skip to content

macOS

macOS is Unix underneath with Apple's own layers on top: the XNU kernel, launchd instead of systemd, APFS, and a security model built from SIP, Gatekeeper, and TCC. Relevant for Apple-platform and developer-tooling roles.

on this pageshow

explore

questions

page 2 of 2

What is a Mach port on macOS, and how do send and receive rights differ from a Unix file descriptor?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

A Mach port is a kernel-managed message queue that tasks reach through capabilities called rights. Exactly one task holds the receive right; any number may hold send rights. Like a file descriptor, a port name is task-local, but it names a capability to communicate rather than an open object.

open as a page

What does it mean for a macOS launchd job to be launched on demand through its Sockets dictionary, and how does the program end up holding the listening socket?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

launchd creates and binds the listening socket itself at load time and watches it. The job's process is started only when a connection arrives, and it receives the already-bound file descriptors from launchd by checking in with launch_activate_socket, keyed by the name used in the plist.

open as a page

On Apple hardware, what does it mean that a private key was generated "in the Secure Enclave", and what does that let you do that a key in a file cannot?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

The key is created inside a separate coprocessor and never leaves it in usable form. Software can ask the enclave to sign or perform key agreement, but cannot read, copy or back up the key material, and the enclave enforces a per-use policy such as requiring a biometric match.

open as a page

You need to apply macOS updates across a fleet of Macs without a person at each keyboard. What does the softwareupdate command let you do, and why do Apple Silicon machines make fully unattended OS updates harder?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

softwareupdate lists, downloads and installs updates from the command line and can fetch a full macOS installer. On Apple Silicon, installing a macOS update requires credentials of a volume owner, supplied with --user and --stdinpass or authorised centrally by an MDM-escrowed bootstrap token, so a plain root script is not enough.

open as a page

You own the developer toolchain for a team whose Macs and macOS CI runners install everything with Homebrew. How would you make that toolchain reproducible across machines, and what does Homebrew fundamentally make hard?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Homebrew is rolling-release with no lockfile, so a Brewfile pins which packages are installed but not their versions. Reproducibility comes from versioned formulae, per-project version managers, an internal tap or bottle mirror, and moving builds into Linux containers.

open as a page

showing 31–35 of 35