23 ms·
You very much _can_ run unsigned software on Apple silicon. At work my department has a bit less than 50 engineers with Macs (M1 to M4) and nobody complained th
by yaris 11mo ago
You very much _can_ run unsigned software on Apple silicon. At work my department has a bit less than 50 engineers with Macs (M1 to M4) and nobody complained that they can't build and run our product (using GCC from Homebrew, not Clang from Apple). But it involves some jumping through hoops, yes.
- kragen 11mo agoWhat are the hoops?
- yaris 11mo agoAs mentioned above you have to approve the binary two times (at least), being careful the first time because the dialog popup offers to remove the binary. Also since our product has some networking to do one has to mingle with firewall settings to allow the binary to do the networking.
- kragen 11mo agoI see, thanks!
- john_alan 11mo agothis is completely false, compile a binary strip the signature and see for yourself. AS requires code sign with adhoc, minimum.
- yaris 11mo agoTo check I did this: removed the signature (LC_CODE_SIGNATURE section) using lief Python package (no affiliation, just looked suitable for the task), checked by otool that the section is indeed gone, started the binary - it worked. The spctl said that the binary is "rejected", but it says so about every non-Apple binary I checked on my machine so not informative. The codesign tool shows "is not signed at all" on the binary with stripped signature. I'm not too well-versed in OSX system/dev tools, so if there is a more correct/precise method of checking the signatures I'd very much like to know.
- john_alan 11mo agohmmm this is really bizarre. are you running < 15.1?
- yaris 11mo agoNope, 15.7.2. Maybe there are some settings, unknown to me, that are configured by MDM and that allow for such behaviour - our Macbooks are managed by the employer and are intended for development, so would be logical to set them up this way.
- kragen 11mo agoI greatly appreciate having the opportunity to read this dialogue.
- john_alan 11mo ago_A Mac with Apple silicon doesn’t permit native arm64 code to execute unless a valid signature is attached. This signature can be as simple as an ad hoc code signature (cf. codesign(1)) that doesn’t bear any actual identity from the secret half of an asymmetric key pair (it’s simply an unauthenticated measurement of the binary)._ _For binary compatibility, translated x86_64 code is permitted to execute through Rosetta with no signature information at all. No specific identity is conveyed to this code through the device-specific Secure Enclave signing procedure, and it executes with precisely the same limitations as native unsigned code executing on an Intel-based Mac._ Maybe it's Rosetta bins? - src from Apple: https://support.apple.com/en-gb/guide/security/secebb113be1/1/web/1 https://support.apple.com/en-gb/guide/security/secebb113be1/...
- deleted 11mo ago[deleted]