net/dns, util/winutil: improve detection of group policy affecting NRPT

Due to a customer issue, I investigated the Windows Dnscache service more
intensively. I learned that the only time it attempts to read the NRPT
from group policy is in response to a group policy change notification.

Under the hypothesis that policy refresh is not effectively delivering GP
notifications due to its dependency on reaching a DC, I replaced our use
of the RefreshPolicyEx with the quasi-documented GenerateGPNotification API.

Tests have been updated to ensure they check that they are running as
LocalSystem, which is required for GenerateGPNotification.

Fixes #20187

Signed-off-by: Aaron Klotz <aaron@tailscale.com>
This commit is contained in:
Aaron Klotz
2026-07-10 13:53:26 -06:00
parent a68be19739
commit 2b62cb54a7
7 changed files with 102 additions and 58 deletions
+12
View File
@@ -9,6 +9,7 @@ package gp
import (
"fmt"
"runtime"
"unsafe"
"golang.org/x/sys/windows"
)
@@ -77,3 +78,14 @@ func toRefreshPolicyFlags(force bool) uint32 {
}
return 0
}
var mgmtProductTailscale = unsafe.SliceData([]uint16{'T', 'a', 'i', 'l', 's', 'c', 'a', 'l', 'e', 0})
// NotifyMachinePolicyChange sends a machine-scoped group policy change
// notification which Windows broadcasts to group policy change subscribers.
// The caller must be running as LocalSystem.
func NotifyMachinePolicyChange() error {
// GenerateGPNotification is quasi-documented. Note that its implementation
// contains an access check ensuring that the calling user is LocalSystem!
return generateGPNotification(true, mgmtProductTailscale, 0)
}