Skip to content
BSD syscall#479

svc · unix #479

openbyid_np

Opens a vnode by filesystem id and inode number rather than by path (macOS-specific).

Prototype

int openbyid_np(user_addr_t fsid, user_addr_t objid, int oflags);

Returns: int

Arguments

NameTypeDirDescription
fsiduser_addr_t-
objiduser_addr_t-
oflagsint-

Version history

XNU tagmacOS#
xnu-2782.40.9macOS 10.10 Yosemite479
xnu-3247.1.106macOS 10.11 El Capitan479
xnu-3789.1.32macOS 10.12 Sierra479
xnu-4570.1.46macOS 10.13 High Sierra479
xnu-4903.221.2macOS 10.14 Mojave479
xnu-6153.11.26macOS 10.15 Catalina479
xnu-7195.50.7.100.1macOS 11.0 Big Sur479
xnu-8019.41.5macOS 12.0 Monterey479
xnu-8792.41.9macOS 13.0 Ventura479
xnu-10002.1.13macOS 14.0 Sonoma479
xnu-11215.1.10macOS 15.0 Sequoia479
xnu-11417.101.15macOS 15.4 Sequoia479
xnu-12377.1.9macOS 26.0 Tahoe479
xnu-10002.41.9479
xnu-10002.61.3479
xnu-10002.81.5479
xnu-10063.101.15479
xnu-10063.121.3479
xnu-10063.141.1479
xnu-11215.41.3479
xnu-11215.61.5479
xnu-11215.81.4479
xnu-11417.121.6479
xnu-11417.140.69479
xnu-12377.101.15479
xnu-12377.41.6479
xnu-12377.61.12479
xnu-12377.81.4479
xnu-2782.1.97479
xnu-2782.10.72479
xnu-2782.20.48479
xnu-2782.30.5479
xnu-3247.10.11479
xnu-3248.20.55479
xnu-3248.30.4479
xnu-3248.40.184479
xnu-3248.50.21479
xnu-3248.60.10479
xnu-3789.21.4479
xnu-3789.31.2479
xnu-3789.41.3479
xnu-3789.51.2479
xnu-3789.60.24479
xnu-3789.70.16479
xnu-4570.20.62479
xnu-4570.31.3479
xnu-4570.41.2479
xnu-4570.51.1479
xnu-4570.61.1479
xnu-4570.71.2479
xnu-4903.231.4479
xnu-4903.241.1479
xnu-4903.270.47479
xnu-6153.101.6479
xnu-6153.121.1479
xnu-6153.141.1479
xnu-6153.41.3479
xnu-6153.61.1479
xnu-6153.81.5479
xnu-7195.101.1479
xnu-7195.121.3479
xnu-7195.141.2479
xnu-7195.60.75479
xnu-7195.81.3479
xnu-8019.61.5479
xnu-8019.80.24479
xnu-8020.101.4479
xnu-8020.121.3479
xnu-8020.140.41479
xnu-8792.61.2479
xnu-8792.81.2479
xnu-8796.101.5479
xnu-8796.121.2479
xnu-8796.141.3479

Notes

Used by Time Machine, FSEvents replay tooling and indexing daemons to reopen objects whose path may have changed. Requires that the caller already know the (fsid, fileid) pair, typically from getattrlist. Subject to TCC and SIP checks like a regular open.

Detection

syscall::openbyid_np:entry in DTrace. Translates to a VFS lookup by id; resulting opens appear in ES_EVENT_TYPE_NOTIFY_OPEN.

Related APIs

openopenatgetattrlistfsgetpathfhopen