diff --git a/CHANGELOG.md b/CHANGELOG.md index 400aaba..16e8e40 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -85,5 +85,8 @@ The format is based on copied a folder that contained files - Fix `Disable-Privileges`, which couldn't disable the privileges when the module setting `EnablePrivileges` was `$false` +- Fix the inheritance cmdlets, which enabled the Backup, Restore, Take + Ownership, and Security privileges even when the module setting + `EnablePrivileges` was `$false`, and left them enabled [Unreleased]: https://github.com/raandree/NTFSSecurity/compare/4.2.6...HEAD diff --git a/Docs/Cmdlets/Disable-NTFSAccessInheritance.md b/Docs/Cmdlets/Disable-NTFSAccessInheritance.md index 6c9d98b..4166f56 100644 --- a/Docs/Cmdlets/Disable-NTFSAccessInheritance.md +++ b/Docs/Cmdlets/Disable-NTFSAccessInheritance.md @@ -168,6 +168,8 @@ Blocking access inheritance requires permission to change the DACL of the item, A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Enable-NTFSAccessInheritance](Enable-NTFSAccessInheritance.md) diff --git a/Docs/Cmdlets/Disable-NTFSAuditInheritance.md b/Docs/Cmdlets/Disable-NTFSAuditInheritance.md index 59d9246..3e08779 100644 --- a/Docs/Cmdlets/Disable-NTFSAuditInheritance.md +++ b/Docs/Cmdlets/Disable-NTFSAuditInheritance.md @@ -170,6 +170,8 @@ If the descriptor cannot be opened because the account has no permission to the A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Enable-NTFSAuditInheritance](Enable-NTFSAuditInheritance.md) diff --git a/Docs/Cmdlets/Enable-NTFSAccessInheritance.md b/Docs/Cmdlets/Enable-NTFSAccessInheritance.md index 2d8fb50..dc029fc 100644 --- a/Docs/Cmdlets/Enable-NTFSAccessInheritance.md +++ b/Docs/Cmdlets/Enable-NTFSAccessInheritance.md @@ -167,6 +167,8 @@ Restoring access inheritance requires permission to change the DACL of the item, A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Disable-NTFSAccessInheritance](Disable-NTFSAccessInheritance.md) diff --git a/Docs/Cmdlets/Enable-NTFSAuditInheritance.md b/Docs/Cmdlets/Enable-NTFSAuditInheritance.md index fec40fe..f7c7704 100644 --- a/Docs/Cmdlets/Enable-NTFSAuditInheritance.md +++ b/Docs/Cmdlets/Enable-NTFSAuditInheritance.md @@ -169,6 +169,8 @@ If the descriptor cannot be opened because the account has no permission to the A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Disable-NTFSAuditInheritance](Disable-NTFSAuditInheritance.md) diff --git a/Docs/Cmdlets/Get-NTFSInheritance.md b/Docs/Cmdlets/Get-NTFSInheritance.md index a9b0656..e2d67ea 100644 --- a/Docs/Cmdlets/Get-NTFSInheritance.md +++ b/Docs/Cmdlets/Get-NTFSInheritance.md @@ -136,6 +136,8 @@ If the security descriptor of an item cannot be opened because the account has n A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Set-NTFSInheritance](Set-NTFSInheritance.md) diff --git a/Docs/Cmdlets/Set-NTFSInheritance.md b/Docs/Cmdlets/Set-NTFSInheritance.md index 51c45c2..f9986a8 100644 --- a/Docs/Cmdlets/Set-NTFSInheritance.md +++ b/Docs/Cmdlets/Set-NTFSInheritance.md @@ -194,6 +194,8 @@ A path that does not exist produces a non-terminating error and the cmdlet conti Before 5.0.0, omitting `-AccessInheritanceEnabled` or `-AuditInheritanceEnabled` could fail with the error "Nullable object must have a value". +Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. + ## RELATED LINKS [Get-NTFSInheritance](Get-NTFSInheritance.md) diff --git a/Docs/Concepts.md b/Docs/Concepts.md index d51cb0d..b9237bf 100644 --- a/Docs/Concepts.md +++ b/Docs/Concepts.md @@ -188,9 +188,9 @@ The access, audit, inheritance, owner, and security descriptor cmdlets enable these privileges automatically while they run and disable the ones they enabled when they finish. If a privilege cannot be enabled, the cmdlet continues without it. You can turn this behavior off with the -`EnablePrivileges` module setting. The inheritance cmdlets are an exception: -they always try to enable the privileges, and when `EnablePrivileges` is -`$false`, they leave them enabled. +`EnablePrivileges` module setting. Before 5.0.0, the inheritance cmdlets were +an exception: they always tried to enable the privileges, and when +`EnablePrivileges` was `$false`, they left them enabled. `Enable-Privileges` enables the four privileges for the current PowerShell process until you run `Disable-Privileges` or close the