AUTH_EXEC fail-closed behaviour after Endpoint Security client loss

I am reviewing an isolated synthetic worker design using public macOS 27 Endpoint Security APIs. The SDK declares es_set_deadline_miss_mode and es_new_descendants_client.

The documentation describes ES_DEADLINE_MISS_MODE_FAIL_CLOSED for unanswered AUTH messages and queue overflow. I have not found a contract covering client loss.

  1. If the authorisation client crashes, disconnects or is deleted while AUTH_EXEC is pending, what verdict does the kernel apply?
  2. After the last matching client has disappeared, what happens to a subsequent exec by an already-running worker previously covered by that client?
  3. Is there a supported kernel-enforced mechanism that preserves replacement-exec denial for that worker until its original lifetime ends, despite authorisation-client failure? If not, please confirm that limitation.
  4. Are these client-loss semantics different for es_new_client and es_new_descendants_client, and which released macOS versions support the relevant contract?

This is a documentation/design question; these APIs have not been exercised in this candidate. A post-exec watchdog or later termination would not establish pre-exec denial.

References: https://developer.apple.com/documentation/endpointsecurity/es_set_deadline_miss_mode(::) https://developer.apple.com/documentation/endpointsecurity/es_new_descendants_client(::) https://developer.apple.com/documentation/endpointsecurity/es_delete_client(_:)

I have not found a contract covering client loss.

When the es_new_descendants_client goes away, every restriction it applied goes away.

If the authorisation client crashes, disconnects or is deleted while AUTH_EXEC is pending, what verdict does the kernel apply?

It "allows" everything.

After the last matching client has disappeared, what happens to a subsequent exec by an already-running worker previously covered by that client?

Same answer.

Are these client-loss semantics different for es_new_client and es_new_descendants_client,

No.

and which released macOS versions support the relevant contract?

This is how it's always worked.

__
Kevin Elliott
DTS Engineer, CoreOS/Hardware

AUTH_EXEC fail-closed behaviour after Endpoint Security client loss
 
 
Q