Can I mount the root (system) filesystem as writable in macOS Monterey?

Viewed 303

I'm trying to make my python code read and write a file at the system root, so I disabled System Integrity Protection following these steps. But when I run the command sudo mount -uw / I get this error:

mount_apfs: volume could not be mounted: Permission denied mount: / failed with 66

What should I do now?

1 Answers

On Monterey there are some additional steps required, and several important caveats noted below.

First, this requires that FileVault to be disabled (in System Preferences → Security & Privacy → FileVault). This means the data on your hard drive will no longer be encrypted, i.e. anyone with physical access to your system would be able to gain full access to your data.

In addition to disabling System Integrity Protection (SIP), you'll also need to disable the Signed System Volume (SSV), which is a mechanism that checks the system volume at runtime and rejects any data that doesn't have a cryptographically valid Apple signature. This means you won't be able to turn SSV (or SIP) back on without losing the changes you've made to the root drive.

To disable SIP and SSV, reboot in Recovery Mode (holding ⌘+r). In Recovery Mode, open Terminal and execute:

csrutil disable                     # disable System Integrity Protection (SIP)
csrutil authenticated-root disable  # disable Signed System Volume (SSV)
reboot

Once rebooted back into standard mode, create a new directory in a location where your user has write access, e.g. $HOME. I believe it needs to have fully open permissions, so, for example:

mkdir -m777 ~/rootmount 

You then need to mount your root device to this directory. The root device will be listed in the output of mount with something like /dev/disk1s5s1 on / (apfs, sealed, local, read-only, journaled). Mount the listed device without the final s1—for example:

cd ~
sudo mount -o nobrowse -t apfs /dev/disk1s5 rootmount
cd rootmount
## whatever changes you want to make

Once you've done cd rootmount you're in the writable copy of your root drive. Make whatever changes you want to make there. After that, you'll have to tell the system to use the new version as the root device. To do so:

sudo bless -folder /Users/<your-username>/rootmount/System/Library/CoreServices -bootefi -create-snapshot

When you reboot, the changes you've made should persist on the root drive.

Important reiterated warning: if you re-enable SIP and/or SSV, your root drive will revert to its Apple-approved state, reverting all changes you've made. In addition, updates to the OS will likely also cause the changes to revert. (I haven't confirmed this, nor have I confirmed whether updating the OS even works without SSV enabled). Apparently Apple really doesn't trust their users to be able to change their own computers in any significant way. Good thing Apple is there to protect us from ourselves. It's a wonder we ever managed not to mess everything up without their kindly oversight.

Related