MegaBites-AI/Windows-powershell
0308
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3 4Import-Module HelpersCommon5 6#7# These are general tests that verify non-Windows behavior8#9Describe "ExecutionPolicy" -Tags "CI" {10 11 Context "Check Get-ExecutionPolicy behavior" {12 It "Should unrestricted when not on Windows" -Skip:$IsWindows {13 Get-ExecutionPolicy | Should -Be Unrestricted14 }15 16 It "Should return Microsoft.Powershell.ExecutionPolicy PSObject on Windows" -Skip:($IsLinux -Or $IsMacOS) {17 Get-ExecutionPolicy | Should -BeOfType Microsoft.Powershell.ExecutionPolicy18 }19 }20 21 Context "Check Set-ExecutionPolicy behavior" {22 It "Should throw PlatformNotSupported when not on Windows" -Skip:$IsWindows {23 { Set-ExecutionPolicy Unrestricted } | Should -Throw "Operation is not supported on this platform."24 }25 26 It "Should succeed on Windows" -Skip:($IsLinux -Or $IsMacOS) {27 # We use the Process scope to avoid affecting the system28 # Unrestricted is assumed "safe", otherwise these tests would not be running29 { Set-ExecutionPolicy -Force -Scope Process -ExecutionPolicy Unrestricted } | Should -Not -Throw30 }31 }32}33 34#35# Ported from MultiMachine Tests36# Tests\Engine\HelpSystem\Pester.Engine.HelpSystem.BugFix.Tests.ps137# Tests\Commands\Cmdlets\Microsoft.PowerShell.Security\Pester.Command.Cmdlets.Security.Tests.ps138#39# These tests verify behavior of the ExecutionPolicy cmdlets on supported40# systems. Right now, ExecutionPolicy is only supported on Windows, so these41# tests only run if ($IsWindows -eq $true)42#43 44try {45 46 #skip all tests on non-windows platform47 $originalDefaultParameterValues = $PSDefaultParameterValues.Clone()48 $IsNotSkipped = ($IsWindows -eq $true);49 $PSDefaultParameterValues["it:skip"] = !$IsNotSkipped50 $ShouldSkipTest = !$IsNotSkipped -or !(Test-CanWriteToPsHome)51 52 Describe "Help work with ExecutionPolicy Restricted " -Tags "Feature" {53 54 # Validate that 'Get-Help Get-Disk' returns one result when the execution policy is 'Restricted' on Nano55 # From an internal bug - [Regression] Get-Help returns multiple matches when there is an exact match56 57 # Skip the test if Storage module is not available, return a pseudo result58 # ExecutionPolicy only works on windows59 It "Test for Get-Help Get-Disk" -Skip:(!(Test-Path (Join-Path -Path $PSHOME -ChildPath Modules\Storage\Storage.psd1)) -or $ShouldSkipTest) {60 61 try62 {63 $currentExecutionPolicy = Get-ExecutionPolicy64 Get-Module -Name Storage | Remove-Module -Force -ErrorAction Stop65 66 # 'Get-Help Get-Disk' should return one result back67 Set-ExecutionPolicy -ExecutionPolicy Restricted -Force -ErrorAction Stop68 (Get-Help -Name Get-Disk -ErrorAction Stop).Name | Should -Be 'Get-Disk'69 }70 finally71 {72 Set-ExecutionPolicy $currentExecutionPolicy -Force73 }74 }75 }76 77 Describe "Validate ExecutionPolicy cmdlets in PowerShell" -Tags "CI" {78 79 BeforeAll {80 if ($IsNotSkipped) {81 #Generate test data82 $drive = 'TestDrive:\'83 $testDirectory = Join-Path $drive ("MultiMachineTestData\Commands\Cmdlets\Security_TestData\ExecutionPolicyTestData")84 if(Test-Path $testDirectory)85 {86 Remove-Item -Force -Recurse $testDirectory -ErrorAction SilentlyContinue87 }88 $null = New-Item $testDirectory -ItemType Directory -Force89 $remoteTestDirectory = $testDirectory90 91 $InternetSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath InternetSignatureCorruptedScript.ps192 $InternetSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath InternetSignedScript.ps193 $InternetUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath InternetUnsignedScript.ps194 $IntranetSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath IntranetSignatureCorruptedScript.ps195 $IntranetSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath IntranetSignedScript.ps196 $IntranetUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath IntranetUnsignedScript.ps197 $LocalSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath LocalSignatureCorruptedScript.ps198 $LocalSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath LocalSignedScript.ps199 $LocalUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath LocalUnsignedScript.ps1100 $PSHomeUnsignedModule = Join-Path -Path $PSHOME -ChildPath 'Modules' -AdditionalChildPath 'LocalUnsignedModule', 'LocalUnsignedModule.psm1'101 $PSHomeUntrustedModule = Join-Path -Path $PSHOME -ChildPath 'Modules' -AdditionalChildPath 'LocalUntrustedModule', 'LocalUntrustedModule.psm1'102 $TrustedSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath TrustedSignatureCorruptedScript.ps1103 $TrustedSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath TrustedSignedScript.ps1104 $TrustedUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath TrustedUnsignedScript.ps1105 $UntrustedSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath UntrustedSignatureCorruptedScript.ps1106 $UntrustedSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath