Skip to content

Improve processor integrity validation - #6556

Merged
JohnMcPMS merged 8 commits into
microsoft:masterfrom
JohnMcPMS:config-int
Oct 1, 2026
Merged

JohnMcPMS merged 8 commits into
microsoft:masterfrom
JohnMcPMS:config-int

Conversation

@JohnMcPMS

@JohnMcPMS JohnMcPMS commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

📖 Description

Improves the processor integrity checks by pinning the target files to prevent modification.

🔍 Validation

Added tests, regression tests, manual validation of basic flow.

Microsoft Reviewers: Open in CodeFlow

@JohnMcPMS
JohnMcPMS requested a review from a team as a code owner September 22, 2026 21:06
@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

@ranm-msft ranm-msft left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The pinning design reads well - holding the ancestor directory handles to stop a component swap is a nice touch. One gap on the re-entry path below.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-sensitive Windows reparse-point and handle-sharing behavior warrants final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Strengthens DSC processor integrity by pinning verified files and ancestor directories against replacement.

Changes:

  • Adds handle-based file, link-target, and directory pinning.
  • Launches processors through normalized verified paths.
  • Adds tests, HRESULT mapping, documentation, and localization.
File Description
DSCv3ProcessorPathIntegrityUnitTests.cs Tests pinning and path resolution.
Errors.cs Adds test HRESULT.
ErrorCodes.cs Adds processor-path error code.
DscProcessorPathChangedException.cs Defines the new exception.
ProcessorSettings.cs Manages shared path bindings.
ProcessorPathIntegrity.cs Implements handle-based verification.
ProcessorPathBinding.cs Pins files and ancestor directories.
PinnedProcessorFile.cs Owns pinned file handles.
AppInstallerErrors.h Exposes the HRESULT.
Errors.cpp Maps the HRESULT message.
winget.resw Adds localized error text.
returnCodes.md Documents the return code.
allow.txt Allows new terminology.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

This comment was marked as outdated.

Comment thread src/Microsoft.Management.Configuration.UnitTests/Helpers/TestSkip.cs Outdated
Comment thread src/Microsoft.Management.Configuration.UnitTests/Helpers/TestSkip.cs Outdated
Comment on lines +116 to +147
public static void CreateSymbolicLinkOrSkip(string path, string target)
{
IfCannotCreateSymbolicLinks();

try
{
File.CreateSymbolicLink(path, target);
}
catch (Exception e) when (IsSymbolicLinkPermissionError(e))
{
throw new SkipException($"Unable to create the symbolic link '{path}': {e.Message}");
}
}

/// <summary>
/// Creates a symbolic link to a directory, skipping the test if symbolic links cannot be created.
/// </summary>
/// <param name="path">The link to create.</param>
/// <param name="target">The target of the link.</param>
public static void CreateDirectorySymbolicLinkOrSkip(string path, string target)
{
IfCannotCreateSymbolicLinks();

try
{
Directory.CreateSymbolicLink(path, target);
}
catch (Exception e) when (IsSymbolicLinkPermissionError(e))
{
throw new SkipException($"Unable to create the symbolic link '{path}': {e.Message}");
}
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These feel weird to have here

@JohnMcPMS
JohnMcPMS merged commit df1118d into microsoft:master Oct 1, 2026
10 of 11 checks passed
@JohnMcPMS
JohnMcPMS deleted the config-int branch October 1, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants