feat: checkpoint reviewed native registry SACL recovery

This commit is contained in:
Shirofune-Security committed 2026-09-22 10:11:02 +09:00
1 parent 03039cb1c6
commit 530b49f26b
7 files changed
+592

No files matched your search

@@ -0,0 +1,43 @@
name: Native reviewed registry SACL recovery
on:
push:
branches: ['**']
paths:
- 'tests/RegistrySacl*'
- 'scripts/RegistrySaclRecovery*'
- 'scripts/SelectedSacl*'
- 'scripts/TargetedSaclPlanning.ps1'
- 'WELA.ps1'
- '.github/workflows/registry-sacl-recovery.yml'
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
registry-sacl-recovery:
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
engine: [powershell, pwsh]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- name: Actual public registry lifecycle in Windows PowerShell 5.1
if: matrix.engine == 'powershell'
shell: powershell
run: |
./tests/RegistrySaclRecovery.Windows.Tests.ps1 -AllowDisposableHiveWrite
- name: Actual public registry lifecycle in PowerShell 7
if: matrix.engine == 'pwsh'
shell: pwsh
run: |
./tests/RegistrySaclRecovery.Windows.Tests.ps1 -AllowDisposableHiveWrite
- name: Retain public receipts, actual XML and exact cleanup
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: registry-sacl-recovery-${{ matrix.os }}-${{ matrix.engine }}
path: ${{ runner.temp }}/wela-registry-recovery-*/
if-no-files-found: error