made in the generated code. Once it figures that bit out, it can then know where to dispatch the control to handle this case — in most cases, throwing NullPointerException or branching somewhere. https://shipilev.net/jvm/anatomy-quarks/25-implicit-null-checks/#_theory https://shipilev.net/jvm/anatomy-quarks/25-implicit-null-che...
- Vogtinator 3y agoIt's documented and part of the interface for POSIX: > Write attempts to memory that was mapped without write access, or any access to > memory mapped PROT_NONE, shall result in a SIGSEGV signal. > > References to unmapped addresses shall result in a SIGSEGV signal. How a SIGSEGV can be handled by the program to continue execution normally need some OS specific code. For Linux there's also userfaultfd to suit this need better.
- devsda 3y agoI have two emails in my work Inbox in this order. One that says don't update mac os to avoid breaking Java. Another that essentially says upgrade macos to latest version within x days else the issue will be escalated. It is going to be quite a hassle for IT teams across companies to deal with this problem.
- KingMob 3y agoReminds me of this exchange from the bank robbery scene in Raising Arizona: As Gale and Evelle bang in through the door. Evelle holds a shotgun; Gale holds a shotgun in one hand and Nathan Jr. in his car seat in the other. GALE All right you hayseeds, it's a stick- up! Everbody freeze! Everbody down on the ground! Everyone freezes, staring at Gale and Evelle. An Old Hayseed with his hands in the air speaks up: HAYSEED Well which is it young fella? You want I should freeze or get down on the ground? Mean to say, iffen I freeze, I can't rightly drop. And iffen I drop, I'm a gonna be in motion. Ya see - GALE SHUTUP! Promptly: HAYSEED Yessir. GALE Everone down on the ground! EVELLE Y'all can just forget that part about freezin'. GALE That is until they get down there. EVELLE Y'all hear that?
- baq 3y agoBeen saying this for as long as I’ve been using macOS: it is not a developer friendly OS and am close to the conclusion that this reputation is a psy-op. Yeah it’s pretty, it mostly works when the box is first turned on and the hardware is unmatched but macOS itself is actually subpar. QA seems second tier, things you’d except from other OSes like, I don’t know, using a third party second display are just bad experiences. Docker sucks, posix compatibility is technically there but isn’t really useful, the thing randomly loses network and only rebooting fixes it. I reboot my corporate Mac more often than I rebooted my windows enterprise laptop.
- EthicalSimilar 3y agoI’ve been using macOS as my primary development environment for the past ~4 years and have loved every minute of it. I haven’t run into any of the issues you’ve mentioned thankfully, and docker works absolutely fine for my use cases. I can’t see myself ever switching for any reason.
- surgical_fire 3y agoI've been using MacOS for about 5 years, as it is the machine issued by my workplace. And I hate it. It's so much worse than Linux that it's not even a joke. Hell, I think I would have preferred to work on Windows with WSL than this crap. The hardware is not even that good. I presume people like it because it looks slick and serves as a status symbol.
- sneak 3y agoI didn’t realize you were joking until the second paragraph.
- surgical_fire 3y agoThe only joke here is people white-knighting for a manufacturer of luxury toys. How dare someone doesn't like a MBP?
- 3y ago
- ecmascript 3y agoImagine all devs working on macs, myself included. If I were to update and I can't run java, I can't work so this is pretty serious.
- aardvark179 3y agoThis is obviously a problem, but it does appear to be an intermittent one, and not easy to provoke for me. I upgraded last week, and have seen precisely one unexpected exit of a JVM process, and I think that memory analysis toolkit running out of memory, and I have been running a lot of stuff.
- grodriguez100 3y ago“The problem does not affect most typical Mac users, as Java was deprecated for the Mac back in 2012.” This is misleading. What was deprecated was the browser Java plug-in distributed by Apple. That’s very different from “deprecating Java”.
- usrusr 3y agoDidn't they have their own JVM distribution back in the Sun days? The sarcastic take would be on MacOS, third party software is deprecated, period.
