mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-10-06 00:56:35 -05:00
macOS: isolate FUSE-T auxiliary mount paths
Create a fresh private parent for each FUSE-T auxiliary mount. Elevated parents stay root-owned and grant only the original user read/search access, restricting access through the auxiliary mount path and preventing caller-controlled path replacement during elevated setup. Clear inherited ACLs and reject temporary filesystems that ignore ownership. Remove per-mount parents on setup failure and service teardown, while preserving legacy temporary directories and discovery behavior. Add regression coverage for permissions, unique parent creation, rollback, and cleanup. FUSE-T transport authentication is outside this change.
This commit is contained in:
11 files changed
+442
-12
No files matched your search
@@ -14,8 +14,25 @@ build, then run:
|
||||
VC_TEST_BUILD_SRC=/absolute/path/to/build/src
|
||||
python3 Tests/test_macos_discovery.py --platform-archive "$VC_TEST_BUILD_SRC/Platform/Platform.a"
|
||||
python3 Tests/test_fuset_cleanup.py --build-dir "$VC_TEST_BUILD_SRC"
|
||||
python3 Tests/test_fuset_aux_directory.py --build-dir "$VC_TEST_BUILD_SRC"
|
||||
```
|
||||
|
||||
The auxiliary-directory check exercises the production FUSE-T private-parent
|
||||
helpers against disposable local directories, including concurrent creation,
|
||||
inherited ACL removal, setup failure cleanup, per-mount parent removal, and
|
||||
discovery ownership. The temporary filesystem must support ownership and ACLs.
|
||||
The helper check simulates disabled ownership without mounting a filesystem.
|
||||
An optional elevated run also checks caller access, parent immutability, and
|
||||
actual uid isolation using a harmless fixture:
|
||||
|
||||
```sh
|
||||
sudo python3 Tests/test_fuset_aux_directory.py --build-dir "$VC_TEST_BUILD_SRC" --owner "$(id -u)"
|
||||
```
|
||||
|
||||
The private parent protects auxiliary filesystem paths; these checks do not
|
||||
assess FUSE-T transport authentication. Existing volumes must be dismounted and
|
||||
remounted with the updated build to receive this protection.
|
||||
|
||||
The discovery runner compiles the production plist and batch-refresh methods
|
||||
with an in-memory inventory provider. It checks exact and legacy alias matches,
|
||||
unresolved inventory, stale-field invalidation, one query per refresh, and fresh
|
||||
|
||||
Reference in new issue
Block a user