test: prove native reconnect recovery
This commit is contained in:
@@ -216,6 +216,11 @@ func runClientDaemon(ctx context.Context, configPath string, diagnostics io.Writ
|
||||
Jitter: agent.CryptoJitter, Now: func() time.Time { return time.Now().UTC() },
|
||||
OnDispatch: executor.Dispatch, OnScriptReady: executor.ScriptReady, OnStdin: executor.Stdin,
|
||||
OnCloseStdin: executor.CloseStdin, OnSignal: executor.Signal, OnTerminate: executor.Terminate, EventReady: eventReady,
|
||||
OnSessionError: func(sessionErr error) {
|
||||
if diagnostics != nil {
|
||||
_, _ = fmt.Fprintf(diagnostics, "rvbox client session retry: %v\n", sessionErr)
|
||||
}
|
||||
},
|
||||
}); runErr != nil && ctx.Err() == nil && diagnostics != nil {
|
||||
_, _ = fmt.Fprintf(diagnostics, "rvbox client session stopped: %v\n", runErr)
|
||||
}
|
||||
|
||||
@@ -14,6 +14,7 @@ import (
|
||||
clientwindows "github.com/rvbox/rvbox/internal/client/supervisor/windows"
|
||||
"github.com/rvbox/rvbox/internal/client/windowsservice"
|
||||
"github.com/rvbox/rvbox/internal/client/windowstray"
|
||||
"golang.org/x/sys/windows"
|
||||
"golang.org/x/sys/windows/svc"
|
||||
)
|
||||
|
||||
@@ -90,6 +91,16 @@ func openServiceDiagnostics(configPath string, diagnostics io.Writer) (io.Writer
|
||||
}
|
||||
return diagnostics, func() {}
|
||||
}
|
||||
// Service diagnostics are intentionally not private spool data. Preserve a
|
||||
// protected SYSTEM/Administrators DACL so an operator can diagnose an SCM
|
||||
// startup or reconnect failure without weakening access to command state.
|
||||
if err := applyServiceDiagnosticsACL(path); err != nil {
|
||||
_ = file.Close()
|
||||
if diagnostics == nil {
|
||||
return io.Discard, func() {}
|
||||
}
|
||||
return diagnostics, func() {}
|
||||
}
|
||||
if diagnostics == nil {
|
||||
return file, func() { _ = file.Close() }
|
||||
}
|
||||
@@ -99,6 +110,18 @@ func openServiceDiagnostics(configPath string, diagnostics io.Writer) (io.Writer
|
||||
return io.MultiWriter(file, diagnostics), func() { _ = file.Close() }
|
||||
}
|
||||
|
||||
func applyServiceDiagnosticsACL(path string) error {
|
||||
descriptor, err := windows.SecurityDescriptorFromString("D:P(A;;FA;;;SY)(A;;FA;;;BA)")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
dacl, _, err := descriptor.DACL()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return windows.SetNamedSecurityInfo(path, windows.SE_FILE_OBJECT, windows.DACL_SECURITY_INFORMATION|windows.PROTECTED_DACL_SECURITY_INFORMATION, nil, nil, dacl, nil)
|
||||
}
|
||||
|
||||
func runTray(configPath string, diagnostics io.Writer) error {
|
||||
_ = configPath // the tray obtains the canonical paths from the service.
|
||||
return windowstray.Run(context.Background(), diagnostics)
|
||||
|
||||
Reference in New Issue
Block a user