You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/tstest/integration
Nick Khyl f0db47338e cmd/tailscaled,util/syspolicy/source,util/winutil/gp: disallow acquiring the GP lock during service startup
In v1.78, we started acquiring the GP lock when reading policy settings. This led to a deadlock during
Tailscale installation via Group Policy Software Installation because the GP engine holds the write lock
for the duration of policy processing, which in turn waits for the installation to complete, which in turn
waits for the service to enter the running state.

In this PR, we prevent the acquisition of GP locks (aka EnterCriticalPolicySection) during service startup
and update the Windows Registry-based util/syspolicy/source.PlatformPolicyStore to handle this failure
gracefully. The GP lock is somewhat optional; it’s safe to read policy settings without it, but acquiring
the lock is recommended when reading multiple values to prevent the Group Policy engine from modifying
settings mid-read and to avoid inconsistent results.

Fixes #14416

Signed-off-by: Nick Khyl <nickk@tailscale.com>
10 months ago
..
nat wgengine/magicsock: disable raw disco by default; add envknob to enable 1 year ago
testcontrol all: add Node.HomeDERP int, phase out "127.3.3.40:$region" hack [capver 111] 11 months ago
vms all: fix new lint warnings from bumping staticcheck 1 year ago
gen_deps.go all: update tools that manage copyright headers 3 years ago
integration.go vnet: add control/derps to test, stateful firewall 1 year ago
integration_test.go control/control{client,http}: don't noise dial localhost:443 in http-only tests 1 year ago
tailscaled_deps_test_darwin.go feature/*: make Wake-on-LAN conditional, start supporting modular features 10 months ago
tailscaled_deps_test_freebsd.go feature/*: make Wake-on-LAN conditional, start supporting modular features 10 months ago
tailscaled_deps_test_linux.go feature/*: make Wake-on-LAN conditional, start supporting modular features 10 months ago
tailscaled_deps_test_openbsd.go feature/*: make Wake-on-LAN conditional, start supporting modular features 10 months ago
tailscaled_deps_test_windows.go cmd/tailscaled,util/syspolicy/source,util/winutil/gp: disallow acquiring the GP lock during service startup 10 months ago