Skip to content

[release/v7.4.21] Add support for new WLDP setting EnableFileOnlyEntry - #28041

Open
Aditya Patwardhan (adityapatwardhan) wants to merge 2 commits into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/26752-2ca393d6b
Open

Aditya Patwardhan (adityapatwardhan) wants to merge 2 commits into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/26752-2ca393d6b

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #26752 to release/v7.4.21

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Patrick Meinecke (@SeeminglyScience)

Original CL Label: CL-Engine

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Customer Impact

  • Customer reported
  • Found internally

Adds support for the Windows WLDP EnableFileOnlyEntry policy so managed systems can require a script file and disallow unintended interactive or ad-hoc PowerShell entry. Without the change, release/v7.4 does not honor this policy setting.

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

Cherry-pick validated with git diff --check. Added PowerShell tests and HelpersSecurity module both parse successfully with no conflict markers. A focused ConsoleHost dotnet build was attempted after restore; it is blocked by pre-existing generated-resource errors for DotNetEventingStrings in Microsoft.PowerShell.CoreCLR.Eventing, unrelated to this change. Full validation is delegated to backport CI.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk because this changes ConsoleHost startup and Windows WLDP policy enforcement. The implementation and tests are carried from the merged original PR, the sole conflict was a control-flow/formatting divergence, and the resolution preserved release-branch structure while retaining the intended successful return.

Merge Conflicts

src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHost.cs conflicted because release/v7.4.21 retained older V2 socket-server formatting/control flow while the original PR used the refactored early-return form. Resolved by keeping the release context and using return ExitCodeSuccess after HyperVSocketMediator.Run, matching the surrounding release-branch server-mode paths and preserving the backport intent.

Copilot AI lite review requested due to automatic review settings September 21, 2026 21:08
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-Engine Indicates that a PR should be marked as an engine change in the Change Log label Sep 21, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

This comment was marked as outdated.

Comment thread src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHost.cs Outdated
@microsoft-github-policy-service microsoft-github-policy-service Bot added the Review - Needed The PR is being reviewed label Oct 1, 2026
@microsoft-github-policy-service

Copy link
Copy Markdown
Contributor

This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days.
Maintainer, please provide feedback and/or mark it as Waiting on Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-Engine Indicates that a PR should be marked as an engine change in the Change Log Review - Needed The PR is being reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants