diff --git a/tests/Test-ConfigurationReadOnlyWindows.ps1 b/tests/Test-ConfigurationReadOnlyWindows.ps1 index 87597fa9..a95f35d3 100644 --- a/tests/Test-ConfigurationReadOnlyWindows.ps1 +++ b/tests/Test-ConfigurationReadOnlyWindows.ps1 @@ -13,4 +13,7 @@ catch { $caught = $_.ToString() } if ($caught -notmatch 'exit: 9' -or $caught -notmatch 'WELA-smoke-diagnostic') { throw "Native exit/stderr capture failed: $caught" } +# The intentionally failed child was asserted above; do not leak its expected +# exit code into a CI shell wrapper after a successful smoke test. +$global:LASTEXITCODE = 0 Write-Host "Read-only Windows smoke checks passed (process creation audit mask: $mask). No Windows settings changed." diff --git a/tests/Test-ConfigurationResults.ps1 b/tests/Test-ConfigurationResults.ps1 index f7b7b954..2e552e56 100644 --- a/tests/Test-ConfigurationResults.ps1 +++ b/tests/Test-ConfigurationResults.ps1 @@ -166,6 +166,9 @@ try { $encoded = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes($child)) $childOutput = @(& $engine -NoProfile -EncodedCommand $encoded 2>&1) $childExit = $global:LASTEXITCODE + # GitHub's PowerShell wrapper propagates LASTEXITCODE after the script. This + # child was deliberately failed; assertions below decide the test outcome. + $global:LASTEXITCODE = 0 Assert ($childExit -eq 1) 'The actual configure dispatcher returns nonzero for a failed control report' # CA-specific wrapper: registry read succeeds, certutil succeeds, restart