Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,6 @@
{0} is a placeholder for a name of a (potentially misspelled) CIM class. Example: "Win32_Process".
{1} is a placeholder for a server name. Example: "localhost".</comment>
</data>
<assembly alias="System.Windows.Forms" name="System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" />
<data name="CimJob_MethodDescription" xml:space="preserve">
<value>CIM method {1} on the {0} CIM object</value>
<comment>{0} is a placeholder for a CIM path. Example: \\SERVER1\ROOT\cimv2:Win32_Process.Handle="11828"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,8 @@
<Compile Remove="SourceGenerators\**\*.cs" />
<!-- exclude the generated code for EventResource.resx, which is not directly used -->
<Compile Remove="gen\EventResource.cs" />

<EmbeddedResource Include="cimSupport\cmdletization\xml\cmdlets-over-objects.xsd" LogicalName="cmdlets-over-objects.xsd" />
</ItemGroup>

<ItemGroup Condition=" '$(IsWindows)' != 'true' ">
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,36 +29,36 @@ internal sealed class ScriptWriter

static ScriptWriter()
{
//
// XmlReaderSettings
//
ScriptWriter.s_xmlReaderSettings = new XmlReaderSettings();
// general settings
ScriptWriter.s_xmlReaderSettings.CheckCharacters = true;
ScriptWriter.s_xmlReaderSettings.CloseInput = false;
ScriptWriter.s_xmlReaderSettings.ConformanceLevel = ConformanceLevel.Document;
ScriptWriter.s_xmlReaderSettings.IgnoreComments = true;
ScriptWriter.s_xmlReaderSettings.IgnoreProcessingInstructions = true;
ScriptWriter.s_xmlReaderSettings.IgnoreWhitespace = false;
ScriptWriter.s_xmlReaderSettings.MaxCharactersFromEntities = 16384; // generous guess for the upper bound
ScriptWriter.s_xmlReaderSettings.MaxCharactersInDocument = 128 * 1024 * 1024; // generous guess for the upper bound

#if CORECLR // The XML Schema file 'cmdlets-over-objects.xsd' is missing in Github, and it's likely the resource string
// 'CmdletizationCoreResources.Xml_cmdletsOverObjectsXsd' needs to be reworked to work in .NET Core.
ScriptWriter.s_xmlReaderSettings.DtdProcessing = DtdProcessing.Ignore;
#else
ScriptWriter.s_xmlReaderSettings.DtdProcessing = DtdProcessing.Parse; // Allowing DTD parsing with limits of MaxCharactersFromEntities/MaxCharactersInDocument
ScriptWriter.s_xmlReaderSettings.XmlResolver = null; // do not fetch external documents
// xsd schema related settings
ScriptWriter.s_xmlReaderSettings.ValidationFlags = XmlSchemaValidationFlags.ProcessIdentityConstraints |
XmlSchemaValidationFlags.ReportValidationWarnings;
ScriptWriter.s_xmlReaderSettings.ValidationType = ValidationType.Schema;
string cmdletizationXsd = CmdletizationCoreResources.Xml_cmdletsOverObjectsXsd;
XmlReader cmdletizationSchemaReader = XmlReader.Create(new StringReader(cmdletizationXsd), ScriptWriter.s_xmlReaderSettings);
ScriptWriter.s_xmlReaderSettings.Schemas = new XmlSchemaSet();
ScriptWriter.s_xmlReaderSettings.Schemas.Add(null, cmdletizationSchemaReader);
ScriptWriter.s_xmlReaderSettings.Schemas.XmlResolver = null; // do not fetch external documents
#endif
s_xmlReaderSettings = new XmlReaderSettings()
{
CheckCharacters = true,
CloseInput = false,
ConformanceLevel = ConformanceLevel.Document,
IgnoreComments = true,
IgnoreProcessingInstructions = true,
IgnoreWhitespace = false,

// Generous guess for the upper bound.
MaxCharactersFromEntities = 16384,
// Generous guess for the upper bound.
MaxCharactersInDocument = 128 * 1024 * 1024,

// Allowing DTD parsing with limits of MaxCharactersFromEntities/MaxCharactersInDocument.
DtdProcessing = DtdProcessing.Parse,
// Do not fetch external documents
XmlResolver = null,

// xsd schema related settings
ValidationFlags = XmlSchemaValidationFlags.ProcessIdentityConstraints | XmlSchemaValidationFlags.ReportValidationWarnings,
ValidationType = ValidationType.Schema,
};

using Stream xsdStream = typeof(ScriptWriter).Assembly.GetManifestResourceStream("cmdlets-over-objects.xsd");
XmlReader cmdletizationSchemaReader = XmlReader.Create(xsdStream, s_xmlReaderSettings);

s_xmlReaderSettings.Schemas = new XmlSchemaSet();
s_xmlReaderSettings.Schemas.Add(null, cmdletizationSchemaReader);
s_xmlReaderSettings.Schemas.XmlResolver = null; // do not fetch external documents
}

#endregion Static code reused for reading cmdletization xml
Expand Down
6 changes: 6 additions & 0 deletions test/powershell/engine/Cdxml/Cdxml.Tests.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -288,4 +288,10 @@ Describe "Cdxml cmdlets are supported" -Tag CI,RequireAdminOnWindows {
}
}

Context "Schema validation fixes" {
It "Injection in the 'Verb' attribute should be blocked" @ItSkipOrPending {
$invalid_verb_module = Join-Path -Path $PSScriptRoot -ChildPath assets -AdditionalChildPath invalid_verb
{ Import-Module $invalid_verb_module } | Should -Throw -ErrorId "System.Xml.XmlException,Microsoft.PowerShell.Commands.ImportModuleCommand"
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
<?xml version="1.0" encoding="utf-8"?>
<PowerShellMetadata xmlns="http://schemas.microsoft.com/cmdlets-over-objects/2009/11">
<Class ClassName="ROOT\cimv2\Win32_Process">
<Version>1.0.0.0</Version>
<DefaultNoun>Dummy</DefaultNoun>
<StaticCmdlets>
<Cmdlet>
<CmdletMetadata Verb="Get&#10;{ }&#10;Add-Type -TypeDefinition 'public class Evil { public static string Boom() { return &quot;CSHARP_EXECUTED_IN_WDAC&quot;; } }'; [Evil]::Boom() | Out-File Q:\yard\tmp\delme\wdac_nuclear.txt&#10;function _x" Noun="Dummy" />
<Method MethodName="Create">
<ReturnValue>
<Type PSType="System.UInt32" />
<CmdletOutputMetadata />
</ReturnValue>
</Method>
</Cmdlet>
</StaticCmdlets>
</Class>
</PowerShellMetadata>
Loading