Repository navigation
test(rules): the 7-only cmdlet, parameter and value tables are checked against both hosts - #12
Conversation
00a254a to
c745a01
Compare
fadwen
left a comment
There was a problem hiding this comment.
Notes on the lines whose reason the diff does not show.
| # Switch-Process is not here: PowerShell 7 has it on Linux and macOS only, so a script that | ||
| # calls it fails on both Windows hosts. Get-ChildItem -FollowSymlink is not here either: | ||
| # Windows PowerShell 5.0 already had it. Both were listed until the test below ran | ||
| Commands = [string[]]@( |
There was a problem hiding this comment.
Typed, here and for the Out-File value below, so a table cut down to one entry still serializes as an array when the test sends it to the hosts as JSON; a lone string would arrive as a scalar and the probe would iterate its characters.
| Commands = @($script:Table.Commands) | ||
| Parameters = @(foreach ($command in $script:Table.Parameters.Keys) { | ||
| @{ Command = $command; Parameters = @($script:Table.Parameters[$command]) } | ||
| }) + @(@{ Command = 'ForEach-Object'; Parameters = @('Parallel') }) |
There was a problem hiding this comment.
ForEach-Object -Parallel is not in the table because the rule handles it on its own path, with the REM-PS7-PARALLEL evidence. Added to the probe here so it is held against the hosts all the same.
| }) | ||
| } | ||
| $json = $flat | ConvertTo-Json -Depth 5 -Compress | ||
| $command = "& { $($probe.ToString()) } '$($json.Replace("'", "''"))'" |
There was a problem hiding this comment.
The table travels as a single-quoted literal argument inside the encoded command, so no JSON quoting crosses the command line, and -EncodedCommand carries the same bytes to both hosts.
| function script:Get-HostAnswer { | ||
| param([string]$Exe, [string]$Command) | ||
| $raw = & $Exe -NoProfile -NonInteractive -EncodedCommand $Command 2>&1 | ||
| ($raw | Where-Object { "$_".StartsWith('{') } | Select-Object -Last 1) | ConvertFrom-Json |
There was a problem hiding this comment.
Either host can print lines of its own before the answer: module import noise, or a stderr record merged in by 2>&1. The answer is the last line that starts with a brace.
|
|
||
| It 'every listed parameter is missing from the 5.1 command and present on the 7 one' { | ||
| $keys = @($script:Core.Parameters.PSObject.Properties.Name) | ||
| $keys.Count | Should-BeGreaterThan 30 |
There was a problem hiding this comment.
A guard that the probe answered at all. Without it a probe that failed to read the table would return no keys, and the three assertions would pass on an empty set.
…d against both hosts The tables IslPowerShell7Syntax reports from were kept by hand inside the rule; the 0.26.0 audit found entries that exist on neither host. They live in Get-IslCoreOnlyFeature now, and a unit test sends them to powershell.exe and pwsh.exe as child processes: every entry must be absent from 5.1 and present in 7. On its first run it found three more wrong entries, removed here: Switch-Process (Linux and macOS only), Invoke-WebRequest -StatusCodeVariable (neither host) and Get-ChildItem -FollowSymlink (in 5.1 since 5.0).
c745a01 to
54b42a1
Compare
Summary
IslPowerShell7Syntaxreports cmdlets, parameters and parameter values that PowerShell 7 has and Windows PowerShell 5.1 lacks, from tables kept by hand inside the rule. The 0.26.0 audit found two parameters there that exist on neither host, and a value the rule never matched. This moves the tables into one private function and adds a unit test that holds every entry against both hosts as child processes, so a wrong entry fails the suite instead of waiting for the next audit.The test found three more wrong entries on its first run, which this pull request also removes.
Changes
Private/Get-IslCoreOnlyFeature.ps1(new). The three tables,Commands,ParametersandValues, in one place; the rule reads them from here. No finding changes its message, severity or evidence;docs/Rules.mdis unchanged.Switch-Process: PowerShell 7 has it on Linux and macOS only, so a script calling it fails on both Windows hosts.Invoke-WebRequest -StatusCodeVariable: exists on neither host; onlyInvoke-RestMethodhas it.Get-ChildItem -FollowSymlink: Windows PowerShell has had it since 5.0.Tests/Unit/Private/Get-IslCoreOnlyFeature.Tests.ps1(new). Sends the tables topowershell.exeandpwsh.exeas child processes, which answer for every command whether it exists, for every parameter whether its command has it, and for every value whether the parameter'sValidateSettakes it. Each entry must be absent from 5.1 and present in 7; a value must be refused by 5.1 and taken by 7.ForEach-Object -Parallel, which the rule handles on its own, is checked the same way. The hosts are asked as child processes, so the test gives the same answer whichever host runs it; it is skipped where either executable is missing. CI's Windows runners have both.Verification
Notes
mainas its parent merges and the checks run then. The changelog's Unreleased section carries every entry of the stack.