Does anyone actually understand macOS update security?
My MacBook Pro (M2) is now on macOS 26.6.2 Tahoe. I have a SuperDuper! clone that is macOS 15.7.5 Sequoia. I want to update it to Tahoe.
I could, of course, do a full (asr) re-clone. But this has disadvantages, such as:
- If the clone fails, now the backup is completely lost
- ASR clones result in an unencrypted drive, so have to boot up to the clone and to turn FileVault back on, and then it takes time to re-encrypt. For an external drive this means it has to actually encrypt all the data.
With macOS on Intel there was an easier way: apply the macOS update to the clone. There are, in theory, three ways to do this:
- Boot into the clone, accept the macOS update in System Preferences > General > Software update
- Boot into the clone, run the full macOS updater
- Run the macOS updater from the host computer, telling it to update the external volume
Method #1 is preferable; it is a less intensive upgrade if it is offered through Software Update.
And note that regardless of which method is chosen, it didn’t matter what it changed on the Data volume – that volume will get back in sync with the next SuperDuper! Smart Update.
I don’t think I’ve ever been successful with any of these methods on Apple Silicon. But undaunted by past failure, I tried method #1 yesterday:
- Booted into the backup (Sequoia) SSD.
- Unmounted the internal (Tahoe) drive, just in case.
- Opened Software Update
- macOS Tahoe 26.6.2 was available. Clicked Upgrade Now.
This failed: it asked for a password, but the dialog just shook when I enter it.
I verified that the password was accepted for other purposes (such as lock and unlock) and that this startup drive had a Secure token enabled for the user account I was entering the password to, and that the cryptographic users for that disk has a Local Open Directory User and Volume Owner that matched that same user. So why didn’t it accept the password and continue the upgrade?
It gets worse. I tried restarting (still with the Sequoia drive as the Startup drive), and when it got to the window to unlock the drive, it wouldn’t accept my password there either!
So I gave up and changed the startup back to Tahoe. And that’s when I discovered that the seal on the Sequoia signed-sealed-volume was broken.*
But it must have been OK when I first booted to that Sequoia drive yesterday. This implies to me that Software Update broke the seal.
This is concerning to me: that merely trying to run Software Update and apply a macOS update can render your drive unbootable.
Where did I go wrong?
* There is some question of whether the seal is really broken. I’ve seen before where diskutil will say it is broken, but it is in fact OK, because the seal is actually applied to a snapshot of the volume. But I compared diskutil’s report to a Ventura clone, on Ventura, and it said the seal was OK there. So, I’m tentatively concluding that in Tahoe I can trust diskutil.