Provisioned VM Image Preparation

Nucleic-Session: 28559516-7571-4295-A21C-28B0B95D9427
Co-authored-by: Nucleic <[email protected]>
This commit is contained in:
2026-07-07 03:23:59 -07:00
co-authored by nucleic
parent fae31a5bbf
commit 5071094df1
+6 -1
View File
@@ -547,7 +547,12 @@ Pre-granting TCC unattended is the sharp edge, and there's no clean path:
when SIP is on rather than failing.
- **`csrutil disable` is a one-time MANUAL step**: it must run from **recoveryOS**, which has no SSH
and no scripting hook, so a human boots the base VM into recoveryOS once, runs `csrutil disable`,
and re-runs the provisioner. There is no way around this on stock macOS.
and re-runs the provisioner. There is no way around this on stock macOS. Nucleic makes it as easy as
it can: **Settings ▸ Virtual Machines** shows a **Boot base in Recovery** button
(`MacVMRecoveryWindowController`, `VZMacOSVirtualMachineStartOptions.startUpFromMacOSRecovery`) that
opens the base in an interactive window — the operator runs `csrutil disable`, reboots, shuts down,
and clicks **Build base image** again; the reentrant provisioning pass (§4.4) then writes the TCC
grants over SSH. Everything **except** this SIP toggle is automated by the button.
If screenshots come back black or clicks no-op on a live base, check (in the guest) that SIP is
disabled (`csrutil status`), the TCC rows exist and are allowed