OS X El Capitan on the Mac App Store
itunes.apple.com
itunes.apple.com
It's worth mentioning that after the upgrade you might run into permissions problems: https://github.com/Homebrew/homebrew/blob/master/share/doc/h...
You might want to run `brew update` before updating, so `brew doctor` can help you troubleshoot issues afterwards.
rsync -rtvpl /usr/local ~/usr.local.backup
A lot of other apps do put stuff there though (when I wish they'd keep it in their own bundle).
Even worse, a lot of other apps drop stuff into /usr/bin.
You can't even do it with root:
[mason@IT-PC-MACPRO ~]$ sudo bash
Password:
[root@IT-PC-MACPRO ~]# touch /usr/bin/nope
touch: /usr/bin/nope: Operation not permitted
[root@IT-PC-MACPRO ~]# cat 'nope nope' >> /usr/bin/nope
bash: /usr/bin/nope: Operation not permittedI knew about /usr/local problem from Yosemite, though on El Capitan (same time as Yosemite, with /usr/local moved to ~/local) it was smooth as butter (I did not move /usr/local). All upgrade took about 30 minutes, and after it was done, I did sudo chown -R $(whoami):admin /usr/local and I was good to go.
I just ignored this and waited for the installer to do whatever it wanted. It took about 1 hour but everything went fine and I'm now up and running.
Whatever problems Yosemite had, they weren't caused because of "file accretion", nor would they remain after the OS is updated (as if it somehow reads old problematic files and goes back to its old buggy ways).
(That said, I had zero problems as a heavy dev+audio/video user of Yosemite, and zero too after updating to El Capitan GM -- with the exception of Cubase and NI audio units not working in Logic).
What OS are you talking about? OS X has always had buggy .0 releases. If anything it's gotten better over time, though I still agree with waiting for a .1 or .2.
If you mean Mac OS or earlier, then I wouldn't know. I was young and we always just kept whatever came on the computer.
My point about the .1 and .2 releases were that they're buggy, too. I look into my crystal ball and predict that 10.11.1 and 10.11.2 will both have serious issues (though not as much as 10.11.0. You really have to wait for the waves of bugfix releases after a point release to end before it's safe for human consumption.
Spotlight: Invisible files limitation; Processor usage and performance problems
DHCP Problems: AirPort networking dropouts, D-Link router problems, more
AirPort: No auto-reconnect after sleep; Connections dropping when switching from one base station to another Freezes during shutdown or startup, fixes
Widgets: Possible security exploit; Excessive memory usage; more
Check for bad login/startup items
CD/DVD burning problems: Errors, blank discs not recognized, more
Classic: Problems starting, more
Printer problems: Deleting, then re-adding
Font issues: "Fuzzy" type, more
SCSI Issues: Fix for Adaptec cards; Drives causing startup/shut down problems, more
Problems caused by QuickTime codecs
"Beeping" or "Chirping" noise back for some G5s
Bonjour issue and fix
Removable media devices not mounting, fixes
SMB connection problems, solutions
Wake-from-sleep issues
Speakable Items fails; workaround
Keychain import issue and fix
Safari 2.0: Problematic plug-ins, more
iPhoto 5.0.x: Unwanted image changes; Freezes on launch, fix
iSync 2.0: Deleted data; Problems synchronizing phones, iPods
Mail.app 2.0: Plug-in problems, removing bad bundles; Import problems; more
iChat AV 3.0: Performance issues
iTunes: Play does not continue during fast user switching, more
(...)
http://www.cnet.com/news/special-report-troubleshooting-mac-...
Quite simply because I've never once been bitten by them -- with the exception of some haxies not working.
>I'm old enough to remember when Apple's OS was mostly rock-solid.
When was that? Because I remember Mac OS (pre X) beeing anything but rock-solid. I also remember the first X release being a disaster, and people moaning about issues I've never encountered in my (heavy) Mac use for every new release.
(I also remember the hardware problems, from the overheating cube and the G3 logic boards that died by the ton to the G5 tower leaking cooling goo).
First, because a lot of those bugs you only find in real-life bizarro setups, and beta testers are not enough. Besides not all beta testers actually help with bug reports -- some programmers just test their own software, others just want to play with the latest OS, etc.
Second, because not all of those bugs will be fixed even if a beta tester finds them. There will be a cost-benefit (opportunity cost) analysis, and some might need extensive changes to some subsystems, and only get fixed with the X.2 or even X.4 or X.5 release, half a year or more later.
Third, because there will always be bugs, and at some point you need to release.
Fourth, because OS releases usually also enable or leverage several new hardware features in Macs and iOS devices. Delaying the OS would mean delaying those hardware units, or putting them out with the old OS and no way to use some new advanced hardware stuff they are advertised with (stuff like Bluetooth 4 back in the day, Retina support, or something similar).
