mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Integrate changes between [SD:717473] and [SD:725290]
This commit is contained in:
committed by
Sergei Vorobev
parent
2280bea11e
commit
0dd425da19
@@ -3777,7 +3777,7 @@ namespace Microsoft.PowerShell.Commands
|
||||
if (workflowsToProcess != null && workflowsToProcess.Count > 0)
|
||||
{
|
||||
// In ConstrainedLanguage, XAML workflows are not supported (even from a trusted FullLanguage state),
|
||||
// since we can't prevent tampering.
|
||||
// unless they are signed in-box OS binaries.
|
||||
if ((SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) ||
|
||||
(Context.LanguageMode == PSLanguageMode.ConstrainedLanguage))
|
||||
{
|
||||
@@ -3785,15 +3785,30 @@ namespace Microsoft.PowerShell.Commands
|
||||
// in full-language mode.
|
||||
if (! SystemPolicy.XamlWorkflowSupported)
|
||||
{
|
||||
throw new NotSupportedException(Modules.XamlWorkflowsNotSupported);
|
||||
foreach (string workflowPath in ResolveWorkflowFiles(moduleBase, workflowsToProcess))
|
||||
{
|
||||
if (!SecuritySupport.IsProductBinary(workflowPath))
|
||||
{
|
||||
throw new NotSupportedException(Modules.XamlWorkflowsNotSupported);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
SessionStateInternal oldSessionStateWF = Context.EngineSessionState;
|
||||
PSLanguageMode? savedLanguageMode = null;
|
||||
try
|
||||
{
|
||||
Context.EngineSessionState = ss.Internal;
|
||||
|
||||
// Always run workflow import script as trusted since only signed in-box files can be imported
|
||||
// on locked down machines.
|
||||
if (Context.LanguageMode != PSLanguageMode.FullLanguage)
|
||||
{
|
||||
savedLanguageMode = Context.LanguageMode;
|
||||
Context.LanguageMode = PSLanguageMode.FullLanguage;
|
||||
}
|
||||
|
||||
if (dependentWorkflows != null && dependentWorkflows.Count > 0)
|
||||
{
|
||||
ScriptBlock importWorkflow = ScriptBlock.Create(Context,
|
||||
@@ -3811,7 +3826,7 @@ namespace Microsoft.PowerShell.Commands
|
||||
else
|
||||
{
|
||||
ScriptBlock importWorkflow = ScriptBlock.Create(Context,
|
||||
"param($files, $dependentFiles) Microsoft.PowerShell.Workflow.ServiceCore\\Import-PSWorkflow -Path \"$files\" -Force:$"+BaseForce
|
||||
"param($files, $dependentFiles) Microsoft.PowerShell.Workflow.ServiceCore\\Import-PSWorkflow -Path \"$files\" -Force:$" + BaseForce
|
||||
);
|
||||
|
||||
foreach (string workflowPath in ResolveWorkflowFiles(moduleBase, workflowsToProcess))
|
||||
@@ -3830,6 +3845,11 @@ namespace Microsoft.PowerShell.Commands
|
||||
finally
|
||||
{
|
||||
Context.EngineSessionState = oldSessionStateWF;
|
||||
|
||||
if (savedLanguageMode != null)
|
||||
{
|
||||
Context.LanguageMode = savedLanguageMode.Value;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -11084,6 +11084,9 @@ namespace System.Management.Automation.Internal
|
||||
/// <summary/>
|
||||
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, InitialSessionState initialSessionState, out ParseException parsingErrors);
|
||||
|
||||
/// <summary/>
|
||||
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, InitialSessionState initialSessionState, PSLanguageMode? languageMode, out ParseException parsingErrors);
|
||||
|
||||
/// <summary/>
|
||||
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, string rootWorkflowName);
|
||||
|
||||
|
||||
@@ -1828,7 +1828,7 @@ namespace System.Management.Automation
|
||||
|
||||
if (_scriptBlock.HasBeginBlock)
|
||||
{
|
||||
RunClause(_runOptimized ? _scriptBlock.BeginBlock : _scriptBlock.UnoptimizedBeginBlock, AutomationNull.Value, _input.GetEnumerator());
|
||||
