Skip to content

refactor(agent-installer): deduplicate helper registry values - #1992

Closed
Benoît Cortier (CBenoit) wants to merge 53 commits into
cbenoit-agent-policy-consent-helperfrom
cbenoit-deduplicate-installer-registry-views
Closed

Benoît Cortier (CBenoit) wants to merge 53 commits into
cbenoit-agent-policy-consent-helperfrom
cbenoit-deduplicate-installer-registry-views

Conversation

@CBenoit

Copy link
Copy Markdown
Member

Centralize the PolicyConsentHelper discovery values so native and WOW6432Node registry views stay synchronized without changing installer behavior.

@CBenoit
Benoît Cortier (CBenoit) added this pull request to stack #1976 September 18, 2026 06:38
Record bounded write attempts and operation-specific outcomes without exposing policy content or blocking request admission on Event Log I/O.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Compile localized message resources for release and production builds using trusted installed Windows SDK tools.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Verify every shared event code and policy insertion string across both localized Windows message catalogs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restrict message compiler discovery to trusted SDK paths, keep thread-local audit assertions on one runtime thread, and avoid an unnecessary path allocation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Distinguish legacy-contract disk rejection without exposing document values.
Cover validator9 receipt rejection, conversion observation, no-op reloads,
and abandoned audit scopes without duplicating terminal write events.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Terminate every language block and declare UTF-8 input so the message
compiler produces separate, correctly encoded EN/FR/DE resources.
Require these properties in event catalog parity tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply policy audit outcomes to the canonical storage contract and record the Agent Event Log source through MSI lifecycle registration. Keep a focused reflection test without retaining policy migration infrastructure.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Replace Unicode line, paragraph, and bidirectional controls before audit values reach Windows Event Log insertion strings.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@CBenoit
Benoît Cortier (CBenoit) removed this pull request from stack #1976 September 18, 2026 07:26
Move policy audit event definitions and Agent catalog parity checks out of the shared Gateway event-code crate. Gateway no longer embeds Agent-only policy event messages.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Move test-only audit recorders and thread-local capture into an explicit mock module.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep test recorders and capture within the audit tests module.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Make policy replacement require its audit lifecycle and keep uninstrumented test calls behind a test-only helper.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adopt the released policy API contract and preserve advisory findings without a broker-specific acknowledgement gate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise policy management through a protected standard-user client and a LocalSystem client without weakening executable or path checks.

Cover validation and write denial, managed Create, Update, Repair, stale conflicts, confirmed overwrite, restart persistence, durable managed authority, and observable audit outcomes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the protected policy tester under a restricted standard-user token before the existing LocalSystem lifecycle.

Keep feature-gated route authorization tests in the same Windows job so the development signature feature cannot hide them from the default workspace suite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the Agent and test server under LocalSystem while a distinct restricted process exercises the named-pipe management endpoints.

Coordinate readiness and shutdown through a protected, read-only test directory so authorization regressions cannot pass by inspecting the server token.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Treat PsExec's detached-process PID as diagnostic output and use bounded, validated readiness as the authoritative launch result.

Publish readiness atomically, preserve launch diagnostics, and keep shutdown and cleanup idempotent so orchestration errors remain actionable.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Launch policy authorization requests from a unique temporary standard-user account instead of a Low-integrity PsExec token.

Require the exact account SID and Medium mandatory integrity level, keep credentials out of arguments and logs, and remove the account and profile after the bounded run.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Own LocalSystem test-server shutdown as soon as detached launch is attempted, even when readiness validation fails.

