禁用SIP仍无法绕过权限校验?Endpoint Security框架运行问题
使用Endpoint Security框架时禁用SIP仍提示“缺少权限”的问题
问题描述
出于研究目的,我尝试用Endpoint Security框架搭建日志收集本地端点,但因项目特性无法申请官方权限。根据Apple文档,禁用SIP(System Integrity Protection)应该能让二进制跳过权限校验,但在已禁用SIP的macOS系统中运行编译后的二进制时,仍出现"权限拒绝"错误。
已执行步骤
- 进入恢复模式执行
csrutil disable禁用SIP,并用csrutil status验证已禁用 - 编写的Demo代码:
import Foundation import EndpointSecurity var client: OpaquePointer? // 创建客户端并监听消息 let res = es_new_client(&client) { (client, message) in // 消息处理逻辑 } // 打印错误码 print("Result code: \(res)") switch res { case ES_NEW_CLIENT_RESULT_SUCCESS: print("success") case ES_NEW_CLIENT_RESULT_ERR_NOT_ENTITLED: print("error: lack of entitlement") case ES_NEW_CLIENT_RESULT_ERR_NOT_PERMITTED: print("error: application does not have required system permissions") case ES_NEW_CLIENT_RESULT_ERR_NOT_PRIVILEGED: print("error: root privileges required") case ES_NEW_CLIENT_RESULT_ERR_INVALID_ARGUMENT: print("error: invalid argument") case ES_NEW_CLIENT_RESULT_ERR_TOO_MANY_CLIENTS: print("error: maximum number of clients reached") case ES_NEW_CLIENT_RESULT_ERR_INTERNAL: print("error: internal error") default: print("unknown error: \(res)") } if res != ES_NEW_CLIENT_RESULT_SUCCESS { exit(EXIT_FAILURE) }
- 编译命令:
swiftc main.swift -o es_demo \ -framework Foundation \ -I /Library/Developer/CommandLineTools/SDKs/MacOSX14.4.sdk/usr/include \ -L /Library/Developer/CommandLineTools/SDKs/MacOSX14.4.sdk/usr/lib \ -lEndpointSecurity \ -sdk /Library/Developer/CommandLineTools/SDKs/MacOSX14.4.sdk
- 运行错误输出:
Result code: es_new_client_result_t(rawValue: 3) error: lack of entitlement
疑问
- 如何让该Demo正常运行?
- macOS 15更新后SIP规则是否发生变化?
解答
1. 让Demo正常运行的方法
即使禁用SIP,Endpoint Security框架仍要求二进制携带com.apple.developer.endpoint-security.client权限字段,只是不需要Apple的官方签名。你可以按以下步骤操作:
- 创建权限配置文件
entitlements.plist:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>com.apple.developer.endpoint-security.client</key> <true/> </dict> </plist>
- 用自签名给二进制文件添加权限:
codesign --force --sign - --entitlements entitlements.plist es_demo
- 以root权限运行程序(Endpoint Security客户端必须root权限才能初始化):
sudo ./es_demo
2. macOS 15(Sequoia)的SIP规则变化
macOS 15确实收紧了SIP限制:
- 即使执行
csrutil disable,部分系统框架的权限校验逻辑并未完全跳过,Endpoint Security就是其中之一,仍要求二进制携带对应权限字段,只是无需Apple官方签名。 - 另外,macOS 15中
csrutil disable不再完全关闭所有SIP组件,部分内核级保护仍会生效,但对Endpoint Security来说,核心影响还是权限字段的必要性,而非SIP是否完全关闭。
内容的提问来源于stack exchange,提问作者Xiaozheng Zou
相关产品推荐
相关产品推荐

