10.2 Dispatch and Authorisation

A parsed command runs a fixed sequence before it does anything.

  1. The shutdown gate. If peinit is shutting down, everything except status, list and operation-status is rejected. The gate runs before the access check, so during shutdown a caller who would have been denied is told the command is invalid for the current state rather than that they lack the right.
  2. Resolve the target. A command naming no definition, and no addressable definition-removed entry, returns UNKNOWN_SERVICE. peinit does not synthesise a descriptor for something that does not exist.
  3. AccessCheck. The caller's token, the target's descriptor, the generic mapping, and the right the command requires (§4.6, §4.7).
  4. On denial, return ACCESS_DENIED and record an access.denied event carrying the caller's SID, the target, the requested right by name, and the access bits requested and granted. Silent denial is not acceptable; a denial an administrator cannot see is indistinguishable from a bug.
  5. On grant, classify the command against the service's state (§10.3) and act.

10.2.1 Rights #

CommandRight
startSERVICE_START
stopSERVICE_STOP
restartSERVICE_START and SERVICE_STOP
reloadSERVICE_INTERROGATE
resetSERVICE_STOP
statusSERVICE_QUERY_STATUS
listFiltered per service by SERVICE_QUERY_STATUS
operation-statusSERVICE_QUERY_STATUS on the target service
shutdownSYSTEM_SHUTDOWN
reload-configSYSTEM_RELOAD_CONFIG

operation-status resolves the operation before it checks the right, so an unknown identifier is reported as unknown regardless of who asked.

10.2.2 Filtering #

list checks every service and partitions the result. Services the caller can query are returned; services it cannot are omitted, and the denials become audit events rather than anything the caller sees. A caller with no query rights anywhere gets an empty list and a successful response, not a denial — the filtering exists to avoid answering the question "does this service exist", and reporting the denials would answer it.

Definition-removed services are listed, and the list entry does not say so. A status query on one does.

Edit this page