Reverse-engineering Rosetta 2 Part 1: Analyzing AoT files and the runtime
ffri.github.io
ffri.github.io
Atop of that you also need understanding of computer architecture, for which I vaguely recommend Hen.&Pat. but again you get this knowledge by playing around mainly.
A bit of compiler design would help too if you want to write one of these - Engineering a compiler is a good one.
inode meta data such as timestamps are insufficient I think. They can be tampered with.
In macOS, there is a security-policy layer of some kind on top of xattrs, separate from the security-policy of the file itself. `com.apple.rootless` is an example of an xattr protected by this mechanism: users (even root) can't apply or remove `com.apple.rootless` from files on a filesystem mounted as the rootfs.
With this mechanism, it'd likely be possible to give executable binaries an xattr containing the checksum, generated by Gatekeeper+Rosetta, that the user couldn't modify, while still being able to otherwise modify/delete the file. (And, presumably, modifying the file would automatically invalidate/remove the checksum xattr.)
https://gist.github.com/nonylene/d08977e8952c83d20d2c5f7cbaf...