Skip to content

Glossary

User-approved flag (0x0040)

Bit 0x0040 in the com.apple.quarantine flags, set when the user approves or overrides a Gatekeeper decision for a downloaded item.

0x0040 is the bit of the quarantine flags named QTN_FLAG_USER_APPROVED in WebKit's QuarantineSPI.h. Apple's open-source Security code (policyengine.cpp) sets the bit it calls QTN_FLAG_ASSESSMENT_OK when the user approves or overrides a Gatekeeper decision, and the 0x0040 value is consistent across these sources. Apple does not document the flags publicly.

A change from 0083 to 00c3 on the same file means the user approved it through Gatekeeper. The reverse inference does not hold: the absence of 0x0040 does not prove a document was never opened, because only executables, installers and apps go through that approval. See .LastGKReject and Gatekeeper evidence.