Edit: upgrading to the appstore version. Not sure if this was GM specific, or they are locking the Os down even more.
Edit2: if you forget your password immeadiately and use the resetpassword feature in terminal, keychain breaks, can't find "login". Prob fix it with permissions. Note, NOT the case. Had to make an entire new user.
Also, with >30mbps connection, 850mb upgrade is taking ~4hrs. They must be getting slammed.
Edit : Boot args didnt fix. Trying carutul disable at recovery terminal.
Bash-3.2# csrutil diasable
Seems to work.
Edit n: seperate and unrelated, system does not seem to restart well. Eiter hangs or takes ages.
"OS X adds a new feature called "Rootless" that keeps the root user found on Unix-based systems from being able to be run. This can cause some troubles for disk management and backup utilities, so they included a way to turn it off. Open the Terminal and type sudo nvram boot-args="kext-dev-mode=1 rootless=0";sudo reboot to disable rootless and reboot your Mac. Only disable rootless if you know what this feature is used for, and you are experienced with the OS X command line." [1]
[1] http://www.techradar.com/us/how-to/computing/apple/52-os-x-e...
This can be disabled but I wouldn’t advise doing so unless you have a really good reason to.
> /usr is shareable, read-only data. That means that /usr should be shareable between various FHS-compliant hosts and must not be written to.
Pretty much all modern unices consider that /usr, aside from /usr/local (which the FHS defines as "for use by the system administrator when installing software locally. It needs to be safe from being overwritten when the system software is updated."[1]), is part of the operating system.
It is thus very much unusual to modify /usr[2], and in line with current practices to lock it down tightly.
/usr/local is not under SIP.
[0] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04.html#pu...
[1] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html
[2] in fact the FHS specifically notes[3]:
> Software placed in /usr may be overwritten by system upgrades. For this reason, local software must not be placed outside of /usr/local without good reason.
"we specify that the system can overwrite or remove anything you put there" is pretty much a dead ringer for "modifying this is unusual"
[3] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html...
No. Not Game Center.app. Grand parent is right, this is bloatware that neither he, nor I, nor many others want. If I wanted a bloatware Windows box I would have bought one. There's no excuse for making this app non-removable.
On the other hand, if we’re talking about the junk that your average Windows or Android device comes preinstalled with that is either configured to run at startup and/or modifies the stock UI (TouchWiz for example), yeah, that’s definitely bloatware and it’s reprehensible to make that unremovable. That isn’t what Apple is doing, however.
No, it doesn't, but what does bother me are the gigabyte+ apps that, like Game Center, Apple does not allow users to remove (without jumping through hoops that are probably both scary and technically challenging for most users).
Are you an Apple fan? Because I am (or was). I've been with Apple since the OS 7 days.
This lack of attention to detail is very uncharacteristic of the Apple I knew and loved.
The comparison to "what others are doing" is also very un-Apple like. Apple did not use others as a benchmark to decide what it should be doing, and the day it starts to do that is the day it's no longer Apple.
While the attention to detail is lacking, it is becoming even more walled off. I reapect that because the market wants all there stuff synced all the time. Howecer, i don't. I dont need my search results sent to apple so i can get recommendations, i font want every message i text to be an imessage so it goes through there servers as well as att. I am disappoinr.
On 10.11, there are many apps that are not deleteable, but all of them seem to be under a gig (unless I'm missing something because I had, long ago, deleted an app and the OS update didn't restore it).
These include: Game Center, iBooks, Safari, iTunes, Photos, Contacts, Maps, Automator, Font Book, Dictionary, Notes, FaceTime, Chess, Reminders, Photo Booth, and perhaps a few other small-ish apps. These are less than 1 gig. I don't know why Apple did not choose to simply make whatever is so vital in the app bundle a system framework instead.
It's not a big deal to me if these small apps are non-deleteable. I assumed—incorrectly—that the big ones (iMovie, Garage Band, etc.) were non-deleteable as well.
I used game center as an example. Of coure the launchctl list uses an insane amount of resources for apple stuff. I also deleted several other apps and a few other things. Shit, running monolingual alone saved me ~1.2GB.
So thanks. I agree as well. If possible I will turn it back on after.
what happens when you assume apps that came with the OS are legit?
You can't do that unless you turned it off in the first place. And if you did, you're on your own anyway.
> a really good reason?
I think access to my own filesystem is good enough. I admit when I looked at the reviews, I made sure there were no major issues before upgrade but missed this "sys integrity" thing.
Since it is possible to disable, why not disable it as-needed rather than always?
i am. ;)
Windows also has the System Integrity Protection equivalent.
Game Center is ~4MB, and you'll never remove all the potential "phone home" hooks without rewriting the OS. Your approach is akin to taking wheels off a car to reduce weight so it goes faster.
If I may say so though, I think you're coming at this the wrong way.
