Remediate Set-ToolsRepo external download security risk - #422
Merged
Kavyareddyguntaka11 merged 7 commits intoSep 21, 2026
Merged
Conversation
…efactor into focused helper functions
…d require source datastore, ZIP path, and SHA-256 hash in upload mode
Kavyareddyguntaka11
force-pushed
the
kguntaka/39455329-Remediate-set-toolsrepo
branch
from
September 14, 2026 17:12
a3a4bde to
378aea7
Compare
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Seven unresolved review findings remain in the implementation.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This PR replaces external VMware Tools downloads with staged vSAN uploads, integrity validation, and expanded failure handling.
Changes:
- Adds datastore, ZIP path, and SHA-256 hash inputs.
- Validates paths, archives, metadata, and versions.
- Expands cleanup, datastore handling, host configuration, and Pester coverage.
File summaries
| File | Summary |
|---|---|
tests/Microsoft.AVS.Management.Tests.ps1 |
Adds coverage for validation, hash/archive errors, metadata, cleanup, version handling, and partial failures. |
Microsoft.AVS.Management/Microsoft.AVS.Management.psm1 |
Implements the staged-upload workflow. Findings remain at lines 181, 430, 526, 651, 793, 815, and 833: six moderate findings (votes: 2, 2, 2, 1, 1, 1) and one nit (1 vote) concerning metadata consistency, rollback, sanitization, PSDrive cleanup, missing or invalid metadata, and version-aware artifact copying. |
Review details
Suppressed comments (4)
Microsoft.AVS.Management/Microsoft.AVS.Management.psm1:837
- This condition now gates the copy of every non-metadata file from
windows64on the incoming version being newer. The previous flow copied those top-level GuestStore artifacts for every upload and only gatedmetadata.json; uploading an older version will therefore leave its top-level artifacts absent, even though its version folder is stored. Keep the artifact-copy block unconditional and apply$shouldUpdateTopLevelMetadataonly to the top-level metadata file.
# Update top-level files only when the uploaded version is newer.
if ($shouldUpdateTopLevelMetadata) {
# Copy any additional top-level files from windows64, if present.
# Handle metadata.json separately below.
$topLevelSourceDir = Split-Path -Path $sourceDir -Parent
Microsoft.AVS.Management/Microsoft.AVS.Management.psm1:795
- When the destination already has a higher version but its top-level
metadata.jsonis missing,$highestExistingVersionis non-null and this condition preserves the missing file. The upload then reports success while leaving a repository that-Validatewill reject at the required top-level metadata check; treat a missing top-level metadata file as an update condition or fail before copying.
if ($null -eq $highestExistingVersion -or
(Compare-ToolsRepoVersion -Left $tools_short_version -Right $highestExistingVersion) -gt 0) {
$shouldUpdateTopLevelMetadata = $true
Microsoft.AVS.Management/Microsoft.AVS.Management.psm1:821
- An existing version folder is treated as valid solely because a
metadata.jsonfile exists. If that file is malformed or describes a different version, upload mode skips the verified archive and still proceeds to host configuration, so the command can report success while the same repository fails-Validate. Parse and verify the existing metadata before skipping the copy, or fail this datastore when it is invalid.
if (Test-Path -Path $versionDestPath) {
$versionMetadataPath = Join-Path -Path $versionDestPath -ChildPath 'metadata.json'
if (-not (Test-Path -Path $versionMetadataPath -PathType Leaf)) {
throw "Version folder '$tools_version' already exists on datastore '$ds_name', but its required metadata.json is missing. Inspect the folder and, if it is incomplete, remove it and rerun Set-ToolsRepo."
}
Write-Information "Version $tools_version already exists on $ds_name. Skipping copy." -InformationAction Continue
Microsoft.AVS.Management/Microsoft.AVS.Management.psm1:529
- This new upload path bypasses the module's established string-input sanitization:
Get-EsxtopDatasanitizes each string parameter before use (Microsoft.AVS.Management.psm1:1101-1104), butSourceDatastoreName,ToolsZipPath, andExpectedHashare passed directly here. Apply the same sanitizer or an equivalent reject-before-use check to all three inputs before invoking datastore/provider commands.
# Source datastore details and a trusted hash are required for upload mode.
if (-not $Validate) {
Test-ToolsRepoUploadInput -SourceDatastoreName $SourceDatastoreName -ToolsZipPath $ToolsZipPath -ExpectedHash $ExpectedHash
}
- Files reviewed: 2/2 changed files
- Comments generated: 3
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Contributor
|
I'd put a number of comments into the code to help someone who is trying to troubleshoot it. |
Lara Bailen Boluda (larabail)
previously approved these changes
Sep 16, 2026
Eugene Tolmachev (et1975)
approved these changes
Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR partially addresses IcM#850732573.
This PR contains the Set-ToolsRepo changes and incorporates the legacy Set-CustomDRS cleanup from #419. The storage module changes will be submitted in a separate PR.
The changes in this PR are as follows:
ToolsURLdownload flow. The VMware Tools ZIP must now be uploaded to a staging folder on a vSAN datastore before running the command.SourceDatastoreName,ToolsZipPath, andExpectedHashinputs for upload mode.Set-ToolsRepointo smaller helper functions for input validation, archive handling, version comparison, datastore discovery, and ESXi host configuration.windows64directory, version folder, and both requiredmetadata.jsonfiles.Validation performed
Set-ToolsRepo -Validatereported synchronized metadata on both datastores after each upload.I have read the contributor guidelines and have completed the following:
AVSAttributeto newly exported functions.