- grodriguez100 3y agoYes, Apple had their own Java runtime in the past, but this was discontinued. I think Mojave (10.14) was the first version without official Java support from Apple.
- pocketarc 3y agoI'm on 14.4 and using Jetbrain's IDE. So -this- is the reason my IDE randomly crashes. I'd been chalking it up to 14.4 but didn't have any specifics. It's mostly fine, though. The crashes are rare, and since everything auto-saves, you're not really losing anything. It's just an "oh, okay." moment. Obviously it'll be good when it's fixed, but on my personal list of impactful bugs, this doesn't crack the top 10.
- mikiobraun 3y agoYeah, I've been hearing about that, too. And yeah, it's probably a nuisance. I'm wondering how this extends to running Java inside docker... If you're a dev and you run a lot of Java code locally during development and testing, this would bea real nuisance... .
- grodriguez100 3y agoI find it difficult to imagine how a change like this (sending a SIGKILL to the process instead of SIGSEGV on a page fault) can be done in the final release and not in one of the EA releases or betas. It is clearly a breaking change with no easy workaround (since SIGKILL cannot be caught), for a behaviour which is well defined by POSIX. Even if you momentarily ignore the reasons why someone thought this could be a good idea, why not do it in one of the pre-releases or betas??? Doesn’t look like the kind of thing you’d want to do in a last minute change. The real problem in my opinion is the fact that you cannot go back after a macOS upgrade. So if something like this happens, you literally have no option but waiting for Apple to release a fix, if they want to do it at all.
- lupusreal 3y agoIt sounds like the kind of half-baked change a junior dev might come up with, but lord knows how it made it through code review and into a release.
- raverbashing 3y agoThat's easy to guess The good kernel engineers are working on iPhone or Vision Pro, not on MacOS
- t-sauer 3y agoDon't they all use the same kernel?
- pjmlp 3y agoNo, because naturally it is different kind of requirements and space is at a price as well. Technically it is kind of the same, but with different set of configured features. Already a bit oldie, "Mac OS X and iOS Internals: To the Apple's Core" https://www.amazon.com/Mac-OS-iOS-Internals-Apples/dp/1118057651 https://www.amazon.com/Mac-OS-iOS-Internals-Apples/dp/111805...
- 3y ago
- t-writescode 3y agoI'm not comfortable upgrading my macbook to test this; but, if you migrate your java build pipeline to use a docker container for the jdk, do you think it might not run into this problem?
- Karupan 3y agoSo this will break IDEs and anything that uses the JVM natively on macOS. But if I’m reading the bug report right, should leave dockerized JVM services intact? This is why most enterprise workplace tech teams don’t roll out any OS level updates immediately. Regardless of whether they are on windows or macOS. Also a good idea to disable automatic updates on all devices that you use daily.
- mikiobraun 3y agoYeah, I was also wondering what happens to JVM within docker. I don't really know enough about how deep the virtualization goes... . On the other hand, I'd find it difficult if CPU level signal handling would be emulated within MacOS to fit what Linux expects to happen...
- aden1ne 3y agoDocker on MacOS runs through a Linux VM. Native containerization on MacOS is so badly supported many container runtimes don't even try. E.g. Podman on MacOS also runs through a Linux VM.
- Mashimo 3y ago> The problem does not affect most typical Mac users, as Java was deprecated for the Mac back in 2012. Haha, this article is quite something :D The Java Applet was removed from the safari browser. That is unrelated to java apps running on the desktop.
- mihau 3y agoDoes Apple consider this to be a serious issue? Does anyone know if Apple plans to release a fix soon, perhaps in version 14.4.1?
- neonsunset 3y ago[flagged]
- lynguist 3y agoUse Rider and you will. How do you develop .NET?
- neonsunset 3y agoHaha, touché! AFAIK JB are quite conservative when it comes to bumping up JVM (or .NET for that matter) versions for their tooling. Rider aside, I do most input in VS Code and occasionally Visual Studio (when not using laptop) because it has really nice extension Disasmo which helps a lot to iterate on methods quickly for low-level optimization.
