From abcdce4e3e816f3fb465b2b27ec0359a57db950f Mon Sep 17 00:00:00 2001 From: Steve Lee Date: Tue, 19 Jun 2018 17:53:32 -0700 Subject: [PATCH] Don't fail if SaferPolicy API is not available on Win10 IoT or NanoServer (#7075) * don't fail if SaferApi is not available * fix install-powershellremoting to work on Windows PowerShell 5.1 --- .../security/SecuritySupport.cs | 17 ++++++- .../security/nativeMethods.cs | 47 +++++++++++++++++++ .../Install-PowerShellRemoting.ps1 | 14 +++++- 3 files changed, 75 insertions(+), 3 deletions(-) diff --git a/src/System.Management.Automation/security/SecuritySupport.cs b/src/System.Management.Automation/security/SecuritySupport.cs index dbd84efe1c..51bfaf55a3 100644 --- a/src/System.Management.Automation/security/SecuritySupport.cs +++ b/src/System.Management.Automation/security/SecuritySupport.cs @@ -477,6 +477,8 @@ namespace System.Management.Automation.Internal #endregion execution policy + private static bool _saferIdentifyLevelApiSupported = true; + /// /// Get the pass / fail result of calling the SAFER API /// @@ -489,6 +491,11 @@ namespace System.Management.Automation.Internal { SaferPolicy status = SaferPolicy.Allowed; + if (!_saferIdentifyLevelApiSupported) + { + return status; + } + SAFER_CODE_PROPERTIES codeProperties = new SAFER_CODE_PROPERTIES(); IntPtr hAuthzLevel; @@ -555,7 +562,15 @@ namespace System.Management.Automation.Internal } else { - throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error()); + int lastError = Marshal.GetLastWin32Error(); + if (lastError == NativeConstants.FUNCTION_NOT_SUPPORTED) + { + _saferIdentifyLevelApiSupported = false; + } + else + { + throw new System.ComponentModel.Win32Exception(lastError); + } } return status; diff --git a/src/System.Management.Automation/security/nativeMethods.cs b/src/System.Management.Automation/security/nativeMethods.cs index fcad158b3a..6c560bbe33 100644 --- a/src/System.Management.Automation/security/nativeMethods.cs +++ b/src/System.Management.Automation/security/nativeMethods.cs @@ -24,68 +24,115 @@ namespace System.Management.Automation.Security // Safer native constants internal partial class NativeConstants { + /// /// SAFER_TOKEN_NULL_IF_EQUAL -> 0x00000001 + /// public const int SAFER_TOKEN_NULL_IF_EQUAL = 1; + /// /// SAFER_TOKEN_COMPARE_ONLY -> 0x00000002 + /// public const int SAFER_TOKEN_COMPARE_ONLY = 2; + /// /// SAFER_TOKEN_MAKE_INERT -> 0x00000004 + /// public const int SAFER_TOKEN_MAKE_INERT = 4; + /// /// SAFER_CRITERIA_IMAGEPATH -> 0x00001 + /// public const int SAFER_CRITERIA_IMAGEPATH = 1; + /// /// SAFER_CRITERIA_NOSIGNEDHASH -> 0x00002 + /// public const int SAFER_CRITERIA_NOSIGNEDHASH = 2; + /// /// SAFER_CRITERIA_IMAGEHASH -> 0x00004 + /// public const int SAFER_CRITERIA_IMAGEHASH = 4; + /// /// SAFER_CRITERIA_AUTHENTICODE -> 0x00008 + /// public const int SAFER_CRITERIA_AUTHENTICODE = 8; + /// /// SAFER_CRITERIA_URLZONE -> 0x00010 + /// public const int SAFER_CRITERIA_URLZONE = 16; + /// /// SAFER_CRITERIA_IMAGEPATH_NT -> 0x01000 + /// public const int SAFER_CRITERIA_IMAGEPATH_NT = 4096; + /// /// WTD_UI_NONE -> 0x00002 + /// public const int WTD_UI_NONE = 2; + /// /// S_OK -> ((HRESULT)0L) + /// public const int S_OK = 0; + /// /// S_FALSE -> ((HRESULT)1L) + /// public const int S_FALSE = 1; + /// /// ERROR_MORE_DATA -> 234L + /// public const int ERROR_MORE_DATA = 234; + /// /// ERROR_ACCESS_DISABLED_BY_POLICY -> 1260L + /// public const int ERROR_ACCESS_DISABLED_BY_POLICY = 1260; + /// /// ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY -> 786L + /// public const int ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY = 786; + /// /// SAFER_MAX_HASH_SIZE -> 64 + /// public const int SAFER_MAX_HASH_SIZE = 64; + /// /// SRP_POLICY_SCRIPT -> L"SCRIPT" + /// public const string SRP_POLICY_SCRIPT = "SCRIPT"; + /// /// SIGNATURE_DISPLAYNAME_LENGTH -> MAX_PATH + /// internal const int SIGNATURE_DISPLAYNAME_LENGTH = NativeConstants.MAX_PATH; + /// /// SIGNATURE_PUBLISHER_LENGTH -> 128 + /// internal const int SIGNATURE_PUBLISHER_LENGTH = 128; + /// /// SIGNATURE_HASH_LENGTH -> 64 + /// internal const int SIGNATURE_HASH_LENGTH = 64; + /// /// MAX_PATH -> 260 + /// internal const int MAX_PATH = 260; + + /// + /// This function is not supported on this system + /// + internal const int FUNCTION_NOT_SUPPORTED = 120; } /// diff --git a/src/powershell-native/Install-PowerShellRemoting.ps1 b/src/powershell-native/Install-PowerShellRemoting.ps1 index 6c3d01285f..c143127c00 100644 --- a/src/powershell-native/Install-PowerShellRemoting.ps1 +++ b/src/powershell-native/Install-PowerShellRemoting.ps1 @@ -124,7 +124,7 @@ function Install-PluginEndpoint { # # ###################### - if ($PsCmdlet.ParameterSetName -eq "ByPath") + if ($PowerShellHome -ne $null) { $targetPsHome = $PowerShellHome $targetPsVersion = & "$targetPsHome\pwsh" -NoProfile -Command '$PSVersionTable.PSVersion.ToString()' @@ -135,6 +135,7 @@ function Install-PluginEndpoint { $targetPsHome = $PSHOME $targetPsVersion = $PSVersionTable.PSVersion.ToString() } + Write-Verbose "PowerShellHome: $targetPsHome" -Verbose # For default, not tied to the specific version endpoint, we apply # only first number in the PSVersion string to the endpoint name. @@ -163,7 +164,16 @@ function Install-PluginEndpoint { return } - $pluginBasePath = Join-Path ([System.Environment]::GetFolderPath([System.Environment+SpecialFolder]::Windows) + "\System32\PowerShell") $targetPsVersion + if ($PSVersionTable.PSVersion -lt "6.0") + { + # This script is primarily used from Windows PowerShell for Win10 IoT and NanoServer to setup PSCore6 remoting endpoint + # so it's ok to hardcode to 'C:\Windows' for those systems + $pluginBasePath = Join-Path "C:\Windows\System32\PowerShell" $targetPsVersion + } + else + { + $pluginBasePath = Join-Path ([System.Environment]::GetFolderPath([System.Environment+SpecialFolder]::Windows) + "\System32\PowerShell") $targetPsVersion + } $resolvedPluginAbsolutePath = "" if (! (Test-Path $pluginBasePath))