Files
meeting-assistant/tools/ci/macos-native-disk-guard.sh
T

34 lines
2.1 KiB
Bash

#!/bin/bash
# Apple pre-.NET boot seam, sourced in Recovery and on installed first boot.
# A match requires the exact run-owned emulated serial, one whole writable 64-GiB disk.
verify_owned_disk() {
local disk="$1" state="$2" token="$3" info serial matches bytes
[[ "$disk" =~ ^/dev/disk[0-9]+$ && "$token" =~ ^[0-9a-f]{32}$ ]] || return 1
[ "$(cat "$state/run.owner" 2>/dev/null)" = "$token" ] || return 1
serial="${token:0:20}"
/usr/sbin/diskutil list physical > "$state/disk-list-current.log" 2>&1 || return 1
/usr/bin/grep -Eq "^$disk[[:space:]].*physical" "$state/disk-list-current.log" || return 1
/usr/sbin/diskutil info "$disk" > "$state/disk-info-current.log" 2>&1 || return 1
info=$(cat "$state/disk-info-current.log")
printf '%s\n' "$info" | /usr/bin/grep -Eq '^[[:space:]]*Whole:[[:space:]]*Yes' || return 1
printf '%s\n' "$info" | /usr/bin/grep -Eq '^[[:space:]]*(Read-Only (Media|Device)|(Media|Device) Read-Only):[[:space:]]*Yes' && return 1
printf '%s\n' "$info" | /usr/bin/grep -Eq '^[[:space:]]*(Read-Only (Media|Device)|(Media|Device) Read-Only):[[:space:]]*No' || return 1
bytes=$(printf '%s\n' "$info" | /usr/bin/sed -nE 's/^[[:space:]]*Disk Size:.*\(([0-9]+) Bytes\).*/\1/p')
[ "$bytes" = 68719476736 ] || return 1
/usr/sbin/ioreg -r -c IOBlockStorageDevice -l -w 0 > "$state/disk-ownership-ioreg.log" 2>&1 || return 1
matches=$(/usr/bin/awk -v expected="$serial" -v disk="${disk#/dev/}" '
function finish_root() { if (serialCount == 1 && serial == expected && ownedDisk) found++ }
/^\+-o/ { finish_root(); serial=""; serialCount=0; ownedDisk=0 }
/"Serial Number"[[:space:]]*=[[:space:]]*"/ {
serialCount++; serial=$0; sub(/^.*"Serial Number"[[:space:]]*=[[:space:]]*"/, "", serial); sub(/".*$/, "", serial); sub(/[[:space:]]+$/, "", serial)
}
/"BSD Name"[[:space:]]*=[[:space:]]*"/ {
name=$0; sub(/^.*"BSD Name"[[:space:]]*=[[:space:]]*"/, "", name); sub(/".*$/, "", name)
if (name == disk) ownedDisk=1
}
END { finish_root(); print found+0 }
' "$state/disk-ownership-ioreg.log")
[ "$matches" = 1 ] || return 1
printf '[owned-disk] %s serial=%s bytes=%s\n' "$disk" "$serial" "$bytes"
}