Count the root in bounded WMI descriptor evidence

This commit is contained in:
Shirofune-Security committed 2026-09-22 14:49:07 +09:00
1 parent e34ede7c38
commit 488d179f09
2 files changed
+5

No files matched your search

+3
View File
@@ -52,6 +52,9 @@ function Get-WelaWmiDescendants {
try {
if($Namespace -cnotmatch '^root(\\[A-Za-z_][A-Za-z0-9_]{0,63}){1,8}$'){throw 'An exact local WMI namespace is required.'}
$root=Get-WelaWmiNamespaceSnapshot $Namespace
if($root.Namespace -cne $Namespace -or -not $root.DescriptorJson -or -not $root.DescriptorMof){throw 'Incomplete selected namespace descriptor.'}
$bytes=[Text.Encoding]::UTF8.GetByteCount($root.DescriptorJson+$root.DescriptorMof)
if($bytes -gt 2097152){throw 'WMI tree descriptor evidence exceeds two MiB.'}
$queue.Enqueue([pscustomobject]@{Namespace=$Namespace;Depth=0;ProtectedBarrier=$false})
$null=$seen.Add($Namespace)
while($queue.Count){
+2
View File
@@ -53,6 +53,8 @@ try{
Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'Depth overflow fails rather than truncates.'
Reset;$script:tree['root\default\A'].Opaque='x'*2097153
Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'Serialized descriptor budget enforced.'
Reset;$script:tree['root\default'].Opaque='x'*2097153
Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'The selected root also counts toward the descriptor budget.'
Reset
$p=@(Get-WelaWmiAuditPlan -Namespace 'root\default' -IncludeChildren)
$c=New-WelaConfigurationContext -Auto -DryRun -BackupPath $temp