installed-update-network.ps1 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. param([string]$Script, [string]$Plan, [string]$Case)
  2. $ErrorActionPreference = 'Stop'
  3. [Console]::OutputEncoding = [Text.UTF8Encoding]::new()
  4. $spec = Get-Content -LiteralPath $Plan -Raw -Encoding UTF8 | ConvertFrom-Json
  5. $global:dshNetworkRules = @()
  6. $global:dshNetworkCreated = 0
  7. $global:dshNetworkRemoved = 0
  8. function Get-NetFirewallRule { param($PolicyStore) return $global:dshNetworkRules }
  9. function Get-NetFirewallApplicationFilter {
  10. param([Parameter(ValueFromPipeline = $true)]$InputObject)
  11. process { return [pscustomobject]@{ Program = $InputObject.Program } }
  12. }
  13. function New-NetFirewallRule {
  14. param($Name, $DisplayName, $Description, $Direction, $Program, $Action, $Profile, $Enabled, $PolicyStore)
  15. $global:dshNetworkCreated++
  16. if ($Case -eq 'creation-failure') { throw 'inert creation failure' }
  17. $global:dshNetworkRules = @([pscustomobject]@{ Name = $Name; Description = $Description; Direction = $Direction;
  18. Program = $Program; Action = $Action; Enabled = $Enabled; Profile = $Profile; PolicyStore = $PolicyStore })
  19. return $global:dshNetworkRules
  20. }
  21. function Remove-NetFirewallRule {
  22. param([Parameter(ValueFromPipeline = $true)]$InputObject)
  23. process {
  24. $global:dshNetworkRemoved++
  25. if ($Case -ne 'restore-failure') { $global:dshNetworkRules = @() }
  26. }
  27. }
  28. function Read-Host {
  29. param($Prompt)
  30. if ($Case -in @('declined', 'restore-declined')) { return 'NO' }
  31. if ($Case -eq 'changed-during-confirmation') { [IO.File]::WriteAllText($spec.executable, 'changed during confirmation') }
  32. if ($Prompt -like 'Type RESTORE*') { return "RESTORE $($spec.runId)" }
  33. return "BLOCK $($spec.runId)"
  34. }
  35. if ($Case -in @('existing', 'foreign', 'restore', 'restore-failure', 'restore-declined', 'status')) {
  36. $global:dshNetworkRules = @([pscustomobject]@{ Name = $spec.ruleName; Direction = 'Outbound'; Action = 'Block';
  37. Program = $spec.executable; Enabled = 'True'; Description = "dsh-update-qualification:$($spec.runId):$($spec.sha512Hex)" })
  38. if ($Case -eq 'foreign') { $global:dshNetworkRules[0].Program = 'C:\not-the-test-application.exe' }
  39. }
  40. $action = if ($Case -like 'restore*') { 'Restore' } elseif ($Case -eq 'status') { 'Status' } else { 'Block' }
  41. $failure = $null
  42. try { & $Script -Plan $Plan -Action $action } catch { $failure = $_.Exception.Message }
  43. @{ failure = $failure; created = $global:dshNetworkCreated; removed = $global:dshNetworkRemoved;
  44. remaining = $global:dshNetworkRules.Count } | ConvertTo-Json -Compress