[client] Drop the unreachable helper timeout from certificate proof collection

Both platform collectors wrapped the helper launch in a 30 second deadline, but
the context they wrapped was already capped at 10 seconds by the collector that
calls them, and CollectProofs has no other caller. The inner deadline could
never be reached, so it described a budget the code does not have.

Leave the collector as the single owner of the deadline rather than picking a
smaller inner value: on macOS one budget has to cover the System keychain read
and the helper launch that follows it, and how to divide it is a question about
the budget as a whole, not about the helper alone.
This commit is contained in:
riccardom
2026-10-02 16:21:04 +02:00
parent ec48a92065
commit 3e360ebe0f
2 changed files with 0 additions and 12 deletions
@@ -8,7 +8,6 @@ import (
"os"
"os/exec"
"strconv"
"time"
log "github.com/sirupsen/logrus"
@@ -16,8 +15,6 @@ import (
"github.com/netbirdio/netbird/shared/management/proto"
)
const helperTimeout = 30 * time.Second
// CollectProofs answers the certificate challenges in checks from every store this Mac
// can reach. The root daemon reads the System keychain itself, which is where MDM
// installs device identities, and reaches the console user's login keychain only by
@@ -78,9 +75,6 @@ func collectAsConsoleUser(ctx context.Context, owner string, challenges []*proto
return nil, fmt.Errorf("resolve own binary: %w", err)
}
ctx, cancel := context.WithTimeout(ctx, helperTimeout)
defer cancel()
// Absolute paths, because the daemon's PATH is configurable through the service
// environment, and sudo selects the user by uid so the name never has to round-trip.
uid := strconv.FormatUint(uint64(user.UID), 10)
@@ -6,7 +6,6 @@ import (
"os"
"os/exec"
"syscall"
"time"
log "github.com/sirupsen/logrus"
"golang.org/x/sys/windows"
@@ -15,8 +14,6 @@ import (
"github.com/netbirdio/netbird/shared/management/proto"
)
const helperTimeout = 30 * time.Second
// CollectProofs answers the certificate challenges in checks from every store this
// machine can reach. The service reads the local machine store itself, where AD and
// Intune enrol device certificates, and reaches the signed-in user's store by launching
@@ -87,9 +84,6 @@ func collectAsDesktopUser(ctx context.Context, owner string, challenges []*proto
return nil, fmt.Errorf("build environment of %s: %w", user.Name, err)
}
ctx, cancel := context.WithTimeout(ctx, helperTimeout)
defer cancel()
cmd := exec.CommandContext(ctx, binary, "posture", "cert-proof")
cmd.Env = env
cmd.SysProcAttr = &syscall.SysProcAttr{