asmvik / asmvik/yabai

macOS 27 Golden Gate Beta - Scripting Addition Offsets & Patterns

Open
#2,802 13 comments 24 reactions 0 assignees View on GitHub
Dominant language
C
Stars
29.6k
Forks
750
PR merge metrics
No merged PRs in 30d

Description

> [!NOTE]
> This is for yabai users who, like me, move to each new Golden Gate beta the moment it drops and want to keep things working without waiting for an official build. The maintainers are welcome to use these values too.
>
> It's filed as an issue rather than a pull request only because PRs are disabled on this repo.
>
> @asmvik, feel free to pin this while Golden Gate is in beta if it'd help people find it; it can come down once the public release ships.

The scripting addition works on the macOS 27 developer beta. Five of the seven Dock signatures carried over from Tahoe unchanged and only needed their offsets bumped to wherever Apple moved them. `add_space` and `set_front_window` needed new patterns.

Derived against build `26A5353q`, Dock SHA-256 `34af810d533a6b9be3d4fa8eeda1bb0bb399c22bb38fc6373581f9fedb9e697c`. Only `arm64e`, as macOS Golden Gate dropped Intel support.

## What changed

Check out [this commit on my fork](https://github.com/AhsanFazal/yabai/commit/49c2d035aa0a7d99f6ebf7f7d327972d6a707bb4). If you keep your own source, diff that and you're done.

In the two that changed, only one byte actually moved: a `bl` target in `add_space`, and the `cbz` displacement before the prologue in `set_front_window`. Tahoe matched those bytes literally, which is why its patterns broke on Golden Gate; the ones below wildcard them:

| target | offset | pattern |
| :--- | :--- | :--- |
| `dock.spaces` | `0x30000` | `?8 ?? ?? ?? 08 ?? ?? 91 00 01 40 F9 E2 03 13 AA ?? ?? ?? 94 ?? ?? ?? ?? 08` |
| `dp_desktop_picture_manager` | `0x40000` | `?? ?? 00 ?? 08 ?? ?? 91 00 01 40 F9 E2 03 16 AA E3 03 19 AA ?? ?? ?? 94` |
| `add_space` (changed) | `0x210000` | `7F 23 03 D5 E1 03 1E AA ?? ?? ?? 97 FE 03 01 AA ?? ?? ?? A9 FD 43 01 91 F3 03 14 AA F5 03 00 AA 96 8E 43 F8` |
| `remove_space` | `0x170000` | `7F 23 03 D5 FF ?? ?? D1 FC ?? ?? A9 FA ?? ?? A9 F8 ?? ?? A9 F6 ?? ?? A9 F4 ?? ?? A9 FD ?? ?? A9 FD ?? ?? 91 ?? 03 03 AA F5 03 02 AA F4 03 01 AA` |
| `move_space` | `0x170000` | `7F 23 03 D5 E3 03 1E AA ?? ?? ?? 97 FE 03 03 AA FD 7B ?? A9 FD ?? ?? 91 F6 03 14 AA` |
| `set_front_window` (changed) | `0x10000` | `?? ?? ?? 34 7F 23 03 D5 FF C3 01 D1 ?? ?? ?? A9 ?? ?? ?? A9 ?? ?? ?? A9 FD 83 01 91 F3 03 01 AA F5 03 00 AA` |
| `animation_time` | `0x210000` | `00 10 6A 1E A8 ?? ?? D1 ?? 01 ?? F8` |

## Checking the offsets on a later beta

Apple shuffles these every few betas, and most of the time it's only the offsets. You can find the new ones yourself in a minute. The script below reads a Dock binary and tells you, per target, whether the signature is unchanged, moved (and where to), or actually changed:

```
python3 verify_offsets.py /System/Library/CoreServices/Dock.app/Contents/MacOS/Dock
```

Here's the script: [Yabai scripting-addition offset checker, verify/find Dock offsets on new macOS (beta) builds](https://gist.github.com/AhsanFazal/d18a54b9dc0f259b49e21b8ed70078d2).

A moved offset is a one-line edit. A changed pattern is the only case that needs you to open Ghidra.

## Just want it working?

Offsets aren't the whole patch. A new macOS major also needs `verify_os_version` (set `macOSSequoia = true` for `27`, or the scan never runs), an `OSAX_VERSION` bump in `common.h`, and an entry in the `workspace_is_macos_*` table in `workspace.h`.

My fork has all of these, plus a `make install-local` target that handles the rest:

> [!CAUTION]
> Do you actually know what's in this fork? You don't, not until you read it yourself. These commands pull code from a stranger on the internet (me), ask for your `sudo` password, write a passwordless rule into `/etc/sudoers.d`, codesign a binary, and inject a payload into one of the system services.
>
> Don't trust me. Always check for yourself. Read the [commit](https://github.com/AhsanFazal/yabai/commit/49c2d035aa0a7d99f6ebf7f7d327972d6a707bb4).

```
git clone https://github.com/AhsanFazal/yabai
cd yabai
make install-local
```

What `install-local` does:

- builds yabai
- drops the binary on your `PATH`
- codesigns it with your `yabai-cert` so the Accessibility grant survives rebuilds instead of re-prompting every time
- sets up the passwordless `--load-sa` sudoers entry
- loads the scripting addition
- starts the service

You'll need a `yabai-cert` Code Signing certificate in your keychain first (the usual yabai-from-source step).

I'll keep the fork's `master` on whatever Golden Gate beta I've upgraded to myself, so it'll trail Apple's public release by a bit.

Contributor guide

No contributing guide indexed for this repository

Research direction

Read commit 49c2d035aa0a7d99f6ebf7f7d327972d6a707bb4 and run verify_offsets.py against the current Dock binary. Then inspect verify_os_version, common.h, and workspace.h alongside the listed signatures and offsets. Done means the scripting addition supports the Golden Gate beta on arm64e and the offsets, patterns, OS version, OSAX version, and workspace table are updated and validated.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, macos, python
Domain
operating-systems, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.