You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/winutil
Nick Khyl f0db47338e cmd/tailscaled,util/syspolicy/source,util/winutil/gp: disallow acquiring the GP lock during service startup
In v1.78, we started acquiring the GP lock when reading policy settings. This led to a deadlock during
Tailscale installation via Group Policy Software Installation because the GP engine holds the write lock
for the duration of policy processing, which in turn waits for the installation to complete, which in turn
waits for the service to enter the running state.

In this PR, we prevent the acquisition of GP locks (aka EnterCriticalPolicySection) during service startup
and update the Windows Registry-based util/syspolicy/source.PlatformPolicyStore to handle this failure
gracefully. The GP lock is somewhat optional; it’s safe to read policy settings without it, but acquiring
the lock is recommended when reading multiple values to prevent the Group Policy engine from modifying
settings mid-read and to avoid inconsistent results.

Fixes #14416

Signed-off-by: Nick Khyl <nickk@tailscale.com>
10 months ago
..
authenticode all: add test for package comments, fix, add comments as needed 1 year ago
conpty util/winutil: add conpty package and helper for building windows.StartupInfoEx 2 years ago
gp cmd/tailscaled,util/syspolicy/source,util/winutil/gp: disallow acquiring the GP lock during service startup 10 months ago
policy winutil: refactor methods to get values from registry to also return (#9536) 2 years ago
s4u util/winutil/s4u: fix token handle leak 1 year ago
testdata/testrestartableprocesses all: add test for package comments, fix, add comments as needed 1 year ago
winenv all: add test for package comments, fix, add comments as needed 1 year ago
mksyscall.go util/winutil: ensure domain controller address is used when retrieving remote profile information 1 year ago
restartmgr_windows.go util/winutil: add package for logging into Windows via Service-for-User (S4U) 1 year ago
restartmgr_windows_test.go all: use Go 1.22 range-over-int 2 years ago
startupinfo_windows.go util/winutil: add constants from Win32 SDK for dll blocking mitigation policies 1 year ago
subprocess_windows_test.go all: cleanup unused code, part 2 (#10670) 2 years ago
svcdiag_windows.go util/winutil: publicize existing functions for opening read-only connections to the Windows Service Control Manager 2 years ago
userprofile_windows.go util/winutil: ensure domain controller address is used when retrieving remote profile information 1 year ago
userprofile_windows_test.go util/winutil: ensure domain controller address is used when retrieving remote profile information 1 year ago
winutil.go util/syspolicy: add ReadStringArray interface (#11857) 2 years ago
winutil_notwindows.go util/syspolicy: add ReadStringArray interface (#11857) 2 years ago
winutil_windows.go util/winutil: add GetRegUserString/SetRegUserString accessors for storage and retrieval of string values in HKEY_CURRENT_USER 1 year ago
winutil_windows_test.go util/winutil: add AllocateContiguousBuffer and SetNTString helper funcs 2 years ago
zsyscall_windows.go util/winutil: ensure domain controller address is used when retrieving remote profile information 1 year ago