Add fix for Start-Job initialization script should not be executed as trusted in system lockdown (#8284)

This commit is contained in:
Paul Higinbotham
2018-11-26 10:38:13 -08:00
committed by Aditya Patwardhan
parent e2b5aaca20
commit 6a388f0b7d
2 changed files with 25 additions and 1 deletions
@@ -546,7 +546,9 @@ namespace System.Management.Automation
{
Debug.Assert(cmdToRun != null, "cmdToRun shouldn't be null");
cmdToRun.CommandOrigin = CommandOrigin.Internal;
// Don't invoke initialization script as trusted (CommandOrigin == Internal) if the system is in lock down mode.
cmdToRun.CommandOrigin = (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) ? CommandOrigin.Runspace : CommandOrigin.Internal;
cmdToRun.MergeMyResults(PipelineResultTypes.Error, PipelineResultTypes.Output);
PowerShell powershell = PowerShell.Create();
powershell.AddCommand(cmdToRun).AddCommand("out-default");
@@ -54,6 +54,28 @@ try
}
}
Describe "Start-Job initialization script should work in system lock down" -Tags 'Feature','RequireAdminOnWindows' {
It "Verifies that Start-Job initialization script runs successfully in system lock down" {
try
{
Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode
$ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage"
$job = Start-Job -InitializationScript { function Hello { "Hello" } } -ScriptBlock { Hello }
$result = $job | Wait-Job | Receive-Job
}
finally
{
Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode
}
$result | Should -BeExactly "Hello"
$job | Remove-Job
}
}
# End Describe blocks
}
finally