forked from Manuel/meeting-assistant
Observe owned Recovery process without a guest SDK or task control rights
This commit is contained in:
1 parent
81a3b9c7d2
commit
4b7fd160ef
7 files changed
+374
-11
No files matched your search
@@ -20,10 +20,18 @@ Run 4192 at `6122be2` captured the actual 603-byte guest file and strictly parse
|
||||
|
||||
Run 4193 at `9164fe4` successfully derived the same current-file version in both guest and host. Its single `diskutil list physical` process was stopped at 124 seconds by the 120-second watchdog without output. The observer saw one runnable row and 3.18 seconds of accumulated CPU time, without a stack or proven IPC endpoint. `ioreg` was also stopped before producing output. The post-disk service gates, permit, installation and tests were not reached. A prior modified Recovery14 reference image has byte-identical SystemVersion contents but a different image hash; it contains StorageKit with the `com.apple.storagekitd` and `com.apple.storagekitd.dm` MachServices, not `diskmanagementd`. The next observation targets that actual service family and the own diskutil stack; this reference does not establish the live service state of run 4193.
|
||||
|
||||
Run 4194 at `81a3b9c` stopped the same single query after 606 seconds without output. StorageKit exists but was not running and had never started in the before/live snapshots; the live snapshot covers approximately 103–160 seconds of the query, not its entire lifetime. `sample` hit its own watchdog without even its sampling-start message or report. This does not establish symbolication as the cause. The observed `1T` is a current Timeshare priority, not a thread count or proof of background policy. Neither installation nor tests ran.
|
||||
|
||||
## Entry points and dependencies
|
||||
|
||||
Orchestration remains the .NET 10 file-based app `tools/ci/MacOsNativeDiagnostic.cs`. Existing Bash/Python boot integration is necessary before a guest SDK exists. NASM assembles the CPU probe in the disposable image build, without host/runner installation. No new runner, device, capability, secret or service is used.
|
||||
|
||||
The disposable native process diagnostic uses a small C boundary linked only to libSystem, so it can record entry and kernel observations before the guest has .NET or CLT. Its C# file-based build driver and retained source/compiler/SDK/minimum-OS/import/signature/hash receipt describe the one-time local build. The pipeline receives this diagnostic asset and does not invoke an Apple compiler or request a macOS runner. This asset is not one of the application's four freshly built helpers and cannot qualify a test or readiness gate.
|
||||
|
||||
The probe validates both the target PID and expected parent before reading role/task data. Public BSD observations include background flags, Nice, role and raw CPU/page-in counters. A read-only Mach port is attempted separately, with return and errno recorded before any DYLD/thread reads. The local Apple-sleep fixture returned EPERM; actual Recovery rights remain unknown. The probe has no control-port fallback, process suspension, remote writes, extra entitlements or SIP change. Unsuspended snapshots may be incomplete.
|
||||
|
||||
For local maintenance with an existing Apple SDK, run `dotnet run --file tools/ci/native-process-probe/ProbeDriver.cs -- tools/ci/native-process-probe`. It builds and signs into that folder's `artifacts/`, observes and cleans up its own temporary sleep child, and retains the build/self-test receipt there. Publishing a changed asset requires reviewing that receipt, refreshing the portable `build-manifest.json` and updating all four controller hash pins. CI verifies those pins before staging the binary and manifest into the owned Recovery state; it never runs the build driver.
|
||||
|
||||
```sh
|
||||
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --validate
|
||||
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --validate --source /path/to/clean/pinned/dockur-clone --output /path/to/fresh/validation
|
||||
@@ -49,7 +57,7 @@ Native readiness requires x86_64, UID 0, macOS 14+, successful launchd service q
|
||||
|
||||
The raw file, exact source path, length, SHA256 and parsing receipt are retained and bound to the current token. This version evidence travels only from guest to host and requires no reply. The guest uses its existing Bash before any SDK exists; authoritative XML logic stays in C#/.NET. A Bash candidate alone cannot authorize installation or qualify readiness. This method establishes the current guest version, not successful execution of `sw_vers`.
|
||||
|
||||
Required commands retain 45 seconds and UID 180 seconds. The single disk query receives a 600-second diagnostic window under the existing 90-minute Recovery deadline. The owned observer captures StorageKit state, thread CPU snapshots and an optional one-second/100-ms `sample -mayDie` stack of only that live diskutil child. Each observation retains its own 60-second watchdog and two-second TERM/KILL grace. Missing tools, failed or timed-out samples remain explicit missing evidence; thread states alone do not identify an IPC endpoint. Stack output is captured directly from the owned state with a 512-KiB bound, without another native copy command. Observation failure passes no gate. Owned children are stopped on query completion/cancellation; output remains 512 KiB per command and 4 MiB proof. No service is started or restarted by the observer.
|
||||
Required commands retain 45 seconds and UID 180 seconds. The single disk query retains its 600-second diagnostic window under the existing 90-minute Recovery deadline. An optional no-target `sample` CLI control precedes it. The owned observer takes an early native process snapshot, requests an ordinary one-second/100-ms `sample` without eager `-mayDie` symbol loading, and records live StorageKit state. After a cancelable 180-second builtin pause it takes a late snapshot of the same live disk child and expected parent. Each observation retains its own 60-second watchdog and two-second TERM/KILL grace. Missing tools, denied reads, failures and timed-out samples remain explicit missing evidence. Stack output is captured directly from the owned state with a 512-KiB bound, without another native copy command. Observation failure passes no gate. Owned children are stopped on query completion/cancellation; output remains 512 KiB per command and 4 MiB proof. No service is started or restarted by the observer.
|
||||
|
||||
The container retains 6 GiB memory/swap, two-CPU limit, 512 MiB shared memory and a 4-GiB/two-vCPU guest. One fresh anonymous /storage volume holds the sparse 64-GiB target. Inspection rejects devices, capabilities, binds, ports, host networking and privileged mode. KVM is disabled with no /dev/kvm mapping; guest networking stays slirp.
|
||||
|
||||
|
||||
Reference in new issue
Block a user