mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-10-05 16:46:35 -05:00
macOS: harden FUSE-T dismount ownership and teardown
Keep FUSE serving until the auxiliary SMB filesystem is unmounted, then join the shutdown worker before destroying the FUSE handle. Authenticate socket peers and bind each request to the service and filesystem instance; carry the force flag through to unmount and reply before teardown. Resolve the current disk image before detach instead of trusting cached BSD device numbers. Clear device and mount metadata when the image is gone, and abort on inventory errors. Refresh ownership during enumeration and before filesystem checks. Give each auxiliary mount a random path so an old backend cannot target a subsequent VeraCrypt mount during cleanup. Canonicalize the auxiliary path before service startup and hdiutil attach. Resolve older clients' image paths through TMPDIR aliases without accessing unrelated images. Treat candidate resolution failures as errors rather than evidence that an attached image is gone. Keep a new service provisional over a private inherited socketpair until control-file readiness and public shutdown endpoint checks succeed. On startup failure or caller exit, unmount while FUSE still serves and wait for volume closure and service exit. Report incomplete cleanup explicitly and keep retrying cleanup in the service if unmounting is temporarily blocked. Restore dismounts of released services without /shutdown through a validated legacy flow. Preserve incoming file-protocol notifications and watch for external unmounts independently of those notifications. Legacy unmount cannot guarantee termination of an already-running old service. Use one fixed versioned socket frame and publish the random endpoint in /shutdown-socket, preserving the three-field /shutdown identity. Remove compatibility with unpublished socket protocols. Recover from transient accept and mount-enumeration failures, bound partial-request lifetimes, and report connection refusal as an availability error. Handle join failure without unwinding the destructor or freeing a live worker's context. Map auxiliary EBUSY to MountedVolumeInUse for the GUI force prompt. Return failure for a single busy non-interactive dismount and log automatic-dismount failures. Mark inherited descriptors close-on-exec before FUSE setup and make File::SetCloseOnExec const. Extend disposable-container tests for released clients and services, reused device numbers, partial requests, identity validation, forced write integrity, TMPDIR aliases, and injected startup and rollback failures. Validated without sudo with a clean arm64 build, unchanged warnings, algorithm self-tests, the compatibility matrix, descriptor audits, worker fault-recovery checks, and 24 conditional compilation checks.
This commit is contained in:
14 files changed
+1421
-162
No files matched your search
@@ -1691,6 +1691,8 @@
|
||||
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
|
||||
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
|
||||
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
|
||||
<entry lang="en" key="MOUNT_SERVICE_INCOMPATIBLE">The service running this volume does not support the requested dismount operation.\n\nDismount the volume using the version of VeraCrypt that mounted it, then mount it again with this version. Close files using the volume if necessary. Always dismount volumes before upgrading VeraCrypt.</entry>
|
||||
<entry lang="en" key="MOUNT_SERVICE_CLEANUP_FAILED">VeraCrypt could not complete cleanup after a failed mount. The volume may still be accessible.\n\nDismount the volume in VeraCrypt. If dismounting fails, restart the computer before relying on the volume being locked.</entry>
|
||||
</localization>
|
||||
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
|
||||
<xs:element name="VeraCrypt">
|
||||
|
||||
Reference in new issue
Block a user