Repository navigation
fix(repair): Repair-IntuneScript takes -Context, -Architecture and -EnforceSignatureCheck #16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -128,6 +128,37 @@ Describe 'Repair-IntuneScript' -Tag 'Unit', 'Public' { | |
| $fixed.Applied | Should-Be 1 | ||
| } | ||
|
|
||
| It 'hands -Context and -EnforceSignatureCheck to the analysis, on both runs' { | ||
| # Without them the repair analyzed every script under the inferred context whatever the | ||
| # caller deployed to, so Remaining could disagree with Test-IntuneScript run with the | ||
| # same options. HKCU: and USERPROFILE are two errors under System (REM-PROBE-SYS64) and | ||
| # under User the rule gives one note; an unsigned Win32 detection is an error only with | ||
| # the signature check enforced | ||
| $body = "Get-ItemProperty HKCU:\Software\Contoso`nTest-Path `$env:USERPROFILE\x`nexit 1" | ||
| $path = New-TestScript 'Remediations\F\Detect.ps1' $body -Bom | ||
| $asUser = Repair-IntuneScript -Path $path -Context User -IncludeRule IslContextIssue | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Limited to IslContextIssue because the rule gives one note under User (the Entra-join reminder) in place of the two System errors, so the total counts alone would be equal and prove nothing; the rule on its own gives 1 against 2. |
||
| $asSystem = Repair-IntuneScript -Path $path -Context System -IncludeRule IslContextIssue | ||
| $asUser.Remaining | Should-Be 1 | ||
| $asSystem.Remaining | Should-Be 2 | ||
|
|
||
| $unsigned = New-TestScript 'Win32\F\Detect-App.ps1' "if (Test-Path C:\x) { exit 0 }`nexit 1" -Bom | ||
| $enforced = Repair-IntuneScript -Path $unsigned -ScriptType Win32Detection -EnforceSignatureCheck | ||
| $plain = Repair-IntuneScript -Path $unsigned -ScriptType Win32Detection | ||
| $enforced.Remaining | Should-Be ($plain.Remaining + 1) | ||
| } | ||
|
|
||
| It 'counts the architecture the caller names, not the inferred one, in Remaining' { | ||
| # x86 is the portal default for a remediation, so the 32-bit System32 finding is there | ||
| # under Auto and gone under -Architecture x64 (REM-PROBE-SYS32) | ||
| $body = "Start-Process C:\Windows\System32\msiexec.exe -Wait`nexit 0" | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. A remediation infers x86, the portal default, where System32 is redirected (REM-PROBE-SYS32); -Architecture x64 is the native host and the finding goes. The third assertion compares the two repairs, so a change in the rule's other findings cannot hide a pass-through regression. |
||
| $folder = New-TestScript 'Remediations\G\Detect.ps1' $body -Bom | ||
| $inferred = Repair-IntuneScript -Path $folder | ||
| $native = Repair-IntuneScript -Path $folder -Architecture x64 | ||
| $inferred.Remaining | Should-Be (@(Test-IntuneScript -Path $folder).Count) | ||
| $native.Remaining | Should-Be (@(Test-IntuneScript -Path $folder -Architecture x64).Count) | ||
| $native.Remaining | Should-BeLessThan $inferred.Remaining | ||
| } | ||
|
|
||
| It 'expands a folder and reports one object per script' { | ||
| $folder = Join-Path $TestDrive 'Tree' | ||
| New-TestScript 'Tree\Remediations\One\Detect.ps1' "if (`$a) { return 'a' }`nexit 1" -Bom | Out-Null | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added to the splat only when set: Test-IntuneScript resolves an unset switch through the directive and the settings file, and a literal $false here would override both.