From 4ab4c275a52929b7b1e4327ea46c9e028218e7bc Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 14:57:47 +0900 Subject: [PATCH] Preserve positional bindings and propagate native fixture failures --- WELA.ps1 | 8 ++++---- tests/PowerShellLogging.Cli.Tests.ps1 | 3 +++ tests/PowerShellLogging.Windows.Tests.ps1 | 5 +++-- 3 files changed, 10 insertions(+), 6 deletions(-) diff --git a/WELA.ps1 b/WELA.ps1 index d6b438fa..3719b9fe 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -77,9 +77,6 @@ [string]$RuleEvidencePath, [string]$RuleCorpusPath, [string]$RuleManifestPath, - [ValidateSet('Audit','Plan','Configure')][string]$PowerShellLoggingAction = 'Audit', - [ValidateSet('ScriptBlock','Module')][string[]]$PowerShellLoggingControl, - [string[]]$PowerShellLoggingModuleName, [ValidateSet('Audit', 'Plan', 'Configure')][string]$TranscriptionAction = 'Audit', [string]$TranscriptDirectory, [ValidateSet('Audit','Plan','Configure')][string]$LdapAction = 'Audit', @@ -231,7 +228,10 @@ [ValidateRange(1,1024)][int]$MeasurementMaximumEvents = 256, [string]$MeasurementOutputPath, [switch]$MeasurementExportEvtx, - [switch]$Help + [switch]$Help, + [ValidateSet('Audit','Plan','Configure')][string]$PowerShellLoggingAction = 'Audit', + [ValidateSet('ScriptBlock','Module')][string[]]$PowerShellLoggingControl, + [string[]]$PowerShellLoggingModuleName ) $WELAVersion = "2.2.0" diff --git a/tests/PowerShellLogging.Cli.Tests.ps1 b/tests/PowerShellLogging.Cli.Tests.ps1 index b5304391..3a1da779 100644 --- a/tests/PowerShellLogging.Cli.Tests.ps1 +++ b/tests/PowerShellLogging.Cli.Tests.ps1 @@ -1,4 +1,7 @@ $ErrorActionPreference='Stop';$repo=Split-Path $PSScriptRoot -Parent;$engine=(Get-Process -Id $PID).Path;$count=0 +$parameterAst=[Management.Automation.Language.Parser]::ParseFile((Join-Path $repo 'WELA.ps1'),[ref]$null,[ref]$null).ParamBlock.Parameters +$names=@($parameterAst|ForEach-Object {$_.Name.VariablePath.UserPath});$helpIndex=[array]::IndexOf($names,'Help') +foreach($name in @('PowerShellLoggingAction','PowerShellLoggingControl','PowerShellLoggingModuleName')){if([array]::IndexOf($names,$name) -le $helpIndex){throw 'New logging parameters must follow existing Help to preserve legacy positional binding.'};$count++} $cases=@( @{Args=@('powershell-logging','-Help');Code=0;Pattern='Windows PowerShell 5.1'}, @{Args=@('configure','-PowerShellLoggingAction','Configure');Code=1;Pattern='require powershell-logging'}, diff --git a/tests/PowerShellLogging.Windows.Tests.ps1 b/tests/PowerShellLogging.Windows.Tests.ps1 index d6be351d..a494fbb7 100644 --- a/tests/PowerShellLogging.Windows.Tests.ps1 +++ b/tests/PowerShellLogging.Windows.Tests.ps1 @@ -37,8 +37,9 @@ param([string]$Repository,[string]$Request) $ErrorActionPreference='Stop' $data=Get-Content -LiteralPath $Request -Raw|ConvertFrom-Json;$options=@{} foreach($property in $data.PSObject.Properties){$options[$property.Name]=$property.Value} +$global:LASTEXITCODE=0 & (Join-Path $Repository 'WELA.ps1') @options -exit 0 +exit $LASTEXITCODE '@ | Set-Content -LiteralPath $wrapper -Encoding UTF8 function Public([string]$Label,[hashtable]$Parameters,[int]$ExpectedExit=0){ $Parameters.Cmd='powershell-logging';$Parameters.ResultsPath=Join-Path $root ($Label+'.json');$request=Join-Path $root ($Label+'-request.json');$Parameters|ConvertTo-Json -Depth 8|Set-Content -LiteralPath $request -Encoding UTF8 @@ -134,7 +135,7 @@ finally{ try{RemoveCreatedKeys $original.Machine}catch{$cleanupErrors+=$_.ToString()} try{$after=Get-WelaPsLoggingSnapshot;Save 'cleanup-after.json' $after;if((ConvertTo-WelaPsLoggingKey $after) -cne (ConvertTo-WelaPsLoggingKey $original)){$cleanupErrors+='Full policy/host/source/channel snapshot did not restore exactly.'};if($masks -and (Masks) -cne $masks){$cleanupErrors+='Audit masks changed.'}}catch{$cleanupErrors+=$_.ToString()} } - Save 'cleanup.json' @{Status=$(if($cleanupErrors.Count){'Failed'}else{'Restored'});Errors=$cleanupErrors;OriginalCaptured=[bool]$original;MutationStarted=$mutationStarted;All59MasksUnchanged=($masks -and (Masks) -ceq $masks)} + Save 'cleanup.json' @{Status=$(if($cleanupErrors.Count){'Failed'}elseif($mutationStarted){'Restored'}else{'NotMutated'});Errors=$cleanupErrors;OriginalCaptured=[bool]$original;MutationStarted=$mutationStarted;All59MasksUnchanged=($masks -and (Masks) -ceq $masks)} $artifacts=@(Get-ChildItem -LiteralPath $root -File -Recurse|ForEach-Object{[pscustomobject]@{Path=$_.FullName.Substring($root.Length+1);Sha256=(Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLowerInvariant()}}) Save 'manifest.json' @{Kind='WelaPowerShellLoggingNativeFixture';Head=$env:GITHUB_SHA;Engine=$PSVersionTable.PSVersion.ToString();Assertions=$script:count;Failure=$failure;CleanupErrors=$cleanupErrors;ReadyRuleCredit=0;Artifacts=$artifacts} }