auv-api-server 0.0.23

Protocol adapters for AUV daemon control and capability APIs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
//! Dedicated Windows DeviceLocalService pipe and verified peer identity.
//!
//! The pipe ACL controls who may connect. Authorization uses the SID obtained
//! by impersonating the client after a successful pipe read, never that ACL or
//! a process ID alone. No DeviceService route is installed on this listener.

use std::ffi::c_void;
use std::io;
use std::mem::{align_of, offset_of, size_of};
use std::os::windows::io::AsRawHandle;
use std::pin::Pin;
use std::sync::{Arc, OnceLock};
use std::task::{Context, Poll};

use auv_api_proto::auv::api::daemon::v1::device_local_service_server::DeviceLocalServiceServer;
use futures_util::stream;
use tokio::io::{AsyncRead, AsyncWrite, ReadBuf};
use tokio::net::windows::named_pipe::{NamedPipeServer, ServerOptions};
use tonic::transport::server::Connected;
use windows::Win32::Foundation::{BOOL, CloseHandle, HANDLE, HLOCAL, LocalFree};
use windows::Win32::Security::Authorization::{
  ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, SDDL_REVISION_1,
};
use windows::Win32::Security::{
  GetTokenInformation, IsWellKnownSid, PSECURITY_DESCRIPTOR, RevertToSelf, SECURITY_ATTRIBUTES, SID_AND_ATTRIBUTES, TOKEN_GROUPS,
  TOKEN_QUERY, TOKEN_USER, TokenGroups, TokenUser, WinAnonymousSid, WinBuiltinAdministratorsSid,
};
use windows::Win32::System::Pipes::ImpersonateNamedPipeClient;
use windows::Win32::System::SystemServices::{SE_GROUP_ENABLED, SE_GROUP_USE_FOR_DENY_ONLY};
use windows::Win32::System::Threading::{GetCurrentThread, OpenThreadToken};
use windows::core::{PCWSTR, PWSTR};

use super::{DeviceLocalControl, DeviceLocalGrpc, LocalOsPrincipal};

// NOTICE(device-local-pipe-attributes): The installed Windows gate showed
// CreateFileW requires FILE_READ_ATTRIBUTES (0x80) even when the client only
// asks for data, READ_CONTROL, and SYNCHRONIZE. A target-local pipe matrix
// admitted the same client with 0x00120083 and denied it with 0x00120003.
// Keep FILE_CREATE_PIPE_INSTANCE (0x4) excluded; remove the extra attribute
// right only after a Windows-native gate shows it is no longer required.
const AUTHENTICATED_USER_PIPE_ACCESS: u32 = 0x0012_0083;

#[derive(Clone, Debug, Eq, PartialEq)]
struct ClientIdentity {
  sid: String,
  administrator: bool,
}

#[derive(Clone, Default)]
pub(super) struct PeerIdentity(Arc<OnceLock<ClientIdentity>>);

impl PeerIdentity {
  pub(super) fn principal(&self) -> Option<LocalOsPrincipal> {
    self.0.get().map(|identity| {
      if identity.administrator {
        LocalOsPrincipal::WindowsAdministratorSid(identity.sid.clone())
      } else {
        LocalOsPrincipal::WindowsSid(identity.sid.clone())
      }
    })
  }

  fn accept_read(&self, identity: ClientIdentity) -> io::Result<()> {
    match self.0.get() {
      Some(existing) if existing == &identity => Ok(()),
      Some(_) => Err(identity_error()),
      None => {
        self.0.set(identity).map_err(|_| identity_error())?;
        Ok(())
      }
    }
  }
}

struct VerifiedPipe {
  pipe: NamedPipeServer,
  identity: PeerIdentity,
}

impl AsyncRead for VerifiedPipe {
  fn poll_read(mut self: Pin<&mut Self>, context: &mut Context<'_>, buffer: &mut ReadBuf<'_>) -> Poll<io::Result<()>> {
    let filled_before = buffer.filled().len();

