Skip to content

Glossary

Quarantine flags

The hexadecimal bit field that opens a com.apple.quarantine value. Apple does not document it; known bits come from open-source code.

The first field of a quarantine attribute is a hexadecimal bit field, and Apple does not document it publicly. WebKit's open-source QuarantineSPI.h declares 0x0001 QTN_FLAG_DOWNLOAD, 0x0002 QTN_FLAG_SANDBOX, 0x0004 QTN_FLAG_HARD and 0x0040 QTN_FLAG_USER_APPROVED. The names QTN_FLAG_TRANSLOCATE and QTN_FLAG_DO_NOT_TRANSLOCATE appear in Apple's sources, but their values, 0x0080 and 0x0100, come from third-party re-declarations and carry medium confidence. Every other bit, such as 0x0020, is unknown.

Commonly seen values include 0081, 0083, 0082 (a sandboxed app wrote the file), 00c3 and 00c1 (the user-approved flag is set), 0183 and 0086. Read them as bit combinations rather than fixed codes. See com.apple.quarantine flags explained.