Signal the unique protected stop marker with a direct fallback, preserve the original scenario error, and bound status collection before cleanup.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Cover the current policy contract, receipt invalidation, warnings, and
interrupted Repair recovery. Exercise actual installer conversion and
managed authority under the hosted LocalSystem gate without accepting
skipped privileged tests or incomplete server completion status.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Pass the restored package root explicitly to the LocalSystem test
invocation so generated imports discover the test SDK and produce its
required privileged-test result.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve the restored NuGet imports and the product Agent filename
when running the privileged installer lifecycle tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run migration lifecycle probes through the staged trusted test client
instead of the hosted .NET test process, whose executable image cannot
be retained by the package broker.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove installer migration and retired-policy compatibility coverage while
preserving the canonical policy management lifecycle and its security
boundaries.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise the final canonical policy rule shapes and validation semantics
through the end-to-end policy management harness.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise standard-user read access, stale overwrite rejection, and
LocalSystem shutdown verification after failed readiness.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove retired warning acknowledgment requests while retaining receipt and
conflict enforcement in policy management E2E coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Install one protected NativeAOT helper that authenticates retained UniGetUI and Agent process identities before forwarding bounded policy replacement requests. Preserve protocol 2.0 conflict and uncertainty semantics while integrating transactional discovery, signing, and packaging.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply the canonical policy API safe-ASCII character set to helper credentials before a privileged request is dispatched.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Accept only current-signed UniGetUI hosts from version 2026.2.7. Remove transition signer discovery while retaining protected helper authorization and ARM64 installer coverage.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Publish the configured broker pipe through the protected helper discovery key so consent writes work with custom local pipe names. Reject malformed discovery and oversized requests before dispatch.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Document the required NativeAOT consent helper publish and packaging argument for local Agent MSI builds.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject remote-provider parent images before retaining them for policy consent. Document every required local Agent package artifact argument.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve the retained UniGetUI image path before trusting its local volume. Keep already-correct package inputs absolute while the MSI build changes directories.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the bounded broker connection lifetime aligned with the consent helper's two-minute policy replacement exchange.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep ordinary pipe capture and requests bounded to 30 seconds. Allow the two-minute exchange only after the exact consent helper is authorized.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep unauthenticated and ordinary pipe connections at 30 seconds. Extend only a successfully authorized consent-helper policy write to the two-minute exchange limit.

Issue: #1963

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Retire only verified protected probe remnants after an interrupted
capability check, and require retained Agent ancestor handles to remain
expected directories.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use Unicode-aware literal matching for source names so a policy deny
uses the same case semantics as PowerShell repository lookup.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Normalize source names before ordinal matching so policy evaluation uses
the same canonical repository identity as PowerShell.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject source spellings containing default-ignorable characters before
PowerShell can resolve them to a different policy identity.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject default-ignorable source spellings before policy evaluation and
command construction can disagree.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Carry the ordinary pipe deadline through client capture and serving so
unauthenticated clients cannot reserve a connection slot twice as long.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject noncanonical source spellings before policy matching so PowerShell
repository trimming cannot bypass a source-specific rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply PowerShell source canonicalization only to PowerShell so other
package managers retain their own source identity semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject policy source spellings that cannot safely match package requests
before they can create unusable source-specific rules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise ambiguous SourceNames with a valid PowerShell rule so the
regression protects the shared policy-validation predicate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Publish consent-helper discovery and configured broker-pipe values to the
32-bit registry view so supported x86 consumers find the protected helper.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the obsolete warning acknowledgement field so helper replacement
requests match the released policy API after the parent rebase.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Centralize the PolicyConsentHelper discovery values so native and
WOW6432Node registry views stay synchronized without changing installer
behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@CBenoit
Benoît Cortier (CBenoit) force-pushed the cbenoit-deduplicate-installer-registry-views branch from 6a73838 to 70bd15e Compare September 20, 2026 09:16
@CBenoit
Benoît Cortier (CBenoit) force-pushed the cbenoit-agent-policy-consent-helper branch from c13d2a1 to 1145f0c Compare September 30, 2026 06:57
@CBenoit

Copy link
Copy Markdown
Member Author

Closing: the Agent-installed policy consent helper (#1982) is not needed because UniGetUI ships its own elevated helper (UniGetUI.PolicyElevator.exe). This PR only refactored the helper's installer registry values, so it is obsolete.

@CBenoit
Benoît Cortier (CBenoit) deleted the cbenoit-deduplicate-installer-registry-views branch September 30, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant