Operation not permitted on Mac when Wireshark downloaded with SigmaOS browser

asked 2022-08-29

Riesartman

updated 2022-08-30

Guy Harris


I’ve downloaded the last stable version of Wireshark, but impossible to launch it. When I launch from the app, it says that it’s impossible to open without any infos. When I try to laiunch from the terminal via wireshark command. It just say operation not permitted, even in sudo mode and even if I launch directly from /Applications/

I’ve tried to compare with a friend who also possess a M1 Mac and we got exactly the same rights.

I’ve tried to disable protections from app too with the command sudo spctl --master-disable. Same thing, it didn’t work, always the same error message.

Does someone got the same issue at one point ?

What is 'last stable version'? Can you give us a number?

Jaap ( 2022-08-30 )

What is all the text that's printed if you run wireshark from the command line? (Not just the "operation not permitted" part, but everything that's printed after you hit "return".)

Guy Harris ( 2022-08-30 )

@Guy Harris, it’s written zsh: operation not permitted: wireshark

Riesartman ( 2022-08-30 )

@Jaap the last stable version is 3.6.7. I’ve tried also the 3.4.15 version but same error

Riesartman ( 2022-08-30 )

Let's see, what's the output for spctl -a /Applications/ You might need to enable it first to get some valid response.

Jaap ( 2022-08-30 )

answered 2022-08-30

Riesartman

Ok I’ve got /Applications/ File created by an AppSandbox, exec/open not allowed. So i tried to use the command xattr -l /Applications/ and I’ve got 0186;630c937d;;. So I was wondering maybe it’s because I’ve download it from a special web browser called « SigmaOS » that is sandboxed. And it appears that if I download Wireshark from Chrome, I can launch it now. So it’s solved and but a bit incovenient for the browser that I use but it’s not Wireshark related.

Safari's also sandboxed, but, at least as of when this was described to me, the code that implements the file open/save dialog box in Cocoa runs a non-sandboxed process and does something such as do the open of the file to read or write (so the file is, for example, created by a non-sandboxed process) and hands it to the sandboxed code to write to, allowing a sandboxed app to write files that aren't locked up. Perhaps SigmaOS is doing things differently; you might want to report this to the SigmaOS people as a bug.

Guy Harris ( 2022-08-30 )

I’ve discussed with a developer of sigmaos browser. They made a mistake when changing so it explains why there are some issues with certain files. It’s not at all Wireshark related.

Riesartman ( 2022-08-30 )

Asked: 2022-08-29 22:12:19 +0000

Seen: 469 times

Last updated: Aug 30 '22