A System Integrity Protection (SIP) bypass flag decoded from the CSR (Configurable Security Restrictions) bitmask. Each value represents a protection that is currently bypassed on the system. An empty list indicates SIP is fully enabled. Reference: System Integrity Protection Guide (Apple) Reference: csrutil(8) — Apple man page
Values
| Enum Value | Description |
|---|---|
|
|
Allow Apple-internal use; enables additional diagnostic and development features. |
|
|
Allow booting into any recovery OS, bypassing recovery OS verification. |
|
|
Allow device configuration changes that SIP would normally restrict. |
|
|
Allow overriding executable policy enforcement. |
|
|
Allow attaching a kernel debugger to the running kernel. |
|
|
Allow task_for_pid calls for arbitrary processes (disables process memory protections). |
|
|
Allow booting from an unauthenticated (unsigned) root volume. |
|
|
Allow loading unapproved (not notarized) kernel extensions. |
|
|
Allow unrestricted use of DTrace probes (disables SIP DTrace restrictions). |
|
|
Allow unrestricted filesystem access (disables SIP filesystem restrictions). |
|
|
Allow unrestricted NVRAM variable access. |
|
|
Allow loading unsigned or untrusted kernel extensions. |
Used by
SystemSettingsMacOStype: macOS-specific system settings including power management, privacy permissions, backup configuration, and security settings.
Example
Example
"ALLOW_APPLE_INTERNAL"