[release/v7.4.21] Fix FileOnlyEntry crashing on older versions of Windows - #28043
Open
Aditya Patwardhan (adityapatwardhan) wants to merge 2 commits into
Conversation
Aditya Patwardhan (adityapatwardhan)
requested a review
from a team
as a code owner
September 21, 2026 21:09
Aditya Patwardhan (adityapatwardhan)
requested review from
Patrick Meinecke (SeeminglyScience) and
Travis Plunk (TravisEz13)
as code owners
September 21, 2026 21:09
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Copilot started reviewing on behalf of
Aditya Patwardhan (adityapatwardhan)
September 21, 2026 21:09
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Valid positional script paths are incorrectly rejected when FileOnlyEntry is enabled.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Backports the WLDP FileOnlyEntry compatibility fix to prevent crashes on older Windows versions when the native entry point is unavailable.
Changes:
- Safely handles missing WLDP DLL entry points.
- Enforces file-only policy in console argument parsing.
- Adds Windows security helpers, resources, and tests.
| File | Description |
|---|---|
HelpersSecurity.psm1 |
Adds test policy toggles. |
FileOnlyEntry.Tests.ps1 |
Adds policy behavior tests. |
wldpNativeMethods.cs |
Adds safe WLDP setting access. |
CommandLineParameterParserStrings.resx |
Adds policy error messages. |
ConsoleHost.cs |
Blocks policy-incompatible server modes. |
CommandLineParameterParser.cs |
Applies file-only entry validation. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+1300
to
+1304
| if (_error is null | ||
| && !_showVersion | ||
| && !_showHelp | ||
| && !ParametersUsed.HasFlag(ParameterBitmap.File) | ||
| && IsFileOnlyEntryEnabled) |
3 of 9 tasks
Justin Chung (jshigetomi)
approved these changes
Sep 23, 2026
Contributor
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Backport of #27880 to release/v7.4.21
Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Patrick Meinecke (@SeeminglyScience)
Original CL Label: CL-Engine
/cc @PowerShell/powershell-maintainers
Impact
REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.
Tooling Impact
Customer Impact
Prevents PowerShell from crashing on older Windows versions when the EnableFileOnlyEntry WLDP support is present but the operating system does not expose the required native entry point. Expected behavior is to treat the unavailable setting as disabled.
Regression
REQUIRED: Check exactly one box.
Fixes the compatibility regression introduced by original PR #26752, which adds EnableFileOnlyEntry support and is the prerequisite backport.
Testing
Validated the stacked prerequisite and fix with git diff --check and a clean worktree. A focused ConsoleHost build was attempted and is blocked by unrelated pre-existing generated-resource errors for DotNetEventingStrings in Microsoft.PowerShell.CoreCLR.Eventing; backport CI will perform full validation.
Risk
REQUIRED: Check exactly one box.
High risk because this changes Windows WLDP interop behavior in the engine. The change is narrowly scoped to catching EntryPointNotFoundException on Windows versions that lack the newer WLDP entry point, and it is stacked on the required EnableFileOnlyEntry prerequisite.
Merge Conflicts
The initial cherry-pick conflicted because prerequisite PR #26752 is not yet merged into release/v7.4.21. The cherry-pick was aborted, the validated #26752 backport commit was applied first, and #27880 then cherry-picked cleanly. This PR is therefore stacked on backport PR #28041; after #28041 merges, only the #27880 fix remains in this PR's effective diff.