UntrustedSignedScript.ps1107 $UntrustedUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath UntrustedUnsignedScript.ps1108 $MyComputerSignatureCorruptedScript = Join-Path -Path $remoteTestDirectory -ChildPath MyComputerSignatureCorruptedScript.ps1109 $MyComputerSignedScript = Join-Path -Path $remoteTestDirectory -ChildPath MyComputerSignedScript.ps1110 $MyComputerUnsignedScript = Join-Path -Path $remoteTestDirectory -ChildPath MyComputerUnsignedScript.ps1111 112 $fileType = @{113 "Local" = -1114 "MyComputer" = 0115 "Intranet" = 1116 "Trusted" = 2117 "Internet" = 3118 "Untrusted" = 4119 }120 121 $testFilesInfo = @(122 @{123 FilePath = $InternetSignatureCorruptedScript124 FileType = $fileType.Internet125 AddSignature = $true126 Corrupted = $true127 }128 @{129 FilePath = $InternetSignedScript130 FileType = $fileType.Internet131 AddSignature = $true132 Corrupted = $false133 }134 @{135 FilePath = $InternetUnsignedScript136 FileType = $fileType.Internet137 AddSignature = $false138 Corrupted = $false139 }140 @{141 FilePath = $IntranetSignatureCorruptedScript142 FileType = $fileType.Intranet143 AddSignature = $true144 Corrupted = $true145 }146 @{147 FilePath = $IntranetSignedScript148 FileType = $fileType.Intranet149 AddSignature = $true150 Corrupted = $false151 }152 @{153 FilePath = $IntranetUnsignedScript154 FileType = $fileType.Intranet155 AddSignature = $true156 Corrupted = $true157 }158 @{159 FilePath = $LocalSignatureCorruptedScript160 FileType = $fileType.Local161 AddSignature = $true162 Corrupted = $true163 }164 @{165 FilePath = $LocalSignedScript166 FileType = $fileType.Local167 AddSignature = $true168 Corrupted = $false169 }170 @{171 FilePath = $LocalUnsignedScript172 FileType = $fileType.Local173 AddSignature = $false174 Corrupted = $false175 }176 @{177 FilePath = $PSHomeUnsignedModule178 FileType = $fileType.Local179 AddSignature = $false180 Corrupted = $false181 }182 @{183 FilePath = $PSHomeUntrustedModule184 FileType = $fileType.Untrusted185 AddSignature = $false186 Corrupted = $false187 }188 @{189 FilePath = $TrustedSignatureCorruptedScript190 FileType = $fileType.Trusted191 AddSignature = $true192 Corrupted = $true193 }194 @{195 FilePath = $TrustedSignedScript196 FileType = $fileType.Trusted197 AddSignature = $true198 Corrupted = $false199 }200 @{201 FilePath = $TrustedUnsignedScript202 FileType = $fileType.Trusted203 AddSignature = $false204 Corrupted = $false205 }206 @{207 FilePath = $UntrustedSignatureCorruptedScript208 FileType = $fileType.Untrusted209 AddSignature = $true210 Corrupted = $true211 }212 @{213 FilePath = $UntrustedSignedScript214 FileType = $fileType.Untrusted215 AddSignature = $true216 Corrupted = $true217 }218 @{219 FilePath = $UntrustedUnsignedScript220 FileType = $fileType.Untrusted221 AddSignature = $true222 Corrupted = $false223 }224 @{225 FilePath = $MyComputerSignatureCorruptedScript226 FileType = $fileType.MyComputer227 AddSignature = $true228 Corrupted = $true229 }230 @{231 FilePath = $MyComputerSignedScript232 FileType = $fileType.MyComputer233 AddSignature = $true234 Corrupted = $false235 }236 @{237 FilePath = $MyComputerUnsignedScript238 FileType = $fileType.MyComputer239 AddSignature = $false240 Corrupted = $false241 }242 )243 244 #Generate Test Data on remote machine and get the execution policy245 246 function createTestFile247 {248 param (249 [Parameter(Mandatory)]250 [string]251 $FilePath,252 253 [Parameter(Mandatory)]254 [int]255 $FileType,256 257 [switch]258 $AddSignature,259 260 [switch]261 $Corrupted262 )263 264 $folder = Split-Path -Path $FilePath265 # create folder if it doesn't already exist266 if(!(Test-Path $folder))267 {268 $null = New-Item -Path $folder -ItemType Directory269 }270 271 $null = New-Item -Path $filePath -ItemType File -Force272 273 $content = "`"Hello`"" + "`r`n"274 if($AddSignature)275 {276 if($Corrupted)277 {278 # Add corrupted signature279 $content += @"280# SIG # Begin signature block281# MIIPTAYJKoZIhvcNAQcCoIIPPTCCDzkCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB282# gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR283# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUYkdwUPVVR4frPbdbTE8ZPwfD284# +XegggyDMIIGFTCCA/2gAwIBAgITMwAAABrJQBS8Ii1KJQAAAAAAGjANBgkqhkiG285# 9w0BAQsFADCBkDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAO286# BgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjE6287# MDgGA1UEAxMxTWljcm9zb2Z0IFRlc3RpbmcgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRo288# b3JpdHkgMjAxMDAeFw0xNDAyMDQxODAyMjVaFw0xODAyMDQxODAyMjVaMIGBMRMw289# EQYKCZImiZPyLGQBGRYDY29tMRkwFwYKCZImiZPyLGQBGRYJbWljcm9zb2Z0MRQw290# EgYKCZImiZPyLGQBGRYEY29ycDEXMBUGCgmSJomT8ixkARkWB3JlZG1vbmQxIDAe291# BgNVBAMTF01TSVQgVGVzdCBDb2RlU2lnbiBDQSAzMIIBIjANBgkqhkiG9w0BAQEF292# AAOCAQ8AMIIBCgKCAQEAuV1NahtVcKSQ6osSVsCcXSsk5finBZfPTbq39nQiX9L0293# PY+5Zi73qGhDv3m+exmvWoYTgI2AQZ48lQtohf4QV0THWjsvvP/r12WZSlOfUGi5294# 5639OAmXiAPpFwPffubajzyIcYBDthJonBlhRsGCWoSaZRBZnp/39tDDvHvQqb+i295# w94CDTFfjcQ/K6xtSCNH1IaKQd6TP2mVdtbYBHIfuLWWO/quLuVgKKxz9sHjONVx296# 