refactor(agent-installer): deduplicate helper registry values - #1992
Closed
Benoît Cortier (CBenoit) wants to merge 53 commits into
Closed
Benoît Cortier (CBenoit) wants to merge 53 commits into
Benoît Cortier (CBenoit) wants to merge 53 commits into
Conversation
Benoît Cortier (CBenoit)
added this pull request to stack #1976
September 18, 2026 06:38
Record bounded write attempts and operation-specific outcomes without exposing policy content or blocking request admission on Event Log I/O. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Compile localized message resources for release and production builds using trusted installed Windows SDK tools. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Verify every shared event code and policy insertion string across both localized Windows message catalogs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restrict message compiler discovery to trusted SDK paths, keep thread-local audit assertions on one runtime thread, and avoid an unnecessary path allocation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Distinguish legacy-contract disk rejection without exposing document values. Cover validator9 receipt rejection, conversion observation, no-op reloads, and abandoned audit scopes without duplicating terminal write events. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Terminate every language block and declare UTF-8 input so the message compiler produces separate, correctly encoded EN/FR/DE resources. Require these properties in event catalog parity tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply policy audit outcomes to the canonical storage contract and record the Agent Event Log source through MSI lifecycle registration. Keep a focused reflection test without retaining policy migration infrastructure. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Replace Unicode line, paragraph, and bidirectional controls before audit values reach Windows Event Log insertion strings. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Benoît Cortier (CBenoit)
removed this pull request from stack #1976
September 18, 2026 07:26
Move policy audit event definitions and Agent catalog parity checks out of the shared Gateway event-code crate. Gateway no longer embeds Agent-only policy event messages. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Move test-only audit recorders and thread-local capture into an explicit mock module. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep test recorders and capture within the audit tests module. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Make policy replacement require its audit lifecycle and keep uninstrumented test calls behind a test-only helper. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adopt the released policy API contract and preserve advisory findings without a broker-specific acknowledgement gate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise policy management through a protected standard-user client and a LocalSystem client without weakening executable or path checks. Cover validation and write denial, managed Create, Update, Repair, stale conflicts, confirmed overwrite, restart persistence, durable managed authority, and observable audit outcomes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the protected policy tester under a restricted standard-user token before the existing LocalSystem lifecycle. Keep feature-gated route authorization tests in the same Windows job so the development signature feature cannot hide them from the default workspace suite. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the Agent and test server under LocalSystem while a distinct restricted process exercises the named-pipe management endpoints. Coordinate readiness and shutdown through a protected, read-only test directory so authorization regressions cannot pass by inspecting the server token. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Treat PsExec's detached-process PID as diagnostic output and use bounded, validated readiness as the authoritative launch result. Publish readiness atomically, preserve launch diagnostics, and keep shutdown and cleanup idempotent so orchestration errors remain actionable. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Launch policy authorization requests from a unique temporary standard-user account instead of a Low-integrity PsExec token. Require the exact account SID and Medium mandatory integrity level, keep credentials out of arguments and logs, and remove the account and profile after the bounded run. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Own LocalSystem test-server shutdown as soon as detached launch is attempted, even when readiness validation fails. Signal the unique protected stop marker with a direct fallback, preserve the original scenario error, and bound status collection before cleanup. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Cover the current policy contract, receipt invalidation, warnings, and interrupted Repair recovery. Exercise actual installer conversion and managed authority under the hosted LocalSystem gate without accepting skipped privileged tests or incomplete server completion status. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Pass the restored package root explicitly to the LocalSystem test invocation so generated imports discover the test SDK and produce its required privileged-test result. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve the restored NuGet imports and the product Agent filename when running the privileged installer lifecycle tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run migration lifecycle probes through the staged trusted test client instead of the hosted .NET test process, whose executable image cannot be retained by the package broker. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove installer migration and retired-policy compatibility coverage while preserving the canonical policy management lifecycle and its security boundaries. