Mac OS X SIP (System Integrity Protection) and Restic


#1

Hi,

I’m using restic (installed using brew) to backup all my users data on my mac (/Users).

Since mojave upgrade, my system has SIP activated and now my backups gives a lot of ‘operation not permited’ error messages.

I don’t want to system wide disable SIP, but I would prefer to configure /usr/local/bin/restic to be a strusted
binary, having at least read access to the whole system when runned by sudo. I wasn’t able to find out how to do that.

Does anyone did achieves that or could give me some guidelines ?

Thanks in advance


#2

Yeah, this is a bugger of an issue. You can see others trying to tackle it here: https://github.com/restic/restic/issues/2051

(I’m really quite annoyed at Apple for this one.)


#3

Thanks.
Sorry, I should have search opened issues.
It seems that Apple seems to move toward allowing signed only binaries even on desktop OS … such a pitty. :frowning: