Fix macOS AUTO_UPDATE when updates are disabled

The check read only AutomaticCheckEnabled from /Library/Preferences,
falling back to softwareupdate --schedule when that key was absent.
Both describe automatic checking alone, so a Mac with downloads or
installs turned off still reported PASS. The key is also absent when
a configuration profile manages it, since the value then lives in
/Library/Managed Preferences, a layer never consulted.

Read the five Software Update preferences backing the System Settings
toggles, resolving each from the managed layer before the system one.
macOS treats them as enabled when unset, so only an explicit disabled
value fails. The now-unused softwareupdate binary leaves the command
allowlist.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-24 22:12:32 +02:00
parent 2532b0bb6b
commit af7f44c0c1
2 changed files with 140 additions and 41 deletions

View File

@@ -21,16 +21,15 @@
package checks
var darwinCommandPaths = map[string][]string{
"defaults": {"/usr/bin/defaults"},
"fdesetup": {"/usr/bin/fdesetup"},
"osascript": {"/usr/bin/osascript"},
"pwpolicy": {"/usr/bin/pwpolicy"},
"softwareupdate": {"/usr/sbin/softwareupdate"},
"stat": {"/usr/bin/stat"},
"sudo": {"/usr/bin/sudo"},
"sw_vers": {"/usr/bin/sw_vers"},
"sysadminctl": {"/usr/sbin/sysadminctl"},
"systemsetup": {"/usr/sbin/systemsetup"},
"defaults": {"/usr/bin/defaults"},
"fdesetup": {"/usr/bin/fdesetup"},
"osascript": {"/usr/bin/osascript"},
"pwpolicy": {"/usr/bin/pwpolicy"},
"stat": {"/usr/bin/stat"},
"sudo": {"/usr/bin/sudo"},
"sw_vers": {"/usr/bin/sw_vers"},
"sysadminctl": {"/usr/sbin/sysadminctl"},
"systemsetup": {"/usr/sbin/systemsetup"},
}
func commandCandidates(cmd string) []string {