mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Merged PR 38918: Update MaxVisitCount and MaxHashtableKeyCount if VisitorSafeValueContext indicates SkipLimitCheck is true
Update MaxVisitCount and MaxHashtableKeyCount if visitor safe value context indicates SkipLimitCheck is true Related work items: #163537 ---- #### AI description (iteration 1) #### PR Classification Enhancement: Conditionally update AST limit checks based on safe value context flags. #### PR Summary This pull request refactors the safe value visitor to initialize runtime limit values, setting them to maximum if the `SkipLimitCheck` flag is present, and adjusts the corresponding condition checks to support larger AST structures safely. - `src/System.Management.Automation/engine/parser/SafeValues.cs`: Replaced hard-coded limit constants with runtime-initialized readonly fields based on the safe value context, and updated conditional checks in `IsAstSafe` and `VisitHashtable`. - `test/powershell/Modules/Microsoft.PowerShell.Utility/PowerShellData.tests.ps1`: Added tests to validate behavior when using `-SkipLimitCheck`, ensuring insecure PSD1 files are properly rejected. <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot --> Related work items: #163537
This commit is contained in:
@@ -49,4 +49,10 @@ Describe "Tests for the Import-PowerShellDataFile cmdlet" -Tags "CI" {
|
||||
$result = Import-PowerShellDataFile $largePsd1Path -SkipLimitCheck
|
||||
$result.Keys.Count | Should -Be 501
|
||||
}
|
||||
|
||||
It 'Fails if psd1 file is insecure while -SkipLimitCheck is used' {
|
||||
$path = Setup -f insecure2.psd1 -Content '@{ Foo = [object] (calc.exe) }' -pass
|
||||
{ Import-PowerShellDataFile $path -SkipLimitCheck -ErrorAction Stop } |
|
||||
Should -Throw -ErrorId "System.InvalidOperationException,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user