From 488d179f09ed14494aa23d4d389ce904882639b4 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 14:49:07 +0900 Subject: [PATCH] Count the root in bounded WMI descriptor evidence --- scripts/WmiNamespaceDescendants.ps1 | 3 +++ tests/WmiNamespaceDescendants.Tests.ps1 | 2 ++ 2 files changed, 5 insertions(+) diff --git a/scripts/WmiNamespaceDescendants.ps1 b/scripts/WmiNamespaceDescendants.ps1 index 394807fe..bc8a7601 100644 --- a/scripts/WmiNamespaceDescendants.ps1 +++ b/scripts/WmiNamespaceDescendants.ps1 @@ -52,6 +52,9 @@ function Get-WelaWmiDescendants { try { if($Namespace -cnotmatch '^root(\\[A-Za-z_][A-Za-z0-9_]{0,63}){1,8}$'){throw 'An exact local WMI namespace is required.'} $root=Get-WelaWmiNamespaceSnapshot $Namespace + if($root.Namespace -cne $Namespace -or -not $root.DescriptorJson -or -not $root.DescriptorMof){throw 'Incomplete selected namespace descriptor.'} + $bytes=[Text.Encoding]::UTF8.GetByteCount($root.DescriptorJson+$root.DescriptorMof) + if($bytes -gt 2097152){throw 'WMI tree descriptor evidence exceeds two MiB.'} $queue.Enqueue([pscustomobject]@{Namespace=$Namespace;Depth=0;ProtectedBarrier=$false}) $null=$seen.Add($Namespace) while($queue.Count){ diff --git a/tests/WmiNamespaceDescendants.Tests.ps1 b/tests/WmiNamespaceDescendants.Tests.ps1 index e123c08d..532c7d3e 100644 --- a/tests/WmiNamespaceDescendants.Tests.ps1 +++ b/tests/WmiNamespaceDescendants.Tests.ps1 @@ -53,6 +53,8 @@ try{ Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'Depth overflow fails rather than truncates.' Reset;$script:tree['root\default\A'].Opaque='x'*2097153 Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'Serialized descriptor budget enforced.' + Reset;$script:tree['root\default'].Opaque='x'*2097153 + Assert ((Get-WelaWmiDescendants 'root\default').Status -eq 'Incomplete') 'The selected root also counts toward the descriptor budget.' Reset $p=@(Get-WelaWmiAuditPlan -Namespace 'root\default' -IncludeChildren) $c=New-WelaConfigurationContext -Auto -DryRun -BackupPath $temp