As others have pointed out, it may also help if they are moving to add back bootcamp support for Windows (on ARM).
Apple has added better support for virtualization at the OS level in recent years and that handles the needs of most devs.
The M1 Macs have their security settings applied per partition instead of per computer.
If you set the bootloader to "permissive security policy", you can boot from a Linux partition without effecting the security of the system when you boot from the MacOS partition.
This is a big change over the way things have previously worked on iOS (where there is no option to unlock the bootloader) or the Mac. It probably wasn't a quick hack that a couple of guys stuck in when nobody was looking.
Reduced security mode is needed to boot into outdated macOS installs (specifically, I believe this is "outdated, insecure, at install-time"), along with loading kernel extensions (which aren't supported in full security mode on Apple Silicon).
Permissive security mode is needed to boot into macOS with a custom XNU kernel.
But yes, this is a significant change to iOS devices, but not to older macOS devices.
Previously the Macs had their security settings applied per computer, not per partition.
The fact that someone decided to provide support for a raw image instead of a Mach-O file could very well be the work of someone ar a much lower level.
Likely there is a very small bit of bootstrap code stuffed into a ROM somewhere, and the only thing that bootstrap code enables it to read from some protected part of the onboard SSD, which then gives you the next round of bootstrap enabling you to read from other devices (e.g. all the code needed to power up and use the hardware needed to get to an external drive, and the code to read the partitions on said drive).
Someone made the decision that it would be better to use the bit of internal SSD (since it would "always" be there), that could be changed later, rather than hard-code this into comparatively expensive silicon. Unless your internal drive goes bad, it is a pretty good compromise. I seriously doubt that anyone in marketing cared about this.
The SecureROM boots iBoot1 from NOR flash, then that has the SSD driver code. It would certainly be possible to add support for external storage, as long as it still fits in NOR. But I doubt they will.
My take is the company deliberated about this trade-off quite explicitly at some length and decided the Mac serves the world in its current capacity as a "computer" (i.e. the truck in the truck vs car analogy) and that they do not wish to limit the capabilities of the existing Mac that people love in any shape or form by moving to ARM, which was highly speculated and ripe for potential backlash. They probably decided the Mac would be an "open" system to some degree (at least as open as it already was) and iOS would be the closed mass market computing device optimizing for security and dependable end-to-end experience.
I mean, that's not what the parent comment said:
> I agree that this is mostly a small number of engineers (with approval) being helpful.
Here's some more details from someone who actually worked on this: https://twitter.com/XenoKovah/status/1339914714055368704
The bigger opportunity is expanding the footprint and flexibility of Apple Silicon in general. As a developer the new MacBook Pros performance characteristics were too juicy to ignore, the main pain points are virtualization and architecture shift. I'm not knowledgeable enough about the low level details to have a fully formed idea of impact of these pain points yet—maybe Apple Silicon and ARM support are equivalent in practice when it comes to development/deployment—but it certainly makes me feel more comfortable paying the Apple premium the more diverse and open the supported use cases are.
"Apple helps Asahi Linux" (American).
"Apple help Asahi Linux" (British), as if there's a "people" after Apple.
However, the word Americans is not a group of people in the same sense that USA, England, Apple, or family is. Its kind of like the distinction between people and persons.
Edit: the term for words like family is "collective noun". More at https://blog.harwardcommunications.com/2017/02/07/the-family...
> Labour [singular] takes comfort partly from the fact it expended little effort or money on the seat, allowing the Lib Dems [plural] to declare themselves in the best position to challenge the Tories.
But an American publication would probably write the same, because the name Lib Dems is itself pluralized.
British English peers past the corporate veil to see the singular corporation as it's underlying people.
Brits would be more likely to say “Led Zeppelin are on stage”, while Americans would prefer “Led Zeppelin is on stage”, and the reason is the disagreement between whether Led Zeppelin is singular (one band) or plural (4 people constituting the band.)
See here for details: https://editorsmanual.com/articles/collective-nouns-singular...
We get constantly bombarded by our own employers with messages of unity and vision statements and the business plan and the message etcetera. So even when we pause and think about our own experiences and we realize how many varied voices and agendas there are within, we’re conditioned when referring to a brand employer like Apple to reduce them to a single point of view.
we’re conditioned when referring to a brand employer
like Apple to reduce them to a single point of view.
Maybe? Americans also tend to be individualistic (often to a fault, many would say)so I'm not sure there's a cultural significance at work here.It's probably informative that British English tends to refer to most (all?) collective nouns this way. It's not some corporation-specific thing.
Sports teams are the most obvious example - a Brit would say "Team A have defeated Team B" rather than "Team A has defeated Team B."
You're assuming wrong. Booting unsigned kernels on Apple hardware has been possible since January. This just makes it slightly less annoying since you don't need to build a Mach-O binary to do it, and more future-proof since it decouples it from Apple's binary format which they can change the requirements for at any time (as they did this time). It means I don't have to go off and reverse engineer what the new requirements are, I can just stop using Mach-Os and know the raw option will never break (assuming it continues to exist), since there is nothing to break with a raw file.
Apple's machines are designed as an end-to-end ecosystem that suits their needs, and that they can change at any time - open, but without stability guarantees. This feature is effectively an acknowledgement that people using these machines outside of their ecosystem exist, and might want some stability guarantees.
The addition of raw mode sounds like a stable abi for booting linux. The Asahi developers have found "stuff" with the hardware. Just that feedback will be of great value to the continued development of the Apple SoCs. So my guess is that the raw mode is a gift with the expectation to be able to see how the Linux folks solves other issues.
And outside of government intervention, the response from the general public will be: who cares? None of them want to or care to run Linux on a macbook. Heck even within the HN community I'm willing to bet the number of folks who run linux as a daily driver desktop on a macbook is a rounding error.
if anyone on the outside knows, then Federighi (sp?) and insiders know and approved publishing with visibility?