mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-10-06 00:56:35 -05:00
macOS: isolate FUSE-T auxiliary mount paths
Create a fresh private parent for each FUSE-T auxiliary mount. Elevated parents stay root-owned and grant only the original user read/search access, restricting access through the auxiliary mount path and preventing caller-controlled path replacement during elevated setup. Clear inherited ACLs and reject temporary filesystems that ignore ownership. Remove per-mount parents on setup failure and service teardown, while preserving legacy temporary directories and discovery behavior. Add regression coverage for permissions, unique parent creation, rollback, and cleanup. FUSE-T transport authentication is outside this change.
This commit is contained in:
11 files changed
+442
-12
No files matched your search
@@ -71,7 +71,7 @@ def main():
|
||||
vc("mount", "--mount", volume, mountpoint, "--password=" + password,
|
||||
"--pim=1", "--keyfiles=", "--protect-hidden=no",
|
||||
*(["--mount-options=ro"] if read_only else []))
|
||||
identities = list(temporary.glob(".veracrypt_aux_mnt*/shutdown"))
|
||||
identities = list(temporary.glob("**/.veracrypt_aux_mnt*/shutdown"))
|
||||
assert len(identities) == 1, "Expected one disposable FUSE-T service"
|
||||
aux = identities[0].parent
|
||||
active = (int(identities[0].read_text().split()[0]), aux,
|
||||
@@ -86,7 +86,7 @@ def main():
|
||||
pass
|
||||
else:
|
||||
raise AssertionError("Disposable service still running")
|
||||
assert not aux.exists() and not endpoint.exists(), "Cleanup paths remain"
|
||||
assert not aux.exists() and not aux.parent.exists() and not endpoint.exists(), "Cleanup paths remain"
|
||||
assert str(root) not in mounts(), "Disposable mount remains"
|
||||
handles = subprocess.run(["/usr/sbin/lsof", "-t", str(volume)], capture_output=True, text=True)
|
||||
assert handles.returncode == 1 and not handles.stdout.strip(), "Backing file still open"
|
||||
|
||||
Reference in new issue
Block a user