It is signed by apple and verified as part of the secure boot process.
> The Secure Enclave Processor runs an Apple-customized version of the L4 microkernel.
[1] https://support.apple.com/guide/security/secure-enclave-sec5...
It is signed by apple and verified as part of the secure boot process.
> The Secure Enclave Processor runs an Apple-customized version of the L4 microkernel.
[1] https://support.apple.com/guide/security/secure-enclave-sec5...
For what it's worth, I'm not sure Apple publishes which variant of L4 it runs on, and there are many of them. The whole formal verification conversation here might be moot.
The SEPOS kernel is an apparently derived from a fork of L4-embedded they used in Darbat (a fork of XNU to run on top of L4). Not formally verified unless Apple internally has done so.
And they've made a lot of pretty deep changes for example adding native support for Mach-O files.
https://www.zdnet.com/article/minix-intels-hidden-in-chip-op...