upvote
The certification documents read like the world's most abstruse bar trivia quiz...

"1.12 Threads

1.12.1 Cancellation Points

Question 31: Which C stdio functions have cancellation points that occur when a thread is executing?"

https://www.opengroup.org/csq/repository/noreferences=1&RID=...

reply
If you'd try to certify any modern Linux distribution, you'd end up with a very similar list.

- The Linux kernel also has timer coalescing

- Linux also has lazy atime ('relatime') by default

- No Linux distro installs uucp by default, and certainly not suid

- Desktop distros will also run a file indexer of some sort

etc.

reply
Isn’t the difference here that Linux was never trying to claim UNIX certification?
reply
If I remember correctly, two Linux variants were on the list at one time.

They were:

Inspur K-UX (expired on 3 February 2019)

Huawei EulerOS (expired in September 2022)

https://en.wikipedia.org/wiki/Inspur_K-UX

https://en.wikipedia.org/wiki/EulerOS

These were both based on Red Hat.

reply
And famously, GNU's Not UNIX
reply
Huawei managed to get their RHEL fork (EulerOS) UNIX certified. However their certificate expired (probably due to sanctions?)

So legally at one point a Linux was Unix.

reply
I had no idea there was a built-in way to make the filesystem case sensitive. My employer probably does not want me to spend time reinstalling my OS for this now but maybe next time I'm given a MacBook for a job I should do this...
reply
Curiously, the iOS filesystem is case-sensitive. A bit of a trap for developers on macOS. I’d expect plenty of third-party stuff to break switching the system drive to case-sensitive.
reply
Makes sense; the iOS filesystem isn't exposed to the user, but macOS' is.
reply
The relevant text from the article, (the rest of this comment is a direct quote from the article):

So, if you want your installation of macOS 15.0 to pass the UNIX® 03 certification test suites, you need to disable System Integrity Protection, enable the root account, enable core file generation, disable timeout coalescing, mount any APFS partitions with the strictatime option, format your APFS partitions case-sensitive (by default, APFS is case-insensitive, so you’ll need to reinstall), disable Spotlight, copy the binaries uucp, uuname, uustat, and uux from /usr/bin to /usr/local/bin and the binaries uucico and uuxqt from /usr/sbin to /usr/local/bin, set the setuid bit on all of these binaries, add /usr/local/bin to your PATH before /usr/bin and /usr/sbin, enable the uucp service, and handle the mystery issues listed in the four Temporary Waivers.

Then, and only then, is your macOS 15.0 actually UNIX® 03-certified.

This is batshit insane. I can guarantee you with 100% certainly not a single macOS installation in the entire history of macOS – let alone when just counting macOS 15.0 – has implemented even half of these changes. I’m sure there is a small number of people who have System Integrity Protection disabled permanently, and an even smaller number of people who have enabled the root account, and an even smaller number of people who have done both of those things – but that’s it. All the other changes are far too obscure and specific to be of any use to anyone.

reply
This uucico stuff is funny. Do you think there is anyone actually using UUCP on MacOS?
reply
That’s a bit of a weird article and I’m not 100% sure what its point is.

> This is batshit insane. I can guarantee you with 100% certainly not a single macOS installation in the entire history of macOS – let alone when just counting macOS 15.0 – has implemented even half of these changes.

Well, maybe that means it doesn’t really matter and especially not to the extent that the author seems (?) to be making it out to be. If no one disables System Integrity Protection in order to be UNIX® 03-compliant, maybe that means that to the extent that people care about macOS being “a UNIX”, they don’t care specifically about the parts of the specification that are incompatible with System Integrity Protection.

reply
The certification also was kind of bad at actually checking that the standard interfaces behaved as they should.
reply
Reminds me of (technically) POSIX compatible Windows.
reply
"""POSIXLY_CORRECT (originally proposed as POSIX_ME_HARDER) is a historical environment variable used in GNU utilities to force strict compliance with the POSIX standard."""
reply
ah, yes! https://en.wikipedia.org/wiki/Microsoft_POSIX_subsystem

the netbsd gallery (https://netbsd.org/gallery/) had a picture of somebody using that on windows xp (iirc) in order to compile pkgsrc packages in a "posix compliant" environment. the picture seem to be gone now :(

reply
The whole UNIX certified thing is a bit odd to start with, but those addendums are really just saying that because the UNIX compliance tests are thoroughly stuck in the past, a bunch of security measures (that users expect to exist on modern systems) have to be disabled to run the test suite.
reply
Yup. And why is UUCP still in there? I mean, yes I have used it, so far back that the docs were written in Quenya. But requiring it now?

Btw, MacOS 27 (the current version) still has UUCP.

reply
SIP is not some irrelevant detail, nor is it an obviously good "modern security practice". A system that the hardware owner cannot modify is not really on the same wavelength as traditional UNIX.
reply
The hardware owner can modify it all they want, disable SIP. For a large swath of average and non-average users that will not be modifying the closed-source OS they're running, it is obviously good.

Traditional UNIX is does not mean having an open source core you're intended to tinker with. Traditional UNIX was entirely proprietary, connected with well-defined text-based interfaces. This is entirely orthogonal to user control and manipulation of the OS.

reply
Also worth keeping in mind that macOS is intended for use with commercial third party software that’s repeatedly been proven untrustworthy, doing things like prodding system internals and installing dodgy kernel extensions where neither is warranted.

SIP is as much defense from the likes of Adobe and Google as it is from more traditional malware.

reply
For now SIP can be disabled (on mac, not of course on iOS that is completely closed) but I wonder for how much. It's clear that the desire of Apple is to make macOS a closed system like iOS, installing third party software outside the AppStore is more and more difficult, with Gatekeeper that asks you to enter the system settings and warn about "potential insecure stuff" each time you want to run an application downloaded from the internet not signed by Apple (yes I know that if you disable SIP you can get rid of Gatekeeper as well).

I think that piece by piece Apple wants to go into direction of making macOS just a desktop version of iOS, that is closed and impossible to modify. They will use of course security as an excuse, the practical thing is that with iOS they succeeded because they went to the market with an OS that was already closed, but making users accept that in new version downloading a software from the internet and installing it it's no longer possible takes time. But they are getting there soon to me.

reply
deleted
reply
Traditional UNIX was entirely proprietary, with source you're intended to tinker with.

AT&T was forbidden by its consent decree from productizing Unix. Licensees received the source code, on an as-is basis, with no official support from AT&T.

reply
Sure, but that just means UNIX vendors had access to the source code.

It doesn't mean end users had access to the source code.

In fact, vendors would have been prohibited from distributing AT&T source code to customers who weren't themselves AT&T licensees, just as CSRG was prohibited from distributing BSD to customers who weren't licensees before 4.4BSD-Lite.

The same goes for most other proprietary source-available products. For example, game developers can't open source Unreal Engine projects even though Unreal Engine source licenses are available to end users for free.

reply
You would absolutely normally get source to the vast majority of the unix components with a unix install.

At a bare minimum, you would almost have to have source to the vast majority of the kernel because there was no kernel modules. Sysgenning for a particular system involved compiling the kernel for that set of hardware.

I'm literally working on an early sun system emulator right now, heavily assisted by the standard sec tape that came with the standard software distribution of sunos, which has plenty of AT&T code.

reply
Sure, if by “you” you mean universities, Sun, DEC, IBM, etc.

As a non corporation end user with a sublicense from one of the above licensees (which is the apt analogy for an individual user in my opinion) you most certainly did not receive the source or have the rights to it.

reply