Report an actionable error when the PrjFlt driver service is disabled - #2122
Draft
Tyrie Vella (tyrielv) wants to merge 1 commit into
Draft
Tyrie Vella (tyrielv) wants to merge 1 commit into
Tyrie Vella (tyrielv) wants to merge 1 commit into
Conversation
VFS for Git requires the PrjFlt ProjFS minifilter driver on every volume. Its load behavior is governed by the service Start type. When a security baseline, an anti-virus product, Group Policy, or manual troubleshooting disables the service, the driver cannot start. Today ProjFSFilter.TryStartService calls ServiceController.Start() on the disabled service. That fails with ERROR_SERVICE_DISABLED (1058), which is caught by a generic Win32Exception handler and surfaces to the user as the dead-end message "Failed to start prjflt service" with no indication that the driver is disabled and no way to fix it. Nothing else in the product detects this state (the existing AutoLogger Start handling is an unrelated ETW logging key). Detect the disabled state and report it, rather than silently re-enabling a driver that an administrator or security tool may have disabled on purpose. Changes: - TryStartService checks ServiceController.StartType and, when it is Disabled, returns a specific error naming the driver and the exact elevated command to re-enable it. It also maps ERROR_SERVICE_DISABLED from a failed start as a fallback, and now reports its error through an out parameter so the caller surfaces the specific message. - EnableAndAttachProjFSHandler.TryEnablePrjFlt propagates that message instead of the generic "Failed to start prjflt service", and records the start-failure reason in the health-summary telemetry so a disabled driver is detectable in aggregate. - Add a pure GetStartServiceFailureError seam and unit tests covering the disabled error code and other start-failure codes. Assisted-by: Claude Opus 4.8 Signed-off-by: Tyrie Vella <tyrielv@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and Context
VFS for Git requires the
PrjFltProjFS minifilter driver on every volume. The driver's load behavior is governed by its service Start type. A security-hardening baseline, an anti-virus/EDR product, Group Policy, or manual troubleshooting can set the service to Disabled. When that happens, VFS for Git cannot start the driver.Today
ProjFSFilter.TryStartServicecallsServiceController.Start()on the disabled service. The call fails withERROR_SERVICE_DISABLED(1058), which is caught by a genericWin32Exceptionhandler.EnableAndAttachProjFSHandler.TryEnablePrjFltthen reports the dead-end message "Failed to start prjflt service" — with no indication that the driver is disabled and no hint at the fix. No other code path detects or reports this state. (The existing AutoLoggerStarthandling is an unrelated ETW logging key, not the driver service.)This change detects the disabled state and reports it with an actionable message. It does not re-enable the driver: a disabled driver is often disabled deliberately by an administrator or a security tool, so silently re-enabling it would change the machine's security posture without consent.
Changes
ProjFSFilter.TryStartServicenow checksServiceController.StartType. When the service isDisabled, it returns a specific error that names the driver and gives the exact elevated command to re-enable it (sc.exe config prjflt start= auto). It also mapsERROR_SERVICE_DISABLEDfrom a failedStart()as a fallback for the disable-after-check race.TryStartServicenow reports its failure through anout string errorparameter instead of returning only a bool, so the caller can surface the specific message.EnableAndAttachProjFSHandler.TryEnablePrjFltpropagates that message instead of the generic "Failed to start prjflt service", and records the start-failure reason in theTryEnablePrjFlt_Summaryhealth telemetry so a disabled driver is detectable in aggregate.internal GetStartServiceFailureError(int nativeErrorCode)seam and unit tests inProjFSFilterTestscovering the disabled error code and other start-failure codes.