    match Pin::new(&mut self.pipe).poll_read(context, buffer) {
      Poll::Ready(Ok(())) if buffer.filled().len() > filled_before => {
        // NOTICE(named-pipe-peer-sid): Microsoft documents that this API uses
        // the security context of the last message read from this pipe. Check
        // every successful read before forwarding those bytes to HTTP/2.
        let handle = HANDLE(self.pipe.as_raw_handle());

        match client_identity(handle).and_then(|identity| self.identity.accept_read(identity)) {
          Ok(()) => Poll::Ready(Ok(())),
          Err(error) => {
            buffer.clear();
            Poll::Ready(Err(error))
          }
        }
      }
      result => result,
    }
  }
}

impl AsyncWrite for VerifiedPipe {
  fn poll_write(mut self: Pin<&mut Self>, context: &mut Context<'_>, buffer: &[u8]) -> Poll<io::Result<usize>> {
    Pin::new(&mut self.pipe).poll_write(context, buffer)
  }

  fn poll_flush(mut self: Pin<&mut Self>, context: &mut Context<'_>) -> Poll<io::Result<()>> {
    Pin::new(&mut self.pipe).poll_flush(context)
  }

  fn poll_shutdown(mut self: Pin<&mut Self>, context: &mut Context<'_>) -> Poll<io::Result<()>> {
    Pin::new(&mut self.pipe).poll_shutdown(context)
  }
}

impl Connected for VerifiedPipe {
  type ConnectInfo = PeerIdentity;

  fn connect_info(&self) -> Self::ConnectInfo {
    self.identity.clone()
  }
}

/// Serve only target-local enrollment RPCs on a separate Windows pipe.
///
/// This transport authenticates the connecting SID. The supplied backend must
/// still authorize that SID for each requested account or policy operation.
pub async fn serve_named_pipe(
  name: &str,
  control: Arc<dyn DeviceLocalControl>,
  shutdown: tokio_util::sync::CancellationToken,
) -> Result<(), String> {
  let first = create_pipe(name, true).map_err(|_| "cannot bind DeviceLocalService named pipe".to_string())?;
  let service = DeviceLocalServiceServer::new(DeviceLocalGrpc { control }).max_decoding_message_size(16 * 1024);
  let name = name.to_owned();
  let incoming = stream::try_unfold((first, name), |(pipe, name)| async move {
    pipe.connect().await?;
    let next = create_pipe(&name, false)?;
    Ok::<_, io::Error>(Some((
      VerifiedPipe {
        pipe,
        identity: PeerIdentity::default(),
      },
      (next, name),
    )))
  });
  tonic::transport::Server::builder()
    .add_service(service)
    .serve_with_incoming_shutdown(incoming, shutdown.cancelled_owned())
    .await
    .map_err(|_| "DeviceLocalService named-pipe server failed".to_string())
}

fn create_pipe(name: &str, first: bool) -> io::Result<NamedPipeServer> {
  if !name.starts_with("auv-device-local-") || !name.bytes().all(|byte| byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'_' | b'.')) {
    return Err(io::Error::new(io::ErrorKind::InvalidInput, "invalid DeviceLocalService pipe name"));
  }

  // Authenticated local users may connect so an ordinary account can later
  // self-enroll. Grant READ_CONTROL, SYNCHRONIZE, FILE_READ_ATTRIBUTES,
  // FILE_READ_DATA, and FILE_WRITE_DATA (0x00120083). GENERIC_WRITE includes
  // the bit shared by FILE_APPEND_DATA and FILE_CREATE_PIPE_INSTANCE, letting an AU
  // caller create a competing instance. See
  // https://learn.microsoft.com/en-us/windows/win32/ipc/named-pipe-security-and-access-rights.
  // SID verification and backend policy remain mandatory.
  // NOTICE(device-local-pipe-integrity): A LocalSystem service creates System
  // integrity objects by default. That mandatory label rejects writes from
  // ordinary interactive users even when the DACL grants the exact pipe data
  // rights. Medium integrity admits those users; the DACL, SID impersonation,
  // and per-account policy still authorize each request. Remove this explicit
  // label only if the host no longer accepts local non-System enrollment.
  // https://learn.microsoft.com/en-us/windows/win32/secauthz/mandatory-integrity-control
  let sddl = format!("D:P(A;;GA;;;SY)(A;;0x{AUTHENTICATED_USER_PIPE_ACCESS:08x};;;AU)S:(ML;;NW;;;ME)");
  let sddl = sddl.encode_utf16().chain(Some(0)).collect::<Vec<_>>();
  let mut descriptor = PSECURITY_DESCRIPTOR::default();
  // SAFETY: The UTF-16 buffer is NUL-terminated and stays live for this call;
  // descriptor is a live output. Its allocation outlives pipe creation.
  unsafe { ConvertStringSecurityDescriptorToSecurityDescriptorW(PCWSTR(sddl.as_ptr()), SDDL_REVISION_1, &mut descriptor, None) }
    .map_err(|_| identity_error())?;

  let descriptor = SecurityDescriptor(descriptor);
  let mut attributes = SECURITY_ATTRIBUTES {
    nLength: size_of::<SECURITY_ATTRIBUTES>() as u32,
    lpSecurityDescriptor: descriptor.0.0,
    bInheritHandle: BOOL(0),
  };
  let mut options = ServerOptions::new();
  options.first_pipe_instance(first).reject_remote_clients(true);
  let path = format!(r"\\.\pipe\{name}");
  // SAFETY: Tokio copies SECURITY_ATTRIBUTES during this synchronous call;
  // the descriptor guard outlives it. The pipe rejects remote clients.
  unsafe { options.create_with_security_attributes_raw(&path, (&raw mut attributes).cast()) }
}

fn client_identity(pipe: HANDLE) -> io::Result<ClientIdentity> {
  // SAFETY: `pipe` is the live server end whose read just completed. Microsoft
  // binds this thread to that read's client security context on success.
  unsafe { ImpersonateNamedPipeClient(pipe) }.map_err(|_| identity_error())?;
  let _impersonation = ImpersonationGuard;
  let mut raw_token = HANDLE::default();
  // SAFETY: The current thread is impersonating the last pipe reader. The
  // output handle is owned and closed before this function returns.
  unsafe { OpenThreadToken(GetCurrentThread(), TOKEN_QUERY, true, &mut raw_token) }.map_err(|_| identity_error())?;
  let token = Token(raw_token);
  let mut bytes = 0u32;
  // SAFETY: A null output buffer asks Windows for the required TOKEN_USER size.
  let _ = unsafe { GetTokenInformation(token.0, TokenUser, None, 0, &mut bytes) };

  if bytes < size_of::<TOKEN_USER>() as u32 || align_of::<TOKEN_USER>() > align_of::<usize>() {
    return Err(identity_error());
  }

  let mut data = vec![0usize; (bytes as usize).div_ceil(size_of::<usize>())];
  // SAFETY: The word buffer is aligned and large enough for TOKEN_USER and its
  // embedded SID; it stays live through SID conversion below.
  unsafe { GetTokenInformation(token.0, TokenUser, Some(data.as_mut_ptr().cast()), bytes, &mut bytes) }.map_err(|_| identity_error())?;

  if (bytes as usize) < size_of::<TOKEN_USER>() {
    return Err(identity_error());
  }

  // SAFETY: Windows initialized an aligned TOKEN_USER in `data`.
  let token_user = unsafe { data.as_ptr().cast::<TOKEN_USER>().read() };

  if token_user.User.Sid.0.is_null() {
    return Err(identity_error());
  }

  // SAFETY: The SID remains valid in `data`; anonymous identity cannot own an
  // enrollment even if a client changed its token after opening the pipe.
  if unsafe { IsWellKnownSid(token_user.User.Sid, WinAnonymousSid) }.as_bool() {
    return Err(identity_error());
  }

  let mut raw_sid = PWSTR::null();
  // SAFETY: The SID remains live in `data`; Windows returns one LocalAlloc
  // UTF-16 string, which the guard frees after conversion.
  unsafe { ConvertSidToStringSidW(token_user.User.Sid, &mut raw_sid) }.map_err(|_| identity_error())?;

