I'm trying to connect to a vintage USB storage device. Everything works except this one call which prevents telling the device to sign the data to the drive. Without it, the entire project is useless because asking people to turn on FDA is not responsible and I won't ask them to do it.
So while I understand that the entitlement is intended for virtualization apps that ship on the Mac App Store, elevating privileges in the app doesn't solve the problem or else I'd simply do that and move on. I don't NEED the app to be on the Mac App Store, but I need a way for IOUSBHostInterface(ioService:options:queue:interestHandler:) to succeed without FDA.
So this is a Catch-22.
In fact, here's a chart of everything attempted:
App itself - user (501) - refused — "needs root or com.apple.vm.device-access"
Terminal - root - works
LaunchDaemon - (SMAppService) root - fails
Daemon + launchctl asuser - root - fails
Daemon + audit-session join - root - fails
Daemon + disclaim - root - fails
Admin prompt (do shell script) - root - fails
Self-signed entitlement — SIGKILL by AMFI