Serialize enrollment install with enrolling.lock
Concurrent enroll-url launches could both pass the enrollment
marker check and run overlapping elevated installs, racing on
LoadOrExchangeAPIKey and overwriting agent.key.
Add an exclusive flock on {configDir}/enrolling.lock for the
full install path and re-check IsEnrolled under that lock so
only one install exchanges a token and configures the device.
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -39,6 +39,10 @@ func Install(cfg Config) error {
|
||||
|
||||
name := DefaultWindowsName
|
||||
|
||||
// Remove any previous registration so install is idempotent
|
||||
// (matches Darwin's bootout-before-bootstrap).
|
||||
_ = Uninstall(cfg)
|
||||
|
||||
bin := fmt.Sprintf(`"%s" run --dir "%s"`, cfg.ExePath, cfg.Dir)
|
||||
if out, err := exec.Command(
|
||||
"sc.exe",
|
||||
|
||||
Reference in New Issue
Block a user