Skip to content

fix(repair): Repair-IntuneScript takes -Context, -Architecture and -EnforceSignatureCheck - #16

Merged
fadwen merged 1 commit into
mainfrom
fix/repair-passes-analysis-options
Oct 6, 2026
Merged

fadwen merged 1 commit into
mainfrom
fix/repair-passes-analysis-options

Conversation

@fadwen

@fadwen fadwen commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

Repair-IntuneScript ran its analysis with Test-IntuneScript's defaults for the context, the architecture and the signature check, because it had no parameter to pass on for any of them. A script deployed to the 64-bit host in system context was repaired as the inferred script, so its findings, its fixes and the Remaining count could disagree with Test-IntuneScript run for the deployment. The command takes -Context, -Architecture and -EnforceSignatureCheck now, with the same values and defaults as Test-IntuneScript, and hands them to both analyses: the one that finds the fixes and the one that counts what is left after the write.

Changes

  • Public/Repair-IntuneScript.ps1. The three parameters, passed through in the splat both analyses share.
  • Help. Parameter descriptions and a fourth example; MAML rebuilt. README's repair paragraph names the options.
  • Tests. -Context changes Remaining the way it changes Test-IntuneScript's count (two errors for HKCU: and USERPROFILE under System, one note under User); -EnforceSignatureCheck adds the unsigned-script error for a Win32 detection; -Architecture x64 removes the 32-bit System32 finding that the remediation default reports, and Remaining equals Test-IntuneScript's count for the same value in both cases.

Verification

  • Unit and integration suites: 963 pass on PowerShell 7.6.6 (8 skipped: elevation, lab credential); Repair's tests and the module contract pass on Windows PowerShell 5.1 (29 of 29). PSScriptAnalyzer (Error and Warning) is clean; no new line over 115 characters; help Markdown validates and the MAML matches.

…nforceSignatureCheck

Repair-IntuneScript ran its analysis with Test-IntuneScript's defaults for
the context, the architecture and the signature check, because it had no
parameter to pass on for any of them. A script deployed to the 64-bit
host in system context was repaired as the inferred 32-bit user-or-system
script, so its findings, its fixes and the Remaining count could disagree
with Test-IntuneScript run for the deployment.

The command takes the three parameters now, with the same values and
defaults as Test-IntuneScript, and hands them to both analyses: the one
that finds the fixes and the one that counts what is left after the
write. Help and README updated; MAML rebuilt.

@fadwen fadwen left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Notes on the lines whose reason the diff does not show.

$testSplat = @{
Path = $file; ScriptType = $ScriptType; Context = $Context; Architecture = $Architecture
}
if ($EnforceSignatureCheck) { $testSplat.EnforceSignatureCheck = $true }

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added to the splat only when set: Test-IntuneScript resolves an unset switch through the directive and the settings file, and a literal $false here would override both.

# the signature check enforced
$body = "Get-ItemProperty HKCU:\Software\Contoso`nTest-Path `$env:USERPROFILE\x`nexit 1"
$path = New-TestScript 'Remediations\F\Detect.ps1' $body -Bom
$asUser = Repair-IntuneScript -Path $path -Context User -IncludeRule IslContextIssue

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Limited to IslContextIssue because the rule gives one note under User (the Entra-join reminder) in place of the two System errors, so the total counts alone would be equal and prove nothing; the rule on its own gives 1 against 2.

It 'counts the architecture the caller names, not the inferred one, in Remaining' {
# x86 is the portal default for a remediation, so the 32-bit System32 finding is there
# under Auto and gone under -Architecture x64 (REM-PROBE-SYS32)
$body = "Start-Process C:\Windows\System32\msiexec.exe -Wait`nexit 0"

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A remediation infers x86, the portal default, where System32 is redirected (REM-PROBE-SYS32); -Architecture x64 is the native host and the finding goes. The third assertion compares the two repairs, so a change in the rule's other findings cannot hide a pass-through regression.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant