From 38bceb3de158a46483537326e0cdf17d8f5209b7 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Sat, 19 Sep 2026 05:42:06 +0900 Subject: [PATCH] Construct unknown ACE fixture without PowerShell enum validation --- tests/NativeChannelAccess.Windows.Tests.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/NativeChannelAccess.Windows.Tests.ps1 b/tests/NativeChannelAccess.Windows.Tests.ps1 index 9ad1d6ca..d669b60b 100644 --- a/tests/NativeChannelAccess.Windows.Tests.ps1 +++ b/tests/NativeChannelAccess.Windows.Tests.ps1 @@ -53,7 +53,7 @@ foreach ($sddl in @('', 'invalid', 'O:BAG:SY', 'O:BAG:SYD:NO_ACCESS_CONTROL', 'O # The original unknown ACE bytes must never be discarded. SDDL has no representation # for arbitrary custom ACEs; parsing/planning must refuse instead of replacing them. $raw = [System.Security.AccessControl.RawSecurityDescriptor]::new('O:BAG:SYD:(A;;0x7;;;BA)') -$raw.DiscretionaryAcl.InsertAce(1, [System.Security.AccessControl.CustomAce]::new([System.Security.AccessControl.AceType]127, [System.Security.AccessControl.AceFlags]::None, [byte[]]@(0, 0, 0, 0))) +$raw.DiscretionaryAcl.InsertAce(1, [System.Security.AccessControl.CustomAce]::new(([Enum]::ToObject([System.Security.AccessControl.AceType], 127)), [System.Security.AccessControl.AceFlags]::None, [byte[]]@(0, 0, 0, 0))) $binaryBefore = Binary $raw $refused = $false try {