Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/BinSkim.Driver/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@
</security>
</trustInfo>

<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>

<file name="msdia140.dll">
<comClass description="Debug Information Accessor" clsid="{E6756135-1E65-4D17-8576-610761398C3C}" threadingModel = "Both"/>
</file>
Expand Down
2 changes: 1 addition & 1 deletion src/Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
<PackageVersion Include="ELFSharp" Version="2.17.3" />
<PackageVersion Include="FluentAssertions" Version="7.0.0" />
<PackageVersion Include="Microsoft.ApplicationInsights" Version="2.22.0" />
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.12.0" />
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.14.1" />

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this was needed since the testhost binary itself was made longPathAware in that version

<PackageVersion Include="Moq" Version="4.20.72" />
<PackageVersion Include="Newtonsoft.Json" Version="13.0.3" />
<PackageVersion Include="Sarif.Driver" Version="4.6.0" />
Expand Down
63 changes: 57 additions & 6 deletions src/Test.FunctionalTests.BinSkim.Rules/RuleTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,11 @@
using Microsoft.CodeAnalysis.IL.Sdk;
using Microsoft.CodeAnalysis.Sarif;
using Microsoft.CodeAnalysis.Sarif.Driver;
using Microsoft.Win32;

using Xunit;
using Xunit.Abstractions;
using Xunit.Sdk;

namespace Microsoft.CodeAnalysis.IL.Rules
{
Expand Down Expand Up @@ -94,17 +96,23 @@ private void Verify(
foreach (string target in targets)
{
context = CreateContext(logger, policy, target);
try
{
if (!context.IsValidAnalysisTarget) { continue; }

if (!context.IsValidAnalysisTarget) { continue; }
context.Rule = skimmer;

context.Rule = skimmer;
if (skimmer.CanAnalyze(context, out string reasonForNotAnalyzing) != AnalysisApplicability.ApplicableToSpecifiedTarget)
{
continue;
}

if (skimmer.CanAnalyze(context, out string reasonForNotAnalyzing) != AnalysisApplicability.ApplicableToSpecifiedTarget)
skimmer.Analyze(context);
}
finally
{
continue;
context.Dispose();

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this was needed since otherwise the context was leaking and keeping file handles open

}

skimmer.Analyze(context);
}

var failTargets = new HashSet<string>(logger.ErrorTargets.Union(logger.WarningTargets));
Expand Down Expand Up @@ -1197,6 +1205,49 @@ public void BA2022_SignSecurely_Pass()
}
}

[Fact]
public void BA2022_SignSecurely_LongPath_Pass()
{
const int maxPath = 260;

if (!OperatingSystem.IsWindows()) { return; }

const string fileSystemKey = @"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem";
if (!Equals(Registry.GetValue(fileSystemKey, "LongPathsEnabled", defaultValue: 0), 1))
{
throw SkipException.ForSkip("Windows long-path support is not enabled.");
}

string kernel32Path = Environment.GetFolderPath(Environment.SpecialFolder.System);
kernel32Path = Path.Combine(kernel32Path, "kernel32.dll");

string tempRoot = Path.Combine(Path.GetTempPath(), $"{nameof(BA2022_SignSecurely_LongPath_Pass)}-{Guid.NewGuid():N}");
string longDirectory = tempRoot;
string targetFile = "";

try
{
do
{
longDirectory = Path.Combine(longDirectory, new string('a', 32));
targetFile = Path.Combine(longDirectory, Path.GetFileName(kernel32Path));
} while (targetFile.Length <= maxPath);

Directory.CreateDirectory(longDirectory);
File.Copy(kernel32Path, targetFile);

Assert.True(targetFile.Length > maxPath);
this.VerifyPass(new SignSecurely(), additionalTestFiles: new[] { targetFile });
}
finally
{
if (Directory.Exists(tempRoot))
{
Directory.Delete(tempRoot, recursive: true);
}
}
}

[Fact]
public void BA2022_SignSecurely_NotApplicable()
{
Expand Down