- classified 3y agoI won't "upgrade" to Sonoma at all. I'm done with Apple shitting all over my apps and data.
- chrismsimpson 3y agolol, Java has been broken for some time and I’m convinced Apple do this intentionally
- dickersnoodle 3y agoOh, no. Anyway...
- dangus 3y agoThis is affecting me on Minecraft Java Edition.
- pdimitar 3y agoSo I ranted about macOS a month ago here -- https://news.ycombinator.com/item?id=39369788 https://news.ycombinator.com/item?id=39369788 -- and in the meantime my Alacritty and iTerm2 began doing cold start up for 2-3 seconds now (granted they get cached so the cold start delay does not happen more than two or three times a day) and I am just left scratching my head and wondering WTF are the macOS devs thinking. As other posters said: macOS might have had an edge over Windows and Linux before but that's no longer the case for a few years now. I'll definitely be looking for ways to use 5K display with my Linux laptop and will likely make a full transition to Linux in the next year or two. Macs have amazing displays. So I'll use mine as thin clients I suppose. My eyes are happier with an Apple display so I'll use them for that alone. Apple can still turn this around but their bogus security claims that serve mostly to annoy devs is them shooting themselves in the foot and making themselves a very uncomfortable bed to sleep in just some very short years in the future. Hope somebody at HQ understands that and is able to see the problem before too many people leave.
- baxuz 3y agoGood thing that the changelog for the 3gb update only mentions emoji and podcasts: macOS Sonoma 14.4 introduces new emoji as well as other features, bug fixes and security updates for your Mac. Emoji • New mushroom, phoenix, lime, broken chain and shaking heads emoji are now available in emoji keyboard • 18 people and body emoji support facing the opposite direction This update also includes the following improvements and bug fixes: • Podcasts Episode text can be read in full, searched for a word or phrase, clicked to play from a specific point, and used with accessibility features such as Text Size, Increase Contrast and VoiceOver • Safari Favourites Bar adds an option to show only icons for websites
- croes 3y ago"It just works" ... not
- 23ioj2oij23 3y agoMacOS is the worst OS on planet. I lost all my data after MacOS updated to 14.x from 13.x, because the laptop stopped starting after update and apple employees have to factory reset the entire system. And unlike any other laptop, where you can just remove hard drive and save your data, this is not possible on Apple devices, because HDD cannot be removed... Also since 14.x in on my laptop, it restarts EVERY SINGLE DAY. I also have a lot of other issues, but I will not write a book here. This was the last time I bought something from Apple.
- kjkjadksj 3y agoApple has a great backup tool called Time Machine that would have had you whistling a different tune if it were used before your system failure (which can happen with any system fwiw).
- KingOfLechia 3y agoWindows 10 IoT Enterprise LTSC doesn't have this problem.
- kernal 3y agoAccording to the bug tracker changing it from a WRITE to an EXEC avoids the SIGKILL issue.
- ZephyrOhm 3y agoJava? Who's still running Java on their PCs? Wild.
- not_me_ever 3y agoBroken software might crash -- no news move on
- kaycey2022 3y agoSonoma has been trash so far. I faced an issue where they changed they way linking is done in the new Xcode version and that broke builds for erlang. This is so bad that programs that run on versions of OTP prior to 25 don’t work on the m1 macs anymore. At least last time I checked. Yes, this affects Xcode primarily but still it makes one think what the hell is going on over there. They basically bamboozled us with fancy wallpapers and gave us this immensely substandard software.
- rsaddey 3y agoHas anyone here actually experienced the SIGKILL? M1 Pro Max on 14.4 for ten days now, using Eclipse & Tomcat & whatever Java all the time, and still waiting for it to happen...
- rsaddey 3y agoAnd yes, I did just now. I had to work for 10 hours to let Eclipse crash...
- rsaddey 3y agoHas anyone as yet designed a work-around? My thought is to (at least partially) avoid JIT compiliations. This will of course greatly reduce performance (50 times slower?). But with GUI programs, such as Eclipse, it will hopefully hardly be noticeable.