Skip to content

require opt-in for PowerShell whole-drive read access - #1463

Open
Matt Van Horn (mvanhorn) wants to merge 1 commit into
microsoft:mainfrom
mvanhorn:fix/1455-powershell-drive-root-opt-in
Open

Matt Van Horn (mvanhorn) wants to merge 1 commit into
microsoft:mainfrom
mvanhorn:fix/1455-powershell-drive-root-opt-in

Conversation

@mvanhorn

@mvanhorn Matt Van Horn (mvanhorn) commented Oct 10, 2026 •

Copy link
Copy Markdown

📖 Description

The drive root is added only when allowPowerShellDriveRootRead is true; the default is false. Finding pwsh.exe still adds the PSReadLine history directory to readwritePaths, and a drive root that is already a PATH entry is still returned as a tool directory. The README and the helper comments state that the opt-in permits recursive whole-drive reads on BaseContainer, and they point at wxc-host-prep prepare-system-drive or enumeratePaths for a root check that does not grant subtree reads. FilesystemPolicyResult still only carries readonlyPaths and readwritePaths.

With PowerShell 7 on PATH, getAvailableToolsPolicy puts the system-drive root in readonlyPaths. On BaseContainer that entry covers the whole drive, so a sandbox built from the recommended discovery baseline can list and read every file the user can, including the profile and credential stores, and the policy result gives no sign that reads are no longer limited. getPowerShellPolicy appended SystemDrive (falling back to C:) plus a trailing slash to readonlyPaths whenever it found pwsh.exe. BaseContainer treats a drive-root readonly path as a recursive read of the subtree, so the grant meant to let PowerShell stat the root became a whole-drive content read.

Fixes #1455

🔗 References

Not applicable to this change.

🔍 Validation

Ran cargo test --workspace locally; it fails the same way on the base branch, so the failure predates this change (it fails the same way on main).
Tests for this live in sdk/node/tests/unit/policy.test.ts.

✅ Checklist

  • Signed the Contributor License Agreement
    Left unticked: nothing in this change to sdk/node/src/v1/policy/filesystem.ts backs it.
  • Linked to an issue
  • Updated documentation (if applicable)
  • Updated Copilot instructions (if build, architecture, or conventions changed)
  • If this PR changes Cargo.lock, the dependency-feed-check check passes (see pull request builds)
    Not claimed: ran cargo test --workspace locally; it fails the same way on the base branch, so the failure predates this change (it fails the same way on main).

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See pull request builds.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See pull request builds
for the steps.

AI was used for assistance.

Microsoft Reviewers: Open in CodeFlow

The drive root is added only when allowPowerShellDriveRootRead is true;
the default is false. Finding pwsh.exe still adds the PSReadLine history
directory to readwritePaths, and a drive root that is already a PATH
entry is still returned as a tool directory. The README and the helper
comments state that the opt-in permits recursive whole-drive reads on
BaseContainer, and they point at wxc-host-prep prepare-system-drive or
enumeratePaths for a root check that does not grant subtree reads.
FilesystemPolicyResult still only carries readonlyPaths and
readwritePaths.

Fixes microsoft#1455

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The Rust helper remains vulnerable by default, and public Node documentation is incomplete or misleading.

4 open findings
What changed in this PR

Makes PowerShell whole-drive read access opt-in for Node SDK filesystem discovery.

Changes:

  • Adds allowPowerShellDriveRootRead.
  • Preserves PowerShell history/tool discovery.
  • Adds tests and security guidance.
File Description
sdk/​node/​src/​v1/​policy/​filesystem.ts Gates synthetic drive-root grants.
sdk/​node/​tests/​unit/​policy.test.ts Tests opt-in and discovery behavior.
sdk/​node/​README.md Documents security implications and alternatives.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +342 to +345
const pwshPolicy = getPowerShellPolicy(
pathDirs,
environment,
options?.allowPowerShellDriveRootRead === true,
Comment thread sdk/node/README.md
Comment on lines +267 to +272
emit a diagnostic warning. When `pwsh.exe` is on `PATH`, discovery adds the
PSReadLine history directory to `readwritePaths` and leaves the system-drive
root out of `readonlyPaths`. Set `allowPowerShellDriveRootRead: true` to
restore that root for callers who accept the compatibility grant. On
BaseContainer, a drive-root `readonlyPaths` entry permits recursive reads of
the whole drive, including unrelated user files. `getUserProfilePolicy` uses
Comment on lines +44 to +48
* Defaults to `false`. Opting in permits recursive whole-drive reads on
* BaseContainer. PowerShell startup that only needs to stat the drive root
* should use host preparation or tier-supported configuration instead.
*/
allowPowerShellDriveRootRead?: boolean;
Comment on lines +289 to +295
* Additionally, if PowerShell (`pwsh.exe`) is found on PATH, the PSReadLine
* history directory is added to `readwritePaths`. The system-drive root is
* added to `readonlyPaths` only when `options.allowPowerShellDriveRootRead`
* is true (the default is `false`). That opt-in permits recursive whole-drive
* reads on BaseContainer. PowerShell startup that stats the drive root may
* need explicit host preparation or tier-supported configuration; the opt-in
* is the compatibility path for callers who accept the broad read.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

getAvailableToolsPolicy grants read access to the whole system drive on BaseContainer when pwsh is on PATH

2 participants