From 4421a2d62ba36b172c62d18d8a07e0d78907fe98 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Lomig=20Me=CC=81gard?= Date: Tue, 22 Sep 2026 21:09:42 +0200 Subject: [PATCH] fix: an Intel Mac no longer reports Apple Silicon memory protections The macOS hardening check assumed Apple Silicon for every macOS build, so rite built from source on an Intel Mac recorded RAM encryption and DMA protection as active. The Apple Silicon check now applies to aarch64 only, and other macOS builds report both as unavailable. --- crates/rite-stdlib/src/verification/host.rs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/crates/rite-stdlib/src/verification/host.rs b/crates/rite-stdlib/src/verification/host.rs index 739784f..e08ff55 100644 --- a/crates/rite-stdlib/src/verification/host.rs +++ b/crates/rite-stdlib/src/verification/host.rs @@ -202,7 +202,7 @@ fn collect_security_features() -> Hardening { // Apple Silicon has always-on hardware memory encryption via the Secure // Enclave. DART (per-device IOMMU) is also always active on Apple Silicon. -#[cfg(target_os = "macos")] +#[cfg(all(target_os = "macos", target_arch = "aarch64"))] fn collect_security_features() -> Hardening { Hardening { ram_encryption: FeatureCheck::with_detail( @@ -217,11 +217,11 @@ fn collect_security_features() -> Hardening { } } -// Windows and other platforms report everything as unavailable for now. +// Windows, Intel Macs and other platforms report everything as unavailable. // TODO(windows): probe real posture (BitLocker, VBS/HVCI, Kernel DMA // Protection). Low priority: the Windows binary is meant for authoring // ceremonies, not running them, where this posture matters. -#[cfg(not(any(target_os = "linux", target_os = "macos")))] +#[cfg(not(any(target_os = "linux", all(target_os = "macos", target_arch = "aarch64"))))] fn collect_security_features() -> Hardening { Hardening { ram_encryption: FeatureCheck::new(FeatureStatus::Unavailable),