Apple quarantine warning

I’m seeing an unusual quarantine behavior with Bike on macOS 26.6.2.

When I create a new Markdown file in Bike, the file receives a com.apple.quarantine extended attribute:

com.apple.quarantine: 0082;...;Bike;

For example, a completely new .md file created with Bike shows:

com.apple.quarantine: 0082;6a9fdad9;Bike;

If I then go to Finder → Get Info → Open with and select Bike for that individual file, macOS displays this warning:

Apple could not verify “[filename].md” is free of malware that may harm your Mac or compromise your privacy.

The file itself is just a normal Markdown file created by Bike.

Removing only the quarantine attribute:

xattr -d com.apple.quarantine "/path/to/file.md"

makes the problem go away.

I reproduced this with both Bike 2 Preview and Bike 1.22.2 from the Mac App Store

A completely new file created with the Mac App Store version also receives:

com.apple.quarantine: 0082;...;Bike;

Is Bike intentionally causing newly created documents to receive the 0082 quarantine attribute, or could this be an interaction between Bike’s document handling and macOS 26?

  • macOS 26.6.2
  • Bike 2 Preview (301)
  • Bike 1.22.2 (Mac App Store)

I think that’s normal system behavior… at least I don’t believe Bike is don’t anything special related to quarantine when writing files, and I see other apps doing the same thing. For example when I save a new file with MarkEdit it adds xattr (or really system frameworks add I think):

com.apple.quarantine: 0082;6a9ff8e6;MarkEdit;

Why exactly? I don’t know, but seems expected.

…

This part on other hand seems wrong, but I also can’t reproduce it:

Anyone else know what could be going on here?

Jesse

I’ve seen a report of this at TidBITS Talk, albeit for webarchive files. I’m not sure there was a solution.

https://talk.tidbits.com/t/did-apple-deliberately-break-webarchives/33640

Both bike and webarchive involve html.

What Safari are you running?

What files are registered for Quick Look on the problematic files? I’m wondering if there’s a newly installed app creating problems. Guide

1 Like

I did a direct comparison using newly created Markdown files on the same Mac and in the same folder.

I created and saved a new .md file separately in Bike, BBEdit, and MarkEdit. Immediately after saving each file, I checked its extended attributes with:

xattr -l '/path/to/file.md'

I then specifically checked for the quarantine attribute with:

xattr -p com.apple.quarantine '/path/to/file.md'

The results were:

Bike:

0082;6aa2c372;Bike;

BBEdit:

No such xattr: com.apple.quarantine

MarkEdit:

No such xattr: com.apple.quarantine

I also tested whether the quarantine attribute was related to the launch warning.

With com.apple.quarantine present on a Bike file, opening it externally with:

open -a Bike '/path/to/file.md'

triggered the same macOS malware/quarantine warning and failed with Launch Services error -128.

I then quit Bike and removed only the quarantine attribute:

killall Bike 2>/dev/null
xattr -d com.apple.quarantine '/path/to/file.md'

I confirmed that it was gone:

xattr -p com.apple.quarantine '/path/to/file.md'

which returned:

No such xattr: com.apple.quarantine

Without making any other changes to the file, I ran the same command again:

open -a Bike '/path/to/file.md'

This time the file opened normally without the warning.

So, on my system:

  • Bike adds com.apple.quarantine to a newly created Markdown file.
  • BBEdit does not.
  • MarkEdit does not.
  • A Bike file that fails to open externally opens normally after removing only com.apple.quarantine.

This seems different from your MarkEdit test and, at least on my Mac, appears to be specific to Bike rather than a general macOS document-save behavior.

1 Like

I wonder if this started happening with a specific version of Bike. Might be worth trying some older versions?

If it doesn’t happen with a version from before your first report, you can then use binary search to bisect and find the offending one. (Pick one half way and go left or right depending on the result.)

1 Like

Sorry if I missed this, but can you reproduce this whole bug with a .bike file? Or does it require .md file?

Also, can anyone else reproduce the original problem? Ie can anyone generate the error:

Apple could not verify “[filename].md” is free of malware that may harm your Mac or compromise your privacy.

???


