amfidont
Description
A macOS utility that attaches to amfid with LLDB and bypasses app signature validation for explicitly allowed binaries.
Allowed targets are matched by executable path prefix and/or cdhash.
Requirements
- SIP configuration that allows debugging system processes by either:
- fully disable SIP
- disable only debugging restrictions (
csrutil enable --without debug)
Installation
xcrun python3 -m pip install -U amfidont
Usage
Usage: amfidont [OPTIONS] COMMAND [ARGS]...
A simple utility for bypassing amfid signature verification
Options:
--path, -p TEXT path of executable to allow (can be specified multiple times, merged with ~/.amfidont/paths)
--cdhash, -c TEXT cdhash of executable to allow (can be specified multiple times, merged with ~/.amfidont/cdhashes)
--verbose, -v enable verbose output
--allow-all allow all validations to pass
--spoof-apple, -S patch isApple to return true for allowed binaries
--install-completion Install completion for the current shell.
--show-completion Show completion for the current shell, to copy it or customize the installation.
--help Show this message and exit.
Commands:
daemon Start amfidont in daemon mode.
add-path Add an allowed path prefix to persistent configuration.
remove-path Remove an allowed path prefix from persistent configuration.
add-cdhash Add an allowed cdhash to persistent configuration.
remove-cdhash Remove an allowed cdhash from persistent configuration.
Example
-
Add a persistent allowed path:
sudo amfidont add-path /Users/user/dev/myapp/build/Release/MyApp.app/
-
Start bypass mode (foreground):
sudo amfidont --verbose
-
(Optional) Start as daemon instead:
sudo amfidont daemon --verbose
-
(Optional) Spoof allowed binaries as Apple-signed:
sudo amfidont --spoof-apple --verbose
For example, this can be used to run self-signed
arm64ebinaries without setting thearm64e_preview_abiboot argument. -
Stop foreground mode with
Ctrl-C(this detachesamfidontand leavesamfidrunning).
Inner implementation details
amfidontattaches to/usr/libexec/amfidusing LLDB.- It sets a breakpoint on:
-[AMFIPathValidator_macos validateWithError:]
- On each breakpoint hit, it inspects validator fields:
- code path (
codePath) - cdhash (
cdhashAsData) - validation state (
isValid)
- code path (
- If the validator is invalid but the path/cdhash matches configured allow-rules, the return register is patched to success and execution continues.
- When
--spoof-appleis enabled, an additional breakpoint is set on:
-[AMFIPathValidator_macos isApple]
This patches isApple to return true for allowed binaries, making them appear
Apple-signed. For example, this allows running self-signed arm64e binaries
without the arm64e_preview_abi boot argument.
- Persistent configuration is stored in:
~/.amfidont/paths~/.amfidont/cdhashes
Metadata
Release files for amfidont 0.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| amfidont-0.0.3.tar.gz | 52.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| amfidont-0.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 92.2 kB
Release files / amfidont-0.0.3.tar.gz
| Download URL | amfidont-0.0.3.tar.gz |
|---|---|
| Size | 52.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
172da70fb8e78252732eff13d3d3c6f2aff114c76d8999d265b42c99c29a8b4a
|
|
BLAKE2b-256 checksum How to use checksums |
db97ce8b0e3759973ee26f267d2c677117035c3dd944d106e17690e5f1657987
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 10, 2026.
Transparency logRelease files / amfidont-0.0.3-py3-none-any.whl
| Download URL | amfidont-0.0.3-py3-none-any.whl |
|---|---|
| Size | 39.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4cbd929c49083848210dc8806b22182ff99e7fa42edb5bbe6d832b7246fd3ce7
|
|
BLAKE2b-256 checksum How to use checksums |
2ec2d9f450eb196b5fb50c4917cdb955560f5802d1e4dc57ceeb8499d3281495
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 10, 2026.
Transparency log