feat: add native Windows hierarchy test harness
This commit is contained in:
@@ -388,6 +388,10 @@ func (manager *execSupervisor) selectToken(elevated bool) (winapi.Token, supervi
|
||||
}
|
||||
for _, attempt := range selection.Attempts {
|
||||
token, identity, err := openTokenForAttempt(attempt.Context, selected)
|
||||
if err == nil && manager.options.TestContextFailures[attempt.Context] {
|
||||
_ = token.Close()
|
||||
err = errors.New("native test fixture forced pre-launch context failure")
|
||||
}
|
||||
if err == nil {
|
||||
return token, withEvidence(identity), nil
|
||||
}
|
||||
@@ -396,6 +400,33 @@ func (manager *execSupervisor) selectToken(elevated bool) (winapi.Token, supervi
|
||||
return 0, supervisor.EffectiveIdentity{}, rejection(err)
|
||||
}
|
||||
}
|
||||
// Select stops at the first policy-available elevated context. Native
|
||||
// preparation can still fail after that point (a linked token can vanish or
|
||||
// SeTcbPrivilege can be unavailable), so preserve the documented order by
|
||||
// trying ACTIVE_SYSTEM before the final LOCAL_SYSTEM fallback. This is a
|
||||
// preparation fallback only: no child has been created yet.
|
||||
if elevated && selected != nil {
|
||||
seenActiveSystem := false
|
||||
for _, contextName := range attempted {
|
||||
if contextName == string(ContextActiveSystem) {
|
||||
seenActiveSystem = true
|
||||
break
|
||||
}
|
||||
}
|
||||
if !seenActiveSystem {
|
||||
addAttempt(ContextActiveSystem, "fallback after active-user-elevated preparation failure")
|
||||
if token, identity, err := openTokenForAttempt(ContextActiveSystem, selected); err == nil {
|
||||
if manager.options.TestContextFailures[ContextActiveSystem] {
|
||||
_ = token.Close()
|
||||
addAttempt(ContextActiveSystem, "native test fixture forced pre-launch context failure")
|
||||
} else {
|
||||
return token, withEvidence(identity), nil
|
||||
}
|
||||
} else {
|
||||
addAttempt(ContextActiveSystem, "native preparation failed: "+err.Error())
|
||||
}
|
||||
}
|
||||
}
|
||||
// The pure selector stops as soon as ACTIVE_SYSTEM is available. A native
|
||||
// privilege/session operation can still fail (for example, SeTcb was
|
||||
// removed), so the final LOCAL_SYSTEM fallback is attempted here before
|
||||
|
||||
Reference in New Issue
Block a user