Security model

What Nightlid’s helper can and can’t do

Keeping a closed MacBook awake needs one system setting that only an administrator process can change. So Nightlid comes with a small helper that runs as root. You should know exactly what it does — here it is, including the limits.

In one sentence: the helper can turn macOS’s “sleep disabled” flag on and off and put the Mac to sleep — only for the signed Nightlid app and CLI, only while they keep renewing a short lease, and it falls back to normal sleep whenever anything goes wrong.

Why a root helper at all

With the lid closed, on battery and without an external display, macOS sleeps a MacBook no matter which power assertions apps hold (that’s why caffeinate doesn’t help). The only switch that changes this is the system power setting SleepDisabled — the same one sudo pmset -a disablesleep 1 sets. Changing it requires root.

The helper is a launch daemon that macOS registers through its own SMAppService API. You approve it once in System Settings → General → Login Items, and you can switch it off there at any time. Nightlid never asks you to edit sudoers and never stores your password.

What the helper can do

CallWhat it does
acquireLease / renewLease / releaseLeaseHold, extend or give back a time-limited lease. Sleep is disabled if and only if at least one unexpired lease exists.
sleepNowPut the Mac to sleep right away.
setEmergencyFloorSet the emergency battery floor (3–20 %) that the helper enforces on its own.
status, protocolVersionReport its state: leases, the sleep flag, last action.

That is the entire interface. Internally the helper calls exactly two system functions that change anything: set the SleepDisabled power setting, and request system sleep.

What it can’t do

Who may talk to it

The app and the nightlid command-line tool talk to the helper over XPC (the macOS inter-process channel) on the privileged Mach service app.nightlid.helper. Both sides check each other’s code signature on every connection:

Leases: crash-safe by design

Ending a session actually sleeps the Mac

Turning SleepDisabled off does not put a Mac to sleep whose lid is already closed — macOS only re-checks the lid when it opens or closes. A naïve tool can therefore leave a closed Mac running until the battery is empty. When the last lease ends with the lid closed, Nightlid’s helper clears the flag, verifies it was cleared, re-checks that the lid is still closed and then requests sleep. If the Mac is still awake, it retries every 60 seconds (up to 3 times within 5 minutes).

Exceptions: with an external display and power connected, macOS keeps a closed Mac awake itself (clamshell mode), so the helper doesn’t force sleep after a normal release — but it does when the app crashed and can’t confirm the display. During logout, restart and shutdown the helper clears the flag but never forces sleep, so it can’t get in the way.

Emergency limits in the helper

These apply even when the app isn’t running:

Everything else — your battery floor (default 20 %), the thermal cut-off you choose, timers, the maximum length, “only when connected to power”, Low Power Mode — is enforced by the app, which ends its lease when a rule triggers.

The app side

Limits — what we can’t promise

Reporting a vulnerability

Please email support@nightlid.app with “security” in the subject. We’ll acknowledge within a few days and credit you if you like. Security fixes to the helper are free for every license, including after the update period.