9nEcWwatIPiz5J9TsR/bbDxzF5AH9U8jm++ZNECu2zYPhqNj9t3HKYOrUNIEi/b9297# xYlQfMw85hPkMBTJWieyufXHkhzouvTzI3E+VhJ8EwIDAQABo4IBczCCAW8wEgYJ298# KwYBBAGCNxUBBAUCAwEAATAjBgkrBgEEAYI3FQIEFgQUxeHTk4FfDvbJdORSZob2299# 57rUxG4wHQYDVR0OBBYEFLU0zfVssWSEb3tmjxXucfADs2jrMBkGCSsGAQQBgjcU300# AgQMHgoAUwB1AGIAQwBBMAsGA1UdDwQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEA301# MB8GA1UdIwQYMBaAFKMBBH4wiDPruTGcyuuFdmf8ZbTRMFkGA1UdHwRSMFAwTqBM302# oEqGSGh0dHA6Ly9jcmwubWljcm9zb2Z0LmNvbS9wa2kvY3JsL3Byb2R1Y3RzL01p303# Y1Rlc1Jvb0NlckF1dF8yMDEwLTA2LTE3LmNybDBdBggrBgEFBQcBAQRRME8wTQYI304# KwYBBQUHMAKGQWh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2kvY2VydHMvTWlj305# VGVzUm9vQ2VyQXV0XzIwMTAtMDYtMTcuY3J0MA0GCSqGSIb3DQEBCwUAA4ICAQBt306# 9EVv44wAgXhIItfRrX2LjyEyig6DkExisf3j/RNwa3BLNK5PlfNjU/0H58V1k/Dy307# S3CIzLhvn+PBCrpjWr5R1blkJbKQUdP/ZNz28QOXd0l+Ha3P6Mne1NNfXDAjkRHK308# SqzndTxJT7s/03jYcCfh3JyiXzT8Dt5GXlWIr1wJfQljhzon3w9sptb5sIJTjB9Z309# 0VWITkvAc2hVjFkpPPWkODXIYXYIRBxKjakXr7fEx3//ECQYcQrKBvUrLirEsI0g310# mxQ2QO30iQMxug5l4VYSuHhjaN6t86OjyUySGeImiLLKpVZt1uXIggpepSS9b6Pt311# cxqD0+L532oYNJMlT/Y04PGtyfKIVFMGYTmlHoHUU78BNrpGj6C/s+qyzwXpKDHI312# eQ2RozXUzt4SS8W1E3YVxWU2AWnP0BdS7PSB9BvVCkIf1bfuM6s88iSGFh0qaZyG313# sGDlU8s7YkS2i32+nTr5NJAH/v7yd6E7DQYZULBKdKfQDXuY+6s8kjg2OduGchge314# aZZh2NLh2V5OgVrXx7CzM0K6TMZNJRhgaHE7dzT3EC2uZ6ZT/SIwxwfKXYDjsPxx315# R4C9qkdnSDVCPncGAHhyR75i3fGJ28FHhd7mtePU+zbPJ/JGyADOdPDWgJFulg97316# 809qAfXmu6I7+ObsqlCMl8hbpctmWSqqpd8wZ36ntTCCBmYwggVOoAMCAQICE0MD317# Bi6W0bK7qmSfpQAAAQMGLpYwDQYJKoZIhvcNAQELBQAwgYExEzARBgoJkiaJk/Is318# ZAEZFgNjb20xGTAXBgoJkiaJk/IsZAEZFgltaWNyb3NvZnQxFDASBgoJkiaJk/Is319# ZAEZFgRjb3JwMRcwFQYKCZImiZPyLGQBGRYHcmVkbW9uZDEgMB4GA1UEAxMXTVNJ320# VCBUZXN0IENvZGVTaWduIENBIDMwHhcNMTQxMjIyMTk0MzQ3WhcNMTYxMjIxMTk0321# MzQ3WjCBhDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNV322# BAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEuMCwG323# A1UEAxMlTWljcm9zb2Z0IENvcnBvcmF0aW9uIDNyZCBwYXJ0eSBXUCBXUzCCASIw324# DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL4ofcc4uy3h6Ai2Bh8guql21/+u325# LMLhEeHbz5STKqMoxXqy8i3uRcK/oo57INq3H+cQ4yqvuUrPwi3wQE9OG7wO4ymc326# 4M/3WTNVfjdOx0FK2y6UuKZpWQlwycuELbONrvXTzdtGuM0aiGbELRJFOq+742I+327# G3x3otZrTSXC1m6aOoKb50rSqUJ0ENb1PMJV9GBTXnRDde7ub7W3jp9Dj0HxFnof328# QRZSWfCDrO1l1hle7zPBuTnLfCXbma0oRHlTz3m3yEGlUQscxYu6BI+aJkKDKa5R329# L2PCPnau3WuUMFsmQZk6pFrACxIvq+OZTLsorTsZUooCL/5V1ofaHahnJ68CAwEA330# AaOCAtAwggLMMD0GCSsGAQQBgjcVBwQwMC4GJisGAQQBgjcVCIPPiU2t8gKFoZ8M331# gvrKfYHh+3SBT4PGhWmH7vANAgFkAgErMAsGA1UdDwQEAwIHgDA4BgkrBgEEAYI3332# FQoEKzApMA0GCysGAQQBgjdMBYIsMAwGCisGAQQBgjdMAwEwCgYIKwYBBQUHAwMw333# LAYDVR0lBCUwIwYLKwYBBAGCN0wFgiwGCisGAQQBgjdMAwEGCCsGAQUFBwMDMB0G334# A1UdDgQWBBT+6HzYZdp8xPv1xylrDwOMuYQkvDAwBgNVHREEKTAnoCUGCisGAQQB335# gjcUAgOgFwwVZG9uZ2Jvd0BtaWNyb3NvZnQuY29tMB8GA1UdIwQYMBaAFLU0zfVs336# sWSEb3tmjxXucfADs2jrMIHxBgNVHR8EgekwgeYwgeOggeCggd2GOWh0dHA6Ly9j337# b3JwcGtpL2NybC9NU0lUJTIwVGVzdCUyMENvZGVTaWduJTIwQ0ElMjAzKDEpLmNy338# bIZQaHR0cDovL21zY3JsLm1pY3Jvc29mdC5jb20vcGtpL21zY29ycC9jcmwvTVNJ339# VCUyMFRlc3QlMjBDb2RlU2lnbiUyMENBJTIwMygxKS5jcmyGTmh0dHA6Ly9jcmwu340# bWljcm9zb2Z0LmNvbS9wa2kvbXNjb3JwL2NybC9NU0lUJTIwVGVzdCUyMENvZGVT341# aWduJTIwQ0ElMjAzKDEpLmNybDCBrwYIKwYBBQUHAQEEgaIwgZ8wRQYIKwYBBQUH342# MAKGOWh0dHA6Ly9jb3JwcGtpL2FpYS9NU0lUJTIwVGVzdCUyMENvZGVTaWduJTIw343# Q0ElMjAzKDEpLmNydDBWBggrBgEFBQcwAoZKaHR0cDovL3d3dy5taWNyb3NvZnQu344# Y29tL3BraS9tc2NvcnAvTVNJVCUyMFRlc3QlMjBDb2RlU2lnbiUyMENBJTIwMygx345# KS5jcnQwDQYJKoZIhvcNAQELBQADggEBAFRprvk5BxGyn5On1ICDyKRw9rLqyMET346# IDuBmX/enKuLRmETJSF7Dvzo/XbSXm+FTbGwnp5TOIPtCAeT0NuUAAjdo2iRT2Xr347# wc/B4x2dWMJmFG86WmPPWByfw1gFSep1xN6vA9qPb2VAXTmz8Ta75vSmCEfRAqOC348# 7U4uv3RBWImDx+7tI71XLKBmn1s1TTs1rL+43MsNMA7YNeM8/G0k2KbcNeLONNMG349# wJwtlu9CutONhULkhi2C3T7huDtNZgg+LnTbNvZeXMhHtfx8obh1fmgfOrdLUgE9350# 1YtW0F6mZ7OsdWPGV1wPOdRuNxgzGWvOIYCUTeeTU7b+Cifz/mTf/9QxggIzMIIC351# LwIBATCBmTCBgTETMBEGCgmSJomT8ixkARkWA2NvbTEZMBcGCgmSJomT8ixkARkW352# CW1pY3Jvc29mdDEUMBIGCgmSJomT8ixkARkWBGNvcnAxFzAVBgoJkiaJk/IsZAEZ353# FgdyZWRtb25kMSAwHgYDVQQDExdNU0lUIFRlc3QgQ29kZVNpZ24gQ0EgMwITQwMG354# LpbRsruqZJ+lAAABAwYuljAJBgUrDgMCGgUAoHAwEAYKKwYBBAGCNwIBDDECMAAw355# GQYJKoZIhvcNAQkDMQwGCisGAQQBgjcCAQQwHAYKKwYBBAGCNwIBCzEOMAwGCisG356# AQQBgjcCARUwIwYJKoZIhvcNAQkEMRYEFDFRa0VJKJQ1h2LG6dYzXKpBneOfMA0G357# CSqGSIb3DQEBAQUABIIBAHbWmEOWfj37SNw8NDnAAg7bl0L3oyGVKPWysRnriHC9358# aYImucAy2QXKo6YUWxHMqFvRPFrF07qkTDV249iC+L8gb1X0wwq/YuWWFbdN2J8s359# 4CnN6I4Ff2AF4Co34MZGhtIHd3D7H1oPMelTlHQOc5CXyB/wkduoNgS0GCoeZXSK360# DdMuN7dbru3PvCxe0ShzRwxBOa4EWZ6dHDAQRdrxkK2vVLWHg+6th8lRNnCJQeb+361# 03tMRItnm/sAmKR9PCWm4YZob3ug9T9Qa1K00TuNskjXO+G2S2mjhFC5+HGKjLZd362# bJydl0MIIMBtlLEGa4CcFtszxaww5Cx+YtCbxPp3iII=363# SIG # End signature block364"@365 }366 else367 {368 # Add correct signature369 $content += @"370# SIG # Begin signature