From 02e506c84617e064002ffe2c02f9930985a7ffd3 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 10 Jan 2023 12:06:41 -0800 Subject: [PATCH] [release/v7.3.2] Fix `SuspiciousContentChecker.Match` to detect a pre-defined string when the text starts with it (#18916) * Fix `SuspiciousContentChecker.Match` to detect a pre-defined string when the text starts with it * Add more tests * Add one more test Co-authored-by: Dongbo Wang --- .../engine/runtime/CompiledScriptBlock.cs | 2 +- .../Api/SuspiciousContentChecker.Tests.ps1 | 35 +++++++++++++++++++ 2 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 test/powershell/engine/Api/SuspiciousContentChecker.Tests.ps1 diff --git a/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs b/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs index 8d4e60ae0a..9feeab9436 100644 --- a/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs +++ b/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs @@ -2033,7 +2033,7 @@ namespace System.Management.Automation continue; } - for (int j = Math.Min(i, runningHash.Length) - 1; j > 0; j--) + for (int j = Math.Min(i, runningHash.Length - 1); j > 0; j--) { // Say our input is: `Emit` (our shortest pattern, len 4). // Towards the end just before matching, we will: diff --git a/test/powershell/engine/Api/SuspiciousContentChecker.Tests.ps1 b/test/powershell/engine/Api/SuspiciousContentChecker.Tests.ps1 new file mode 100644 index 0000000000..8d532dac04 --- /dev/null +++ b/test/powershell/engine/Api/SuspiciousContentChecker.Tests.ps1 @@ -0,0 +1,35 @@ +# Copyright (c) Microsoft Corporation. +# Licensed under the MIT License. + +Describe 'SuspiciousContentChecker verification' -Tags "CI" { + BeforeAll { + $type = [psobject].Assembly.GetType('System.Management.Automation.ScriptBlock+SuspiciousContentChecker') + + $testCases = @( + @{ id = 'Should Detect (1)'; text = "add-TyPe"; expected = "Add-Type" } + @{ id = 'Should Detect (2)'; text = "GetDelegateForFunctionPointer"; expected = "GetDelegateForFunctionPointer" } + @{ id = 'Should Detect (3)'; text = "ZeroFreeGlobalAllocUnicode"; expected = "ZeroFreeGlobalAllocUnicode" } + @{ id = 'Should Detect (4)'; text = "Hello world emit new"; expected = "Emit" } + @{ id = 'Should Detect (5)'; text = "xxxx yyyyMakeByRefTypecccc Type 'help' to get help"; expected = "MakeByRefType" } + @{ id = 'Should Detect (6)'; text = "emjt TypeHandlebegood"; expected = "TypeHandle" } + @{ id = 'Should Detect (7)'; text = "emit*&)(@~>-type"; expected = "Emit" } + @{ id = 'Should Detect (8)'; text = "*&)(@~>-typeemit"; expected = "Emit" } + @{ id = 'Should Detect (9)'; text = "Type`u{48}andle`u{2122}"; expected = "TypeHandle" } + @{ id = 'Should Detect (10)'; text = "`u{2122}Type`u{48}andle`u{2122}"; expected = "TypeHandle" } + @{ id = 'Should Detect (11)'; text = "`u{D83D}`u{DE00}Type`u{48}andle`u{D83D}`u{DE00}"; expected = "TypeHandle" } ## use surrogate pairs in the string. + @{ id = 'Should Detect (12)'; text = "xx`u{48}`u{48}xx()xxx--xx[]xx;'xpox?/xxemit"; expected = "Emit" } ## suspicious string starts at the index 29. + + @{ id = 'Should NOT Detect (1)'; text = "PowerShell Preview Extension v2022.11.2"; expected = $null } + @{ id = 'Should NOT Detect (2)'; text = "add-typu"; expected = $null } + @{ id = 'Should NOT Detect (3)'; text = "GetDelegateForFunctionPointfr"; expected = $null } + @{ id = 'Should NOT Detect (4)'; text = "emjt TypeHandlfe"; expected = $null } + @{ id = 'Should NOT Detect (5)'; text = "Get*&)(@~>-Types"; expected = $null } + ) + } + + It "Smoke testing the suspicious content detection - " -TestCases $testCases { + param($text, $expected) + + $type::Match($text) | Should -BeExactly $expected + } +}