  if raw_sid.is_null() {
    return Err(identity_error());
  }

  let sid = LocalString(raw_sid);
  // SAFETY: ConvertSidToStringSidW returned a NUL-terminated UTF-16 string.
  let value = unsafe { sid.0.to_string() }.map_err(|_| identity_error())?;

  if !value.starts_with("S-1-") {
    return Err(identity_error());
  }

  let administrator = enabled_administrator(token.0)?;
  Ok(ClientIdentity {
    sid: value,
    administrator,
  })
}

fn enabled_administrator(token: HANDLE) -> io::Result<bool> {
  let mut bytes = 0u32;
  // SAFETY: A null output buffer queries the required TokenGroups size.
  let _ = unsafe { GetTokenInformation(token, TokenGroups, None, 0, &mut bytes) };
  let header = offset_of!(TOKEN_GROUPS, Groups);

  if (bytes as usize) < header || bytes > 64 * 1024 || align_of::<SID_AND_ATTRIBUTES>() > align_of::<usize>() {
    return Err(identity_error());
  }

  let mut data = vec![0usize; (bytes as usize).div_ceil(size_of::<usize>())];
  // SAFETY: This aligned buffer has the queried capacity and stays live while
  // Windows writes TokenGroups and group SIDs are inspected below.
  unsafe { GetTokenInformation(token, TokenGroups, Some(data.as_mut_ptr().cast()), bytes, &mut bytes) }.map_err(|_| identity_error())?;

  if (bytes as usize) < header {
    return Err(identity_error());
  }

  // SAFETY: The successful query initialized GroupCount at the buffer start.
  let count = unsafe { data.as_ptr().cast::<u32>().read() as usize };

  if count > (bytes as usize - header) / size_of::<SID_AND_ATTRIBUTES>() {
    return Err(identity_error());
  }

  // SAFETY: The checked count fits the initialized TokenGroups buffer.
  let groups = unsafe { data.as_ptr().cast::<u8>().add(header).cast::<SID_AND_ATTRIBUTES>() };

  for index in 0..count {
    // SAFETY: Each SID_AND_ATTRIBUTES lies inside the checked live buffer.
    let group = unsafe { groups.add(index).read() };

    if group.Sid.0.is_null() {
      return Err(identity_error());
    }

    // SAFETY: Windows returned this SID in the live TokenGroups allocation.
    if group.Attributes & SE_GROUP_ENABLED as u32 != 0
      && group.Attributes & SE_GROUP_USE_FOR_DENY_ONLY as u32 == 0
      && unsafe { IsWellKnownSid(group.Sid, WinBuiltinAdministratorsSid) }.as_bool()
    {
      return Ok(true);
    }
  }

  Ok(false)
}

struct ImpersonationGuard;

impl Drop for ImpersonationGuard {
  fn drop(&mut self) {
    // SAFETY: This guard is created immediately after impersonation succeeds,
    // on the same poll_read thread, and no `.await` can move it elsewhere.
    if unsafe { RevertToSelf() }.is_err() {
      // A service thread must never continue under a client's security token.
      std::process::abort();
    }
  }
}

struct Token(HANDLE);
impl Drop for Token {
  fn drop(&mut self) {
    // SAFETY: OpenThreadToken returned one owned handle.
    let _ = unsafe { CloseHandle(self.0) };
  }
}

struct LocalString(PWSTR);
impl Drop for LocalString {
  fn drop(&mut self) {
    // SAFETY: ConvertSidToStringSidW returned one LocalAlloc allocation.
    let _ = unsafe { LocalFree(HLOCAL(self.0.0.cast::<c_void>())) };
  }
}

struct SecurityDescriptor(PSECURITY_DESCRIPTOR);
impl Drop for SecurityDescriptor {
  fn drop(&mut self) {
    // SAFETY: ConvertStringSecurityDescriptorToSecurityDescriptorW returned
    // one LocalAlloc allocation.
    let _ = unsafe { LocalFree(HLOCAL(self.0.0)) };
  }
}

fn identity_error() -> io::Error {
  io::Error::new(io::ErrorKind::PermissionDenied, "verified named-pipe client SID is required")
}