block371# MIIPTAYJKoZIhvcNAQcCoIIPPTCCDzkCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB372# gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR373# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUYkdwUPVVR4frPbdbTE8ZPwfD374# +XegggyDMIIGFTCCA/2gAwIBAgITMwAAABrJQBS8Ii1KJQAAAAAAGjANBgkqhkiG375# 9w0BAQsFADCBkDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAO376# BgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjE6377# MDgGA1UEAxMxTWljcm9zb2Z0IFRlc3RpbmcgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRo378# b3JpdHkgMjAxMDAeFw0xNDAyMDQxODAyMjVaFw0xODAyMDQxODAyMjVaMIGBMRMw379# EQYKCZImiZPyLGQBGRYDY29tMRkwFwYKCZImiZPyLGQBGRYJbWljcm9zb2Z0MRQw380# EgYKCZImiZPyLGQBGRYEY29ycDEXMBUGCgmSJomT8ixkARkWB3JlZG1vbmQxIDAe381# BgNVBAMTF01TSVQgVGVzdCBDb2RlU2lnbiBDQSAzMIIBIjANBgkqhkiG9w0BAQEF382# AAOCAQ8AMIIBCgKCAQEAuV1NahtVcKSQ6osSVsCcXSsk5finBZfPTbq39nQiX9L0383# PY+5Zi73qGhDv3m+exmvWoYTgI2AQZ48lQtohf4QV0THWjsvvP/r12WZSlOfUGi5384# 5639OAmXiAPpFwPffubajzyIcYBDthJonBlhRsGCWoSaZRBZnp/39tDDvHvQqb+i385# w94CDTFfjcQ/K6xtSCNH1IaKQd6TP2mVdtbYBHIfuLWWO/quLuVgKKxz9sHjONVx386# 9nEcWwatIPiz5J9TsR/bbDxzF5AH9U8jm++ZNECu2zYPhqNj9t3HKYOrUNIEi/b9387# xYlQfMw85hPkMBTJWieyufXHkhzouvTzI3E+VhJ8EwIDAQABo4IBczCCAW8wEgYJ388# KwYBBAGCNxUBBAUCAwEAATAjBgkrBgEEAYI3FQIEFgQUxeHTk4FfDvbJdORSZob2389# 57rUxG4wHQYDVR0OBBYEFLU0zfVssWSEb3tmjxXucfADs2jrMBkGCSsGAQQBgjcU390# AgQMHgoAUwB1AGIAQwBBMAsGA1UdDwQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEA391# MB8GA1UdIwQYMBaAFKMBBH4wiDPruTGcyuuFdmf8ZbTRMFkGA1UdHwRSMFAwTqBM392# oEqGSGh0dHA6Ly9jcmwubWljcm9zb2Z0LmNvbS9wa2kvY3JsL3Byb2R1Y3RzL01p393# Y1Rlc1Jvb0NlckF1dF8yMDEwLTA2LTE3LmNybDBdBggrBgEFBQcBAQRRME8wTQYI394# KwYBBQUHMAKGQWh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2kvY2VydHMvTWlj395# VGVzUm9vQ2VyQXV0XzIwMTAtMDYtMTcuY3J0MA0GCSqGSIb3DQEBCwUAA4ICAQBt396# 9EVv44wAgXhIItfRrX2LjyEyig6DkExisf3j/RNwa3BLNK5PlfNjU/0H58V1k/Dy397# S3CIzLhvn+PBCrpjWr5R1blkJbKQUdP/ZNz28QOXd0l+Ha3P6Mne1NNfXDAjkRHK398# SqzndTxJT7s/03jYcCfh3JyiXzT8Dt5GXlWIr1wJfQljhzon3w9sptb5sIJTjB9Z399# 0VWITkvAc2hVjFkpPPWkODXIYXYIRBxKjakXr7fEx3//ECQYcQrKBvUrLirEsI0g400# mxQ2QO30iQMxug5l4VYSuHhjaN6t86OjyUySGeImiLLKpVZt1uXIggpepSS9b6Pt401# cxqD0+L532oYNJMlT/Y04PGtyfKIVFMGYTmlHoHUU78BNrpGj6C/s+qyzwXpKDHI402# eQ2RozXUzt4SS8W1E3YVxWU2AWnP0BdS7PSB9BvVCkIf1bfuM6s88iSGFh0qaZyG403# sGDlU8s7YkS2i32+nTr5NJAH/v7yd6E7DQYZULBKdKfQDXuY+6s8kjg2OduGchge404# aZZh2NLh2V5OgVrXx7CzM0K6TMZNJRhgaHE7dzT3EC2uZ6ZT/SIwxwfKXYDjsPxx405# R4C9qkdnSDVCPncGAHhyR75i3fGJ28FHhd7mtePU+zbPJ/JGyADOdPDWgJFulg97406# 809qAfXmu6I7+ObsqlCMl8hbpctmWSqqpd8wZ36ntTCCBmYwggVOoAMCAQICE0MD407# Bi6W0bK7qmSfpQAAAQMGLpYwDQYJKoZIhvcNAQELBQAwgYExEzARBgoJkiaJk/Is408# ZAEZFgNjb20xGTAXBgoJkiaJk/IsZAEZFgltaWNyb3NvZnQxFDASBgoJkiaJk/Is409# ZAEZFgRjb3JwMRcwFQYKCZImiZPyLGQBGRYHcmVkbW9uZDEgMB4GA1UEAxMXTVNJ410# VCBUZXN0IENvZGVTaWduIENBIDMwHhcNMTQxMjIyMTk0MzQ3WhcNMTYxMjIxMTk0411# MzQ3WjCBhDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNV412# BAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEuMCwG413# A1UEAxMlTWljcm9zb2Z0IENvcnBvcmF0aW9uIDNyZCBwYXJ0eSBXUCBXUzCCASIw414# DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL4ofcc4uy3h6Ai2Bh8guql21/+u415# LMLhEeHbz5STKqMoxXqy8i3uRcK/oo57INq3H+cQ4yqvuUrPwi3wQE9OG7wO4ymc416# 4M/3WTNVfjdOx0FK2y6UuKZpWQlwycuELbONrvXTzdtGuM0aiGbELRJFOq+742I+417# G3x3otZrTSXC1m6aOoKb50rSqUJ0ENb1PMJV9GBTXnRDde7ub7W3jp9Dj0HxFnof418# QRZSWfCDrO1l1hle7zPBuTnLfCXbma0oRHlTz3m3yEGlUQscxYu6BI+aJkKDKa5R419# L2PCPnau3WuUMFsmQZk6pFrACxIvq+OZTLsorTsZUooCL/5V1ofaHahnJ68CAwEA420# AaOCAtAwggLMMD0GCSsGAQQBgjcVBwQwMC4GJisGAQQBgjcVCIPPiU2t8gKFoZ8M421# gvrKfYHh+3SBT4PGhWmH7vANAgFkAgErMAsGA1UdDwQEAwIHgDA4BgkrBgEEAYI3422# FQoEKzApMA0GCysGAQQBgjdMBYIsMAwGCisGAQQBgjdMAwEwCgYIKwYBBQUHAwMw423# LAYDVR0lBCUwIwYLKwYBBAGCN0wFgiwGCisGAQQBgjdMAwEGCCsGAQUFBwMDMB0G424# A1UdDgQWBBT+6HzYZdp8xPv1xylrDwOMuYQkvDAwBgNVHREEKTAnoCUGCisGAQQB425# gjcUAgOgFwwVZG9uZ2Jvd0BtaWNyb3NvZnQuY29tMB8GA1UdIwQYMBaAFLU0zfVs426# sWSEb3tmjxXucfADs2jrMIHxBgNVHR8EgekwgeYwgeOggeCggd2GOWh0dHA6Ly9j427# b3JwcGtpL2NybC9NU0lUJTIwVGVzdCUyMENvZGVTaWduJTIwQ0ElMjAzKDEpLmNy428# bIZQaHR0cDovL21zY3JsLm1pY3Jvc29mdC5jb20vcGtpL21zY29ycC9jcmwvTVNJ429# VCUyMFRlc3QlMjBDb2RlU2lnbiUyMENBJTIwMygxKS5jcmyGTmh0dHA6Ly9jcmwu430# bWljcm9zb2Z0LmNvbS9wa2kvbXNjb3JwL2NybC9NU0lUJTIwVGVzdCUyMENvZGVT431# aWduJTIwQ0ElMjAzKDEpLmNybDCBrwYIKwYBBQUHAQEEgaIwgZ8wRQYIKwYBBQUH432# MAKGOWh0dHA6Ly9jb3JwcGtpL2FpYS9NU0lUJTIwVGVzdCUyMENvZGVTaWduJTIw433# Q0ElMjAzKDEpLmNydDBWBggrBgEFBQcwAoZKaHR0cDovL3d3dy5taWNyb3NvZnQu434# Y29tL3BraS9tc2NvcnAvTVNJVCUyMFRlc3QlMjBDb2RlU2lnbiUyMENBJTIwMygx435# KS5jcnQwDQYJKoZIhvcNAQELBQADggEBAFRprvk5BxGyn5On1ICDyKRw9rLqyMET436# IDuBmX/enKuLRmETJSF7Dvzo/XbSXm+FTbGwnp5TOIPtCAeT0NuUAAjdo2iRT2Xr437# wc/B4x2dWMJmFG86WmPPWByfw1gFSep1xN6vA9qPb2VAXTmz8Ta75vSmCEfRAqOC438# 7U4uv3RBWImDx+7tI71XLKBmn1s1TTs1rL+43MsNMA7YNeM8/G0k2KbcNeLONNMG439# wJwtlu9CutONhULkhi2C3T7huDtNZgg+LnTbNvZeXMhHtfx8obh1fmgfOrdLUgE9440# 