OS X El Capitan System Integrity Protection - Add access to /Library/Desktop Pictures/El Capitan.jpg

Originator:eriknicolasgomez
Number:rdar://21308772 Date Originated:09-June-2015
Status:Open Resolved:No
Product:OS X El Capitan Product Version:15A178w
Classification:OS X Security Reproducible:Yes
 
Summary:
El Capitan.jpg in /Library/Desktop Pictures is locked and cannot be modified.

This will allow an admin to change the default picture, now that /System/Library/CoreServices/DefaultDesktop.jpg is blocked from modification due to SIP.

/Library/Desktop Pictures itself is not blocked, but try modifying /Library/Desktop Pictures/El Capitan.jpg, which is what /System/Library/CoreServices/DefaultDesktop.jpg points to.
 
I was not able to delete /Library/Desktop Pictures/El Capitan.jpg or remove it in my testing. I could make a copy of the file, and was even able to make a copy of it inside of /Library/Desktop Pictures.

Steps to Reproduce:
1. Go to /Library/Desktop Pictures
2. You can manipulate files in there.
3. Attempt to manipulate El Capitan.jpg (rename, delete). File is locked.
4. Do same process in Terminal. Even as sudo, permission denied.

Expected Results:
Should be able to modify El Capitan.jpg, like all other files.

Actual Results:
Cannot modify file.

Version:
OS X El Capitan Developer Beta 1 / 15A178w

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!