#[cfg(test)]
mod tests {
  use std::os::windows::ffi::OsStrExt;
  use std::os::windows::io::{FromRawHandle, OwnedHandle};
  use std::sync::Mutex;

  use auv_api_proto::auv::api::daemon::v1 as proto;
  use auv_api_proto::auv::api::daemon::v1::device_local_service_server::DeviceLocalService;
  use tokio::io::{AsyncReadExt, AsyncWriteExt};
  use tokio::net::windows::named_pipe::ClientOptions;
  use windows::Win32::Storage::FileSystem::{
    CreateFileW, FILE_FLAG_OVERLAPPED, FILE_SHARE_MODE, OPEN_EXISTING, SECURITY_IDENTIFICATION, SECURITY_SQOS_PRESENT,
  };

  use super::*;
  use crate::device_local::{AuditPage, EnrollAccount, Enrollment, LocalControlError, LocalOsPrincipal};

  #[test]
  fn peer_identity_rejects_group_or_sid_change_after_first_read() {
    let peer = PeerIdentity::default();
    let ordinary = ClientIdentity {
      sid: "S-1-5-21-1001".into(),
      administrator: false,
    };

    assert!(peer.accept_read(ordinary.clone()).is_ok());
    assert!(peer.accept_read(ordinary.clone()).is_ok());
    assert!(matches!(peer.principal(), Some(LocalOsPrincipal::WindowsSid(sid)) if sid == ordinary.sid));
    assert!(
      peer
        .accept_read(ClientIdentity {
          administrator: true,
          ..ordinary.clone()
        })
        .is_err()
    );
    assert!(
      peer
        .accept_read(ClientIdentity {
          sid: "S-1-5-21-1002".into(),
          ..ordinary
        })
        .is_err()
    );

    let administrator = PeerIdentity::default();
    administrator
      .accept_read(ClientIdentity {
        sid: "S-1-5-21-2000".into(),
        administrator: true,
      })
      .unwrap();

    assert!(matches!(administrator.principal(), Some(LocalOsPrincipal::WindowsAdministratorSid(sid)) if sid == "S-1-5-21-2000"));
  }

  #[test]
  fn native_token_groups_are_readable() {
    use windows::Win32::System::Threading::{GetCurrentProcess, OpenProcessToken};

    let mut raw_token = HANDLE::default();
    // SAFETY: This opens the current process token only for a read-only test.
    unsafe { OpenProcessToken(GetCurrentProcess(), TOKEN_QUERY, &mut raw_token) }.unwrap();
    let token = Token(raw_token);

    assert!(enabled_administrator(token.0).is_ok());
  }

  #[tokio::test]
  async fn pipe_read_captures_the_actual_client_token_claim() {
    use windows::Win32::System::Threading::{GetCurrentProcess, OpenProcessToken};

    let nonce = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH).unwrap().as_nanos();
    let path = format!(r"\\.\pipe\auv-device-local-test-{}-{nonce}", std::process::id());
    let server = ServerOptions::new().first_pipe_instance(true).reject_remote_clients(true).create(&path).unwrap();
    let writer = tokio::spawn(async move {
      let mut client = ClientOptions::new().open(&path).unwrap();
      client.write_all(b"x").await.unwrap();
    });
    server.connect().await.unwrap();
    let mut verified = VerifiedPipe {
      pipe: server,
      identity: PeerIdentity::default(),
    };
    let mut byte = [0];
    verified.read_exact(&mut byte).await.unwrap();
    writer.await.unwrap();

    assert_eq!(byte, *b"x");

    let principal = verified.identity.principal().unwrap();
    let mut raw_token = HANDLE::default();
    // SAFETY: This opens the current process token only for a read-only
    // comparison with the same-process pipe client's impersonation token.
    unsafe { OpenProcessToken(GetCurrentProcess(), TOKEN_QUERY, &mut raw_token) }.unwrap();
    let token = Token(raw_token);
    let expected_admin = enabled_administrator(token.0).unwrap();

    assert_eq!(matches!(principal, LocalOsPrincipal::WindowsAdministratorSid(_)), expected_admin);
  }

