SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
Apple New Added 28 August 2026

macOS: Operation not permitted (Full Disk Access / TCC)

macOS privacy protection blocked access to a protected location such as Desktop, Documents, Downloads, or another application's data, even for a process running as root. The permission is granted to the parent application, so a script run from Terminal needs Terminal to hold it.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Confirm it is TCC and not POSIX permissions
ls -le ~/Documents        # extended ACLs
ls -lO ~/Documents        # file flags

# Grant to the app that launches your process:
# System Settings -> Privacy & Security -> Full Disk Access
# add Terminal / iTerm / your IDE, then fully quit and relaunch it

# Check what was denied
log show --predicate 'subsystem == "com.apple.TCC"' --last 10m

How to diagnose Apple errors

macOS developer errors concentrate around three subsystems: the command line tools (xcrun and the active developer directory), the dynamic linker (dyld, library paths, and code signing), and Gatekeeper / notarisation. Apple Silicon added a fourth axis: architecture mismatches between arm64 and x86_64 binaries, which usually surface as confusing "library not loaded" or "bad CPU type" messages rather than as an explicit architecture error.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Check the active developer directory first with xcode-select -p. After every macOS or Xcode update this can point at a path that no longer exists, breaking git, compilers and package managers all at once.
  2. For dyld errors, run otool -L /path/to/binary to list what it actually wants, then verify each path exists. DYLD_PRINT_LIBRARIES=1 shows the resolution order at runtime.
  3. Confirm architecture with file /path/to/binary and uname -m. On Apple Silicon, a Rosetta shell reports x86_64 and will silently install the wrong Homebrew prefix.
  4. Homebrew lives at /opt/homebrew on Apple Silicon and /usr/local on Intel. Permission errors under /usr/local on an M-series Mac almost always mean a Rosetta/native mix-up.
  5. For Gatekeeper and notarisation, use spctl -a -vvv to assess a bundle and xcrun notarytool log to get the actual rejection reason. The submission status alone tells you nothing useful.

Tools worth reaching for

  • xcode-select -p
  • otool -L
  • codesign -dv --verbose=4
  • spctl -a -vvv
  • xcrun notarytool log

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

support.apple.com

Related Apple errors

See all 10 Apple errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.