mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-09-28 18:55:35 +00:00
Keep FUSE serving until the auxiliary SMB filesystem is unmounted, then join the shutdown worker before destroying the FUSE handle. Authenticate socket peers and bind each request to the service and filesystem instance; carry the force flag through to unmount and reply before teardown. Resolve the current disk image before detach instead of trusting cached BSD device numbers. Clear device and mount metadata when the image is gone, and abort on inventory errors. Refresh ownership during enumeration and before filesystem checks. Give each auxiliary mount a random path so an old backend cannot target a subsequent VeraCrypt mount during cleanup. Canonicalize the auxiliary path before service startup and hdiutil attach. Resolve older clients' image paths through TMPDIR aliases without accessing unrelated images. Treat candidate resolution failures as errors rather than evidence that an attached image is gone. Keep a new service provisional over a private inherited socketpair until control-file readiness and public shutdown endpoint checks succeed. On startup failure or caller exit, unmount while FUSE still serves and wait for volume closure and service exit. Report incomplete cleanup explicitly and keep retrying cleanup in the service if unmounting is temporarily blocked. Restore dismounts of released services without /shutdown through a validated legacy flow. Preserve incoming file-protocol notifications and watch for external unmounts independently of those notifications. Legacy unmount cannot guarantee termination of an already-running old service. Use one fixed versioned socket frame and publish the random endpoint in /shutdown-socket, preserving the three-field /shutdown identity. Remove compatibility with unpublished socket protocols. Recover from transient accept and mount-enumeration failures, bound partial-request lifetimes, and report connection refusal as an availability error. Handle join failure without unwinding the destructor or freeing a live worker's context. Map auxiliary EBUSY to MountedVolumeInUse for the GUI force prompt. Return failure for a single busy non-interactive dismount and log automatic-dismount failures. Mark inherited descriptors close-on-exec before FUSE setup and make File::SetCloseOnExec const. Extend disposable-container tests for released clients and services, reused device numbers, partial requests, identity validation, forced write integrity, TMPDIR aliases, and injected startup and rollback failures. Validated without sudo with a clean arm64 build, unchanged warnings, algorithm self-tests, the compatibility matrix, descriptor audits, worker fault-recovery checks, and 24 conditional compilation checks.