It’s also odd, I’m definitely seeing other apps add this quarantine. Previously I was on macOS 26, now I’m on macOS 27 with same result. I just created new doc with MarkdEdit and now I see:

jessegrosjean@Jesses-MacBook-Pro Desktop % xattr -l junk4.md 
com.apple.FinderInfo: 
com.apple.lastuseddate#PS: g\?j
com.apple.metadata:_kMDItemUserTags: bplist00?
com.apple.metadata:kMDLabel_gazkqpyci6ufoj36wzx2qckuem: ??$>??
                                                              :??$/?
                                                                    0M??????q??d?=?t?}o?J]?۱L?????׌PD?L?~~?7 ?R??셮?ڧ???I?:??)?_?N??|rH$W?
com.apple.provenance: 
com.apple.quarantine: 0082;6aa35c67;MarkEdit;

And with Bike:

jessegrosjean@Jesses-MacBook-Pro Desktop % xattr -l junk5.md
com.apple.FinderInfo: 
com.apple.TextEncoding: UTF-8
com.apple.lastuseddate#PS: "]?j
com.apple.metadata:_kMDItemUserTags: bplist00?
com.apple.metadata:kMDItemIdentifier: <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<string>Gz3MOjbqhtuEiR9a3wXfP</string>
</plist>

com.apple.metadata:kMDLabel_gazkqpyci6ufoj36wzx2qckuem: ?<?Y??ܒл??[~m?R_Ҽ??ۜ?6* g??&?Kc$"??m?E??2?k?y????s?4BP$&]W?
??
com.apple.quarantine: 0082;6aa35d22;Bike;

I’ve bumped into this a few times. It seems to only happen when you set Bike as the default to open one markdown file (importantly, I don’t think the warning happens when you set Bike as the default editor for all markdown files, which is also why it doesn’t happen for .bike files).

I think it’s the same issue from this discussion: https://apple.stackexchange.com/a/479468, so possibly a more general issue with all sandboxed apps using filetypes that aren’t exclusively for that one application.

I can now reproduce exactly what @saaaa described.

I restarted the Mac first to test from a clean state, then:

  1. I set MarkEdit as the default application for all .md files using Get Info → Open with → MarkEdit → Change All…
  2. I created and saved a new .md file in Bike, then set Open with → Bike for that individual file only, without using Change All…
  3. I opened the file from Finder.

The warning immediately appeared:

Apple could not verify “[filename].md” is free of malware that may harm your Mac or compromise your privacy.

When I instead set Bike as the default application for all .md files using Change All…, Bike-created .md files opened normally without the warning.

I also tested a native .bike file. It has the same kind of quarantine attribute:

com.apple.quarantine: 0082;6aa3de10;Bike;

but opens normally from Finder without any warning.

So this confirms @saaaa’s observation on my system: the warning is triggered when another app is the default handler for .md and Bike is assigned to open an individual .md file. The presence of com.apple.quarantine alone does not appear to be sufficient to trigger the warning.

1 Like

@saaaa and @LeftHandSolution thank for getting to the bottom of this. I tried a few times, but I’m better at making sense of programs then making sense of system, and I came up empty each time. Useful to know the reason. And helpful to know there’s not some lingering Bike bug that I need to fix.

And also Ugh!

2 Likes

Apple moves in mysterious ways!

What a horrible “feature”

I haven’t yet experimented with ( @ttscoff ) Brett Terpstra’s FileRouter app, but I wonder what happens when FileRouter is made the default app, as far as the system is concerned, for generic file extensions, like .md and .txt, and then delegates to particular editors in the light of a set of user-customized rules ?

Possible that Brett has found a way to a solution here ?

Happy to provide a promo code if you want to test it out and report back :).

I would ! @ttscoff

Thanks – I’ve just picked up a license via Paddle :slight_smile:

It looks interesting !

So far so good in testing @ttscoff 's FileRouter

  • I’ve selected an .md file in Finder and via ⌘I (Open With ... , Change All), I’ve specified FileRouter.app as the default application for that extension.
  • In FileRouter, I’ve specified using Bike for .md files in one folder, and WriteRoom for .md files in another folder:

Double-clicking on .md files in either folder seems to bring up the rule-requested app, for the context of the specific folder, without any quarantine message.

Does that yet constitute a sufficient test ?


Incidentally I also granted the relevant permissions to FileRouter:


Similarly, when the .md is in a folder not covered by the rules, and FileRouter offers an editor picker, I’m finding that on my system (macOS 26.6.2) the file is opened, in the selected editor, without quarantine warning interference.

Note that if you drag a file to the FileRouter menu bar icon, it will add the file type and offer to assign FileRouter as the owner in one step.

3 Likes

@ttscoff 's Filerouter seems to be working for me as well – no more quarantine warnings.

2 Likes