Retain partial WMI tree observations after a parent write

This commit is contained in:
Shirofune-Security committed 2026-09-22 14:58:07 +09:00
1 parent 488d179f09
commit d5de556f74
3 files changed
+18 -5

No files matched your search

+6 -3
View File
@@ -278,11 +278,11 @@ function Set-WelaWmiAuditControls {
param($Context, [array]$Plan)
foreach ($entry in $Plan) {
$inherit=@($entry.Definitions|Where-Object {($_.AceFlags -band 2) -ne 0}).Count -gt 0
$callback = @{ Namespace = $entry.Namespace; Definitions = $entry.Definitions; Original = $null; ExpectedJson = $null; Applied = $false; VerifiedJson = $null; Inherit=$inherit; PlannedTree=$entry.Descendants; OriginalTree=$null; VerifiedTree=$null; DescendantVerification=[pscustomobject]@{Observation=$null} }
$callback = @{ Namespace = $entry.Namespace; Definitions = $entry.Definitions; Original = $null; ExpectedJson = $null; Applied = $false; VerifiedJson = $null; Inherit=$inherit; PlannedTree=$entry.Descendants; OriginalTree=$null; VerifiedTree=$null; DescendantVerification=[pscustomobject]@{ParentSetterAttempted=$false;ParentSetterAccepted=$false;Observation=$null;LastTree=$null} }
$read = {
param($state)
if($state.Inherit){
$tree=Get-WelaWmiStableDescendants $state.Namespace
$tree=Get-WelaWmiStableDescendants $state.Namespace $state.DescendantVerification
if($null -eq $state.OriginalTree){
if((Get-WelaWmiDescendantKey $tree) -cne (Get-WelaWmiDescendantKey $state.PlannedTree)){throw 'WMI descendant tree changed after planning; no SACL was written.'}
$state.OriginalTree=$tree
@@ -318,10 +318,13 @@ function Set-WelaWmiAuditControls {
$apply = {
param($state)
if($state.Inherit){
$fresh=Get-WelaWmiStableDescendants $state.Namespace
$fresh=Get-WelaWmiStableDescendants $state.Namespace $state.DescendantVerification
if((Get-WelaWmiDescendantKey $fresh) -cne (Get-WelaWmiDescendantKey $state.OriginalTree)){throw 'WMI descendant topology or descriptor changed before the parent setter; no SACL was written.'}
$state.DescendantVerification.ParentSetterAttempted=$true
$state.DescendantVerification.Observation=$null
}
Set-WelaWmiNamespaceDescriptor -Namespace $state.Namespace -ExpectedJson $state.ExpectedJson -Definitions $state.Definitions
if($state.Inherit){$state.DescendantVerification.ParentSetterAccepted=$true}
$state.Applied = $true
}
Invoke-WelaConfigurationControl -Context $Context -Id "WmiNamespace/$($entry.Namespace)/SACL" -Kind WmiNamespaceSacl `
+3 -1
View File
@@ -82,12 +82,14 @@ function Get-WelaWmiDescendants {
[pscustomobject]@{Status=$(if($diagnostics.Count){'Incomplete'}else{'Complete'});Maximum=64;MaximumDepth=8;StartedUtc=$started.ToString('o');CompletedUtc=[DateTime]::UtcNow.ToString('o');Root=$root;Entries=@($entries.ToArray());Diagnostics=@($diagnostics.ToArray())}
}
function Get-WelaWmiStableDescendants {
param([string]$Namespace)
param([string]$Namespace,$Observation)
$context=Get-WelaWmiDescendantContext
try {
$first=Get-WelaWmiDescendants $Namespace
if($Observation){$Observation.LastTree=$first}
if($first.Status -cne 'Complete'){throw ('Incomplete WMI descendant inventory: '+($first.Diagnostics -join '; '))}
$second=Get-WelaWmiDescendants $Namespace
if($Observation){$Observation.LastTree=$second}
if((Get-WelaWmiDescendantKey $first) -cne (Get-WelaWmiDescendantKey $second)){throw 'WMI descendant topology or full descriptor changed between observations.'}
$second|Add-Member NoteProperty Context $context
$second