Comment by microtherion
11 hours ago
The certification was always a bit odd, applying only to a configuration nobody would run in practice: https://www.osnews.com/story/141633/apples-macos-unix-certif...
11 hours ago
The certification was always a bit odd, applying only to a configuration nobody would run in practice: https://www.osnews.com/story/141633/apples-macos-unix-certif...
The certification documents read like the world's most abstruse bar trivia quiz...
"1.12 Threads
1.12.1 Cancellation Points
Question 31: Which C stdio functions have cancellation points that occur when a thread is executing?"
https://www.opengroup.org/csq/repository/noreferences=1&RID=...
If you'd try to certify any modern Linux distribution, you'd end up with a very similar list.
- The Linux kernel also has timer coalescing
- Linux also has lazy atime ('relatime') by default
- No Linux distro installs uucp by default, and certainly not suid
- Desktop distros will also run a file indexer of some sort
etc.
Isn’t the difference here that Linux was never trying to claim UNIX certification?
If I remember correctly, two Linux variants were on the list at one time.
They were:
Inspur K-UX (expired on 3 February 2019)
Huawei EulerOS (expired in September 2022)
https://en.wikipedia.org/wiki/Inspur_K-UX
https://en.wikipedia.org/wiki/EulerOS
These were both based on Red Hat.
And famously, GNU's Not UNIX
Huawei managed to get their RHEL fork (EulerOS) UNIX certified. However their certificate expired (probably due to sanctions?)
So legally at one point a Linux was Unix.
I had no idea there was a built-in way to make the filesystem case sensitive. My employer probably does not want me to spend time reinstalling my OS for this now but maybe next time I'm given a MacBook for a job I should do this...
[delayed]
Curiously, the iOS filesystem is case-sensitive. A bit of a trap for developers on macOS. I’d expect plenty of third-party stuff to break switching the system drive to case-sensitive.
Makes sense; the iOS filesystem isn't exposed to the user, but macOS' is.
The relevant text from the article, (the rest of this comment is a direct quote from the article):
So, if you want your installation of macOS 15.0 to pass the UNIX® 03 certification test suites, you need to disable System Integrity Protection, enable the root account, enable core file generation, disable timeout coalescing, mount any APFS partitions with the strictatime option, format your APFS partitions case-sensitive (by default, APFS is case-insensitive, so you’ll need to reinstall), disable Spotlight, copy the binaries uucp, uuname, uustat, and uux from /usr/bin to /usr/local/bin and the binaries uucico and uuxqt from /usr/sbin to /usr/local/bin, set the setuid bit on all of these binaries, add /usr/local/bin to your PATH before /usr/bin and /usr/sbin, enable the uucp service, and handle the mystery issues listed in the four Temporary Waivers.
Then, and only then, is your macOS 15.0 actually UNIX® 03-certified.
This is batshit insane. I can guarantee you with 100% certainly not a single macOS installation in the entire history of macOS – let alone when just counting macOS 15.0 – has implemented even half of these changes. I’m sure there is a small number of people who have System Integrity Protection disabled permanently, and an even smaller number of people who have enabled the root account, and an even smaller number of people who have done both of those things – but that’s it. All the other changes are far too obscure and specific to be of any use to anyone.
This uucico stuff is funny. Do you think there is anyone actually using UUCP on MacOS?
The certification also was kind of bad at actually checking that the standard interfaces behaved as they should.
That’s a bit of a weird article and I’m not 100% sure what its point is.
> This is batshit insane. I can guarantee you with 100% certainly not a single macOS installation in the entire history of macOS – let alone when just counting macOS 15.0 – has implemented even half of these changes.
Well, maybe that means it doesn’t really matter and especially not to the extent that the author seems (?) to be making it out to be. If no one disables System Integrity Protection in order to be UNIX® 03-compliant, maybe that means that to the extent that people care about macOS being “a UNIX”, they don’t care specifically about the parts of the specification that are incompatible with System Integrity Protection.
Reminds me of (technically) POSIX compatible Windows.
My first exposure to ‘compliance is not equivalence’.
"""POSIXLY_CORRECT (originally proposed as POSIX_ME_HARDER) is a historical environment variable used in GNU utilities to force strict compliance with the POSIX standard."""
ah, yes! https://en.wikipedia.org/wiki/Microsoft_POSIX_subsystem
the netbsd gallery (https://netbsd.org/gallery/) had a picture of somebody using that on windows xp (iirc) in order to compile pkgsrc packages in a "posix compliant" environment. the picture seem to be gone now :(
The whole UNIX certified thing is a bit odd to start with, but those addendums are really just saying that because the UNIX compliance tests are thoroughly stuck in the past, a bunch of security measures (that users expect to exist on modern systems) have to be disabled to run the test suite.
Yup. And why is UUCP still in there? I mean, yes I have used it, so far back that the docs were written in Quenya. But requiring it now?
Btw, MacOS 27 (the current version) still has UUCP.
SIP is not some irrelevant detail, nor is it an obviously good "modern security practice". A system that the hardware owner cannot modify is not really on the same wavelength as traditional UNIX.
The hardware owner can modify it all they want, disable SIP. For a large swath of average and non-average users that will not be modifying the closed-source OS they're running, it is obviously good.
Traditional UNIX is does not mean having an open source core you're intended to tinker with. Traditional UNIX was entirely proprietary, connected with well-defined text-based interfaces. This is entirely orthogonal to user control and manipulation of the OS.
7 replies →