https://www.folklore.org/StoryView.py?story=Stolen_From_Appl...
https://www.folklore.org/StoryView.py?story=Stolen_From_Appl...
They don't do that any more on Apple Silicon machines, and the entire OS is free to download from their CDN, completely unencrypted. Still, though, the SMC on M1 machines (which is now part of the M1 chip itself, and completely different from the one on Intel boxes) continues to hold those very same keys, and they're still "secret" and omitted when you enumerate them. macOS no longer even reads them, but you can dump them with the debug tooling I wrote for Asahi Linux a few weeks ago.
$ python tools/smccli.py
m1n1 base: 0x100046dc000
Fetching ADT (0x00070000 bytes)...
[...]
[smcep] Starting up
Have fun!
>>> smc.smcep.read("OSK0", 16) + smc.smcep.read("OSK1", 16)
> 20:0x4f534b3000102010 (TYPE=0x10, UNK=0x0, ID=0x2, SIZE=0x10, KEY=0x4f534b30)
< 20:0x202000
> 20:0x4f534b3100103010 (TYPE=0x10, UNK=0x0, ID=0x3, SIZE=0x10, KEY=0x4f534b31)
< 20:0x203000
b'ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc' Your karma check for today:
There once was was a user that whined
his existing OS was so blind,
he'd do better to pirate
an OS that ran great
but found his hardware declined.
Please don't steal Mac OS!
Really, that's way uncool.
(C) Apple Computer, Inc.
The ARM builds don't have DSMOS.kext, so I imagine the commpage message is gone.edit: also, hello marcan! tyvm for your work :D
From Sega v. Accolade - https://openjurist.org/977/f2d/1510
>We hold that when there is no other method of access to the computer that is known or readily available to rival cartridge manufacturers, the use of the initialization code by a rival does not violate the [Lanham Trademark] Act even though that use triggers a misleading trademark display.
I seem to remember a similar case for the Gameboy ROM that needed to contain an image of the Nintendo trademark to boot, but couldn't find a good online reference. Lexmark tried to pull a similar stunt by claiming the ROM code in their cartridge chips was executable code in a secret language, but courts again said it was an access control code first, and thus functional not creative.
If the comparison fails, the logo was still displayed scrolling down and making the bing sound, but the Gameboy now just halts. Everyone who had one in their youth knows the black block scrolling down with no cartridge inserted, and various variants of corrupted logos if contact was bad or the cartridge broken.
This also means the Gameboy has no “OS” whatsoever, it’s all done by the games. But the system is too simple to need one anyway.
That’s also why it’s so good for writing your first emulator.
But yes, the courts (or at least the 9th Circuit) have looked down on these attempts to use copyright and trademark as methods of preventing access. Of course now they have DMCA anticircumvention provisions to help out instead anyhow.
ModernVintageGamer knows his stuff well.
The world was a lot more reasonable before the DMCA.
My guess is that these methods involved some modchip-style tomfoolery like reset glitching or forcing values onto the bus, and could have been defeated by Sega in a future revision of the console.
There's just one catch. The desktop environment requires GPU acceleration to even start, and your two options are emulating the proprietary Apple GPU, or emulating the paravirtualized Metal GPU they developed for VMs. Neither is likely to be particularly easy... it's why I tell people to not expect to be able to run a macOS VM on Linux on an M1 Mac, unless they want to write a whole Metal implementation. A plain kernel in single user mode? Sure. macOS desktop? Good luck :-).
For macOS on macOS on Apple hardware, Apple have their paravirt GPU support on both sides so it basically "just works" with minimal work from the third-party hypervisors that build on those frameworks.
....hmm, now I think about that I realize it wouldn't have many non-tinkering oriented use cases. Right now I can only think of out-of-band firewalling.
The hypervisor I wrote for research purposes passes through all the hardware (except the UART), which is easier than trying to do it on top of Linux. But it also doesn't try to be a secure hypervisor or anything like that (it would be trivial for the guest to take over).
That basically enforces in hardware what has always been the commercial position of OSX: open kernel, closed (and ruthlessly guarded) desktop libraries.
Rather than just copy those characters into their ROMs, the clone companies would add "NOT IBM" to get around any copyright claim - with the letters "IBM" in the same memory location as the originals of course. I discovered this when hacking on an Elonex PC - if anyone remembers those.