#22617 Detect and warn about XProtect on macOS
Issue created by
huonw
Is your feature request related to a problem? Please describe.
On macOS, there's a single threaded code-signing verification process called XProtect. This adds 100-300ms of overhead to every execution of a "new" executable (where new includes copying an existing executable to a new path, like pants can do when creating a sandbox).
This is extremely bad for pants performance on macOS, since it'll be creating a lot of new executables and executing them in parallel.
Describe the solution you'd like
It's apparently possible to disable XProtect by marking the apps used to run pants (e.g. Terminal) as "developer tools".
Pants can detect if XProtect is active and warn/guide users to that setting for them to opt in (if desired).
Describe alternatives you've considered
Never copying binaries at all, always using a "immutable digest" symlink: this is a lot of effort, and may not always be possible for all backends.
For instance:
#22111 focused on the ruff backend alone.
Additional context
See also:
•
rust-lang/cargo#15908
•
https://nnethercote.github.io/2025/09/04/faster-rust-builds-on-mac.html (especially "the workaround" section)
pantsbuild/pants