diff --git a/tests/IntegrationNtlmConfiguration.Tests.ps1 b/tests/IntegrationNtlmConfiguration.Tests.ps1 index f5e546e4..540f70d1 100644 --- a/tests/IntegrationNtlmConfiguration.Tests.ps1 +++ b/tests/IntegrationNtlmConfiguration.Tests.ps1 @@ -1,5 +1,7 @@ # Composed #362/#363/#365 behavior, using mock registry/CIM and temporary journals only. $ErrorActionPreference = 'Stop' +# Keep mocks in the same script scope as dot-sourced helpers/imported commands; +# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks. $repo = Split-Path $PSScriptRoot -Parent $script:ScriptRoot = $repo . (Join-Path $repo 'scripts/Configuration.ps1') @@ -29,30 +31,30 @@ function Reset-Mocks($Outgoing = 0, $Domain = 2, $ProductType = 2) { $script:writes = 0; $script:readFails = $false; $script:writeFails = '' $script:roleFails = $false } -function global:Get-CimInstance { +function Get-CimInstance { param($ClassName, $Property, $Namespace, $ErrorAction) if ($ClassName -eq 'Win32_OperatingSystem') { if ($script:roleFails) { throw 'Mock role query failure' } return [pscustomobject]@{ ProductType = $script:productType } } } -function global:Test-Path { +function Test-Path { param($LiteralPath, $Path, $ErrorAction) $target = if ($LiteralPath) { $LiteralPath } else { $Path } if ($target -like 'HKLM:*') { return $true } Microsoft.PowerShell.Management\Test-Path -LiteralPath $target } -function global:Get-ItemProperty { +function Get-ItemProperty { param($LiteralPath, $ErrorAction) if ($script:readFails) { throw 'Mock registry read failure' } return [pscustomobject]$script:registry } -function global:Get-WelaRegistryState { +function Get-WelaRegistryState { param($Path, $Name) if ($script:readFails) { throw 'Mock registry read failure' } [pscustomobject]@{ KeyExists = $true; ValueExists = ($null -ne $script:registry[$Name]); Value = $script:registry[$Name]; Type = 'DWord' } } -function global:Set-ItemProperty { +function Set-ItemProperty { param($LiteralPath, $Name, $Value, $Type, $ErrorAction) # Assert the actual mutation cannot run before its matching journal entry. $journal = Join-Path $script:currentContext.BackupPath 'before.jsonl' diff --git a/tests/IntegrationProfileConfiguration.Tests.ps1 b/tests/IntegrationProfileConfiguration.Tests.ps1 index e4188cf2..9fb75430 100644 --- a/tests/IntegrationProfileConfiguration.Tests.ps1 +++ b/tests/IntegrationProfileConfiguration.Tests.ps1 @@ -1,5 +1,7 @@ # Profile command + verified configuration integration. No Windows policy is touched. $ErrorActionPreference = 'Stop' +# Keep mocks in the same script scope as dot-sourced helpers/imported commands; +# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks. $repo = Split-Path $PSScriptRoot -Parent $script:ScriptRoot = $repo Import-Module (Join-Path $repo 'modules/AuditProfiles.psm1') -Force @@ -44,16 +46,16 @@ function Reset-Run([string]$Profile = 'cis-win11-v4-l1', [switch]$DryRun) { $script:cleanup.Add($script:BackupPath) $script:cleanup.Add($script:ResultsPath) } -function global:TestWindows { return $true } -function global:TestAdministrator { return $true } -function global:Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } } -function global:Get-WelaEffectiveAuditPolicy { return $script:state.Clone() } -function global:Get-WelaNativeAuditPolicy { +function TestWindows { return $true } +function TestAdministrator { return $true } +function Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } } +function Get-WelaEffectiveAuditPolicy { return $script:state.Clone() } +function Get-WelaNativeAuditPolicy { param($Guid) if (-not $script:state.ContainsKey($Guid)) { throw "Mock missing policy: $Guid" } return $script:state[$Guid] } -function global:Invoke-WelaNative { +function Invoke-WelaNative { param($FilePath, $Arguments) if ($FilePath -ne 'auditpol.exe' -or $Arguments[0] -ne '/set') { throw 'Unexpected native mutation' } $guid = ($Arguments | Where-Object { $_ -like '/subcategory:*' }) -replace '^/subcategory:\{([^}]+)\}$', '$1' diff --git a/tests/IntegrationSafety.Tests.ps1 b/tests/IntegrationSafety.Tests.ps1 index d655b9ac..a149dee4 100644 --- a/tests/IntegrationSafety.Tests.ps1 +++ b/tests/IntegrationSafety.Tests.ps1 @@ -1,6 +1,8 @@ # Safety regressions use extracted dispatcher statements with stub mutators and mocked registry APIs. # Never dot-source WELA or invoke configure-sacl/update-rules implementations from this test. $ErrorActionPreference = 'Stop' +# Keep mocks in the same script scope as dot-sourced helpers/imported commands; +# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks. $repo = Split-Path $PSScriptRoot -Parent $tokens = $null; $errors = $null $ast = [Management.Automation.Language.Parser]::ParseFile((Join-Path $repo 'WELA.ps1'), [ref]$tokens, [ref]$errors) @@ -54,26 +56,26 @@ function New-RaceContext([switch]$Prompt) { $script:cleanup.Add($path) New-WelaConfigurationContext -Auto:(-not $Prompt) -BackupPath $path } -function global:Get-WelaOutgoingNtlmState { +function Get-WelaOutgoingNtlmState { # The first display is deliberately stale; the shared runner must trust its own fresh read. [pscustomobject]@{ Readable = $true; Value = 0; Description = 'Allow all (initial read)'; PolicySource = 'mock' } } -function global:Get-WelaRegistryState { +function Get-WelaRegistryState { param($Path, $Name) if ($script:journalWritten -and $script:prewriteReadFails) { throw 'Mock prewrite read failure' } [pscustomobject]@{ KeyExists = $true; ValueExists = $true; Value = $script:value; Type = $script:type } } -function global:New-WelaRegistryKey { param($Path) } -function global:Set-ItemProperty { +function New-WelaRegistryKey { param($Path) } +function Set-ItemProperty { param($LiteralPath, $Name, $Value, $Type, $ErrorAction) $script:value = $Value; $script:type = $Type; $script:writes++ } -function global:Read-Host { +function Read-Host { param($Prompt) if ($null -ne $script:changeOnPrompt) { $script:value = $script:changeOnPrompt } return 'Y' } -function global:Add-Content { +function Add-Content { param($LiteralPath, $Value, $Encoding, $ErrorAction) process { # Preserve real temporary recovery files; only the mocked policy state changes.