Skip to content

Commit c85b80d

Browse files
senamakelmedullabot
andcommitted
test: verify credential parser and independent cleanup
Co-authored-by: Medulla <medulla@tinyhumans.ai>
1 parent 6fdb6f6 commit c85b80d

1 file changed

Lines changed: 34 additions & 6 deletions

File tree

‎crates/tinysecurity-audit/src/sink_windows_negative_tests.rs‎

Lines changed: 34 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -309,6 +309,15 @@ try {
309309
$acl.SetSecurityDescriptorSddlForm(('O:' + $env:TINYSECURITY_TEST_OWNER + 'D:P(A;;FA;;;' + $env:TINYSECURITY_TEST_OWNER + ')(A;;FR;;;' + $env:TINYSECURITY_TEST_FOREIGN + ')'))
310310
Set-Acl -LiteralPath $marker -AclObject $acl
311311
$credential = [PSCredential]::new(($env:COMPUTERNAME + '\' + $account), $password)
312+
$stage = 27
313+
$network = $credential.GetNetworkCredential()
314+
$credentialSeparators = $credential.UserName.Split([char]92).Length - 1
315+
$domainSeparators = $network.Domain.Split([char]92).Length - 1
316+
$userSeparators = $network.UserName.Split([char]92).Length - 1
317+
$exactDomain = [int]($network.Domain -ceq $env:COMPUTERNAME)
318+
$exactUser = [int]($network.UserName -ceq $account)
319+
Write-Output ('audit-account-stage=27 credential-separators=' + $credentialSeparators + ' domain-separators=' + $domainSeparators + ' user-separators=' + $userSeparators + ' exact-domain=' + $exactDomain + ' exact-user=' + $exactUser)
320+
if (($credentialSeparators -ne 1) -or ($domainSeparators -ne 0) -or ($userSeparators -ne 0) -or ($exactDomain -ne 1) -or ($exactUser -ne 1)) { throw 'credential parser must preserve the exact local identity' }
312321
$childScript = @'
313322
$ErrorActionPreference = 'Stop'
314323
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
@@ -376,13 +385,32 @@ exit 0
376385
exit 1
377386
} finally {
378387
try {
379-
if ($null -ne $process) {
380-
try {
381-
if (-not $process.HasExited) { $process.Kill() }
382-
$process.WaitForExit()
383-
} finally { $process.Dispose() }
388+
$terminated = $null -eq $process
389+
try {
390+
if ($null -ne $process) {
391+
try {
392+
if (-not $process.HasExited) { $process.Kill() }
393+
$process.WaitForExit()
394+
$terminated = $true
395+
} finally {
396+
try {
397+
if (-not $terminated) {
398+
if (-not $process.HasExited) { $process.Kill(); $process.WaitForExit() }
399+
$terminated = $process.HasExited
400+
}
401+
} finally { $process.Dispose() }
402+
}
403+
}
404+
} finally {
405+
if ($created) {
406+
if ($terminated) { Remove-LocalUser -Name $account }
407+
else {
408+
Disable-LocalUser -Name $account
409+
Write-Output 'audit-account-stage=71 cleanup-incomplete=1'
410+
throw 'owned helper termination unconfirmed; disabled account needs cleanup'
411+
}
412+
}
384413
}
385-
if ($created) { Remove-LocalUser -Name $account }
386414
} catch {
387415
Write-Output ('audit-account-stage=70 hresult=' + $_.Exception.HResult)
388416
exit 1

0 commit comments

Comments
 (0)