session. diff --git a/NTFSSecurity/InheritanceCmdlets/DisableAccessInheritance.cs b/NTFSSecurity/InheritanceCmdlets/DisableAccessInheritance.cs index 235a49b..d196fb7 100644 --- a/NTFSSecurity/InheritanceCmdlets/DisableAccessInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/DisableAccessInheritance.cs @@ -53,7 +53,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); } protected override void ProcessRecord() diff --git a/NTFSSecurity/InheritanceCmdlets/DisableAuditInheritance.cs b/NTFSSecurity/InheritanceCmdlets/DisableAuditInheritance.cs index e8c7769..ac603cf 100644 --- a/NTFSSecurity/InheritanceCmdlets/DisableAuditInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/DisableAuditInheritance.cs @@ -54,7 +54,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); } protected override void ProcessRecord() diff --git a/NTFSSecurity/InheritanceCmdlets/EnableAccessInheritance.cs b/NTFSSecurity/InheritanceCmdlets/EnableAccessInheritance.cs index f7cb8b5..672b98f 100644 --- a/NTFSSecurity/InheritanceCmdlets/EnableAccessInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/EnableAccessInheritance.cs @@ -53,7 +53,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); } protected override void ProcessRecord() diff --git a/NTFSSecurity/InheritanceCmdlets/EnableAuditInheritance.cs b/NTFSSecurity/InheritanceCmdlets/EnableAuditInheritance.cs index c25617b..3f29546 100644 --- a/NTFSSecurity/InheritanceCmdlets/EnableAuditInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/EnableAuditInheritance.cs @@ -53,7 +53,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); } protected override void ProcessRecord() diff --git a/NTFSSecurity/InheritanceCmdlets/GetInheritance.cs b/NTFSSecurity/InheritanceCmdlets/GetInheritance.cs index 895bf79..df19f8d 100644 --- a/NTFSSecurity/InheritanceCmdlets/GetInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/GetInheritance.cs @@ -38,7 +38,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); if (paths.Count == 0) { diff --git a/NTFSSecurity/InheritanceCmdlets/SetInheritance.cs b/NTFSSecurity/InheritanceCmdlets/SetInheritance.cs index a8effe7..3877e43 100644 --- a/NTFSSecurity/InheritanceCmdlets/SetInheritance.cs +++ b/NTFSSecurity/InheritanceCmdlets/SetInheritance.cs @@ -61,7 +61,6 @@ namespace NTFSSecurity protected override void BeginProcessing() { base.BeginProcessing(); - EnableFileSystemPrivileges(true); } protected override void ProcessRecord() diff --git a/NTFSSecurity/en-US/NTFSSecurity.dll-Help.xml b/NTFSSecurity/en-US/NTFSSecurity.dll-Help.xml index 5731ff5..0ba7b55 100644 --- a/NTFSSecurity/en-US/NTFSSecurity.dll-Help.xml +++ b/NTFSSecurity/en-US/NTFSSecurity.dll-Help.xml @@ -2412,6 +2412,7 @@ PS C:\> Set-NTFSSecurityDescriptor -SecurityDescriptor $sd When the module setting `EnablePrivileges` is `$true` (the default in the `PrivateData` section of NTFSSecurity.psd1), this cmdlet tries to enable the Backup, Restore, Take Ownership, and Security privileges while it runs and disables the privileges it enabled when it finishes. These privileges are only available in an elevated session of an account that holds them, such as a member of the local Administrators group. If a privilege cannot be enabled, the cmdlet continues without it and writes a debug message. Blocking access inheritance requires permission to change the DACL of the item, which the owner of an item always has. If the descriptor cannot be opened, the cmdlet takes ownership of the item, applies the change, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; otherwise the cmdlet writes an error and continues with the next item. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. @@ -2656,6 +2657,7 @@ PS C:\> Set-NTFSSecurityDescriptor -SecurityDescriptor $sd The audit section of a security descriptor can only be read and written with the Security privilege (`SeSecurityPrivilege`), which an account can only use in an elevated session. Without it, the cmdlet writes a non-terminating error that reports Windows error 1314, "A required privilege is not held by the client", and the audit rules of the item stay unchanged. If the descriptor cannot be opened because the account has no permission to the item, the cmdlet takes ownership of the item, applies the change, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; a missing Security privilege is not an access problem and is not repaired by it. