# Fix common issues while executing custom scripts on Mac

**Case 1:**

Unable to execute scripts. Argument values are not parsed as expected.

While executing the scripts, the argument values are not parsed to the corresponding variables used in the shell scripts. Hence, the scripts are not executed successfully.

**Reason:**

Failed to parse the argument value as a single entity as it is enclosed in quotes when passed from the Hexnode portal.

For instance,

The shell script to add a user to the device:

Shell script to add a user to the device

Shell

 #!/bin/ksh sysadminctl -addUser "Admin User" -fullName "$1" -password "$2" -hint "$3" 

   1

2

3

   \#!/bin/ksh 

sysadminctl -addUser "Admin User" -fullName "$1" -password "$2" -hint "$3" 

   

 

  

And, if a value “Adam Johns” is passed as $1, it is not considered a single component but two different components, “Adam” and “John”. Hence, the values might not be parsed correctly.

**Solution:**

Always enclose the argument value in single quotes if it contains two or more words separated by spaces while passing.

**<a id="brew"></a>Case 2:**

Running the Homebrew commands as scripts from the Hexnode portal generates the error “Running Homebrew as root is extremely dangerous and no longer supported. As Homebrew does not drop privileges on installation, you would be giving all build scripts full access to your system.”

**Reason:**

By default, Hexnode executes the script command at the root level.

**Solution:**

Homebrew commands need not be executed at the root level. In cases where you do not want specific commands to be run at the root level, you can explicitly execute them at the user level. The following command helps to get the logged-in details of the current user on the device:

`<br></br>currentUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ { print $3 }' )<br></br>`

Include the above command on the script. Then proceeding with the necessary operation as the currentUser helps you run it at the given user level.

For example, the below command changes the default dock orientation of the given user to the value *Left*.

`<br></br>currentUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ { print $3 }' )<br></br>`

`<br></br>sudo -u "$currentUser" defaults write com.apple.dock orientation left<br></br>`

**Case 3:**

Homebrew command raises the “Command not found” error.

**Reason:**

There might be an issue with the Homebrew path variable.

**Solution:**

Specify the full path (default location of Homebrew) for the path variable in the scripts.

For example:

HomeBrew commands

Shell

\#!/bin/sh currentUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ { print $3 }' ) brew=/usr/local/bin/brew $brew -v sudo -u "$currentUser" $brew list 

   1

2

3

4

5

  \#!/bin/sh 

currentUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ { print $3 }' )

brew=/usr/local/bin/brew

$brew -v

sudo -u "$currentUser" $brew list 

   

 

  

**Case 4:**

When a Python script is executed on macOS devices, the error “Script execution failed. Verify the binary path and try again!” may be produced.

**Reason:**

When choosing a script file to be executed, the Binary path field is auto-filled according to the format of the file. When a Python file is uploaded or selected from the Hexnode repository, /usr/bin/python is auto-filled as the binary path. This path may be insufficient in some instances.

Until macOS version 12.3, Macs used to have Python pre-installed in them. In later versions, Python has to be manually installed in order to execute a Python script on the device. But when installed manually, the binary path will be different.

**Solution:**

Execute the following command to get the required binary path:

Python location

Shell

which python

   1

  which python

   

 

  

Re-execute the Python script after replacing the auto-filled Binary path with the output of this command.

![python binary path](https:2022/01/Binary-path-to-execute-python-script.png "Binary path to execute python script")

**Case 5:**

Executing the script generates the error **“Script execution failed. Validate the script and try again!”** and produces the output **“Operation not permitted”**.
![Operation is not permitted for a script to delete a file](https:2022/01/Error-obtained-for-script-to-delete-a-file.png)

**Reason:**

If the script attempts to access/modify the files and folders on the device, the Hexnode agent app on the device requires certain permissions to access them. Otherwise, the script execution can lead to the error **“Script execution failed. Validate the script and try again!”** and generate the output **“Operation not permitted”**.

**Solution:**

You can grant the required permissions for the Hexnode agent app to access files and folders in the following ways:

1. Use the Privacy Preferences policy from the portal You can grant permissions to the Hexnode agent app from the portal by deploying the [Privacy Preferences](https://www.hexnode.com/mobile-device-management/help/how-to-configure-a-privacy-preferences-policy-control-profile-for-macos-devices/) policy.
    
    Here, you can grant permission to a specific folder (such as Desktop, Downloads, Documents, etc.) in which the file is present. Otherwise, you can grant permission to **All files**. To deploy a PPPC profile, follow these steps:
    
    
    1. Navigate to **Policies > macOS > Privacy Preferences**.
    2. Click on **Add new preference**.
    ![Click on Add new preference to configure privacy preferences](https:2023/12/Choose-Add-new-preference.png "Choose Add new preference")
    
    4. Select **Allow** from the drop down for **All files** (or to the specific folder where the file is stored).
    ![Change the access to Allow for All Files](https:2023/12/Modify-access-for-All-Files.png "Modify access for All Files")
    
    6. Click on **Select Apps**.
    7. Click on **Specify Bundle IDs/Path**.
    ![Select Specify Bundle IDs or Path to select app using Bundle ID](https:2023/12/Select-Specify-Bundle-IDs-or-Path.png "Select Specify Bundle IDs or Path")
    
    9. Select **Identifier type** as **Path**.
    ![Choose Path to specify the path and Code requirement for the app](https:2023/12/Choose-Path-to-provide-app-details.png "Choose Path to provide app details")
    
    11. Provide Identifier as:
    `/Library/Application Support/HexnodeMDM/hexnodeagentd`
    
    13. Provide code requirement as:
    `anchor apple generic and identifier "com.hexnode.hexnodeagentd" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = BX6L6CPUN8)`
    
    15. Enable the **Validate code requirement** checkbox. It statically validates the code requirement of the app.
    ![Enter the Identifier and Code requirement for the Agent app in provided fields](https:2023/12/Mention-Identifier-and-Code-requirement-for-the-Agent-app.png "Mention Identifier and Code requirement for the Agent app")
    
    17. Click **Add** to add the preference to the policy.
    ![The configured preferences are added for the Hexnode Agent app](https:2023/12/Preference-are-configured-for-Hexnode-Agent-app.png "Preference are configured for Hexnode Agent app")
    
    
    Deploy the policy to your target devices. You can execute the custom scripts successfully once the policy is associated.
2. Modify the Security & Privacy preference on the device. You need to provide the Hexnode agent app with **Full Disk Access** to be able to modify files and folders. Follow these steps to grant access to the Hexnode agent app from the device.
    
    
    1. Navigate to **System Preferences > Security & Privacy > Privacy > Full Disk Access**.
    ![Open Security & Privacy in System Preferences](https:2022/01/Navigate-to-Security-Privacy-in-System-Preferences.png)
    
    ![Open Privacy tab](https:2022/01/Navigate-to-Privacy-tab.png)
    
    ![Open Full Disk Access](https:2022/01/Navigate-to-Full-Disk-Access.png)
    
    5. Click on the Lock Icon to make changes.
    6. Enter the Administrator’s username and password.
    7. Click on **hexnodeagentd** to grant full disk access.
    ![Hexnode Agent app granted with Full Disk Access](https:2022/01/Full-Disk-Access-granted-to-Hexnode-Agent-app.png)
    
    
    Once the permission is granted, you can execute the custom script from your Hexnode portal.
    
     Note: 
    For devices running macOS 13.0 or above, navigate to **System Settings > Privacy & Security > Full Disk Access** to make changes.