Improve processor integrity validation - #6556
Merged
Merged
Conversation
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
ranm-msft
reviewed
Sep 24, 2026
ranm-msft
left a comment
Contributor
There was a problem hiding this comment.
The pinning design reads well - holding the ancestor directory handles to stop a component swap is a nice touch. One gap on the re-entry path below.
Flor Chacón (florelis)
previously approved these changes
Sep 30, 2026
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Security-sensitive Windows reparse-point and handle-sharing behavior warrants final human validation.
Review effort: Balanced
Findings: None
What changed in this PR
Strengthens DSC processor integrity by pinning verified files and ancestor directories against replacement.
Changes:
- Adds handle-based file, link-target, and directory pinning.
- Launches processors through normalized verified paths.
- Adds tests, HRESULT mapping, documentation, and localization.
| File | Description |
|---|---|
DSCv3ProcessorPathIntegrityUnitTests.cs |
Tests pinning and path resolution. |
Errors.cs |
Adds test HRESULT. |
ErrorCodes.cs |
Adds processor-path error code. |
DscProcessorPathChangedException.cs |
Defines the new exception. |
ProcessorSettings.cs |
Manages shared path bindings. |
ProcessorPathIntegrity.cs |
Implements handle-based verification. |
ProcessorPathBinding.cs |
Pins files and ancestor directories. |
PinnedProcessorFile.cs |
Owns pinned file handles. |
AppInstallerErrors.h |
Exposes the HRESULT. |
Errors.cpp |
Maps the HRESULT message. |
winget.resw |
Adds localized error text. |
returnCodes.md |
Documents the return code. |
allow.txt |
Allows new terminology. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This comment was marked as outdated.
This comment was marked as outdated.
Flor Chacón (florelis)
previously approved these changes
Sep 30, 2026
Comment on lines
+116
to
+147
| public static void CreateSymbolicLinkOrSkip(string path, string target) | ||
| { | ||
| IfCannotCreateSymbolicLinks(); | ||
|
|
||
| try | ||
| { | ||
| File.CreateSymbolicLink(path, target); | ||
| } | ||
| catch (Exception e) when (IsSymbolicLinkPermissionError(e)) | ||
| { | ||
| throw new SkipException($"Unable to create the symbolic link '{path}': {e.Message}"); | ||
| } | ||
| } | ||
|
|
||
| /// <summary> | ||
| /// Creates a symbolic link to a directory, skipping the test if symbolic links cannot be created. | ||
| /// </summary> | ||
| /// <param name="path">The link to create.</param> | ||
| /// <param name="target">The target of the link.</param> | ||
| public static void CreateDirectorySymbolicLinkOrSkip(string path, string target) | ||
| { | ||
| IfCannotCreateSymbolicLinks(); | ||
|
|
||
| try | ||
| { | ||
| Directory.CreateSymbolicLink(path, target); | ||
| } | ||
| catch (Exception e) when (IsSymbolicLinkPermissionError(e)) | ||
| { | ||
| throw new SkipException($"Unable to create the symbolic link '{path}': {e.Message}"); | ||
| } | ||
| } |
There was a problem hiding this comment.
These feel weird to have here
Flor Chacón (florelis)
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📖 Description
Improves the processor integrity checks by pinning the target files to prevent modification.
🔍 Validation
Added tests, regression tests, manual validation of basic flow.
Microsoft Reviewers: Open in CodeFlow