Skip to content
Mach trap#-44

svc · mach trap -44

task_name_for_pid

Returns a name-flavor task port for the given PID — read-only metadata access without memory or thread control.

Prototype

kern_return_t task_name_for_pid(/* 3 args */);

Returns: kern_return_t

Version history

XNU tagmacOS#
xnu-1228macOS 10.5 Leopard-44
xnu-1456.1.26macOS 10.6 Snow Leopard-44
xnu-1699.24.8macOS 10.7 Lion-44
xnu-2050.18.24macOS 10.8 Mountain Lion-44
xnu-2422.115.4macOS 10.9 Mavericks-44
xnu-2782.40.9macOS 10.10 Yosemite-44
xnu-3247.1.106macOS 10.11 El Capitan-44
xnu-3789.1.32macOS 10.12 Sierra-44
xnu-4570.1.46macOS 10.13 High Sierra-44
xnu-4903.221.2macOS 10.14 Mojave-44
xnu-6153.11.26macOS 10.15 Catalina-44
xnu-7195.50.7.100.1macOS 11.0 Big Sur-44
xnu-8019.41.5macOS 12.0 Monterey-44
xnu-8792.41.9macOS 13.0 Ventura-44
xnu-10002.1.13macOS 14.0 Sonoma-44
xnu-11215.1.10macOS 15.0 Sequoia-44
xnu-11417.101.15macOS 15.4 Sequoia-44
xnu-12377.1.9macOS 26.0 Tahoe-44
xnu-10002.41.9-44
xnu-10002.61.3-44
xnu-10002.81.5-44
xnu-10063.101.15-44
xnu-10063.121.3-44
xnu-10063.141.1-44
xnu-11215.41.3-44
xnu-11215.61.5-44
xnu-11215.81.4-44
xnu-11417.121.6-44
xnu-11417.140.69-44
xnu-1228.0.2-44
xnu-1228.12.14-44
xnu-1228.15.4-44
xnu-1228.3.13-44
xnu-1228.5.18-44
xnu-1228.5.20-44
xnu-1228.7.58-44
xnu-1228.9.59-44
xnu-12377.101.15-44
xnu-12377.41.6-44
xnu-12377.61.12-44
xnu-12377.81.4-44
xnu-1486.2.11-44
xnu-1504.15.3-44
xnu-1504.3.12-44
xnu-1504.7.4-44
xnu-1504.9.17-44
xnu-1504.9.26-44
xnu-1504.9.37-44
xnu-1699.22.73-44
xnu-1699.22.81-44
xnu-1699.24.23-44
xnu-1699.26.8-44
xnu-1699.32.7-44
xnu-2050.22.13-44
xnu-2050.24.15-44
xnu-2050.48.11-44
xnu-2050.7.9-44
xnu-2050.9.2-44
xnu-2422.1.72-44
xnu-2422.100.13-44
xnu-2422.110.17-44
xnu-2422.90.20-44
xnu-2782.1.97-44
xnu-2782.10.72-44
xnu-2782.20.48-44
xnu-2782.30.5-44
xnu-3247.10.11-44
xnu-3248.20.55-44
xnu-3248.30.4-44
xnu-3248.40.184-44
xnu-3248.50.21-44
xnu-3248.60.10-44
xnu-3789.21.4-44
xnu-3789.31.2-44
xnu-3789.41.3-44
xnu-3789.51.2-44
xnu-3789.60.24-44
xnu-3789.70.16-44
xnu-4570.20.62-44
xnu-4570.31.3-44
xnu-4570.41.2-44
xnu-4570.51.1-44
xnu-4570.61.1-44
xnu-4570.71.2-44
xnu-4903.231.4-44
xnu-4903.241.1-44
xnu-4903.270.47-44
xnu-6153.101.6-44
xnu-6153.121.1-44
xnu-6153.141.1-44
xnu-6153.41.3-44
xnu-6153.61.1-44
xnu-6153.81.5-44
xnu-7195.101.1-44
xnu-7195.121.3-44
xnu-7195.141.2-44
xnu-7195.60.75-44
xnu-7195.81.3-44
xnu-792.10.96-44
xnu-792.13.8-44
xnu-792.18.15-44
xnu-792.22.5-44
xnu-792.25.20-44
xnu-8019.61.5-44
xnu-8019.80.24-44
xnu-8020.101.4-44
xnu-8020.121.3-44
xnu-8020.140.41-44
xnu-8792.61.2-44
xnu-8792.81.2-44
xnu-8796.101.5-44
xnu-8796.121.2-44
xnu-8796.141.3-44

Notes

task_name_for_pid is the least privileged of the *_for_pid family: the name port lets the holder call task_info, pid_for_task, and a handful of similar query routines, but not vm_read, thread_create, or any control-plane operation. Apple introduced this flavor so that monitoring tools (Activity Monitor, top, sample) can identify processes without holding the dangerous control port. It is allowed for any process against any target with matching real-UID, and for root unconditionally.

Detection

There is no Endpoint Security event for task_name_for_pid specifically — ES_EVENT_TYPE_NOTIFY_GET_TASK_NAME exists on macOS 11.3+ and fires for this exact code path. DTrace can hook the mach_trap entry as a fallback for older systems.

Related APIs

task_for_pidtask_read_for_pidtask_inspect_for_pidpid_for_tasktask_info