Skip to content

fix: enable SeIncreaseBasePriorityPrivilege when setting High I/O priority - #65

Open
SA-Mousavichashmi wants to merge 1 commit into
PrimeBuild-pc:mainfrom
SA-Mousavichashmi:fix/high-io-priority-privilege
Open

SA-Mousavichashmi wants to merge 1 commit into
PrimeBuild-pc:mainfrom
SA-Mousavichashmi:fix/high-io-priority-privilege

Conversation

@SA-Mousavichashmi

Copy link
Copy Markdown
Contributor

Description

When configuring process I/O priority to High (ProcessIoPriority.High / level 3), Windows NT requires SeIncreaseBasePriorityPrivilege in the calling process's token.

Even though ThreadPilot runs elevated as administrator, Windows administrative user tokens have SeIncreaseBasePriorityPrivilege disabled by default until explicitly enabled via AdjustTokenPrivileges. Without enabling this privilege, NtSetInformationProcess(..., ProcessIoPriority, ...) fails with NTSTATUS 0xC0000061 (STATUS_PRIVILEGE_NOT_HELD). In ThreadPilot, this unmapped status previously produced a generic NativeApplyFailed error while leaving targeted processes stuck at default/throttled Low I/O priority.

Changes

  1. Privilege Adjustment P/Invoke:

    • Added standard Win32 token adjustment APIs (OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges) to ProcessMemoryPriorityNativeMethods.
    • Added helper TryEnablePrivilege and exposed TryEnableProcessPrivilege on IProcessMemoryPriorityNativeApi.
  2. Acquire Privilege on High I/O Priority:

    • Updated ProcessMemoryPriorityService.SetIoPriorityAsync to invoke TryEnableProcessPrivilege(SeIncreaseBasePriorityPrivilege) before calling SetIoPriority when requesting ProcessIoPriority.High.
  3. Status Code Mapping:

    • Mapped 0xC0000061 (STATUS_PRIVILEGE_NOT_HELD) alongside 0xC0000022 (STATUS_ACCESS_DENIED) to AffinityApplyErrorCodes.AccessDenied and user-friendly access denied messaging.
  4. Unit Tests:

    • Added test coverage in ProcessMemoryPriorityServiceTests verifying that ProcessIoPriority.High attempts to acquire SeIncreaseBasePriorityPrivilege.
    • Added test verifying NTSTATUS 0xC0000061 maps safely to AccessDenied.

Verification

  • Verified P/Invoke privilege elevation and token adjustment behavior against Windows NT API specifications.
  • Verified unit test suite additions covering privilege request tracking and NTSTATUS 0xC0000061 error mapping.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 12.50000% with 21 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
...orms/Windows/ProcessMemoryPriorityNativeMethods.cs 0.00% 19 Missing ⚠️
...atforms/Windows/IProcessMemoryPriorityNativeApi.cs 0.00% 2 Missing ⚠️

📢 Thoughts on this report? Let us know!

@PrimeBuild-pc

Copy link
Copy Markdown
Owner

Thanks for the PR. Please scope SeIncreaseBasePriorityPrivilege to the NtSetInformationProcess operation. Capture PreviousState when calling AdjustTokenPrivileges and restore it in a finally block on both success and failure. Since this modifies the process-wide token, please also prevent overlapping callers from restoring the privilege while another call still needs it. Add a Windows integration test that verifies the original privilege state is restored. The existing fake-based tests do not exercise the native token path.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants