macOS: isolate FUSE-T auxiliary mount paths

Create a fresh private parent for each FUSE-T auxiliary mount. Elevated
parents stay root-owned and grant only the original user read/search
access, restricting access through the auxiliary mount path and preventing
caller-controlled path replacement during elevated setup.

Clear inherited ACLs and reject temporary filesystems that ignore
ownership. Remove per-mount parents on setup failure and service teardown,
while preserving legacy temporary directories and discovery behavior.

Add regression coverage for permissions, unique parent creation, rollback,
and cleanup. FUSE-T transport authentication is outside this change.
This commit is contained in:
Mounir IDRASSI committed 2026-09-29 10:01:37 +02:00
1 parent c91f386f00
commit 41bc8e5f6a
11 files changed
+442 -12

No files matched your search

+12
View File
@@ -93,6 +93,17 @@ static int test_stat (const char *path, struct stat *value)
return stat (path, value);
}
static char *test_mkdtemp (char *path)
{
if (mode_is ("aux-child") && fixture_path (path, "/.veracrypt_aux_mnt-XXXXXXXXXXXX"))
{
mark_fault();
errno = EACCES;
return NULL;
}
return mkdtemp (path);
}
static unsigned fault_delay (void)
{
const char *delay = getenv ("VC_FUSET_TEST_DELAY");
@@ -136,5 +147,6 @@ static int test_unlinkat (int fd, const char *path, int flags)
INTERPOSE (test_connect, connect);
INTERPOSE (test_open, open);
INTERPOSE (test_stat, stat);
INTERPOSE (test_mkdtemp, mkdtemp);
INTERPOSE (test_unmount, unmount);
INTERPOSE (test_unlinkat, unlinkat);