You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac下为自定义testosqueryd自动授予全盘访问权限

自定义osquery静默安装并授予全盘访问权限解决方案

1. 重新签名自定义二进制文件

原osqueryd的签名标识符为io.osquery.agent,要实现共存并匹配你的plist标识io.testosquery.agent,必须重新签名自定义的testosqueryd:

  • 准备签名证书:使用苹果开发者ID证书(避免Gatekeeper拦截),或自签名证书(仅测试环境使用)。
  • 执行重新签名命令(替换证书名称和二进制路径):
    codesign -s "你的开发者ID证书名称" -i io.testosquery.agent --deep /path/to/testosqueryd
    
  • 验证签名结果:
    codesign -dr - /path/to/testosqueryd
    
    输出应包含identifier "io.testosquery.agent",确保与plist的Label一致。

2. 配置一致的LaunchDaemon plist

确保plist的Label、程序路径与自定义二进制完全匹配,示例plist内容:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>io.testosquery.agent</string>
    <key>Program</key>
    <string>/opt/testosquery/bin/testosqueryd</string>
    <key>RunAtLoad</key>
    <true/>
    <key>KeepAlive</key>
    <true/>
    <key>StandardOutPath</key>
    <string>/var/log/testosqueryd.stdout</string>
    <key>StandardErrorPath</key>
    <string>/var/log/testosqueryd.stderr</string>
</dict>
</plist>

将plist放置到/Library/LaunchDaemons/io.testosquery.agent.plist,并设置权限:

chown root:wheel /Library/LaunchDaemons/io.testosquery.agent.plist
chmod 644 /Library/LaunchDaemons/io.testosquery.agent.plist

3. 静默授予全盘访问权限

macOS的全盘访问权限存储在TCC数据库中,可通过以下两种方式静默配置:

方法1:直接修改TCC.db(需关闭SIP,适用于无MDM环境)

以root权限执行SQL插入命令:

sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db "INSERT OR REPLACE INTO access VALUES('kTCCServiceSystemPolicyAllFiles','io.testosquery.agent',0,1,1,NULL,NULL,NULL,'UNUSED',NULL,0,16777216,NULL,NULL);"

参数说明:

  • kTCCServiceSystemPolicyAllFiles:指定全盘访问权限服务
  • io.testosquery.agent:匹配签名的标识符
  • 第二个1:表示允许权限
  • 第三个1:标记权限为有效状态

方法2:使用TCC配置文件(无需关闭SIP,推荐)

生成TCC配置文件com.testosquery.tcc.plist:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>PayloadIdentifier</key>
    <string>com.testosquery.tcc</string>
    <key>PayloadType</key>
    <string>Configuration</string>
    <key>PayloadVersion</key>
    <integer>1</integer>
    <key>PayloadUUID</key>
    <string>生成一个唯一UUID</string>
    <key>PayloadDisplayName</key>
    <string>Testosquery TCC Settings</string>
    <key>PayloadContent</key>
    <array>
        <dict>
            <key>PayloadType</key>
            <string>com.apple.TCC.configuration-profile-policy</string>
            <key>PayloadIdentifier</key>
            <string>com.testosquery.tcc.policy</string>
            <key>PayloadUUID</key>
            <string>生成另一个唯一UUID</string>
            <key>PayloadVersion</key>
            <integer>1</integer>
            <key>Services</key>
            <dict>
                <key>SystemPolicyAllFiles</key>
                <array>
                    <dict>
                        <key>Identifier</key>
                        <string>io.testosquery.agent</string>
                        <key>IdentifierType</key>
                        <string>bundleID</string>
                        <key>Allowed</key>
                        <true/>
                        <key>CodeRequirement</key>
                        <string>identifier "io.testosquery.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "你的证书OU"</string>
                    </dict>
                </array>
            </dict>
        </dict>
    </array>
</dict>
</plist>

将配置文件打包成.mobileconfig,然后静默安装:

profiles install -path /path/to/com.testosquery.tcc.mobileconfig

4. 确保原osquery与自定义版本共存

  • 安装路径分离:原osquery保留在/opt/osquery,自定义版本安装到/opt/testosquery,避免文件冲突。
  • 服务标识分离:两者的LaunchDaemon plist分别使用io.osquery.agent和io.testosquery.agent作为Label,启动后可通过launchctl list | grep osquery确认两个服务独立运行。
  • 日志分离:各自配置独立的日志输出路径,避免日志混淆。

内容的提问来源于stack exchange,提问作者User0987

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 02:17:49