1YtW0F6mZ7OsdWPGV1wPOdRuNxgzGWvOIYCUTeeTU7b+Cifz/mTf/9QxggIzMIIC441# LwIBATCBmTCBgTETMBEGCgmSJomT8ixkARkWA2NvbTEZMBcGCgmSJomT8ixkARkW442# CW1pY3Jvc29mdDEUMBIGCgmSJomT8ixkARkWBGNvcnAxFzAVBgoJkiaJk/IsZAEZ443# FgdyZWRtb25kMSAwHgYDVQQDExdNU0lUIFRlc3QgQ29kZVNpZ24gQ0EgMwITQwMG444# LpbRsruqZJ+lAAABAwYuljAJBgUrDgMCGgUAoHAwEAYKKwYBBAGCNwIBDDECMAAw445# GQYJKoZIhvcNAQkDMQwGCisGAQQBgjcCAQQwHAYKKwYBBAGCNwIBCzEOMAwGCisG446# AQQBgjcCARUwIwYJKoZIhvcNAQkEMRYEFDFRa0VJKJQ1h2LG6dYzXKpBneOfMA0G447# CSqGSIb3DQEBAQUABIIBAHbWmEOWfj37SNw8NDnAAg7bl0L3oyGVKPWysRnriHC9448# aYImucAy2QXKo6YUWxHMqFvRPFrF07qkTDV249iC+L8gb1X0wwq/YuWWFbdN2J8s449# 4CnN6I4Ff2AF4Co34MZGhtIHd3D7H1oPMelTlHQOc5CXyB/wkduoNgS0GCoeZXSK450# DdMuN7dbru3PvCxe0ShzRwxBOa4EWZ6dHDAQRdrxkK2vVLWHg+6th8lRNnCJQeb+451# 03tMRItnm/sAmKR9PCWm4YZob3ug9T9Qa1K00TuNskjXO+G2S2mjhFC5+HGKjLZd452# bJydl0MIIMBtlLEGa4CcFtszxaww5Cx+YtCbxPp3iII=453# SIG # End signature block454"@455 }456 }457 458 Set-Content $filePath -Value $content459 460 ## Valida File types and their corresponding int values are :461 ##462 ## Local = -1463 ## MyComputer = 0464 ## Intranet = 1465 ## Trusted = 2466 ## Internet = 3467 ## Untrusted = 4468 ## We need to add alternate streams in all files except for the local file469 470 if(-1 -ne $FileType)471 {472 $alternateStreamContent = @"473[ZoneTransfer]474ZoneId=$FileType475"@476 Add-Content -Path $filePath -Value $alternateStreamContent -Stream Zone.Identifier477 }478 }479 480 foreach($fileInfo in $testFilesInfo)481 {482 if ((Test-CanWriteToPsHome) -or (!(Test-CanWriteToPsHome) -and !$fileInfo.filePath.StartsWith($PSHOME, $true, $null)) ) {483 createTestFile -FilePath $fileInfo.filePath -FileType $fileInfo.fileType -AddSignature:$fileInfo.AddSignature -Corrupted:$fileInfo.corrupted484 }485 }486 487 #Get Execution Policy488 $originalExecPolicy = Get-ExecutionPolicy489 $originalExecutionPolicy = $originalExecPolicy490 491 $archiveSigned = $false492 $archivePath = Get-Module -ListAvailable Microsoft.PowerShell.Archive -ErrorAction SilentlyContinue | Select-Object -ExpandProperty Path493 if($archivePath)494 {495 $archiveFolder = Split-Path -Path $archivePath496 497 # get all the certs used to sign the module498 $script:archiveAllCert = Get-ChildItem -File -Path (Join-Path -Path $archiveFolder -ChildPath '*') -Recurse |499 Get-AuthenticodeSignature500 501 # filter only to valid signatures502 $script:archiveCert = $script:archiveAllCert |503 Where-Object { $_.status -eq 'Valid'} |504 Select-Object -Unique -ExpandProperty SignerCertificate505 506 # if we have valid signatures, add them to trusted publishers so powershell will trust them.507 if($script:archiveCert)508 {509 $store = [System.Security.Cryptography.X509Certificates.X509Store]::new([System.Security.Cryptography.X509Certificates.StoreName]::TrustedPublisher,[System.Security.Cryptography.X509Certificates.StoreLocation]::CurrentUser)510 $store.Open([System.Security.Cryptography.X509Certificates.OpenFlags]::ReadWrite)511 $archiveCert | ForEach-Object {512 $store.Add($_)513 }514 $store.Close()515 $archiveSigned = $true516 }517 }518 }519 }520 AfterAll {521 if ($IsNotSkipped) {522 #Clean up523 $testDirectory = $remoteTestDirectory524 525 Remove-Item $testDirectory -Recurse -Force -ErrorAction SilentlyContinue526 Remove-Item function:createTestFile -ErrorAction SilentlyContinue527 }528 }529 530 Context "Prereq: Validate that 'Microsoft.PowerShell.Archive' is signed" {531 It "'Microsoft.PowerShell.Archive' should have a signature" {532 $script:archiveAllCert | Should -Not -Be $null533 }534 It "'Microsoft.PowerShell.Archive' should have a valid signature" {535 $script:archiveCert | Should -Not -Be $null536 }537 }538 539 Context "Validate that 'Restricted' execution policy works on OneCore powershell" {540 541 BeforeAll {542 if ($IsNotSkipped) {543 Set-ExecutionPolicy Restricted -Force -Scope Process | Out-Null544 }545 }546 547 AfterAll {548 if ($IsNotSkipped) {549 Set-ExecutionPolicy $originalExecutionPolicy -Force -Scope Process | Out-Null550 }551 }552 553 function Test-RestrictedExecutionPolicy554 {555 param ($testScript)556 557 $TestTypePrefix = "Test 'Restricted' execution policy."558 559 It "$TestTypePrefix Running $testScript script should raise PSSecurityException" {560 561 $scriptName = $testScript562 563 $exception = { & $scriptName } | Should -Throw -PassThru564 565 $exception.Exception | Should -BeOfType System.Management.Automation.PSSecurityException566 }567 }568 569 $testScripts = @(570 $InternetSignatureCorruptedScript571 $InternetSignedScript572 $InternetUnsignedScript573 $IntranetSignatureCorruptedScript574 $IntranetSignedScript575 $IntranetUnsignedScript576 $LocalSignatureCorruptedScript577 $localSignedScript578 $LocalUnsignedScript579 $TrustedSignatureCorruptedScript580 $TrustedSignedScript581 $UntrustedSignatureCorruptedScript582 $UntrustedSignedScript583 $UntrustedUnsignedScript584 $TrustedUnsignedScript585 $MyComputerSignatureCorruptedScript586 $MyComputerSignedScript587 $MyComputerUnsignedScript588 )589 590 foreach($testScript in $testScripts)591 {592 Test-RestrictedExecutionPolicy $testScript593 }594 }595 596 AfterAll {597 if ($IsNotSkipped) {598 # Clean up599 $testDirectory = $remoteTestDirectory600 601 Remove-Item $testDirectory -Recurse -Force -ErrorAction SilentlyContinue602 Remove-Item function:createTestFile -ErrorAction SilentlyContinue603 }604 }605 Context "Validate that 'Unrestricted' execution policy works on OneCore powershell" {606 607 BeforeAll {608 if ($IsNotSkipped) {609 Set-ExecutionPolicy Unrestricted -Force -Scope Process | Out-Null610 }611 }612 613 AfterAll {614 if ($IsNotSkipped) {615 Set-ExecutionPolicy $originalExecutionPolicy -Force -Scope Process | Out-Null616 }617 }618 619 function Test-UnrestrictedExecutionPolicy {620 621 param($testScript, $expected)622 623 $TestTypePrefix = "Test 'Unrestricted' execution policy."624 625 It "$TestTypePrefix Running $testScript script should return $expected" {626 $scriptName = $testScript627 628 $result = & $scriptName629 630 $result | Should -Be $expected631 }632 }633 634 $expected = "Hello"635 $testScripts = @(636 $IntranetSignatureCorruptedScript637 $IntranetSignedScript638 $IntranetUnsignedScript639 $LocalSignatureCorruptedScript640 $localSignedScript641 $LocalUnsignedScript642 $TrustedSignatureCorruptedScript643 $TrustedSignedScript644 $TrustedUnsignedScript645 $MyComputerSignatureCorruptedScript646 $MyComputerSignedScript647 $MyComputerUnsignedScript648 )649 650 foreach($testScript in $testScripts) {651 Test-UnrestrictedExecutionPolicy $testScript $expected652 }653 654 $expectedError = "UnauthorizedAccess,Microsoft.PowerShell.Commands.ImportModuleCommand"655 656 $testData = @(657 @{658 module = "Microsoft.PowerShell.Archive"659 error = $null660 }661 )662 663 if (Test-CanWriteToPsHome) {664 $testData += @(665 @{666 shouldMarkAsPending = $true667 module = $PSHomeUntrustedModule668 expectedError = $expectedError669 }670 @{671 module = $PSHomeUnsignedModule672 error = $null673 }674 )675 }676 677 $TestTypePrefix = "Test 'Unrestricted' execution policy."678 It "$TestTypePrefix Importing <module> Module should throw '<error>'" -TestCases $testData {679 param([string]$module, [string]$expectedError, [bool]$shouldMarkAsPending)680 681 if ($shouldMarkAsPending)682 {683 Set-ItResult -Pending -Because "Test is unreliable"684 }685 686 $execPolicy = Get-ExecutionPolicy -List | Out-String687 688 $testScript = {Import-Module -Name $module -Force -ErrorAction Stop}689 if($expectedError)690 {691 $testScript | Should -Throw -ErrorId $expectedError -Because "Untrusted modules should not be loaded even on unrestricted execution policy"692 }693 else694 {695 $testScript | Should -Not -Throw -Because "Execution Policy is set as: $execPolicy"696 }697 }698 }699 700 Context "Validate that 'ByPass' execution policy works on OneCore powershell" {701 702 BeforeAll {703 if ($IsNotSkipped) {704 Set-ExecutionPolicy Bypass -Force -Scope Process | Out-Null705 }706 }707 708 AfterAll {709 if ($IsNotSkipped) {710 Set-ExecutionPolicy $originalExecutionPolicy -Force -Scope Process | Out-Null711 }712 }713 714 function Test-ByPassExecutionPolicy {715 716 param($testScript, $expected)717 718 $TestTypePrefix = "Test 'ByPass' execution policy."719 720 It "$TestTypePrefix Running $testScript script should return $expected" {721 $scriptName = $testScript722 723 $result = & $scriptName724 return $result725 726 $result | Should -Be $expected727 }728 }729 730 $expected = "Hello"731 $testScripts = @(732 $InternetSignatureCorruptedScript733 $InternetSignedScript734 $InternetUnsignedScript735 $IntranetSignatureCorruptedScript736 $IntranetSignedScript737 $IntranetUnsignedScript738 $LocalSignatureCorruptedScript739 $LocalSignedScript740 $LocalUnsignedScript741 $TrustedSignatureCorruptedScript742 $TrustedSignedScript743 $TrustedUnsignedScript744 $UntrustedSignatureCorruptedScript745 $UntrustedSignedScript746 $UntrustedUnSignedScript747 $MyComputerSignatureCorruptedScript748 $MyComputerSignedScript749 $MyComputerUnsignedScript750 )751 foreach($testScript in $testScripts) {752 Test-ByPassExecutionPolicy $testScript $expected753 }754 }755 756 Context "'RemoteSigned' execution policy works on OneCore powershell" {757 758 BeforeAll {759 if ($IsNotSkipped) {760 Set-ExecutionPolicy RemoteSigned -Force -Scope Process | Out-Null761 }762 }763 764 AfterAll {765 if ($IsNotSkipped) {766 Set-ExecutionPolicy $originalExecutionPolicy -Force -Scope Process767 }768 }769 770 function Test-RemoteSignedExecutionPolicy {771 772 param ($testScript, $expected, $errorId)773 774 $TestTypePrefix = "Test 'RemoteSigned' execution policy."775 776 It "$TestTypePrefix Running $testScript script should return $expected" {777 $scriptName=$testScript778 779 $scriptResult = $null780 $exception = $null781 782 try783 {784 $scriptResult = & $scriptName785 }786 catch787 {788 $exception = $_789 }790 791 $errorType = $null792 if($null -ne $exception)793 {794 $errorType = $exception.exception.getType()795 $scriptResult = $null796 }797 $result = @{798 "result" = $scriptResult799 "exception" = $errorType800 }801 802 $actualResult = $result."result"803 $actualError = $result."exception"804 