net/dns, util/winutil: improve detection of group policy affecting NRPT
Due to a customer issue, I investigated the Windows Dnscache service more intensively. I learned that the only time it attempts to read the NRPT from group policy is in response to a group policy change notification. Under the hypothesis that policy refresh is not effectively delivering GP notifications due to its dependency on reaching a DC, I replaced our use of the RefreshPolicyEx with the quasi-documented GenerateGPNotification API. Tests have been updated to ensure they check that they are running as LocalSystem, which is required for GenerateGPNotification. Fixes #20187 Signed-off-by: Aaron Klotz <aaron@tailscale.com>
This commit is contained in:
@@ -972,3 +972,25 @@ func GUIPathFromReg() (string, error) {
|
||||
|
||||
return regPath, nil
|
||||
}
|
||||
|
||||
// IsCurrentProcessLocalSystem checks whether the current process is running
|
||||
// as LocalSystem.
|
||||
func IsCurrentProcessLocalSystem() bool {
|
||||
localSystem, err := windows.CreateWellKnownSid(windows.WinLocalSystemSid)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
token := windows.GetCurrentProcessToken()
|
||||
// The current process token is a pseudo-handle so we don't need to close it.
|
||||
if ok, err := token.IsMember(localSystem); err != nil || !ok {
|
||||
return false
|
||||
}
|
||||
|
||||
u, err := token.GetTokenUser()
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
return u.User.Sid.Equals(localSystem)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user