Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

DimaVR

Suspended
Nov 14, 2017
1,146
479
I have now spoken to an Apple senior adviser several times and he have talked to the technicians. We have tried everything (actually more or less what I have tried by myself), including reinstall of the system. Nothing helped. then I was advised to take to a service provider for further diagnose. I will do that on Monday.
Wtf just set your Mac to less secure boot options ? And disable sip
 

vwlinkan

macrumors newbie
Original poster
Dec 27, 2020
10
1
To answer DimaVR: Just that was impossible to do, only got error messages. But now the problem i solved by my Service Provider. But Apple did not want to pay for it:
"Restore via Apple Confugurator 2. Provides both new firmware and OS.
Software defects that are not included in Apple's warranty commitment but feels unreasonable to charge for when it's a new computer so we offer it (we do not receive any compensation from Apple)."
Now I "only" have to wait for Xtrafinder to be ready for M1 Macs ;)
 

DimaVR

Suspended
Nov 14, 2017
1,146
479
To answer DimaVR: Just that was impossible to do, only got error messages. But now the problem i solved by my Service Provider. But Apple did not want to pay for it:
"Restore via Apple Confugurator 2. Provides both new firmware and OS.
Software defects that are not included in Apple's warranty commitment but feels unreasonable to charge for when it's a new computer so we offer it (we do not receive any compensation from Apple)."
Now I "only" have to wait for Xtrafinder to be ready for M1 Macs ;)
That’s on you man, if you didn’t know that you needed latest Mac OS 11.2 RC atleast to try this and set to less secure boot and you had to pay or bring to a shop that’s on you. No skill set than
 

walterpaisley

macrumors 6502
Oct 27, 2004
361
363
Springfield
How does xtrafinder injects its payload into the finder? If it’s via scripting additions (which is how TotalFinder works) disabling SIP won’t fix the issue.

The totalfinder dev talks about the issue in this support thread.
 

k-hawinkler

macrumors 6502
Sep 14, 2011
260
88
I have now spoken to an Apple senior adviser several times and he have talked to the technicians. We have tried everything (actually more or less what I have tried by myself), including reinstall of the system. Nothing helped. then I was advised to take to a service provider for further diagnose. I will do that on Monday.
 

Tparonett

macrumors newbie
Feb 10, 2021
1
0
As I now are completely dependent on Xtrafinder, I want to install it on my Mac mini M1.
The first step is to disable SIP. Previously, it has worked well by starting in recovery mode running terminal and deactivating through csrutil disable. But now on the M1 Terminal also asked for username and password. See photo. Entered the correct username and password, but then only got back that it failed. Others have been successful with this, why not me? Running Big Sur 11.1.
View attachment 1701896
I am having the same issue(s) you’ve described here. I utilized all of the same
Methods. When I attempt to change the boot security to reduced I get the same error (I think bc I speak English). I tried csrutil clear reboot, nothing. I tried csrutil enable, all good with that then status then csrutil disable again same thing failed to create local policy. What does that message even mean? People seem
Not to be attempting to help resolve the problem and are indicating youre doing something wrong. I don’t think you are. Sadly I’m only trying to do this so I can get a game pad configuration updated on steam so I can use my PS4 controller to play games on steam. Always states the update for this failed. It states on various forums to disable SIP and I end up with all of this. I’m not this technologically savvy and I don’t want to accidentally break my Mac lol
 

CodeRush

macrumors newbie
Mar 8, 2021
3
1
The most likely cause of this issue is that recoveryOS is not entered in an expected way for BootPolicy to detect that recoveryOS as "true" (1TR in short).

Please ensure that you enter recoveryOS as follows:
- shutdown the machine normally
- press and hold the power button until you see "Loading startup options". Make sure not to release the power button prematurely, nor press and release it several times, do it all in one press and hold.
- click "Options" and "Continue" to enter recoveryOS.

