Leanpub Header

Skip to main content

Inside macOS

Architecture, Kernel, and Systems Programming on Apple's Operating System

This book is 100% completeLast updated on 2026-07-29

macOS powers millions of devices, but few developers ever explore what lies beneath its polished interface. Inside macOS explains how the XNU kernel, Mach, BSD, Apple Silicon, APFS, and modern security technologies work together, giving systems programmers, security researchers, and engineers a deep understanding of Apple's operating system.

Minimum price

$19.00

$29.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
128
Pages
About

About

About the Book

macOS is one of the most widely used operating systems in the world, yet its internals remain opaque to all but a small community of engineers, security researchers, and reverse engineers. This book provides a comprehensive, technically rigorous exploration of modern macOS internals -- from the XNU kernel through Mach IPC, BSD processes, APFS storage, Apple Silicon architecture, and the layered security mechanisms that protect the system. Whether you are a systems programmer writing low-level code, a security researcher investigating vulnerabilities, or an operating systems student seeking to understand how a real-world hybrid kernel works, this book gives you the deep technical knowledge to navigate macOS's complex architecture with confidence.

Bundles

Bundles that include this book

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers from Ukraine, Belarus and Russia. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

Architecture, Kernel, and Systems Programming on Apple’s Operating System

Introduction

Chapter 1: The Darwin Foundation

  1. From NeXTSTEP to macOS: A Brief History
  2. The Darwin Architecture: Layers and Abstractions
  3. What Is Open Source, What Is Proprietary
  4. macOS vs Linux vs Windows: Architectural Comparison
  5. Setting Up Your Research Environment

Chapter 2: The XNU Kernel

  1. XNU: “X is Not Unix”: Design Philosophy
  2. The Mach Microkernel Subsystem
  3. The BSD Subsystem: POSIX Compliance and Extensions
  4. The I/O Kit Object-Oriented Driver Framework
  5. Kernel Initialization and Early Boot Sequence

Chapter 3: Processes, Threads, and Scheduling

  1. Mach Tasks: The Resource Container Abstraction
  2. BSD Processes and the proc Structure
  3. Thread Management: Kernel Threads, User Threads, and Work Queues
  4. The Scheduling Algorithm: Fair Share, Priority Inheritance, and Energy Awareness
  5. Process Creation, Termination, and the execve Flow

Chapter 4: Virtual Memory and Memory Layout

  1. Page Tables and the ARM64 TTBR Architecture
  2. Physical Memory Management: Pages, Zones, and Plists
  3. The Virtual Memory Map: Stack, Heap, Mappings, and the Shared Region
  4. ASLR, Guard Pages, and Memory Protection Schemes
  5. Compressed Memory (zram) and Memory Pressure

Chapter 5: Mach IPC: Interprocess Communication

  1. Port Rights: Send, Receive, and Make-Receive
  2. Message Structure and Wire Format
  3. The msg_trap Mechanism and Kernel Message Handling
  4. Dead Name Notifications and Port Lifecycle
  5. Practical Mach IPC Example: Sender and Receiver
  6. Higher-Level IPC: XPC, Distributed Objects, and CoreFoundation Bridges

Chapter 6: Synchronization and Concurrency Primitives

  1. Lock Types: Spinlocks, Mutexes, RW Locks, and LCK Variants
  2. Semaphores: Mach vs BSD vs libdispatch
  3. Condition Variables and Futex-Like Mechanisms
  4. Atomic Operations on ARM64 and Apple Silicon
  5. Grand Central Dispatch: The User-Space Concurrency Engine

Chapter 7: Storage: APFS, CoreStorage, and the I/O Stack

  1. The Disk Arbitration Stack and Block Device Drivers
  2. APFS Internal Structure: Containers, Volumes, and Allocation Groups
  3. Copy-on-Write, Clones, and Hard Links in APFS
  4. Snapshots, Journaling, and Crash Consistency
  5. FileVault Encryption and the Secure Enclave Integration

Chapter 8: Networking Stack

  1. The BSD Socket Layer and Protocol Family Abstraction
  2. IP Stack: IPv4/IPv6, Routing, and NAT
  3. TCP/IP Implementation Details in XNU
  4. Network Interfaces: Hardware, Software, and Virtual Adapters
  5. Network Extensions (NE) and the Modern Networking Framework

Chapter 9: Executable Formats: Mach-O, Linking, and Loading

  1. Mach-O File Format: Headers, Load Commands, and Sections
  2. The Dynamic Linker (dyld): Initialization Sequence
  3. The Shared Cache: Prebinding System Libraries for Speed
  4. Code Signing Verification in the Loading Pipeline
  5. Runtime Dylib Resolution and Interposing

Chapter 10: Apple Silicon Architecture and Kernel Adaptations

  1. Apple Silicon SoC: CPU Clusters, GPU, Neural Engine, and I/O
  2. ARM64 Exception Model and Kernel Entry Paths
  3. Pointer Authentication Codes (PAC) in XNU
  4. Unified Memory Architecture and Cross-Device Memory Sharing
  5. Rosetta 2: x86_64 Binary Translation on Apple Silicon

Chapter 11: Security Architecture

  1. System Integrity Protection (SIP): Restricted Paths and Operations
  2. AMFI: The Kernel Code Signing Enforcement Engine
  3. Gatekeeper and the Quarantine Attribute
  4. macOS Sandbox: Policy Language, Profiles, and Enforcement
  5. TCC (Transparency, Consent, and Control) Privacy Architecture
  6. Endpoint Security Framework and Real-Time Threat Detection
  7. Modern Kernel Protections: KASLR, PPC64, and PPL

Chapter 12: Virtualization and Hypervisor.framework

  1. The Apple Silicon Hypervisor: Hardware Virtualization Extensions
  2. Hypervisor.framework API: Creating and Managing VMs
  3. Memory Mapping and Shared Regions in Guests
  4. Device Passthrough and Virtual I/O
  5. Virtualization Security Isolation and Guest Sandboxing

Chapter 13: Power Management and Energy Efficiency

  1. The IOPowerManagement Architecture
  2. CPU Power States: P-States, C-States, and Cluster Management
  3. Energy Scheduler: Integrating Power Awareness into Scheduling
  4. Thermal Management and Throttling Mechanisms
  5. Battery Life Optimization on Apple Silicon Macs

Chapter 14: Debugging, Tracing, and Performance Analysis

  1. DTrace: Dynamic Tracing Architecture and Providers
  2. The Instruments Framework: Time Profiler, Allocations, and System Trace
  3. Kernel Debugging: KDP, Boot Args, and Live Kernel Analysis
  4. Performance Monitoring: AMU Counters and the PMU Interface
  5. Reverse Engineering macOS: Tools, Techniques, and Limitations

Chapter 15: Conclusion: The Future of macOS Internals

  1. Key Architectural Takeaways
  2. The Apple Silicon Transition: Complete and What It Means
  3. Emerging Trends: Kernel Consolidation, Security Hardening, and AI Integration
  4. Where to Go From Here: Resources and Community

Glossary

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub