So there is one year to try out what might still be missing and give respective feedback.
The long term roadmap is that macOS will eventually be much more microkernel like.
The monolithic vs microkernel debate was pretty clueless at times. Core Linux is smaller than dito hurd when configured with similar functionality.
OSX mach has always been a hybrid kernel. In a sense Linux is too but you can also configure it as a mostly-monolithic thing, and most seem to prefer that.
Likewise, eBPF allows userspace programs to perform some work inside kernel space to reduce syscalls.
I wonder if io-uring won't be a starting point for a "microkernelization" of Linux. It seems really effective as a message-passing interface.
https://source.android.com/devices/architecture/hal-types
The Switch (yes the games console) uses a microkernel.
QNX an OS for human critical scenarios is a microkernel.
Finally, when arguing Linux vs Minix/Hurd, think of the irony of running Linux on top of a cloud hypervisor, with an endless load of Kubernetes or Docker loads.
Hmm, Never thought about a stated OS focus like that. Off to look it up. Good mention
The fact that they're no longer going to allow loading of 3rd party kernel modules (a pure political decision) does not a make a microkernel (which is an architectural style).
The kernel is still going to be big and monolithic (it contains the entire BSD kernel in the same address space!), and they're still going to be loading Apple-authorized kernel modules (500MiB of them, according to the article) in the same address space.
I rather be happy for the improvements in the long term roadmap and overall outcome for the eco-system.
If you just consider disallowing 3rd party modules to be a "microkernel" all while the kernel itself still loads most if not all (approved) drivers such as PCI bus, storage devices or filesystems in the same address space, then _all_ current major operating systems are "microkernels".
What you call a kernel like that?
Locked?
"A kernel that only allows user-space third party drivers"?
That this style doesn't have a nifty name isn't a good reason to weaken the established definition of microkernel just so it does.
So, then it becomes a balancing act how many are allowed the priviledge to be part of the main act.
Well, that is kinda the point of a microkernel (or at least one of the points).
Sure, you're not going to have a kernel whatsoever without say an CPU/MMU driver in the same address space. Maybe a driver for the timer.
But when you have graphics, sound, storage, USB controllers, filesystems, networking and most of a BSD kernel (providing all the syscalls) in the same address space, now that is not a microkernel by any definition of the word.
XNU is called an "hybrid" kernel in part because in the original design the BSD parts implementing most of the actual system could have been spun off as a separate process (similar to Windows NT's original design), which would have been an actual microkernel, but in practice they were just stuck together in the same process, making it a monolithic kernel in all but name (just like in Windows).
> So, then it becomes a balancing act how many are allowed the priviledge to be part of the main act.
Yes.
Which is what pjmlp implies, once they are out, isn't it microkernel?
What you call a kernel like that?
This isn't pedantic, nor is it ideology. If you're acquiescing, do it graciously and please refrain from name calling.
From all purposes from a third party driver writer persona, the only path forward are user space drivers.
What you call a kernel like that?
This is basically calling me silly, just as you were calling the previous person ideological and a pedant. If you cut out this commentary that would be great.
macOS does not use “the” BSD kernel (it’s not even obvious what your assertion even means since there are many members of the BSD family, each with their own kernel - none of which macOS uses).
Using a USB network adapter (requires for Ethernet on a MacBook) would bring down my system every time the firewall was running. And the stacktraces all included their calls.
I’m sure Apple, like me, got tired of getting reports about a few known bad actors.
In any case, extensions run in the same address space as the rest of the kernel making any such "rings" pointless.
But then, I haven't delved into how macOS in M1 precisely works.
Yes, I know, but I'm referring to hardware virtualization, essentially making "ring -1" "ring 0" and "ring 0" "ring 1".
Besides that, hyperv seems make use of it to achieve paravirtulization?
macOS on the M1 uses this to prohibit most kernel code from touching pagetables. You have to do that from within the guarded sublevel, which kernel extensions can only call into.
This is more or less the original intent of x86 rings: to separate an OS kernel out into parts with different permissions and levels of isolation.
I would have trusted literally anyone else to do a good job at this. Apple's in the business of brokering power though, I see no reason why they'd be motivated to make those APIs as rich as kexts.
Because of that, nobody would be stupid enough to make those APIs (in the wide sense, as in “what kexts can do, not what they are supposed to do) as rich as kexts.
From what I remember reading from some macOS Application Firewall makers, no. (And that's ofcourse, intentional.)
While it is true that poorly coded Kernel extensions can make an OS unstable, this is just another example of Apple taking away more control from its users and further crippling macOS to make it more like ios.
I still think that it’s a worse in-practice system than kexts but they are responding to feedback at least.
You can still load kernel extensions in Big Sur by disabling SIP, though.
That, however, isn't easy to do, considering Apple has a rather impressive track record of creating products people enjoy and buy.
And to jump two replies ahead: them trying to make it "easy" and "save" doesn't imply their users are idiots. Quite a few developers and scientists use Macs, and the lawyers aren't exactly dumb either. Spending hours trying to somehow get both sound and bluetooth to work at the same time, a favourite pastime on Linux, means lifetime wasted for something that shouldn't need doing. And considering nobody reads the source, there is no reason to believe some "expert" has some ability to avoid installing that one extension that soon starts encrypting their files. At least they tend to have better backups...
I don’t like the way this is going.
Apple can. I can’t. Making APFS snapshots requires special entitlements, which they’re not going to give me.
> It also use checksums for filesystem integrity.
It doesn’t check integrity of the actual data though. But I care about my data.
Or do you want to create an app that performs a snapshot via some API.
That’s not what I want. I want to have a say in snapshot retention, not have some tool make the decision for me.
Specifically, I need precise control over snapshot retention so I can maintain several off-site replicas of my backup.
What makes you think that? Carbon Copy Cloner does this, and is made by a small independent developer.
https://bombich.com/kb/ccc6/leveraging-snapshots-on-apfs-vol...
Source: https://bombich.com/blog/2018/03/30/building-better-backups-...
They’re one of two apps in the world who have been granted the entitlement as far as I know. The other one is Time Machine.
It isn't. They are making it (very) less likely for average simpleton users like myself to expose or fuck up their system.
And for the more elite hackers such as yourself who absolutely want to load third party kernel extensions, they require you to disable SIP. The knowledge and work it takes to do that is a very nice "I hereby declare I know what I'm doing and I alone bear the responsibility if things go wrong" entry barrier.
Why did you use the word Blessed?
I'm curious what made your brain choose that word instead of something neutral.
Reminds me of "Walled garden" marketing speak instead of "Walled Prison".
Edit- is there some sensitive nerve I hit?
I'm curious what made your brain choose that word instead of something neutral.
people use metaphors with a lot of conotation (walled prison) so if there is a more neutral term, i was curious how to state it in either non-positive or non-negative way
Probably the nerve that's tired of people going out of their way to be offended over terms that never were offensive when used in context such as this subject matter.
Context does matter.
It's a fairly common idiom when talking about platform APIs. Some APIs are "blessed" in that they are the APIs that they platform owners would like you to use and others they would like you to avoid. "Blessed" isn't wholly positive as it implies the platform plays favorites, and frequently the new blessed apis don't support all the old functionality.
Here is patio11 using the idiom 7 years ago:
https://news.ycombinator.com/item?id=7658396
It's not as nefarious as you are implying - I don't have an agenda, I've just been on HN for too long.