You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Package source names are now matched more strictly. PowerShell and PowerShell7 source names use Unicode-aware, case-insensitive literal matching, while other package managers keep ASCII case-insensitive matching. The broker rejects requests whose source name has leading or trailing whitespace or default-ignorable code points before evaluating them. For PowerShell managers it also rejects wildcard characters (*, ?, [, ], and backtick). Policy validation rejects rules that use those spellings, and the validator version is now now-package-broker-policy-validator/11. Generated PowerShell commands pin the invariant culture so repository lookup does not depend on the host locale.
The broker also cleans up verified leftovers from an interrupted policy-store write probe instead of failing on them. Each named pipe connection's deadline now starts when the connection is accepted.
These are the general broker fixes from #1982, which will be closed. Its policy consent helper and write-authorization gate are not included.
source_index is derived from iterating the deserialized BTreeSet, not from the submitted JSON array, so sorting/deduplication can make this pointer identify the wrong element. For example, if the invalid spelling is second in input but sorts first, the finding reports /0. Validate against the raw SourceNames array to preserve indices, or report the collection path without an index.
Correct SAFETY rationale for UTF-16 CompareStringOrdinal operands
The operands passed to CompareStringOrdinal are UTF-16 vectors, not UTF-8 strings, so this SAFETY rationale describes the wrong representation. Use the same accurate rationale as the existing call in policy_security.rs:217.
This issue also appears on line 91 of the same file.
Use Unicode-aware literal matching for source names so a policy deny
uses the same case semantics as PowerShell repository lookup.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Normalize source names before ordinal matching so policy evaluation uses
the same canonical repository identity as PowerShell.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject source spellings containing default-ignorable characters before
PowerShell can resolve them to a different policy identity.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject default-ignorable source spellings before policy evaluation and
command construction can disagree.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Apply PowerShell source canonicalization only to PowerShell so other
package managers retain their own source identity semantics.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject policy source spellings that cannot safely match package requests
before they can create unusable source-specific rules.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Exercise ambiguous SourceNames with a valid PowerShell rule so the
regression protects the shared policy-validation predicate.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Retire only verified protected probe remnants after an interrupted write-capability check, and open probe files delete-on-close so an interrupted probe does not leave them behind.
Salvaged from 7b1446a (policy_store/windows.rs only).
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Start the per-connection deadline when the pipe client is accepted rather than when the spawned task first runs, so scheduling delay under load does not extend how long a client can hold a connection slot.
Salvaged from the generic part of 7abc416.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
PowerShell resolves -Repository through WildcardPattern using the current culture, so wildcard syntax or a host locale could select repositories that policy evaluation never matched. Reject PowerShell wildcard characters in request and policy source names, and pin generated PowerShell scripts to the invariant culture.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bump the policy validator version for the new source-name rejections, and make the probe recovery test fail on unexpected fixture errors instead of skipping.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
SourceNames is deserialized into a sorted set, so an element index could point at the wrong submitted entry. Report the SourceNames collection instead, and correct the CompareStringOrdinal safety rationale.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Package source names are now matched more strictly. PowerShell and PowerShell7 source names use Unicode-aware, case-insensitive literal matching, while other package managers keep ASCII case-insensitive matching. The broker rejects requests whose source name has leading or trailing whitespace or default-ignorable code points before evaluating them. For PowerShell managers it also rejects wildcard characters (
*,?,[,], and backtick). Policy validation rejects rules that use those spellings, and the validator version is nownow-package-broker-policy-validator/11. Generated PowerShell commands pin the invariant culture so repository lookup does not depend on the host locale.The broker also cleans up verified leftovers from an interrupted policy-store write probe instead of failing on them. Each named pipe connection's deadline now starts when the connection is accepted.
These are the general broker fixes from #1982, which will be closed. Its policy consent helper and write-authorization gate are not included.