  #[derive(Default)]
  struct PrincipalProbe(Mutex<Option<String>>);

  #[tonic::async_trait]
  impl DeviceLocalControl for PrincipalProbe {
    async fn get_enrollment(&self, _: &LocalOsPrincipal, _: &str) -> Result<Enrollment, LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }

    async fn list_enrollments(&self, _: &LocalOsPrincipal) -> Result<Vec<Enrollment>, LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }

    async fn enroll(&self, _: &LocalOsPrincipal, _: EnrollAccount) -> Result<Enrollment, LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }

    async fn remove_enrollment(&self, _: &LocalOsPrincipal, _: &str) -> Result<(), LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }

    async fn get_policy(&self, principal: &LocalOsPrincipal) -> Result<bool, LocalControlError> {
      let sid = match principal {
        LocalOsPrincipal::WindowsSid(sid) | LocalOsPrincipal::WindowsAdministratorSid(sid) => sid,
        _ => return Err(LocalControlError::PermissionDenied),
      };
      *self.0.lock().unwrap() = Some(sid.clone());
      Ok(true)
    }

    async fn set_policy(&self, _: &LocalOsPrincipal, _: bool) -> Result<bool, LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }

    async fn list_audit(&self, _: &LocalOsPrincipal, _: u64, _: usize) -> Result<AuditPage, LocalControlError> {
      Err(LocalControlError::HostUnavailable)
    }
  }

  #[tokio::test]
  async fn dedicated_pipe_rejects_missing_identity_before_control() {
    let probe = Arc::new(PrincipalProbe::default());
    let direct = DeviceLocalGrpc {
      control: probe.clone(),
    };
    let missing = direct.get_policy(tonic::Request::new(proto::GetPolicyRequest {})).await.unwrap_err();

    assert_eq!(missing.code(), tonic::Code::PermissionDenied);
    assert!(probe.0.lock().unwrap().is_none());
  }

  #[test]
  fn authenticated_user_mask_allows_data_but_not_pipe_instance_creation() {
    assert_eq!(AUTHENTICATED_USER_PIPE_ACCESS & 0x0000_0003, 0x0000_0003);
    assert_eq!(AUTHENTICATED_USER_PIPE_ACCESS & 0x0000_0004, 0);
    assert_eq!(AUTHENTICATED_USER_PIPE_ACCESS & 0x0000_0080, 0x0000_0080);
    assert_eq!(AUTHENTICATED_USER_PIPE_ACCESS & 0x0012_0000, 0x0012_0000);
  }

  #[tokio::test]
  async fn authenticated_user_opens_the_actual_local_pipe_acl() {
    // ROOT CAUSE:
    //
    // A service-created pipe denied the console account before gRPC because
    // Windows requires FILE_READ_ATTRIBUTES when opening a named pipe, even
    // though the client requested only data, READ_CONTROL, and SYNCHRONIZE.
    // Before the fix, CreateFileW returned ERROR_ACCESS_DENIED with 0x00120003.
    // The ACL now admits that client without granting FILE_CREATE_PIPE_INSTANCE.
    let name = format!("auv-device-local-acl-test-{}", std::process::id());
    let _server = create_pipe(&name, true).expect("create the real Device-local pipe ACL");
    let path = format!(r"\\.\pipe\{name}");
    let wide = std::ffi::OsStr::new(&path).encode_wide().chain(Some(0)).collect::<Vec<_>>();
    // SAFETY: The pipe path is NUL-terminated and stays live through the call.
    // The returned handle is transferred to OwnedHandle on success.
    let raw = unsafe {
      CreateFileW(
        PCWSTR(wide.as_ptr()),
        0x0012_0003,
        FILE_SHARE_MODE(0),
        None,
        OPEN_EXISTING,
        FILE_FLAG_OVERLAPPED | SECURITY_SQOS_PRESENT | SECURITY_IDENTIFICATION,
        HANDLE::default(),
      )
    }
    .expect("an authenticated user should open the dedicated pipe");
    // SAFETY: CreateFileW returned one owned handle.
    let _client = unsafe { OwnedHandle::from_raw_handle(raw.0) };
  }
}