Code Signing, Notarization, and Gatekeeper on macOS
How macOS verifies that an application hasn't been tampered with and hasn't been flagged as malware, before it's ever allowed to launch.
Conceptual, architectural explainers - how a subsystem actually works underneath.
How macOS verifies that an application hasn't been tampered with and hasn't been flagged as malware, before it's ever allowed to launch.
What actually happens on disk when you brew install something, and why Homebrew's design differs from a traditional Linux package manager.
How launchd unified boot-time initialization, service supervision, and scheduled tasks into a single declarative system on macOS.
A practical guide to writing, installing, and debugging your own scheduled or persistent launchd jobs, from a first plist through production-grade patterns.
How the App Sandbox confines what an application can access by default, and how entitlements grant it specific, narrow exceptions.
What SIP protects, how it's enforced below the level of the root user, and the legitimate reasons to disable it temporarily.
How mdworker, metadata importers, and Spotlight's index let macOS answer file searches in milliseconds instead of scanning the disk on demand.
How Virtualization.framework exposes Apple Silicon's hardware virtualization support directly to Swift applications, without a third-party hypervisor.
How integer scaling, aspect ratio, scanlines, masks, bloom, interlacing, and sampling interact when reproducing CRT-era video on flat panels.
How libretro separates emulator cores from frontends through a stable C API, callbacks, environment negotiation, serialization, and shared services.