feat: complete Windows client control and recovery paths

This commit is contained in:
2026-09-06 13:37:32 +00:00
parent 56b15c7f4f
commit 486894557d
38 changed files with 2188 additions and 106 deletions
+16 -1
View File
@@ -5,12 +5,25 @@ package windowstray
import (
"bytes"
"context"
"encoding/binary"
"errors"
"fmt"
"unicode/utf8"
)
// PipeName is the machine-local service endpoint used by every tray session.
// The native implementation creates it with PIPE_REJECT_REMOTE_CLIENTS and
// an explicit SYSTEM/Administrators/interactive-user ACL. Keeping the name
// here (rather than deriving it from user input) prevents cross-session and
// path-confusion bugs.
const PipeName = `\\.\pipe\RVBoxClientTrayV1`
// Handler is invoked by the service after the native adapter has verified the
// connecting process token, SID, and session. A response is always encoded
// as ActionStatus; requests other than status deliberately carry no payload.
type Handler func(context.Context, Peer, Frame) (Frame, error)
const (
protocolVersion uint16 = 1
maxFrameBytes = 64 << 10
@@ -33,6 +46,8 @@ const (
ActionStartService
ActionStopService
ActionRestartService
ActionSetAutomatic
ActionSetManual
ActionExitTray
)
@@ -115,7 +130,7 @@ func Authorize(peer Peer, action Action) error {
switch action {
case ActionStatus, ActionOpenConfig, ActionOpenLog, ActionExitTray:
return nil
case ActionStartService, ActionStopService, ActionRestartService:
case ActionStartService, ActionStopService, ActionRestartService, ActionSetAutomatic, ActionSetManual:
if peer.Administrator || peer.System {
return nil
}