@@ -309,6 +309,15 @@ try {
309309 $acl.SetSecurityDescriptorSddlForm(('O:' + $env:TINYSECURITY_TEST_OWNER + 'D:P(A;;FA;;;' + $env:TINYSECURITY_TEST_OWNER + ')(A;;FR;;;' + $env:TINYSECURITY_TEST_FOREIGN + ')'))
310310 Set-Acl -LiteralPath $marker -AclObject $acl
311311 $credential = [PSCredential]::new(($env:COMPUTERNAME + '\' + $account), $password)
312+ $stage = 27
313+ $network = $credential.GetNetworkCredential()
314+ $credentialSeparators = $credential.UserName.Split([char]92).Length - 1
315+ $domainSeparators = $network.Domain.Split([char]92).Length - 1
316+ $userSeparators = $network.UserName.Split([char]92).Length - 1
317+ $exactDomain = [int]($network.Domain -ceq $env:COMPUTERNAME)
318+ $exactUser = [int]($network.UserName -ceq $account)
319+ Write-Output ('audit-account-stage=27 credential-separators=' + $credentialSeparators + ' domain-separators=' + $domainSeparators + ' user-separators=' + $userSeparators + ' exact-domain=' + $exactDomain + ' exact-user=' + $exactUser)
320+ if (($credentialSeparators -ne 1) -or ($domainSeparators -ne 0) -or ($userSeparators -ne 0) -or ($exactDomain -ne 1) -or ($exactUser -ne 1)) { throw 'credential parser must preserve the exact local identity' }
312321 $childScript = @'
313322$ErrorActionPreference = 'Stop'
314323$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
@@ -376,13 +385,32 @@ exit 0
376385 exit 1
377386} finally {
378387 try {
379- if ($null -ne $process) {
380- try {
381- if (-not $process.HasExited) { $process.Kill() }
382- $process.WaitForExit()
383- } finally { $process.Dispose() }
388+ $terminated = $null -eq $process
389+ try {
390+ if ($null -ne $process) {
391+ try {
392+ if (-not $process.HasExited) { $process.Kill() }
393+ $process.WaitForExit()
394+ $terminated = $true
395+ } finally {
396+ try {
397+ if (-not $terminated) {
398+ if (-not $process.HasExited) { $process.Kill(); $process.WaitForExit() }
399+ $terminated = $process.HasExited
400+ }
401+ } finally { $process.Dispose() }
402+ }
403+ }
404+ } finally {
405+ if ($created) {
406+ if ($terminated) { Remove-LocalUser -Name $account }
407+ else {
408+ Disable-LocalUser -Name $account
409+ Write-Output 'audit-account-stage=71 cleanup-incomplete=1'
410+ throw 'owned helper termination unconfirmed; disabled account needs cleanup'
411+ }
412+ }
384413 }
385- if ($created) { Remove-LocalUser -Name $account }
386414 } catch {
387415 Write-Output ('audit-account-stage=70 hresult=' + $_.Exception.HResult)
388416 exit 1
0 commit comments