From 0191946fe30015f11cd0113b16815eb1042a4e5b Mon Sep 17 00:00:00 2001 From: Dan Travison Date: Fri, 2 Feb 2018 10:49:09 -0800 Subject: [PATCH] Fix the filtering of analytic events on Unix platforms. (#6086) - Remove previous `UseAlwaysAnalytic` workaround in `SysLogProvider.Log` - Update Script Block logging to always log to the operational channel with `UseAlwaysOperational` - Fix `PSChannel` on Linux to use a bitmask - Handle `UseAlwaysOperational` and `UseAlwaysAnalytic` keywords but adding to `_keywordFilter` if the associated channels were selected in the configuration --- .../engine/PSConfiguration.cs | 9 ++------- .../engine/remoting/common/PSETWTracer.cs | 14 ++++++++++++++ .../engine/runtime/CompiledScriptBlock.cs | 14 +++++++------- .../utils/tracing/PSSysLogProvider.cs | 7 +++++-- .../utils/tracing/SysLogProvider.cs | 15 ++++++++------- 5 files changed, 36 insertions(+), 23 deletions(-) diff --git a/src/System.Management.Automation/engine/PSConfiguration.cs b/src/System.Management.Automation/engine/PSConfiguration.cs index 8c60d6735d..8861e676c4 100644 --- a/src/System.Management.Automation/engine/PSConfiguration.cs +++ b/src/System.Management.Automation/engine/PSConfiguration.cs @@ -247,8 +247,6 @@ namespace System.Management.Automation.Configuration /// const string LogDefaultValue = "default"; - const PSChannel DefaultChannels = PSChannel.Operational; - /// /// Gets the bitmask of the PSChannel values to log. /// @@ -282,15 +280,12 @@ namespace System.Management.Automation.Configuration if (result == 0) { - result = DefaultChannels; + result = System.Management.Automation.Tracing.PSSysLogProvider.DefaultChannels; } return result; } - // by default, do not include analytic events. - const PSKeyword DefaultKeywords = (PSKeyword) (0xFFFFFFFFFFFFFFFF & ~(ulong)PSKeyword.UseAlwaysAnalytic); - /// /// Gets the bitmask of keywords to log. /// @@ -324,7 +319,7 @@ namespace System.Management.Automation.Configuration if (result == 0) { - result = DefaultKeywords; + result = System.Management.Automation.Tracing.PSSysLogProvider.DefaultKeywords; } return result; diff --git a/src/System.Management.Automation/engine/remoting/common/PSETWTracer.cs b/src/System.Management.Automation/engine/remoting/common/PSETWTracer.cs index 5008ab57dd..0088f2f136 100644 --- a/src/System.Management.Automation/engine/remoting/common/PSETWTracer.cs +++ b/src/System.Management.Automation/engine/remoting/common/PSETWTracer.cs @@ -195,12 +195,26 @@ namespace System.Management.Automation.Internal /// /// Defines enumerations for channels /// + /// + /// On Windows, PSChannel is the numeric channel id value. + /// On Non-Windows, PSChannel is used to filter events and + /// the underlying channel bitmask values are used instead. + /// The bit values are the same as used on Windows. + /// +#if UNIX [Flags] + internal enum PSChannel : byte + { + Operational = 0x80, + Analytic = 0x40 + } +#else internal enum PSChannel : byte { Operational = 0x10, Analytic = 0x11 } +#endif /// /// Defines enumerations for tasks diff --git a/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs b/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs index 6362edd0bc..6b69f89d99 100644 --- a/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs +++ b/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs @@ -1321,7 +1321,7 @@ namespace System.Management.Automation // they can just wait on the compromised box and see the sensitive data eventually anyways. string errorMessage = StringUtil.Format(SecuritySupportStrings.CouldNotEncryptContent, textToLog, error.ToString()); - PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational, 0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty); } else @@ -1334,12 +1334,12 @@ namespace System.Management.Automation if (scriptBlock._scriptBlockData.HasSuspiciousContent) { - PSEtwLog.LogOperationalWarning(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalWarning(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational, segment + 1, segments, textToLog, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty); } else { - PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational, segment + 1, segments, textToLog, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty); } @@ -1405,7 +1405,7 @@ namespace System.Management.Automation // attacker seeing potentially sensitive data. Because if they aren't detected, then // they can just wait on the compromised box and see the sensitive data eventually anyways. string errorMessage = StringUtil.Format(SecuritySupportStrings.CouldNotUseCertificate, error.ToString()); - PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational, 0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty); return true; @@ -1430,7 +1430,7 @@ namespace System.Management.Automation } string errorMessage = StringUtil.Format(SecuritySupportStrings.CertificateContainsPrivateKey, certificateForLog); - PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalError(PSEventId.ScriptBlock_Compile_Detail, PSOpcode.Create, PSTask.ExecuteCommand, PSKeyword.UseAlwaysOperational, 0, 0, errorMessage, scriptBlock.Id.ToString(), scriptBlock.File ?? String.Empty); } } @@ -1794,7 +1794,7 @@ namespace System.Management.Automation if (GetScriptBlockLoggingSetting()?.EnableScriptBlockInvocationLogging == true) { - PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Start_Detail, PSOpcode.Create, PSTask.CommandStart, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Start_Detail, PSOpcode.Create, PSTask.CommandStart, PSKeyword.UseAlwaysOperational, scriptBlock.Id.ToString(), runspaceId.ToString()); } } @@ -1803,7 +1803,7 @@ namespace System.Management.Automation { if (GetScriptBlockLoggingSetting()?.EnableScriptBlockInvocationLogging == true) { - PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Complete_Detail, PSOpcode.Create, PSTask.CommandStop, PSKeyword.UseAlwaysAnalytic, + PSEtwLog.LogOperationalVerbose(PSEventId.ScriptBlock_Invoke_Complete_Detail, PSOpcode.Create, PSTask.CommandStop, PSKeyword.UseAlwaysOperational, scriptBlock.Id.ToString(), runspaceId.ToString()); } } diff --git a/src/System.Management.Automation/utils/tracing/PSSysLogProvider.cs b/src/System.Management.Automation/utils/tracing/PSSysLogProvider.cs index 49d5c8c2f2..7507c1c440 100755 --- a/src/System.Management.Automation/utils/tracing/PSSysLogProvider.cs +++ b/src/System.Management.Automation/utils/tracing/PSSysLogProvider.cs @@ -17,8 +17,11 @@ namespace System.Management.Automation.Tracing { private static SysLogProvider s_provider; - // by default, do not include analytic events - internal const PSKeyword DefaultKeywords = (PSKeyword) (0xFFFFFFFFFFFFFFFF & ~(ulong)PSKeyword.UseAlwaysAnalytic); + // by default, do not include channel bits + internal const PSKeyword DefaultKeywords = (PSKeyword) (0x00FFFFFFFFFFFFFF); + + // the default enabled channel(s) + internal const PSChannel DefaultChannels = PSChannel.Operational; /// /// Class constructor. diff --git a/src/System.Management.Automation/utils/tracing/SysLogProvider.cs b/src/System.Management.Automation/utils/tracing/SysLogProvider.cs index 614bdbdc9e..cd6d9d7392 100755 --- a/src/System.Management.Automation/utils/tracing/SysLogProvider.cs +++ b/src/System.Management.Automation/utils/tracing/SysLogProvider.cs @@ -102,6 +102,14 @@ namespace System.Management.Automation.Tracing _keywordFilter = (ulong)keywords; _levelFilter = (byte) level; _channelFilter = (byte) channels; + if ((_channelFilter & (ulong) PSChannel.Operational) != 0) + { + _keywordFilter |= (ulong) PSKeyword.UseAlwaysOperational; + } + if ((_channelFilter & (ulong) PSChannel.Analytic) != 0) + { + _keywordFilter |= (ulong) PSKeyword.UseAlwaysAnalytic; + } } /// @@ -313,13 +321,6 @@ namespace System.Management.Automation.Tracing /// The payload for the log message. public void Log(PSEventId eventId, PSChannel channel, PSTask task, PSOpcode opcode, PSLevel level, PSKeyword keyword, params object[] args) { - if (keyword == PSKeyword.UseAlwaysAnalytic) - { - // Use the 'DefaultKeywords' to work around the default keyword filter. - // Note that the PSKeyword argument is not really used in writing SysLog. - keyword = PSSysLogProvider.DefaultKeywords; - } - if (ShouldLog(level, keyword, channel)) { int threadId = Thread.CurrentThread.ManagedThreadId;