gcc d.c && sudo dtruss ./a.out dtrace: system integrity protection is on, some features will not be available SYSCALL(args) = return src 3 dst 4 c 14053376 p 20344832 h 20344832 d 6291456 total bytes copied 14053376 / 27551296 access("/AppleInternal/XBS/.isChrooted\0", 0x0, 0x0) = -1 2 bsdthread_register(0x7FF801A75F5C, 0x7FF801A75F48, 0x2000) = 1073742303 0 shm_open(0x7FF801943F5D, 0x0, 0x194278A) = 3 0 fstat64(0x3, 0x7FF7BE802250, 0x0) = 0 0 mmap(0x0, 0x2000, 0x1, 0x40001, 0x3, 0x0) = 0x107C0E000 0 close(0x3) = 0 0 ioctl(0x2, 0x4004667A, 0x7FF7BE802304) = 0 0 mprotect(0x107C15000, 0x1000, 0x0) = 0 0 mprotect(0x107C21000, 0x1000, 0x0) = 0 0 mprotect(0x107C22000, 0x1000, 0x0) = 0 0 mprotect(0x107C2E000, 0x1000, 0x0) = 0 0 mprotect(0x107C2F000, 0x1000, 0x0) = 0 0 mprotect(0x107C3B000, 0x1000, 0x0) = 0 0 mprotect(0x107C10000, 0x90, 0x1) = 0 0 mprotect(0x107C10000, 0x90, 0x3) = 0 0 mprotect(0x107C10000, 0x90, 0x1) = 0 0 mprotect(0x107C3C000, 0x1000, 0x1) = 0 0 mprotect(0x107C3D000, 0x90, 0x1) = 0 0 mprotect(0x107C3D000, 0x90, 0x3) = 0 0 mprotect(0x107C3D000, 0x90, 0x1) = 0 0 mprotect(0x107C10000, 0x90, 0x3) = 0 0 mprotect(0x107C10000, 0x90, 0x1) = 0 0 mprotect(0x107C3C000, 0x1000, 0x3) = 0 0 mprotect(0x107C3C000, 0x1000, 0x1) = 0 0 issetugid(0x0, 0x0, 0x0) = 0 0 getentropy(0x7FF7BE8021E0, 0x20, 0x0) = 0 0 getentropy(0x7FF7BE802240, 0x40, 0x0) = 0 0 getpid(0x0, 0x0, 0x0) = 65055 0 stat64("/AppleInternal\0", 0x7FF7BE802820, 0x0) = -1 2 csops_audittoken(0xFE1F, 0x10, 0x7FF7BE802360) = -1 22 proc_info(0x2, 0xFE1F, 0xD) = 64 0 csops_audittoken(0xFE1F, 0x10, 0x7FF7BE802430) = -1 22 sysctlbyname(kern.osvariant_status, 0x15, 0x7FF7BE802868, 0x7FF7BE802870, 0x0) = 0 0 csops(0xFE1F, 0x0, 0x7FF7BE8028A4) = 0 0 mprotect(0x107B0C000, 0x100000, 0x1) = 0 0 open("cc1\0", 0x0, 0x0) = 3 0 open("cc1-sparse\0", 0x202, 0x1C0) = 4 0 getrlimit(0x1008, 0x7FF7BE803590, 0x0) = 0 0 fstat64(0x1, 0x7FF7BE803578, 0x0) = 0 0 ioctl(0x1, 0x4004667A, 0x7FF7BE8035C4) = 0 0 dtrace: error on enabled probe ID 1700 (ID 963: syscall::write_nocancel:return): invalid kernel access in action #12 at DIF offset 68 lseek(0x3, 0x0, 0x4) = 6291456 0 lseek(0x3, 0x600000, 0x3) = 20344832 0 lseek(0x3, 0x600000, 0x0) = 6291456 0 lseek(0x4, 0x600000, 0x0) = 6291456 0 dtrace: error on enabled probe ID 1701 (ID 175: syscall::read:return): invalid kernel access in action #12 at DIF offset 68 dtrace: error on enabled probe ID 1699 (ID 177: syscall::write:return): invalid kernel access in action #12 at DIF offset 68 lseek(0x3, 0x0, 0x1) = 20344832 0 dtrace: error on enabled probe ID 1700 (ID 963: syscall::write_nocancel:return): invalid kernel access in action #12 at DIF offset 68 lseek(0x3, 0x1367000, 0x4) = -1 6 lseek(0x3, 0xFFFFFFFFFFFFFFFF, 0x3) = -1 22 lseek(0x3, 0xFFFFFFFFFFFFFFFF, 0x0) = -1 22 lseek(0x4, 0xFFFFFFFFFFFFFFFF, 0x0) = -1 22 lseek(0x3, 0x0, 0x2) = 27551296 0 ftruncate(0x4, 0x1A46640, 0x0) = 0 0 close(0x3) = 0 0 close(0x4) = 0 0 dtrace: error on enabled probe ID 1700 (ID 963: syscall::write_nocancel:return): invalid kernel access in action #12 at DIF offset 68