Trying to disable every component in the OS that phones home simply doesn't scale, may I suggest you explore gateway firewall devices such as PFSense, or the free version of Sophos' UTM if you prefer a more polished UI?
I use a Sophos UTM at home and I can see (and block) every request that my Macs use to try to phone home, with HTTP, HTTPS or regular network traffic.
I also use the Always-On VPN on my phone to apply ad blocking at the firewall level which protects my phone as well.
Very much worth checking out. Gateway protections are the only way to go these days IMO.
Edit: Just to add, at first glance I find the SIP system to be rather anti-user, but people in this thread are right. It's valuable protection to have in place. If I used a Mac at home I would only disable this to make the changes I needed before turning it back on again.
Edit to clarify: I use a Mac, but only has a HTPC and not as a desktop or workstation, and all outbound traffic is blocked by default.
I will look into those suggestions. Do to the differences and additions in caputan little snitch does not work. I havent connected to internet yet whoch ice floor needs to be configured properly. Does SOPHOS UTM work well even as a free version. It is annoying when snitch lets traffic out after 3grs.
As sad as this will sound, I cant afford a VPN. I set one up myself using OpenDNS and tunnelblick, which I should probably spin back up. Any other security suggestions? I can only use free stuff ATM .
The utm itself actually hosts and serves the VPN connection by the way. My phone connects directly to the VPN on my UTM. You'll see a speed hit because of the extra hop unless you put your utm in the cloud.
I hope that's helpful :)
The current state of affairs means that users - even non-technical ones - are routinely asked for their admin pwds in everyday use, but every time they enter it they are susceptible to be totally and utterly pwned.
Even expert users fall victim when they turn off system safeguards - XcodeGhost being only the most recent example, where only users who actively disabled Gatekeeper/codesign checking were susceptible.
It's kind of annoying for power users, but time and time again I think we've proven that power users aren't in any way immune to social engineering or simple blanket malware attack.
> > a really good reason?
Honestly, as devs, we're more susceptible to this kind of attack than the average user, not less (e.g. see XcodeGhost). System integrity protection is great for us, yet I see a great deal of hubris when it's mentioned–as if we're somehow immune, or that we audit all the code we run.
I download all manner of tools for development work, and use sudo as and when necessary, and I'm thankful there's now an extra layer of security. If I needed to modify the filesystem (e.g. if I wanted to delete an app like another poster did), I'd disable SIP temporarily to do so, and I think that's fine, but I think it would be unwise to disable it permanently, especially on a whim. I would hope that modification of these sorts of files would be rare enough that it's not a big inconvenience anyway.
On the other hand, maybe this question is rather stupid as I really can't see Apple scaring away the developer community in such an unnecessary way.
/usr/local is not one of the SIP protected paths. The idea behind SIP is to protect system binaries from being surreptitiously patched by malicious parties, not to make the system totally useless.
> Reading about it, one might think 10.11 could have problems with someone trying to use anything but the system-shipped ruby version, or python, etc.
Aside from being really stupid from a customer standpoint, what would be the security benefit of doing this?
I very recently had to attack GarageBand with a hex editor to disable app sandboxing so I could use third party VST plugins. I realize System Integrity Protection can be disabled by a kernel boot param, but this really, really, sticks in my craw.
Use the game the next day and the counters are reset: 5 more cancels on iPad, 3 cancels on iPhone.
GC is the worst thing Apple's done in years. And if they have brought that crap and its fascist ways to MacOSX, then I really am hesitant to install any more MacOSX updates.
This is nothing new for OS X. Mavericks and the last couple of versions cannot restart / shut down properly. I'm sure Apple would say it's a feature not a bug.
I am on 10.11.1 and haven't been notified to upgrade.
That said I’m downloading the official release now and installing it over my GM seed install simply to get beta releases of 10.11.1 to stop showing up in my updates tab.
Anyone else had this happen to them or know why it happens?
They may create /home if it's required to exist for compatibility with other Unix standards. And since an OS upgrade probably has a checklist of things that must succeed (such as the ability to "create" /home), they feel forced to preserve whatever might have been there already before "creating" it again.
On my machine, /home exists but it is completely empty.
So I'd guess the answer is -- it depends on what applications you want to continue using on your computer.
The split-screen view hasn't been fully-thought-through though. I would say almost everything I tried didn't do what I would have expected. There is a way for a window to end up on a space where the menu bar no longer has menus. There's even a mode where almost everything stops working: if the system decides only one of your windows supports splitting, it'll just sit there (even gestures won't work to reenter Mission Control) and you have to click to get out of it.
At the very least, an option to stack top and bottom instead of side by side would have been nice.
Seems like they want it to be congruent with how it works in iOS 9 on the iPad, so I don't hold out any hope. Maybe someone will figure out how to hack it.
However, Spotlight + unix + the dock does wonders for avoiding needing to browse at all.