Earlier quoted context omitted.
Most ridiculous one for me so far: - downloaded json file from my own GitHub account - double click to open in VSCode, Apple says no - try the usual tricks (holding alt and right clicking, i guess), no - drag and drop file into Code, no - right click>get info, lo and behold: the entire file contents displayed in the Get Info preview pane for me to copy I'm actually getting a Windows laptop to do some testing on and i…
Huh? JSON? Did you insert executable preamble bytes and chmod the file to execute or something? Where is this file? Can you post a link? My work issued MacBook is incapable of running unsigned binaries enforced by the MDM kext, and I do all sorts of development all day long. Occasionally I have to resign a precompiled dylib if it was compiled on a coworkers machines, but that’s it. I have never seen anything like you…
Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
291–300 of 301 posts
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#292Earlier quoted context omitted.
Apple Silicon cannot boot Windows ARM and Apple is dropping boot camp support alongside x86 support in the near future.
> Apple Silicon cannot boot Windows ARM That's totally up to Microsoft… they could done a licensing deal with Apple years ago to enable Windows ARM to run natively on Apple Silicon hardware.
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#293Earlier quoted context omitted.
> softwareC # available in nixpkgs, but because nixpkgs maintainers are hardline purists it takes 15 minutes to compile from source and ain't nobody got time for that Which package is that? Is it proprietary but source available? Any free software which is built from source is built by hydra and available from the binary cache to downstream users.
Terraform is a notable example yeah. Takes like 7 minutes to compile it when you would get it in seconds by pulling the binary
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#294Earlier quoted context omitted.
To check I did this: removed the signature (LC_CODE_SIGNATURE section) using lief Python package (no affiliation, just looked suitable for the task), checked by otool that the section is indeed gone, started the binary - it worked. The spctl said that the binary is "rejected", but it says so about every non-Apple binary I checked on my machine so not informative. The codesign tool shows "is not signed at all" on the…
hmmm this is really bizarre. are you running < 15.1?
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#295Earlier quoted context omitted.
> softwareC # available in nixpkgs, but because nixpkgs maintainers are hardline purists it takes 15 minutes to compile What actually happened is that non free software may not be legal to distribute from nixpkgs caches, so you're on your own with building those. That's not really a purist approach.
Only because the purist inventors of nixpkgs structured the policy of what must go into nixpkgs to have this rule. Why doesn’t the same limitation exist for homebrew, for instance? It isn’t some idiosyncracy of the way they are building things, it was a conscious and deliberate policy decision. And it might be the right one for what they are trying to achieve, but if the goal of the project is to make it more accessi…
No. Both lib.licenses.unfree and lib.licenses.unfreeRedistributable are accepted into Nixpkgs, but the former marker indicates that the developer has declared it illegal to distribute builds so the official binary cache (sorry, “substituter”) does not.
What Homebrew likely does is fetch the upstream binaries from the upstream download server. Nixpkgs does have a policy against that when buildable source code is available, but that’s mostly because the way Nix achieves isolation (both from the host system and between packages) is by placing almost all shared libraries and data files in hash-decorated places that are emphatically different from what an upstream binary expects. On Linux, it’s possible, if very distasteful, to cram that peg into this hole using mount namespaces and bind mounts (see buildFHSEnv et al.); not sure about Darwin, but the general response to asking Nixpkgs maintainers to keep this sort of fragile mess working is, indeed, pretty much exactly “ain’t nobody got time for that”.
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#296Earlier quoted context omitted.
hmmm this is really bizarre. are you running < 15.1?
Nope, 15.7.2. Maybe there are some settings, unknown to me, that are configured by MDM and that allow for such behaviour - our Macbooks are managed by the employer and are intended for development, so would be logical to set them up this way.
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#297Homebrew is not really pro in any way: they force updates, deprecate old software that is still widely in use, the maintainers are always very combative and dont allow any discussions or other opinions. In the end it's a package manager for consumers that hand holds you and is not really useful in a pro context. I've been meaning to jump to macports anyway, maybe ill do it now...
As someone who migrated from macports to Homebrew, I'd like to see a third option (or maybe re-investigate macports again to see what's changed recently). Homebrew's insistence on leaving OSes behind that they deem to be "too old" is becoming a problem as the years click by. One of the reasons to use third party software and a third party package manager is to avoid Apple's own insistence on abandoning old OSes. Home…
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#298Earlier quoted context omitted.
hmmm this is really bizarre. are you running < 15.1?
Nope, 15.7.2. Maybe there are some settings, unknown to me, that are configured by MDM and that allow for such behaviour - our Macbooks are managed by the employer and are intended for development, so would be logical to set them up this way.
_For binary compatibility, translated x86_64 code is permitted to execute through Rosetta with no signature information at all. No specific identity is conveyed to this code through the device-specific Secure Enclave signing procedure, and it executes with precisely the same limitations as native unsigned code executing on an Intel-based Mac._
Maybe it's Rosetta bins? - src from Apple:
https://support.apple.com/en-gb/guide/security/secebb113be1/...
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#299I don't understand what this means, although I've read the whole thread. Does this mean people won't be able to use Homebrew to compile software from source (and run it)? Does it mean that they'll be able to use Homebrew to compile software from source, but not download prebuilt binaries (and run them)? Does it mean that they'll be able to download prebuilt binaries, but only run them if they're built by a developer…
All it means is that applications downloaded/installed via Homebrew will no longer be able to bypass the Gatekeeper signing/notarization requirement on Intel platforms (already is the case on Arm). If you didn't need to install a cask with this flag before you won't be impacted by the deprecation.
Re: Homebrew no longer allows bypassing Gatekeeper for unsigned/unnotarized software
#300Alacritty is seemingly affected by this, which sucks for people who install it from homebrew because there's no way the developers are going to shell out to Apple for the signature. https://github.com/alacritty/alacritty/issues/8749 Does anyone know if self-signed binaries will work?
Alacrity is one of my casks. I'm not tied to it. Alternatives? I guess I could just go back to terminal. Here's my other casks: cask "aerospace" cask "alacritty" cask "betterdisplay" cask "emacs" cask "espanso" cask "hammerspoon" cask "jordanbaird-ice" # ice cask "gimp" cask "inkscape" cask "maccy" cask "mactex" cask "macwhisper" cask "qmk-toolbox" cask "zoom"