805 $actualResult | Should -Be $expected806 $actualError | Should -Be $errorId807 }808 }809 $message = "Hello"810 $errorId = "System.Management.Automation.PSSecurityException"811 $testData = @(812 @{813 testScript = $LocalUnsignedScript814 expected = $message815 errorId = $null816 }817 @{818 testScript = $LocalSignatureCorruptedScript819 expected = $message820 errorId = $null821 }822 @{823 testScript = $LocalSignedScript824 expected = "Hello"825 errorId = $null826 }827 @{828 testScript = $MyComputerUnsignedScript829 expected = $message830 errorId = $null831 }832 @{833 testScript = $MyComputerSignatureCorruptedScript834 expected = $message835 errorId = $null836 }837 @{838 testScript = $myComputerSignedScript839 expected = $message840 errorId = $null841 }842 @{843 testScript = $TrustedUnsignedScript844 expected = $message845 errorId = $null846 }847 @{848 testScript = $TrustedSignatureCorruptedScript849 expected = $message850 errorId = $null851 }852 @{853 testScript = $TrustedSignedScript854 expected = $message855 errorId = $null856 }857 @{858 testScript = $IntranetUnsignedScript859 expected = $message860 errorId = $null861 }862 @{863 testScript = $IntranetSignatureCorruptedScript864 expected = $message865 errorId = $null866 }867 @{868 testScript = $IntranetSignedScript869 expected = $message870 errorId = $null871 }872 @{873 testScript = $InternetUnsignedScript874 expected = $null875 errorId = $errorId876 }877 @{878 testScript = $InternetSignatureCorruptedScript879 expected = $null880 errorId = $errorId881 }882 @{883 testScript = $UntrustedUnsignedScript884 expected = $null885 errorId = $errorId886 }887 @{888 testScript = $UntrustedSignatureCorruptedScript889 expected = $null890 errorId = $errorId891 }892 )893 894 foreach($testCase in $testData) {895 Test-RemoteSignedExecutionPolicy @testCase896 }897 }898 899 Context "Validate that 'AllSigned' execution policy works on OneCore powershell" {900 901 BeforeAll {902 if ($IsNotSkipped) {903 Set-ExecutionPolicy AllSigned -Force -Scope Process904 }905 }906 907 AfterAll {908 if ($IsNotSkipped) {909 Set-ExecutionPolicy $originalExecutionPolicy -Force -Scope Process910 }911 }912 913 $TestTypePrefix = "Test 'AllSigned' execution policy."914 915 $errorId = "UnauthorizedAccess,Microsoft.PowerShell.Commands.ImportModuleCommand"916 $testData = @(917 @{918 module = "Microsoft.PowerShell.Archive"919 errorId = $null920 }921 )922 923 if (Test-CanWriteToPsHome) {924 $testData += @(925 @{926 module = $PSHomeUntrustedModule927 errorId = $errorId928 }929 @{930 module = $PSHomeUnsignedModule931 errorId = $errorId932 }933 )934 }935 936 It "$TestTypePrefix Importing <module> Module should throw '<error>'" -TestCases $testData {937 param ([string]$module, [string]$errorId)938 $testScript = {Import-Module -Name $module -Force}939 if ($errorId)940 {941 $testScript | Should -Throw -ErrorId $errorId942 }943 else944 {945 {& $testScript} | Should -Not -Throw946 }947 }948 949 $errorId = "UnauthorizedAccess"950 $pendingTestData = @(951 # The following files are not signed correctly when generated, so we will skip for now952 # filed https://github.com/PowerShell/PowerShell/issues/5559953 @{954 testScript = $MyComputerSignedScript955 errorId = $null956 }957 @{958 testScript = $UntrustedSignedScript959 errorId = $null960 }961 @{962 testScript = $TrustedSignedScript963 errorId = $null964 }965 @{966 testScript = $LocalSignedScript967 errorId = $null968 }969 @{970 testScript = $IntranetSignedScript971 errorId = $null972 }973 @{974 testScript = $InternetSignedScript975 errorId = $null976 }977 )978 It "$TestTypePrefix Running <testScript> Script should throw '<error>'" -TestCases $pendingTestData -Pending {}979 980 $testData = @(981 @{982 testScript = $InternetSignatureCorruptedScript983 errorId = $errorId984 }985 @{986 testScript = $InternetUnsignedScript987 errorId = $errorId988 }989 @{990 testScript = $IntranetSignatureCorruptedScript991 errorId = $errorId992 }993 @{994 testScript = $IntranetSignatureCorruptedScript995 errorId = $errorId996 }997 @{998 testScript = $IntranetUnsignedScript999 errorId = $errorId1000 }1001 @{1002 testScript = $LocalSignatureCorruptedScript1003 errorId = $errorId1004 }1005 @{1006 testScript = $LocalUnsignedScript1007 errorId = $errorId1008 }1009 @{1010 testScript = $TrustedSignatureCorruptedScript1011 errorId = $errorId1012 }1013 @{1014 testScript = $TrustedUnsignedScript1015 errorId = $errorId1016 }1017 @{1018 testScript = $UntrustedSignatureCorruptedScript1019 errorId = $errorId1020 }1021 @{1022 testScript = $UntrustedUnsignedScript1023 errorId = $errorId1024 }1025 @{1026 testScript = $MyComputerSignatureCorruptedScript1027 errorId = $errorId1028 }1029 @{1030 testScript = $MyComputerUnsignedScript1031 errorId = $errorId1032 }1033 1034 )1035 It "$TestTypePrefix Running <testScript> Script should throw '<error>'" -TestCases $testData {1036 param ([string]$testScript, [string]$errorId)1037 $testScript | Should -Exist1038 if ($errorId)1039 {1040 {& $testScript} | Should -Throw -ErrorId $errorId1041 }1042 else1043 {1044 {& $testScript} | Should -Not -Throw1045 }1046 }1047 }1048 }1049 1050 function VerfiyBlockedSetExecutionPolicy1051 {1052 param(1053 [string]1054 $policyScope1055 )1056 { Set-ExecutionPolicy -Scope $policyScope -ExecutionPolicy Restricted } |1057 Should -Throw -ErrorId "CantSetGroupPolicy,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand"1058 }1059 1060 function RestoreExecutionPolicy1061 {1062 param($originalPolicies)1063 1064 foreach ($scopedPolicy in $originalPolicies)1065 {1066 if (($scopedPolicy.Scope -eq "Process") -or1067 ($scopedPolicy.Scope -eq "CurrentUser"))1068 {1069 try {1070 Set-ExecutionPolicy -Scope $scopedPolicy.Scope -ExecutionPolicy $scopedPolicy.ExecutionPolicy -Force1071 }1072 catch {1073 if ($_.FullyQualifiedErrorId -ne "ExecutionPolicyOverride,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand")1074 {1075 # Re-throw unrecognized exceptions. Otherwise, swallow1076 # the exception that warns about overridden policies1077 throw $_1078 }1079 }1080 }1081 elseif($scopedPolicy.Scope -eq "LocalMachine")1082 {1083 try {1084 Set-ExecutionPolicy -Scope $scopedPolicy.Scope -ExecutionPolicy $scopedPolicy.ExecutionPolicy -Force1085 }1086 catch {1087 if ($_.FullyQualifiedErrorId -eq "System.UnauthorizedAccessException,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand")1088 {1089 # Do nothing. Depending on the ownership of the file,1090 # regular users may or may not be able to set its1091 # value.1092 #1093 # When targetting the Registry, regular users cannot1094 # modify this value.1095 }1096 elseif ($_.FullyQualifiedErrorId -ne "ExecutionPolicyOverride,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand")1097 {1098 # Re-throw unrecognized exceptions. Otherwise, swallow1099 # the exception that warns about overridden policies1100 throw $_1101 }1102 }1103 }1104 }1105 }1106 1107 Describe "Validate Set-ExecutionPolicy -Scope" -Tags "CI" {1108 1109 BeforeAll {1110 if ($IsNotSkipped) {1111 $originalPolicies = Get-ExecutionPolicy -List1112 }1113 }1114 1115 AfterAll {1116 if ($IsNotSkipped) {1117 RestoreExecutionPolicy $originalPolicies1118 }1119 }1120 1121 It "-Scope MachinePolicy is not Modifiable" {1122 VerfiyBlockedSetExecutionPolicy "MachinePolicy"1123 }1124 1125 It "-Scope UserPolicy is not Modifiable" {1126 VerfiyBlockedSetExecutionPolicy "UserPolicy"1127 }1128 1129 It "-Scope Process is Settable" {1130 Set-ExecutionPolicy -Scope Process -ExecutionPolicy ByPass1131 Get-ExecutionPolicy -Scope Process | Should -Be "ByPass"1132 }1133 1134 It "-Scope CurrentUser is Settable" {1135 Set-ExecutionPolicy -Scope CurrentUser -ExecutionPolicy ByPass1136 Get-ExecutionPolicy -Scope CurrentUser | Should -Be "ByPass"1137 }1138 }1139 1140 Describe "Validate Set-ExecutionPolicy -Scope (Admin)" -Tags @('CI', 'RequireAdminOnWindows') {1141 1142 BeforeAll {1143 if ($IsNotSkipped)1144 {1145 $originalPolicies = Get-ExecutionPolicy -List1146 }1147 }1148 1149 AfterAll {1150 if ($IsNotSkipped)1151 {1152 RestoreExecutionPolicy $originalPolicies1153 }1154 }1155 1156 It '-Scope LocalMachine is Settable, but overridden' -Skip:$ShouldSkipTest {1157 # In this test, we first setup execution policy in the following way:1158 # CurrentUser is specified and takes precedence over LocalMachine.1159 # That's why we will get an error, when we are setting up LocalMachine policy.1160 # The error is:1161 #1162 # Set-ExecutionPolicy : Windows PowerShell updated your execution policy successfully, but the setting is overridden by1163 # a policy defined at a more specific scope. Due to the override, your shell will retain its current effective1164 # execution policy of RemoteSigned. Type "Get-ExecutionPolicy -List" to view your execution policy settings. For more1165 # information please see "Get-Help Set-ExecutionPolicy".1166 #1167 # Regrdless of that error, the operation should succeed.1168 1169 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Undefined1170 Set-ExecutionPolicy -Scope CurrentUser -ExecutionPolicy Restricted1171 1172 { Set-ExecutionPolicy -Scope LocalMachine -ExecutionPolicy ByPass } |1173 Should -Throw -ErrorId 'ExecutionPolicyOverride,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand'1174 1175 Get-ExecutionPolicy -Scope LocalMachine | Should -Be "ByPass"1176 }1177 1178 It '-Scope LocalMachine is Settable' -Skip:$ShouldSkipTest {1179 # We need to make sure that both Process and CurrentUser policies are Undefined1180 # before we can set LocalMachine policy without ExecutionPolicyOverride error.1181 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Undefined1182 Set-ExecutionPolicy -Scope CurrentUser -ExecutionPolicy Undefined1183 1184 Set-ExecutionPolicy -Scope LocalMachine -ExecutionPolicy ByPass1185 Get-ExecutionPolicy -Scope LocalMachine | Should -Be "ByPass"1186 }1187 }1188}1189finally {1190 $global:PSDefaultParameterValues = $originalDefaultParameterValues1191}1192 