Integrate changes between [SD:717473] and [SD:725290]

This commit is contained in:
PowerShell Team
2016-07-28 18:02:24 -07:00
committed by Sergei Vorobev
parent 2280bea11e
commit 0dd425da19
28 changed files with 848 additions and 342 deletions
@@ -3777,7 +3777,7 @@ namespace Microsoft.PowerShell.Commands
if (workflowsToProcess != null && workflowsToProcess.Count > 0)
{
// In ConstrainedLanguage, XAML workflows are not supported (even from a trusted FullLanguage state),
// since we can't prevent tampering.
// unless they are signed in-box OS binaries.
if ((SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) ||
(Context.LanguageMode == PSLanguageMode.ConstrainedLanguage))
{
@@ -3785,15 +3785,30 @@ namespace Microsoft.PowerShell.Commands
// in full-language mode.
if (! SystemPolicy.XamlWorkflowSupported)
{
throw new NotSupportedException(Modules.XamlWorkflowsNotSupported);
foreach (string workflowPath in ResolveWorkflowFiles(moduleBase, workflowsToProcess))
{
if (!SecuritySupport.IsProductBinary(workflowPath))
{
throw new NotSupportedException(Modules.XamlWorkflowsNotSupported);
}
}
}
}
SessionStateInternal oldSessionStateWF = Context.EngineSessionState;
PSLanguageMode? savedLanguageMode = null;
try
{
Context.EngineSessionState = ss.Internal;
// Always run workflow import script as trusted since only signed in-box files can be imported
// on locked down machines.
if (Context.LanguageMode != PSLanguageMode.FullLanguage)
{
savedLanguageMode = Context.LanguageMode;
Context.LanguageMode = PSLanguageMode.FullLanguage;
}
if (dependentWorkflows != null && dependentWorkflows.Count > 0)
{
ScriptBlock importWorkflow = ScriptBlock.Create(Context,
@@ -3811,7 +3826,7 @@ namespace Microsoft.PowerShell.Commands
else
{
ScriptBlock importWorkflow = ScriptBlock.Create(Context,
"param($files, $dependentFiles) Microsoft.PowerShell.Workflow.ServiceCore\\Import-PSWorkflow -Path \"$files\" -Force:$"+BaseForce
"param($files, $dependentFiles) Microsoft.PowerShell.Workflow.ServiceCore\\Import-PSWorkflow -Path \"$files\" -Force:$" + BaseForce
);
foreach (string workflowPath in ResolveWorkflowFiles(moduleBase, workflowsToProcess))
@@ -3830,6 +3845,11 @@ namespace Microsoft.PowerShell.Commands
finally
{
Context.EngineSessionState = oldSessionStateWF;
if (savedLanguageMode != null)
{
Context.LanguageMode = savedLanguageMode.Value;
}
}
}
}
@@ -11084,6 +11084,9 @@ namespace System.Management.Automation.Internal
/// <summary/>
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, InitialSessionState initialSessionState, out ParseException parsingErrors);
/// <summary/>
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, InitialSessionState initialSessionState, PSLanguageMode? languageMode, out ParseException parsingErrors);
/// <summary/>
List<WorkflowInfo> CompileWorkflows(ScriptBlockAst ast, PSModuleInfo definingModule, string rootWorkflowName);
@@ -1828,7 +1828,7 @@ namespace System.Management.Automation
if (_scriptBlock.HasBeginBlock)
{
RunClause(_runOptimized ? _scriptBlock.BeginBlock : _scriptBlock.UnoptimizedBeginBlock, AutomationNull.Value, _input.GetEnumerator());
RunClause(_runOptimized ? _scriptBlock.BeginBlock : _scriptBlock.UnoptimizedBeginBlock, AutomationNull.Value, _input);
}
}
@@ -1851,7 +1851,7 @@ namespace System.Management.Automation
}
if (_scriptBlock.HasProcessBlock)
{
RunClause(_runOptimized ? _scriptBlock.ProcessBlock : _scriptBlock.UnoptimizedProcessBlock, dollarUnder, _input.GetEnumerator());
RunClause(_runOptimized ? _scriptBlock.ProcessBlock : _scriptBlock.UnoptimizedProcessBlock, dollarUnder, _input);
_input.Clear();
}
}
@@ -1865,7 +1865,7 @@ namespace System.Management.Automation
if (_scriptBlock.HasEndBlock)
{
RunClause(_runOptimized ? _scriptBlock.EndBlock : _scriptBlock.UnoptimizedEndBlock, AutomationNull.Value, _input.ToArray().GetEnumerator());
RunClause(_runOptimized ? _scriptBlock.EndBlock : _scriptBlock.UnoptimizedEndBlock, AutomationNull.Value, _input.ToArray());
}
}
@@ -1125,7 +1125,8 @@ namespace System.Management.Automation
try
{
var converterInstance = Utils.GetAstToWorkflowConverterAndEnsureWorkflowModuleLoaded(context);
var workflows = converterInstance.CompileWorkflows(scriptBlockAst, context.EngineSessionState.Module, null, out parseErrors);
PSLanguageMode? languageMode = (context != null) ? context.LanguageMode : (PSLanguageMode?) null;
var workflows = converterInstance.CompileWorkflows(scriptBlockAst, context.EngineSessionState.Module, null, languageMode, out parseErrors);
foreach (var workflow in workflows)
{
context.EngineSessionState.SetWorkflowRaw(workflow,
@@ -597,7 +597,7 @@
<value>Cannot define the workflow. The language mode for this session is incompatible with the system-wide language mode.</value>
</data>
<data name="XamlWorkflowsNotSupported" xml:space="preserve">
<value>Cannot load the workflow. XAML-based workflows are not supported in the current language mode. Only script-based workflows are supported in this language mode.</value>
<value>Cannot load the workflow. Only signed in-box XAML-based workflows or script-based workflows are supported in the current language mode.</value>
</data>
<data name="CannotDetectNetFrameworkVersion" xml:space="preserve">
<value>Cannot verify the Microsoft .NET Framework version {0} because it is not included in the list of permitted versions.</value>
@@ -100,7 +100,7 @@ namespace Microsoft.PowerShell
}
}
namespace System.Management.Automation
namespace System.Management.Automation.Internal
{
/// <summary>
/// The SAFER policy associated with this file
@@ -118,7 +118,10 @@ namespace System.Management.Automation
Disallowed = 2
}
internal static class SecuritySupport
/// <summary>
/// Security Support APIs
/// </summary>
public static class SecuritySupport
{
#region execution policy
@@ -414,7 +417,12 @@ namespace System.Management.Automation
}
}
internal static bool IsProductBinary(string file)
/// <summary>
/// Returns true if file has product binary signature
/// </summary>
/// <param name="file">Name of file to check</param>
/// <returns>True when file has product binary signature</returns>
public static bool IsProductBinary(string file)
{
if(String.IsNullOrEmpty(file) || (! IO.File.Exists(file)))
{