net/dns, util/winutil: improve detection of group policy affecting NRPT

Due to a customer issue, I investigated the Windows Dnscache service more
intensively. I learned that the only time it attempts to read the NRPT
from group policy is in response to a group policy change notification.

Under the hypothesis that policy refresh is not effectively delivering GP
notifications due to its dependency on reaching a DC, I replaced our use
of the RefreshPolicyEx with the quasi-documented GenerateGPNotification API.

Tests have been updated to ensure they check that they are running as
LocalSystem, which is required for GenerateGPNotification.

Fixes #20187

Signed-off-by: Aaron Klotz <aaron@tailscale.com>
This commit is contained in:
Aaron Klotz
2026-07-10 13:53:26 -06:00
parent a68be19739
commit 2b62cb54a7
7 changed files with 102 additions and 58 deletions
+22
View File
@@ -972,3 +972,25 @@ func GUIPathFromReg() (string, error) {
return regPath, nil
}
// IsCurrentProcessLocalSystem checks whether the current process is running
// as LocalSystem.
func IsCurrentProcessLocalSystem() bool {
localSystem, err := windows.CreateWellKnownSid(windows.WinLocalSystemSid)
if err != nil {
return false
}
token := windows.GetCurrentProcessToken()
// The current process token is a pseudo-handle so we don't need to close it.
if ok, err := token.IsMember(localSystem); err != nil || !ok {
return false
}
u, err := token.GetTokenUser()
if err != nil {
return false
}
return u.User.Sid.Equals(localSystem)
}