Module: EndpointSecurity::Doctor

Defined in:
lib/endpoint_security/doctor.rb

Overview

Reports whether a development host meets Endpoint Security requirements.

Class Method Summary collapse

Class Method Details

.check(out, label, available) ⇒ void

This method is part of a private API. You should avoid using this method if possible, as it may be removed or be changed in the future.

This method returns an undefined value.



31
32
33
# File 'lib/endpoint_security/doctor.rb', line 31

def check(out, label, available)
  out.puts format("%<label>-28s %<status>s", label: label, status: available ? "OK" : "MISSING")
end

.command(*argv) ⇒ String

This method is part of a private API. You should avoid using this method if possible, as it may be removed or be changed in the future.

Returns captured command output.

Returns:

  • (String) —

    captured command output



23
24
25
26
27
# File 'lib/endpoint_security/doctor.rb', line 23

def command(*argv)
  Open3.capture2e(*argv).first
rescue Errno::ENOENT
  ""
end

.run(out: $stdout) ⇒ void

This method returns an undefined value.

Prints development host checks to out.



12
13
14
15
16
17
18
19
# File 'lib/endpoint_security/doctor.rb', line 12

def run(out: $stdout)
  out.puts "Endpoint Security development host diagnosis"
  check(out, "macOS 13+", Gem::Version.new(`sw_vers -productVersion`.strip) >= Gem::Version.new("13"))
  check(out, "root", Process.euid.zero?)
  check(out, "SIP disabled", command("csrutil", "status").include?("disabled"))
  check(out, "AMFI development boot arg", command("nvram", "boot-args").include?("amfi_get_out_of_my_way=0x1"))
  out.puts "WARNING: Disable SIP only on a dedicated development machine."
end