There are several ways to determine if your recoveryOS is 1TR:
- starting with 11.3 betas, open Terminal and run "bputil -d", it will show the current OS environment. The expected one is "one true recoveryOS", if you see "ordinary recoveryOS", you are not in 1TR.
- in any version, open Terminal and run "bputil -k" (this will attempt to enable support for 3rd-party kexts). If the command fails with error 11 (AP boot mode), you are not in 1TR.
- Try enabling user-controlled 3rd-party kexts (requires Reduced Security mode) using Startup Security Utility. If an attempt to enable it fails with error 11, you are not in 1TR.

Once you determine that you indeed are in 1TR, "csrutil disable" should work as expected.
 

Quackers

macrumors 68000
Sep 18, 2013
1,938
708
Manchester, UK
The most likely cause of this issue is that recoveryOS is not entered in an expected way for BootPolicy to detect that recoveryOS as "true" (1TR in short).

Please ensure that you enter recoveryOS as follows:
- shutdown the machine normally
- press and hold the power button until you see "Loading startup options". Make sure not to release the power button prematurely, nor press and release it several times, do it all in one press and hold.
- click "Options" and "Continue" to enter recoveryOS.

There are several ways to determine if your recoveryOS is 1TR:
- starting with 11.3 betas, open Terminal and run "bputil -d", it will show the current OS environment. The expected one is "one true recoveryOS", if you see "ordinary recoveryOS", you are not in 1TR.
- in any version, open Terminal and run "bputil -k" (this will attempt to enable support for 3rd-party kexts). If the command fails with error 11 (AP boot mode), you are not in 1TR.
- Try enabling user-controlled 3rd-party kexts (requires Reduced Security mode) using Startup Security Utility. If an attempt to enable it fails with error 11, you are not in 1TR.

Once you determine that you indeed are in 1TR, "csrutil disable" should work as expected.
I'm not sure there is any other way to get into recovery on an M1.
If you're in recovery then it must be 1TR unless 1TR has somehow failed and the backup ordinary recovery system has been loaded. The ordinary recovery system appears from the article below to be on the Data volume and so is unbootable in any normal way. (Read from after the booting diagrams).
Or maybe I've misunderstood?
https://eclecticlight.co/2021/01/14/m1-macs-radically-change-boot-and-recovery/
 

CodeRush

macrumors newbie
Mar 8, 2021
3
1
1TR is defined as "primary recoveryOS + physical presence flag set by iBoot if power button is held correctly".

This is a relevant bit from bputil manpage:
By design, the SEP application which is responsible for making changes to the LocalPolicy will inspect the boot state of the main Application Processor (AP). It will only allow the below security-downgrading operations if it detects that the AP is in the intended boot state. When System Integrity Protection (SIP) was first introduced to Macs, it was decided that requiring a reboot to macOS Recovery would provide intentional friction which would make it harder for malicious software to downgrade the system. That precedent is extended here to detect the special boot to macOS Recovery via holding the power key at boot time. We refer to this as One True Recovery (1TR), and most of the below downgrade options will only work when booted into 1TR, not when called from normal macOS. This helps ensure that only a physically-present user, not malicious software running in macOS, can permanently downgrade the security settings.

What I'm suggesting is that somehow some users indeed end up in primary recoveryOS, but iBoot doesn't set the required physical presence flag for some reason (power button released too early, jitter, trying to force shutdown by holding power button, and then initiate boot into rOS, something else).
 
  • Like
Reactions: Quackers

moonwalk

macrumors regular
Jul 14, 2009
124
91
It’s great that Apple, in the name of security, has succeeded in locking down the mac to such an extent that owners are unable to gain access to, or control, their own machines.
 
  • Love
Reactions: foliovision

jdb8167

macrumors 601
Nov 17, 2008
4,859
4,599
It’s great that Apple, in the name of security, has succeeded in locking down the mac to such an extent that owners are unable to gain access to, or control, their own machines.
I think it is both a bit buggy and a documentation issue. They'll straighten it out soon. Already some of the documentation is getting better. The M1s have been out for less than 4 months.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.