From 79ee4da4ddd2c10ed9d0034298be903e6d613cfa Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 08:07:36 +0900 Subject: [PATCH] Read registry descriptor from the owned native handle across both engines --- tests/SecurityWarningConfigure.Windows.Tests.ps1 | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/tests/SecurityWarningConfigure.Windows.Tests.ps1 b/tests/SecurityWarningConfigure.Windows.Tests.ps1 index d1d88d56..ef787167 100644 --- a/tests/SecurityWarningConfigure.Windows.Tests.ps1 +++ b/tests/SecurityWarningConfigure.Windows.Tests.ps1 @@ -16,7 +16,7 @@ function Key($Value){ConvertTo-Json -InputObject $Value -Depth 25 -Compress} function Masks($Value){@($Value.Keys|Sort-Object|ForEach-Object{"$_=$($Value[$_])"}) -join ';'} function Warning {Get-WelaRegistryState $path $name} function Unselected { - # Own these .NET handles; disposing a provider-cached Get-Item key breaks later WinPS5.1 reads. + # Own the native registry view and read its descriptor without Get-Acl LiteralPath provider conversion. $baseKey=[Microsoft.Win32.RegistryKey]::OpenBaseKey([Microsoft.Win32.RegistryHive]::LocalMachine,[Microsoft.Win32.RegistryView]::Registry64) $key=$null try{ @@ -26,8 +26,10 @@ function Unselected { if($n -ine $name){[pscustomobject][ordered]@{Name=$n;Type=[string]$key.GetValueKind($n);Value=$key.GetValue($n,$null,[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames)}} }) $subkeys=@($key.GetSubKeyNames()|Sort-Object) + $security=if($PSVersionTable.PSVersion.Major -ge 6){[Microsoft.Win32.RegistryAclExtensions]::GetAccessControl($key)}else{$key.GetAccessControl()} + $acl=$security.GetSecurityDescriptorSddlForm([Security.AccessControl.AccessControlSections]::Access -bor [Security.AccessControl.AccessControlSections]::Owner -bor [Security.AccessControl.AccessControlSections]::Group) }finally{if($key){$key.Dispose()};$baseKey.Dispose()} - [pscustomobject][ordered]@{OtherSecurityValues=$values;SecuritySubkeys=$subkeys;SecurityAcl=(Get-Acl -LiteralPath $path).Sddl;SecurityChannel=Get-WelaNativeChannel Security;ApplicationChannel=Get-WelaNativeChannel Application;OneSettings=Get-WelaRegistryState 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection' EnableOneSettingsAuditing;CrashOnAuditFail=Get-WelaRegistryState 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' CrashOnAuditFail;EventLogService=[string](Get-Service EventLog).Status} + [pscustomobject][ordered]@{OtherSecurityValues=$values;SecuritySubkeys=$subkeys;SecurityAcl=$acl;SecurityChannel=Get-WelaNativeChannel Security;ApplicationChannel=Get-WelaNativeChannel Application;OneSettings=Get-WelaRegistryState 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection' EnableOneSettingsAuditing;CrashOnAuditFail=Get-WelaRegistryState 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' CrashOnAuditFail;EventLogService=[string](Get-Service EventLog).Status} } function Public([string]$Label,[string[]]$Arguments,[int]$Expected=0){ $prior=$ErrorActionPreference