Guard WMI inheritance with bounded descendant observations

This commit is contained in:
Shirofune-Security committed 2026-09-22 14:33:54 +09:00
1 parent 7ef29df61f
commit ea184e5e95
6 files changed
+313 -5

No files matched your search

+39
View File
@@ -0,0 +1,39 @@
name: Native WMI descendant safeguards
on:
push:
branches: ['**']
paths:
- 'scripts/WmiNamespaceAuditing.ps1'
- 'scripts/WmiNamespaceDescendants.ps1'
- 'tests/WmiNamespaceDescendants*'
- '.github/workflows/wmi-descendants.yml'
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
wmi-descendants:
timeout-minutes: 25
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
shell: [powershell, pwsh]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Existing WMI regression contracts
shell: ${{ matrix.shell }}
run: ./tests/WmiNamespaceAuditing.Tests.ps1
- name: Actual owned namespace tree and cleanup
shell: ${{ matrix.shell }}
run: ./tests/WmiNamespaceDescendants.Windows.Tests.ps1 -AllowDisposableNamespaceWrite -EvidencePath wmi-descendants-native.json
- name: Retain complete native observations
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: wmi-descendants-${{ matrix.os }}-${{ matrix.shell }}
path: |
wmi-descendants-native.json
wmi-descendants-native.json.journals
if-no-files-found: error