I am reviewing an isolated synthetic worker design using public macOS 27 Endpoint Security APIs. The SDK declares es_set_deadline_miss_mode and es_new_descendants_client.
The documentation describes ES_DEADLINE_MISS_MODE_FAIL_CLOSED for unanswered AUTH messages and queue overflow. I have not found a contract covering client loss.
If the authorisation client crashes, disconnects or is deleted while AUTH_EXEC is pending, what verdict does the kernel apply?
After the last matching client has disappeared, what happens to a subsequent exec by an already-running worker previously covered by that client?
Is there a supported kernel-enforced mechanism that preserves replacement-exec denial for that worker until its original lifetime ends, despite authorisation-client failure? If not, please confirm that limitation.
Are these client-loss semantics different for es_new_client and es_new_descendants_client, and which released macOS versions support the relevant contract?
This is a documentation/design question; these APIs have not been exercised in this candidate. A post-exec watchdog or later termination would not establish pre-exec denial.
References:
https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::)
https://developer.apple.com/documentation/endpointsecurity/es_new_descendants_client(::)
https://developer.apple.com/documentation/endpointsecurity/es_delete_client(_:)
1
0
27