mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Merged PR 38690: Update MaxVisitCount and MaxHashtableKeyCount if visitor safe value context indicates SkipLimitCheck is true ---- #### AI description (iteration 1) #### PR Classification Bug fix that updates the safe value checks by dynamically adjusting limit values based on the visitor context to improve security. #### PR Summary This pull request refactors the safe value visitor logic to replace hard-coded limit constants with context-driven readonly fields and adjusts the conditional checks accordingly. It also adds a test to verify that insecure psd1 files correctly fail when the -SkipLimitCheck parameter is used. - `src/System.Management.Automation/engine/parser/SafeValues.cs`: Replaces constant limits with dynamic fields (_maxVisitCount and _maxHashtableKeyCount) set based on the safe value context, and updates conditional checks to use these fields. - `test/powershell/Modules/Microsoft.PowerShell.Utility/PowerShellData.tests.ps1`: Adds a test case to ensure that insecure psd1 files trigger an error when -SkipLimitCheck is applied. <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot --> Related work items: #163511
59 lines
2.8 KiB
PowerShell
59 lines
2.8 KiB
PowerShell
# Copyright (c) Microsoft Corporation.
|
|
# Licensed under the MIT License.
|
|
Describe "Tests for the Import-PowerShellDataFile cmdlet" -Tags "CI" {
|
|
BeforeAll {
|
|
$largePsd1Path = Join-Path -Path $TestDrive -ChildPath 'large.psd1'
|
|
$largePsd1Builder = [System.Text.StringBuilder]::new('@{')
|
|
1..501 | ForEach-Object {
|
|
$largePsd1Builder.Append("key$_ = $_;")
|
|
}
|
|
$largePsd1Builder.Append('}')
|
|
Set-Content -Path $largePsd1Path -Value $largePsd1Builder.ToString()
|
|
}
|
|
|
|
It "Validates error on a missing path" {
|
|
{ Import-PowerShellDataFile -Path /SomeMissingDirectory -ErrorAction Stop } |
|
|
Should -Throw -ErrorId "PathNotFound,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
|
}
|
|
|
|
It "Validates error on a directory" {
|
|
{ Import-PowerShellDataFile ${TESTDRIVE} -ErrorAction Stop } |
|
|
Should -Throw -ErrorId "PathNotFound,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
|
|
|
}
|
|
|
|
It "Generates a good error on an insecure file" {
|
|
|
|
$path = Setup -f insecure.psd1 -Content '@{ Foo = Get-Process }' -pass
|
|
{ Import-PowerShellDataFile $path -ErrorAction Stop } |
|
|
Should -Throw -ErrorId "System.InvalidOperationException,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
|
}
|
|
|
|
It "Generates a good error on a file that isn't a PowerShell Data File (missing the hashtable root)" {
|
|
$path = Setup -f NotAPSDataFile -Content '"Hello World"' -Pass
|
|
{ Import-PowerShellDataFile $path -ErrorAction Stop } |
|
|
Should -Throw -ErrorId "CouldNotParseAsPowerShellDataFileNoHashtableRoot,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
|
}
|
|
|
|
It "Can parse a PowerShell Data File (detailed tests are in AST.SafeGetValue tests)" {
|
|
$path = Setup -F gooddatafile -Content '@{ "Hello" = "World" }' -pass
|
|
$result = Import-PowerShellDataFile $path -ErrorAction Stop
|
|
$result.Hello | Should -BeExactly "World"
|
|
}
|
|
|
|
It 'Fails if psd1 file has more than 500 keys' {
|
|
{ Import-PowerShellDataFile $largePsd1Path } | Should -Throw -ErrorId 'System.InvalidOperationException,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand'
|
|
}
|
|
|
|
It 'Succeeds if -NoLimit is used and has more than 500 keys' {
|
|
$result = Import-PowerShellDataFile $largePsd1Path -SkipLimitCheck
|
|
$result.Keys.Count | Should -Be 501
|
|
}
|
|
|
|
It 'Fails if psd1 file is insecure while -SkipLimitCheck is used' {
|
|
$path = Setup -f insecure2.psd1 -Content '@{ Foo = [object] (calc.exe) }' -pass
|
|
{ Import-PowerShellDataFile $path -SkipLimitCheck -ErrorAction Stop } |
|
|
Should -Throw -ErrorId "System.InvalidOperationException,Microsoft.PowerShell.Commands.ImportPowerShellDataFileCommand"
|
|
}
|
|
}
|