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise the final canonical policy rule shapes and validation semantics through the end-to-end policy management harness. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise standard-user read access, stale overwrite rejection, and LocalSystem shutdown verification after failed readiness. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove retired warning acknowledgment requests while retaining receipt and conflict enforcement in policy management E2E coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Install one protected NativeAOT helper that authenticates retained UniGetUI and Agent process identities before forwarding bounded policy replacement requests. Preserve protocol 2.0 conflict and uncertainty semantics while integrating transactional discovery, signing, and packaging. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply the canonical policy API safe-ASCII character set to helper credentials before a privileged request is dispatched. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Accept only current-signed UniGetUI hosts from version 2026.2.7. Remove transition signer discovery while retaining protected helper authorization and ARM64 installer coverage. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Publish the configured broker pipe through the protected helper discovery key so consent writes work with custom local pipe names. Reject malformed discovery and oversized requests before dispatch. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Document the required NativeAOT consent helper publish and packaging argument for local Agent MSI builds. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject remote-provider parent images before retaining them for policy consent. Document every required local Agent package artifact argument. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve the retained UniGetUI image path before trusting its local volume. Keep already-correct package inputs absolute while the MSI build changes directories. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the bounded broker connection lifetime aligned with the consent helper's two-minute policy replacement exchange. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep ordinary pipe capture and requests bounded to 30 seconds. Allow the two-minute exchange only after the exact consent helper is authorized. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep unauthenticated and ordinary pipe connections at 30 seconds. Extend only a successfully authorized consent-helper policy write to the two-minute exchange limit. Issue: #1963 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Retire only verified protected probe remnants after an interrupted capability check, and require retained Agent ancestor handles to remain expected directories. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use Unicode-aware literal matching for source names so a policy deny uses the same case semantics as PowerShell repository lookup. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Normalize source names before ordinal matching so policy evaluation uses the same canonical repository identity as PowerShell. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject source spellings containing default-ignorable characters before PowerShell can resolve them to a different policy identity. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject default-ignorable source spellings before policy evaluation and command construction can disagree. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Carry the ordinary pipe deadline through client capture and serving so unauthenticated clients cannot reserve a connection slot twice as long. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject noncanonical source spellings before policy matching so PowerShell repository trimming cannot bypass a source-specific rule. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply PowerShell source canonicalization only to PowerShell so other package managers retain their own source identity semantics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject policy source spellings that cannot safely match package requests before they can create unusable source-specific rules. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise ambiguous SourceNames with a valid PowerShell rule so the regression protects the shared policy-validation predicate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Publish consent-helper discovery and configured broker-pipe values to the 32-bit registry view so supported x86 consumers find the protected helper. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the obsolete warning acknowledgement field so helper replacement requests match the released policy API after the parent rebase. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Benoît Cortier (CBenoit)
force-pushed
the
cbenoit-agent-policy-consent-helper
branch
from
September 20, 2026 09:12
4c39cb0 to
c13d2a1
Compare
Centralize the PolicyConsentHelper discovery values so native and WOW6432Node registry views stay synchronized without changing installer behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Benoît Cortier (CBenoit)
force-pushed
the
cbenoit-deduplicate-installer-registry-views
branch
from
September 20, 2026 09:16
6a73838 to
70bd15e
Compare
Benoît Cortier (CBenoit)
force-pushed
the
cbenoit-agent-policy-consent-helper
branch
from
September 30, 2026 06:57
c13d2a1 to
1145f0c
Compare
Member
Author
|
Closing: the Agent-installed policy consent helper (#1982) is not needed because UniGetUI ships its own elevated helper ( |
Benoît Cortier (CBenoit)
deleted the
cbenoit-deduplicate-installer-registry-views
branch
September 30, 2026 15:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Centralize the PolicyConsentHelper discovery values so native and WOW6432Node registry views stay synchronized without changing installer behavior.