RunClause(_runOptimized ? _scriptBlock.BeginBlock : _scriptBlock.UnoptimizedBeginBlock, AutomationNull.Value, _input);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1851,7 +1851,7 @@ namespace System.Management.Automation
|
||||
}
|
||||
if (_scriptBlock.HasProcessBlock)
|
||||
{
|
||||
RunClause(_runOptimized ? _scriptBlock.ProcessBlock : _scriptBlock.UnoptimizedProcessBlock, dollarUnder, _input.GetEnumerator());
|
||||
RunClause(_runOptimized ? _scriptBlock.ProcessBlock : _scriptBlock.UnoptimizedProcessBlock, dollarUnder, _input);
|
||||
_input.Clear();
|
||||
}
|
||||
}
|
||||
@@ -1865,7 +1865,7 @@ namespace System.Management.Automation
|
||||
|
||||
if (_scriptBlock.HasEndBlock)
|
||||
{
|
||||
RunClause(_runOptimized ? _scriptBlock.EndBlock : _scriptBlock.UnoptimizedEndBlock, AutomationNull.Value, _input.ToArray().GetEnumerator());
|
||||
RunClause(_runOptimized ? _scriptBlock.EndBlock : _scriptBlock.UnoptimizedEndBlock, AutomationNull.Value, _input.ToArray());
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1125,7 +1125,8 @@ namespace System.Management.Automation
|
||||
try
|
||||
{
|
||||
var converterInstance = Utils.GetAstToWorkflowConverterAndEnsureWorkflowModuleLoaded(context);
|
||||
var workflows = converterInstance.CompileWorkflows(scriptBlockAst, context.EngineSessionState.Module, null, out parseErrors);
|
||||
PSLanguageMode? languageMode = (context != null) ? context.LanguageMode : (PSLanguageMode?) null;
|
||||
var workflows = converterInstance.CompileWorkflows(scriptBlockAst, context.EngineSessionState.Module, null, languageMode, out parseErrors);
|
||||
foreach (var workflow in workflows)
|
||||
{
|
||||
context.EngineSessionState.SetWorkflowRaw(workflow,
|
||||
|
||||
@@ -597,7 +597,7 @@
|
||||
<value>Cannot define the workflow. The language mode for this session is incompatible with the system-wide language mode.</value>
|
||||
</data>
|
||||
<data name="XamlWorkflowsNotSupported" xml:space="preserve">
|
||||
<value>Cannot load the workflow. XAML-based workflows are not supported in the current language mode. Only script-based workflows are supported in this language mode.</value>
|
||||
<value>Cannot load the workflow. Only signed in-box XAML-based workflows or script-based workflows are supported in the current language mode.</value>
|
||||
</data>
|
||||
<data name="CannotDetectNetFrameworkVersion" xml:space="preserve">
|
||||
<value>Cannot verify the Microsoft .NET Framework version {0} because it is not included in the list of permitted versions.</value>
|
||||
|
||||
@@ -100,7 +100,7 @@ namespace Microsoft.PowerShell
|
||||
}
|
||||
}
|
||||
|
||||
namespace System.Management.Automation
|
||||
namespace System.Management.Automation.Internal
|
||||
{
|
||||
/// <summary>
|
||||
/// The SAFER policy associated with this file
|
||||
@@ -118,7 +118,10 @@ namespace System.Management.Automation
|
||||
Disallowed = 2
|
||||
}
|
||||
|
||||
internal static class SecuritySupport
|
||||
/// <summary>
|
||||
/// Security Support APIs
|
||||
/// </summary>
|
||||
public static class SecuritySupport
|
||||
{
|
||||
#region execution policy
|
||||
|
||||
@@ -414,7 +417,12 @@ namespace System.Management.Automation
|
||||
}
|
||||
}
|
||||
|
||||
internal static bool IsProductBinary(string file)
|
||||
/// <summary>
|
||||
/// Returns true if file has product binary signature
|
||||
/// </summary>
|
||||
/// <param name="file">Name of file to check</param>
|
||||
/// <returns>True when file has product binary signature</returns>
|
||||
public static bool IsProductBinary(string file)
|
||||
{
|
||||
if(String.IsNullOrEmpty(file) || (! IO.File.Exists(file)))
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user