> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Uninstall

> Remove Silmaril through MDM and resolve items reported in the uninstall receipt.

export const macosRelease = {
  "version": "0.3.22",
  "build": "1077",
  "guardianEnabled": false,
  "minimumOS": "macOS 14 or later",
  "dmgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.dmg",
  "pkgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.pkg",
  "mdmZipUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip",
  "mdmChecksumUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip.sha256",
  "mdmSHA256": "86efaf60414339c97c5fcaac86d98b215f44010798f58e83ea3850b1243fd92a"
};

<a id="uninstall" />

Use this script to remove Stable {macosRelease.version} ({macosRelease.build}) through Jamf Pro, Iru, or Fleet. [Download the uninstall script](https://silmaril.dev/docs/macos/Silmaril-Uninstall.sh) or copy it below unchanged. It calls the uninstaller bundled with the installed Silmaril app.

## Remove through MDM

<Steps>
  <Step title="Pause installation">
    Pause every Silmaril app installation assignment or policy for the target Macs, so the vendor cannot reinstall Silmaril. Leave unrelated management enabled.

    Do not delete a shared Blueprint, fleet, or group. Removing a tag, group, or label does not uninstall Silmaril.

    **Expected result**<br />
    Jamf, Iru, or Fleet can no longer reinstall Silmaril onto the target Macs. Unrelated management stays enabled. Vendor-specific task placement is in the [Jamf](/docs/macos/jamf), [Iru](/docs/macos/iru), and [Fleet](/docs/macos/fleet) uninstall steps.

    **If this differs**<br />
    Leave the uninstall script unrun until those install policies are paused. Otherwise MDM can put the app back.
  </Step>

  <Step title="Prepare the user session">
    Have the affected user sign in and save their work. The uninstaller removes that user's Silmaril integrations and local data, removes the shared application, and may stop and reopen agent applications. On shared Macs, arrange cleanup for every affected account before removing the app.

    **Expected result**<br />
    The affected user is signed in at the console. Console UID is above 500.

    **If this differs**<br />
    The script exits 69 and attempts no removal when it cannot identify a signed-in user, or when that UID is 500 or below. Sign the user in and run the script again.
  </Step>

  <Step title="Run through MDM">
    Copy the script below unchanged into a root script task in Jamf Pro, Iru, or Fleet, or upload the downloaded file. Keep the JSON receipt and the exit code from the task.

    **Expected result**<br />
    The task runs as root and returns the uninstaller JSON plus exit code 0 or 2, or another code explained below.

    **If this differs**<br />
    Exit 77 means the script was not run as root. Exit 69 before the uninstaller runs means there is no eligible signed-in user, or the bundled uninstaller at `/Applications/Silmaril.app/Contents/Helpers/SilmarilUninstaller` is unavailable. Review the installed app and any previous receipt. A missing app or helper does not prove that earlier cleanup completed.
  </Step>

  <Step title="Complete the reported follow-up">
    Use the exit-code table below to review the result. Remove only the Silmaril configuration profile through MDM when policy should no longer apply. Confirm baseline assignments and controls are still intact. Local credential removal does not revoke the server API key.

    **Expected result**<br />
    Exit 0, with the app removed, and only the Silmaril profile removed through MDM when policy should stop applying. Baseline assignments and controls remain.

    **If this differs**<br />
    Follow the row for that exit code. Profile removal is a separate MDM change. Removing the profile does not uninstall Silmaril, and uninstalling the app does not remove the profile.
  </Step>
</Steps>

## Managed uninstall script

```bash theme={"theme":"github-light-default"}
#!/bin/bash
# Run through MDM as root with the affected user signed in.
set -u

APP="/Applications/Silmaril.app"
UNINSTALLER="$APP/Contents/Helpers/SilmarilUninstaller"

if [[ "$(/usr/bin/id -u)" -ne 0 ]]; then
  echo "Run the Silmaril uninstall script as root through MDM." >&2
  exit 77
fi

console_uid="$(/usr/bin/stat -f %u /dev/console)" || exit 69
case "$console_uid" in
  ''|*[!0-9]*)
    echo "Cannot identify the signed-in user. No removal was attempted." >&2
    exit 69
    ;;
esac
if [[ "$console_uid" -le 500 ]]; then
  echo "The affected user must be signed in. No removal was attempted." >&2
  exit 69
fi

if [[ ! -x "$UNINSTALLER" ]]; then
  echo "The bundled Silmaril uninstaller is unavailable. Review the installed app and any previous uninstall receipt." >&2
  exit 69
fi

if "$UNINSTALLER" --managed --user "$console_uid" --json; then
  result=0
else
  result=$?
fi

case "$result" in
  0) echo "Silmaril removal completed." >&2 ;;
  2) echo "Silmaril reported remaining items (exit 2). Review the JSON receipt for the affected components and required actions." >&2 ;;
  *) echo "Silmaril removal did not complete (exit $result). Review the uninstaller output before retrying." >&2 ;;
esac
exit "$result"
```

## Exit codes

| Exit code | Meaning | Next step |
| - | - | - |
| 0 | Removal completed. | Verify app removal and remove only the Silmaril profile through MDM. Confirm baseline assignments and controls remain intact. |
| 2 | Removal completed with reported remaining items. | Review the receipt's residue or failed steps. The exit code alone does not identify the component or prove Guardian remains. Do not continue until the reported items have been reviewed and resolved. |
| Any other nonzero code | Removal did not complete or could not start. | Read the uninstaller output and correct the reported problem before retrying. A missing app or helper does not prove that earlier cleanup completed. |

For Stable {macosRelease.version} ({macosRelease.build}), Guardian Disabled, a receipt can report successful app and integration removal with only Managed permissions and Notification permission remaining. Managed permissions means MDM policy may remain. Notification permission may be unverified. Remove only the Silmaril profile through MDM and, if Silmaril still appears in System Settings > Notifications, turn off Allow Notifications. Confirm baseline assignments and controls remain intact. These permission entries alone do not indicate remaining protection.

If the receipt reports remaining Guardian components, failed app removal, or `protectionMayStillRun=true`, do not continue until that reported item is resolved. After the app is removed, complete permission follow-up directly through MDM or System Settings. Do not rerun a missing helper to obtain exit 0. Contact support before replacing an incompatible installed variant.

<Warning>
  Exit 2 is a receipt to read, not a Guardian finding. Confirm installed state separately. Check `/Applications/Silmaril.app` and its process, the Guardian daemon `dev.silmaril.guardian`, and the system extension `dev.silmaril.SilmarilMacOS.GuardianExtension`.
</Warning>

<a id="guardian-enabled-034-1053" />

<a id="iru-guardian-enabled" />

<a id="historical-guardian" />

<a id="iru-remove-guardian" />
