mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
Verify actual current-token access to built-in event channels (#432)
* Add actual current-token native channel read evidence * Use supported workflow shells and link channel-read changelogs * Handle real event exceptions and bind loaded token helper to source * Capture query-token interval after evidence and metadata preparation * Retain native child process exit evidence across PowerShell engines * Bound native reader fixture pipe draining and child termination * Preserve native errors from attributed channel query statuses
This commit is contained in:
1 parent
c6da22a2ad
commit
fd7a7924aa
13 files changed
+456
-2
No files matched your search
@@ -0,0 +1,47 @@
|
||||
name: Native current-token channel reads
|
||||
on:
|
||||
push:
|
||||
paths: ['WELA.ps1', 'scripts/ChannelRead*', 'scripts/WefArrival.ps1', 'modules/NativeProviders.psm1', 'config/native_channel_profile.json', 'tests/ChannelRead*', '.github/workflows/channel-read.yml']
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
actual-reader:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [windows-2022, windows-2025]
|
||||
engine: [powershell, pwsh]
|
||||
runs-on: ${{ matrix.os }}
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
|
||||
- name: Safe refusal and drift fixtures (powershell)
|
||||
if: matrix.engine == 'powershell'
|
||||
shell: powershell
|
||||
run: ./tests/ChannelRead.Tests.ps1
|
||||
- name: Disposable owned account and CAPI2 ACE proof (powershell)
|
||||
if: matrix.engine == 'powershell'
|
||||
shell: powershell
|
||||
run: ./tests/ChannelRead.Windows.Tests.ps1 -AllowDisposableAccount -TestEngine powershell
|
||||
- name: Safe refusal and drift fixtures (pwsh)
|
||||
if: matrix.engine == 'pwsh'
|
||||
shell: pwsh
|
||||
run: ./tests/ChannelRead.Tests.ps1
|
||||
- name: Disposable owned account and CAPI2 ACE proof (pwsh)
|
||||
if: matrix.engine == 'pwsh'
|
||||
shell: pwsh
|
||||
run: ./tests/ChannelRead.Windows.Tests.ps1 -AllowDisposableAccount -TestEngine pwsh
|
||||
- name: Retain native metadata and cleanup evidence
|
||||
if: always()
|
||||
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
|
||||
with:
|
||||
name: channel-reader-${{ matrix.os }}-${{ matrix.engine }}
|
||||
path: |
|
||||
${{ runner.temp }}/wela-channel-reader-*/acceptance.json
|
||||
${{ runner.temp }}/wela-channel-reader-*/channel-before.json
|
||||
${{ runner.temp }}/wela-channel-reader-*/reader/
|
||||
${{ runner.temp }}/wela-channel-reader-*/admin/
|
||||
if-no-files-found: warn
|
||||
retention-days: 7
|
||||
Reference in new issue
Block a user