From 3e360ebe0f6a2226d2962254ad94c823c4403346 Mon Sep 17 00:00:00 2001 From: riccardom Date: Thu, 1 Oct 2026 13:29:09 +0200 Subject: [PATCH] [client] Drop the unreachable helper timeout from certificate proof collection Both platform collectors wrapped the helper launch in a 30 second deadline, but the context they wrapped was already capped at 10 seconds by the collector that calls them, and CollectProofs has no other caller. The inner deadline could never be reached, so it described a budget the code does not have. Leave the collector as the single owner of the deadline rather than picking a smaller inner value: on macOS one budget has to cover the System keychain read and the helper launch that follows it, and how to divide it is a question about the budget as a whole, not about the helper alone. --- client/internal/certproof/collect_darwin.go | 6 ------ client/internal/certproof/collect_windows.go | 6 ------ 2 files changed, 12 deletions(-) diff --git a/client/internal/certproof/collect_darwin.go b/client/internal/certproof/collect_darwin.go index 28fa1c183..3bc121ef7 100644 --- a/client/internal/certproof/collect_darwin.go +++ b/client/internal/certproof/collect_darwin.go @@ -8,7 +8,6 @@ import ( "os" "os/exec" "strconv" - "time" log "github.com/sirupsen/logrus" @@ -16,8 +15,6 @@ import ( "github.com/netbirdio/netbird/shared/management/proto" ) -const helperTimeout = 30 * time.Second - // CollectProofs answers the certificate challenges in checks from every store this Mac // can reach. The root daemon reads the System keychain itself, which is where MDM // installs device identities, and reaches the console user's login keychain only by @@ -78,9 +75,6 @@ func collectAsConsoleUser(ctx context.Context, owner string, challenges []*proto return nil, fmt.Errorf("resolve own binary: %w", err) } - ctx, cancel := context.WithTimeout(ctx, helperTimeout) - defer cancel() - // Absolute paths, because the daemon's PATH is configurable through the service // environment, and sudo selects the user by uid so the name never has to round-trip. uid := strconv.FormatUint(uint64(user.UID), 10) diff --git a/client/internal/certproof/collect_windows.go b/client/internal/certproof/collect_windows.go index dcdd2d320..7b6eddbc3 100644 --- a/client/internal/certproof/collect_windows.go +++ b/client/internal/certproof/collect_windows.go @@ -6,7 +6,6 @@ import ( "os" "os/exec" "syscall" - "time" log "github.com/sirupsen/logrus" "golang.org/x/sys/windows" @@ -15,8 +14,6 @@ import ( "github.com/netbirdio/netbird/shared/management/proto" ) -const helperTimeout = 30 * time.Second - // CollectProofs answers the certificate challenges in checks from every store this // machine can reach. The service reads the local machine store itself, where AD and // Intune enrol device certificates, and reaches the signed-in user's store by launching @@ -87,9 +84,6 @@ func collectAsDesktopUser(ctx context.Context, owner string, challenges []*proto return nil, fmt.Errorf("build environment of %s: %w", user.Name, err) } - ctx, cancel := context.WithTimeout(ctx, helperTimeout) - defer cancel() - cmd := exec.CommandContext(ctx, binary, "posture", "cert-proof") cmd.Env = env cmd.SysProcAttr = &syscall.SysProcAttr{