Post

Replies

Boosts

Views

Activity

AUTH_EXEC fail-closed behaviour after Endpoint Security client loss
I am reviewing an isolated synthetic worker design using public macOS 27 Endpoint Security APIs. The SDK declares es_set_deadline_miss_mode and es_new_descendants_client. The documentation describes ES_DEADLINE_MISS_MODE_FAIL_CLOSED for unanswered AUTH messages and queue overflow. I have not found a contract covering client loss. If the authorisation client crashes, disconnects or is deleted while AUTH_EXEC is pending, what verdict does the kernel apply? After the last matching client has disappeared, what happens to a subsequent exec by an already-running worker previously covered by that client? Is there a supported kernel-enforced mechanism that preserves replacement-exec denial for that worker until its original lifetime ends, despite authorisation-client failure? If not, please confirm that limitation. Are these client-loss semantics different for es_new_client and es_new_descendants_client, and which released macOS versions support the relevant contract? This is a documentation/design question; these APIs have not been exercised in this candidate. A post-exec watchdog or later termination would not establish pre-exec denial. References: https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::) https://developer.apple.com/documentation/endpointsecurity/es_new_descendants_client(::) https://developer.apple.com/documentation/endpointsecurity/es_delete_client(_:)
1
0
28
3h
AUTH_EXEC fail-closed behaviour after Endpoint Security client loss
I am reviewing an isolated synthetic worker design using public macOS 27 Endpoint Security APIs. The SDK declares es_set_deadline_miss_mode and es_new_descendants_client. The documentation describes ES_DEADLINE_MISS_MODE_FAIL_CLOSED for unanswered AUTH messages and queue overflow. I have not found a contract covering client loss. If the authorisation client crashes, disconnects or is deleted while AUTH_EXEC is pending, what verdict does the kernel apply? After the last matching client has disappeared, what happens to a subsequent exec by an already-running worker previously covered by that client? Is there a supported kernel-enforced mechanism that preserves replacement-exec denial for that worker until its original lifetime ends, despite authorisation-client failure? If not, please confirm that limitation. Are these client-loss semantics different for es_new_client and es_new_descendants_client, and which released macOS versions support the relevant contract? This is a documentation/design question; these APIs have not been exercised in this candidate. A post-exec watchdog or later termination would not establish pre-exec denial. References: https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::) https://developer.apple.com/documentation/endpointsecurity/es_new_descendants_client(::) https://developer.apple.com/documentation/endpointsecurity/es_delete_client(_:)
Replies
1
Boosts
0
Views
28
Activity
3h