Fix the filtering of analytic events on Unix platforms. (#6086)

- Remove previous `UseAlwaysAnalytic` workaround in `SysLogProvider.Log`
- Update Script Block logging to always log to the operational channel with `UseAlwaysOperational`
- Fix `PSChannel` on Linux to use a bitmask
- Handle `UseAlwaysOperational` and `UseAlwaysAnalytic` keywords but adding to `_keywordFilter` if the associated channels were selected in the configuration
This commit is contained in:
Dan Travison
2018-02-02 10:49:09 -08:00
committed by Dongbo Wang
parent e172e17b9e
commit 0191946fe3
5 changed files with 36 additions and 23 deletions
@@ -247,8 +247,6 @@ namespace System.Management.Automation.Configuration
/// </summary>
const string LogDefaultValue = "default";
const PSChannel DefaultChannels = PSChannel.Operational;
/// <summary>
/// Gets the bitmask of the PSChannel values to log.
/// </summary>
@@ -282,15 +280,12 @@ namespace System.Management.Automation.Configuration
if (result == 0)
{
result = DefaultChannels;
result = System.Management.Automation.Tracing.PSSysLogProvider.DefaultChannels;
}
return result;
}
// by default, do not include analytic events.
const PSKeyword DefaultKeywords = (PSKeyword) (0xFFFFFFFFFFFFFFFF & ~(ulong)PSKeyword.UseAlwaysAnalytic);
/// <summary>
/// Gets the bitmask of keywords to log.
/// </summary>
@@ -324,7 +319,7 @@ namespace System.Management.Automation.Configuration
if (result == 0)
{
result = DefaultKeywords;
result = System.Management.Automation.Tracing.PSSysLogProvider.DefaultKeywords;
}
return result;
@@ -195,12 +195,26 @@ namespace System.Management.Automation.Internal
/// <summary>
/// Defines enumerations for channels
/// </summary>
/// <remarks>
/// On Windows, PSChannel is the numeric channel id value.
/// On Non-Windows, PSChannel is used to filter events and
/// the underlying channel bitmask values are used instead.
/// The bit values are the same as used on Windows.
/// </remarks>
#if UNIX
[Flags]
internal enum PSChannel : byte
{
Operational = 0x80,
Analytic = 0x40
}
#else
internal enum PSChannel : byte
{
Operational = 0x10,
Analytic = 0x11
}
#endif
/// <summary>
/// Defines enumerations for tasks
@@ -1321,7 +1321,7 @@ namespace System.Management.Automation
// they can just wait on the compromised box and see the sensitive data eventually anyways.
string errorMessage = StringUtil.Format(SecuritySupportStrings.CouldNotEncryptContent, textToLog, error.ToString());
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational,
0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty);
}
else
@@ -1334,12 +1334,12 @@ namespace System.Management.Automation
if (scriptBlock._scriptBlockData.HasSuspiciousContent)
{
PSEtwLog.LogOperationalWarning(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalWarning(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational,
segment + 1, segments, textToLog, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty);
}
else
{
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational,
segment + 1, segments, textToLog, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty);
}
@@ -1405,7 +1405,7 @@ namespace System.Management.Automation
// attacker seeing potentially sensitive data. Because if they aren't detected, then
// they can just wait on the compromised box and see the sensitive data eventually anyways.
string errorMessage = StringUtil.Format(SecuritySupportStrings.CouldNotUseCertificate, error.ToString());
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational,
0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty);
return true;
@@ -1430,7 +1430,7 @@ namespace System.Management.Automation
}
string errorMessage = StringUtil.Format(SecuritySupportStrings.CertificateContainsPrivateKey, certificateForLog);
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational,
0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty);
}
}
@@ -1794,7 +1794,7 @@ namespace System.Management.Automation
if (GetScriptBlockLoggingSetting()?.EnableScriptBlockInvocationLogging == true)
{
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Start_Detail, PSOpcode.Create, PSTask.CommandStart, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Start_Detail, PSOpcode.Create, PSTask.CommandStart, PSKeyword.UseAlwaysOperational,
scriptBlock.Id.ToString(), runspaceId.ToString());
}
}
@@ -1803,7 +1803,7 @@ namespace System.Management.Automation
{
if (GetScriptBlockLoggingSetting()?.EnableScriptBlockInvocationLogging == true)
{
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Complete_Detail, PSOpcode.Create, PSTask.CommandStop, PSKeyword.UseAlwaysAnalytic,
PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Complete_Detail, PSOpcode.Create, PSTask.CommandStop, PSKeyword.UseAlwaysOperational,
scriptBlock.Id.ToString(), runspaceId.ToString());
}
}
@@ -17,8 +17,11 @@ namespace System.Management.Automation.Tracing
{
private static SysLogProvider s_provider;
// by default, do not include analytic events
internal const PSKeyword DefaultKeywords = (PSKeyword) (0xFFFFFFFFFFFFFFFF & ~(ulong)PSKeyword.UseAlwaysAnalytic);
// by default, do not include channel bits
internal const PSKeyword DefaultKeywords = (PSKeyword) (0x00FFFFFFFFFFFFFF);
// the default enabled channel(s)
internal const PSChannel DefaultChannels = PSChannel.Operational;
/// <summary>
/// Class constructor.
@@ -102,6 +102,14 @@ namespace System.Management.Automation.Tracing
_keywordFilter = (ulong)keywords;
_levelFilter = (byte) level;
_channelFilter = (byte) channels;
if ((_channelFilter & (ulong) PSChannel.Operational) != 0)
{
_keywordFilter |= (ulong) PSKeyword.UseAlwaysOperational;
}
if ((_channelFilter & (ulong) PSChannel.Analytic) != 0)
{
_keywordFilter |= (ulong) PSKeyword.UseAlwaysAnalytic;
}
}
/// <summary>
@@ -313,13 +321,6 @@ namespace System.Management.Automation.Tracing
/// <param name="args">The payload for the log message.</param>
public void Log(PSEventId eventId, PSChannel channel, PSTask task, PSOpcode opcode, PSLevel level, PSKeyword keyword, params object[] args)
{
if (keyword == PSKeyword.UseAlwaysAnalytic)
{
// Use the 'DefaultKeywords' to work around the default keyword filter.
// Note that the PSKeyword argument is not really used in writing SysLog.
keyword = PSSysLogProvider.DefaultKeywords;
}
if (ShouldLog(level, keyword, channel))
{
int threadId = Thread.CurrentThread.ManagedThreadId;