Endpoint configuration · GraphQL enum

CSRFlag enum

A System Integrity Protection (SIP) bypass flag decoded from the CSR (Configurable Security Restrictions) bitmask. Each value represents a protection that is currently bypassed on the system. An empty list indicates SIP is fully enabled. Reference: System Integrity Protection Guide (Apple) Reference: csrutil(8) — Apple man page

Values

Enum Value Description

ALLOW_APPLE_INTERNAL

Allow Apple-internal use; enables additional diagnostic and development features.

ALLOW_ANY_RECOVERY_OS

Allow booting into any recovery OS, bypassing recovery OS verification.

ALLOW_DEVICE_CONFIGURATION

Allow device configuration changes that SIP would normally restrict.

ALLOW_EXECUTABLE_POLICY_OVERRIDE

Allow overriding executable policy enforcement.

ALLOW_KERNEL_DEBUGGER

Allow attaching a kernel debugger to the running kernel.

ALLOW_TASK_FOR_PID

Allow task_for_pid calls for arbitrary processes (disables process memory protections).

ALLOW_UNAUTHENTICATED_ROOT

Allow booting from an unauthenticated (unsigned) root volume.

ALLOW_UNAPPROVED_KEXTS

Allow loading unapproved (not notarized) kernel extensions.

ALLOW_UNRESTRICTED_DTRACE

Allow unrestricted use of DTrace probes (disables SIP DTrace restrictions).

ALLOW_UNRESTRICTED_FS

Allow unrestricted filesystem access (disables SIP filesystem restrictions).

ALLOW_UNRESTRICTED_NVRAM

Allow unrestricted NVRAM variable access.

ALLOW_UNTRUSTED_KEXTS

Allow loading unsigned or untrusted kernel extensions.

Used by

  • SystemSettingsMacOS type: macOS-specific system settings including power management, privacy permissions, backup configuration, and security settings.

Example

Example

"ALLOW_APPLE_INTERNAL"