Created
September 15, 2026 01:46
-
-
Save sourcec0de/7e92ef92a6d89bedbaec771a3152b063 to your computer and use it in GitHub Desktop.
Determinate Nix from an MDM that runs scripts as root (Iru).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/bin/bash | |
| # Installs or updates Determinate Nix from an MDM that runs scripts as root (Iru). | |
| # | |
| # Adapted from: | |
| # https://docs.determinate.systems/guides/mdm/ | |
| # https://raw.githubusercontent.com/kandji-inc/support/refs/heads/main/Scripts/InstallHomebrew.zsh | |
| # | |
| # The upstream Determinate script expects to be run by a logged-in, non-root admin user | |
| # (via sudo). Under Iru the script runs as root with no console-user identity, so the | |
| # Determinate package cannot tell which user it is being installed for. The block below | |
| # resolves the console user the same way the Kandji InstallHomebrew.zsh script does and | |
| # runs the upstream body with the identity variables sudo would have set for that user. | |
| # Everything after the block is the upstream script. | |
| set -euo pipefail | |
| if [[ "$(/usr/bin/id -u)" -eq 0 && -z "${SUDO_USER:-}" ]]; then | |
| console_user=$(/usr/sbin/scutil <<<"show State:/Users/ConsoleUser" | | |
| /usr/bin/awk '/Name :/ && ! /loginwindow/ && ! /root/ && ! /_mbsetupuser/ { print $3 }' | | |
| /usr/bin/awk -F '@' '{print $1}') | |
| if [[ -z "$console_user" ]] || ! /usr/bin/dscl . -read "/Users/$console_user" >/dev/null 2>&1; then | |
| echo "No valid console user is logged in; cannot install Determinate in user scope." >&2 | |
| exit 1 | |
| fi | |
| SUDO_USER="$console_user" | |
| SUDO_UID="$(/usr/bin/id -u "$console_user")" | |
| SUDO_GID="$(/usr/bin/id -g "$console_user")" | |
| export SUDO_USER SUDO_UID SUDO_GID | |
| fi | |
| TEAM_ID="X3JQ4VPJZ6" | |
| PKG_ID="systems.determinate.Determinate" | |
| PKG_URL="https://install.determinate.systems/determinate-pkg/stable/Universal" | |
| installed_version="$(/usr/sbin/pkgutil --pkg-info-plist "$PKG_ID" 2>/dev/null | | |
| /usr/bin/plutil -extract pkg-version raw -o - - 2>/dev/null || true)" | |
| installed_version="${installed_version#v}" | |
| download_url="$(/usr/bin/curl -fsIL -o /dev/null -w '%{url_effective}' "$PKG_URL")" | |
| latest_version="$(echo "$download_url" | /usr/bin/grep -oE 'v?[0-9]+\.[0-9]+\.[0-9]+' | /usr/bin/head -1 || true)" | |
| latest_version="${latest_version#v}" | |
| if [[ -z "$download_url" || -z "$latest_version" ]]; then | |
| echo "Could not determine the latest Determinate release from $PKG_URL (resolved to '$download_url')" >&2 | |
| exit 1 | |
| fi | |
| if [[ -n "$installed_version" && "$installed_version" == "$latest_version" ]]; then | |
| echo "Determinate $installed_version is already installed and up to date." | |
| exit 0 | |
| fi | |
| tmp_dir="$(/usr/bin/mktemp -d)" | |
| pkg_path="$tmp_dir/Determinate.pkg" | |
| trap '/bin/rm -rf "$tmp_dir"' EXIT | |
| echo "Downloading Determinate $latest_version from $download_url ..." | |
| /usr/bin/curl -fsSL "$download_url" -o "$pkg_path" | |
| if ! /usr/sbin/spctl -a -vv -t install "$pkg_path" 2>&1 | /usr/bin/grep -q "($TEAM_ID)"; then | |
| echo "Determinate.pkg is not signed by Developer ID team $TEAM_ID; refusing to install." >&2 | |
| exit 1 | |
| fi | |
| echo "Installing Determinate $latest_version for user ${SUDO_USER:-$(/usr/bin/id -un)} ..." | |
| /usr/sbin/installer -pkg "$pkg_path" -target / |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment