Observe owned Recovery process without a guest SDK or task control rights

This commit is contained in:
dh
2026-10-04 19:32:31 +02:00
parent 81a3b9c7d2
commit 4b7fd160ef
7 changed files with 374 additions and 11 deletions
+6 -3
View File
@@ -196,7 +196,7 @@ observe_disk_query() {
}
trap cancel_observation TERM INT
printf '[disk-observation] owned-diskutil-child=%s parent-shell=%s\n' "$disk_process" "$$" >> "$output"
observe_live_command diskutil-threads-before /bin/ps -M -p "$disk_process"
observe_live_command diskutil-native-before "$STATE_DIR/native-process-probe-x86_64" "$disk_process" "$$"
if [ ! -x /usr/bin/sample ]; then
printf '[disk-observation-unavailable] diskutil-stack: /usr/bin/sample is unavailable\n' >> "$output"
elif ! kill -0 "$disk_process" 2>/dev/null; then
@@ -205,13 +205,15 @@ observe_disk_query() {
printf '[disk-observation-unavailable] diskutil-stack: output already exists\n' >> "$output"
elif : > "$stack_output"; then
printf '[disk-stack-attempt] owned-diskutil-child=%s duration=1s interval=100ms limit=60s output=%s observation-only=true\n' "$disk_process" "$stack_output" >> "$output"
observe_command diskutil-stack /usr/bin/sample "$disk_process" 1 100 -mayDie -file "$stack_output"
observe_command diskutil-stack /usr/bin/sample "$disk_process" 1 100 -file "$stack_output"
printf '[disk-stack-result] status=%s observation-only=true; raw report is captured by the Linux host\n' "$OBSERVATION_EXIT" >> "$output"
else
printf '[disk-observation-unavailable] diskutil-stack: output cannot be created\n' >> "$output"
fi
observe_live_command storagekit-live /bin/launchctl print system/com.apple.storagekitd
observe_live_command diskutil-threads-after /bin/ps -M -p "$disk_process"
printf '[disk-observation-pause] limit=180s; canceled when owned query ends\n' >> "$output"
IFS= read -r -t 180 -u 9 unused || :
observe_live_command diskutil-native-after "$STATE_DIR/native-process-probe-x86_64" "$disk_process" "$$"
}
stop_disk_observation() {
@@ -335,6 +337,7 @@ flush_outputs || finish false diagnostic_log_budget_exceeded
# BEGIN disk IPC diagnostic
printf '[disk-diagnostic-runtime] bash=%s stack-observation-only=true\n' "$BASH_VERSION" >&3
run_command sample_usage /usr/bin/sample
run_command arbitration_before /bin/launchctl print system/com.apple.diskarbitrationd
run_command management_before /bin/launchctl print system/com.apple.storagekitd
run_command media_before /usr/sbin/ioreg -r -c IOMedia -l -w 0