Repository navigation
require opt-in for PowerShell whole-drive read access - #1463
Open
Matt Van Horn (mvanhorn) wants to merge 1 commit into
Open
Matt Van Horn (mvanhorn) wants to merge 1 commit into
Matt Van Horn (mvanhorn) wants to merge 1 commit into
Conversation
The drive root is added only when allowPowerShellDriveRootRead is true; the default is false. Finding pwsh.exe still adds the PSReadLine history directory to readwritePaths, and a drive root that is already a PATH entry is still returned as a tool directory. The README and the helper comments state that the opt-in permits recursive whole-drive reads on BaseContainer, and they point at wxc-host-prep prepare-system-drive or enumeratePaths for a root check that does not grant subtree reads. FilesystemPolicyResult still only carries readonlyPaths and readwritePaths. Fixes microsoft#1455
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The Rust helper remains vulnerable by default, and public Node documentation is incomplete or misleading.
4 open findings
What changed in this PR
Makes PowerShell whole-drive read access opt-in for Node SDK filesystem discovery.
Changes:
- Adds
allowPowerShellDriveRootRead. - Preserves PowerShell history/tool discovery.
- Adds tests and security guidance.
| File | Description |
|---|---|
sdk/node/src/v1/policy/filesystem.ts |
Gates synthetic drive-root grants. |
sdk/node/tests/unit/policy.test.ts |
Tests opt-in and discovery behavior. |
sdk/node/README.md |
Documents security implications and alternatives. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+342
to
+345
| const pwshPolicy = getPowerShellPolicy( | ||
| pathDirs, | ||
| environment, | ||
| options?.allowPowerShellDriveRootRead === true, |
Comment on lines
+267
to
+272
| emit a diagnostic warning. When `pwsh.exe` is on `PATH`, discovery adds the | ||
| PSReadLine history directory to `readwritePaths` and leaves the system-drive | ||
| root out of `readonlyPaths`. Set `allowPowerShellDriveRootRead: true` to | ||
| restore that root for callers who accept the compatibility grant. On | ||
| BaseContainer, a drive-root `readonlyPaths` entry permits recursive reads of | ||
| the whole drive, including unrelated user files. `getUserProfilePolicy` uses |
Comment on lines
+44
to
+48
| * Defaults to `false`. Opting in permits recursive whole-drive reads on | ||
| * BaseContainer. PowerShell startup that only needs to stat the drive root | ||
| * should use host preparation or tier-supported configuration instead. | ||
| */ | ||
| allowPowerShellDriveRootRead?: boolean; |
Comment on lines
+289
to
+295
| * Additionally, if PowerShell (`pwsh.exe`) is found on PATH, the PSReadLine | ||
| * history directory is added to `readwritePaths`. The system-drive root is | ||
| * added to `readonlyPaths` only when `options.allowPowerShellDriveRootRead` | ||
| * is true (the default is `false`). That opt-in permits recursive whole-drive | ||
| * reads on BaseContainer. PowerShell startup that stats the drive root may | ||
| * need explicit host preparation or tier-supported configuration; the opt-in | ||
| * is the compatibility path for callers who accept the broad read. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


📖 Description
The drive root is added only when allowPowerShellDriveRootRead is true; the default is false. Finding pwsh.exe still adds the PSReadLine history directory to readwritePaths, and a drive root that is already a PATH entry is still returned as a tool directory. The README and the helper comments state that the opt-in permits recursive whole-drive reads on BaseContainer, and they point at wxc-host-prep prepare-system-drive or enumeratePaths for a root check that does not grant subtree reads. FilesystemPolicyResult still only carries readonlyPaths and readwritePaths.
With PowerShell 7 on PATH, getAvailableToolsPolicy puts the system-drive root in readonlyPaths. On BaseContainer that entry covers the whole drive, so a sandbox built from the recommended discovery baseline can list and read every file the user can, including the profile and credential stores, and the policy result gives no sign that reads are no longer limited. getPowerShellPolicy appended SystemDrive (falling back to C:) plus a trailing slash to readonlyPaths whenever it found pwsh.exe. BaseContainer treats a drive-root readonly path as a recursive read of the subtree, so the grant meant to let PowerShell stat the root became a whole-drive content read.
Fixes #1455
🔗 References
Not applicable to this change.
🔍 Validation
Ran
cargo test --workspacelocally; it fails the same way on the base branch, so the failure predates this change (it fails the same way on main).Tests for this live in
sdk/node/tests/unit/policy.test.ts.✅ Checklist
Left unticked: nothing in this change to
sdk/node/src/v1/policy/filesystem.tsbacks it.Cargo.lock, thedependency-feed-checkcheck passes (see pull request builds)Not claimed: ran
cargo test --workspacelocally; it fails the same way on the base branch, so the failure predates this change (it fails the same way on main).📋 Issue Type
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(
MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHubActions build; it runs on merge to
main, and Microsoft reviewers with write access can trigger iton a PR with
/azp run. See pull request builds.If the
dependency-feed-checkcheck fails on a new dependency, the crate must be added tothe feed before the PR can pass. See pull request builds
for the steps.
AI was used for assistance.
Microsoft Reviewers: Open in CodeFlow