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. @@ -3025,6 +3027,7 @@ PS C:\> Get-Privileges | Where-Object { $_.Privilege -in 'Backup', 'Restore', When the module setting `EnablePrivileges` is `$true` (the default in the `PrivateData` section of NTFSSecurity.psd1), this cmdlet tries to enable the Backup, Restore, Take Ownership, and Security privileges while it runs and disables the privileges it enabled when it finishes. These privileges are only available in an elevated session of an account that holds them, such as a member of the local Administrators group. If a privilege cannot be enabled, the cmdlet continues without it and writes a debug message. Restoring access inheritance requires permission to change the DACL of the item, which the owner of an item always has. If the descriptor cannot be opened, the cmdlet takes ownership of the item, applies the change, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; otherwise the cmdlet writes an error and continues with the next item. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. @@ -3269,6 +3272,7 @@ PS C:\> Set-NTFSSecurityDescriptor -SecurityDescriptor $sd The audit section of a security descriptor can only be read and written with the Security privilege (`SeSecurityPrivilege`), which an account can only use in an elevated session. Without it, the cmdlet writes a non-terminating error that reports Windows error 1314, "A required privilege is not held by the client", and the audit rules of the item stay unchanged. If the descriptor cannot be opened because the account has no permission to the item, the cmdlet takes ownership of the item, applies the change, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; a missing Security privilege is not an access problem and is not repaired by it. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. @@ -5430,6 +5434,7 @@ PS C:\> Get-NTFSAudit -SecurityDescriptor $sd Before 5.0.0, a security descriptor that was read without its audit section reported `AuditInheritanceEnabled` as `$true`. If the security descriptor of an item cannot be opened because the account has no permission to it, the cmdlet takes ownership of the item, reads the state, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; otherwise the cmdlet writes an error and continues with the next item. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. @@ -9391,6 +9396,7 @@ PS C:\> Set-NTFSSecurityDescriptor -SecurityDescriptor $sd If the descriptor cannot be opened because the account has no permission to the item, the cmdlet takes ownership of the item, applies the changes, and sets the previous owner back. That fallback only succeeds when the account can take ownership of the item and restore the original owner; otherwise the cmdlet writes an error and continues with the next item. A path that does not exist produces a non-terminating error and the cmdlet continues with the remaining paths. Before 5.0.0, omitting `-AccessInheritanceEnabled` or `-AuditInheritanceEnabled` could fail with the error "Nullable object must have a value". + Before 5.0.0, the cmdlet enabled the privileges even when `EnablePrivileges` was `$false`, and left them enabled. diff --git a/Tests/Privileges.Tests.ps1 b/Tests/Privileges.Tests.ps1 index 5070758..1ebfa5d 100644 --- a/Tests/Privileges.Tests.ps1 +++ b/Tests/Privileges.Tests.ps1 @@ -61,3 +61,28 @@ Describe 'Disable-Privileges' { } } } + +Describe 'Inheritance cmdlets' { + Context 'When the module setting EnablePrivileges is $false' { + BeforeAll { + $privateData['EnablePrivileges'] = $false + $file = New-TestSandboxItem -Sandbox $sandbox -Name 'Inheritance' + } + + AfterAll { + $privateData['EnablePrivileges'] = $enablePrivileges + } + + # Before 5.0.0, the inheritance cmdlets enabled the privileges anyway and left them enabled. + It '<_> should leave the privileges disabled' -Skip:(-not $holdsPrivileges) -ForEach @( + 'Get-NTFSInheritance', 'Set-NTFSInheritance', 'Enable-NTFSAccessInheritance', + 'Disable-NTFSAccessInheritance', 'Enable-NTFSAuditInheritance', 'Disable-NTFSAuditInheritance' + ) { + Get-BackupPrivilegeState | Should -Be 'Disabled' + + & $_ -Path $file -ErrorAction SilentlyContinue | Out-Null + + Get-BackupPrivilegeState | Should -Be 'Disabled' + } + } +}