Fix Authenticode checks when switching PowerShell editions - #136
AmirMS (AmelBawa-msft) wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Cross-edition signature verification needs Windows validation, and unresolved launcher and regression-harness issues require attention.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Improves Authenticode verification when Windows Dev Config runs across PowerShell editions.
Changes:
- Prioritizes native modules in bootstrap, elevation, and engine startup.
- Adds cross-edition checks for signatures, hashing, and permissions.
- Documents module handling and the Windows regression-check command.
| File | Description |
|---|---|
| src/windows-dev-config/README.md | Documents module prioritization and regression checks. |
| src/windows-dev-config/dev-config.ps1 | Prioritizes the running shell’s built-in modules. |
| src/windows-dev-config/bootstrap.ps1 | Applies module priority during bootstrap and elevation. |
| src/tests/calm-os/module-path-checks.ps1 | Adds cross-edition module and signature probes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
ranm-msft
left a comment
There was a problem hiding this comment.
Reviewed the full diff. The C:\Program Files\PowerShell\7\Modules prepend in all three prologues is the right fix: PowerShell resolves modules by first match on PSModulePath, so prepending the host shell's own module root deterministically wins over an inherited path from the other edition. Covering bootstrap.ps1 in both the outer and the elevated-relaunch prologue is the part that is easy to miss, and it is here.
src/tests/calm-os/module-path-checks.ps1 is a genuinely good test: extracting the prologue via AST rather than duplicating it means the test cannot drift from the shipping code, and running it under both 5.1 and pwsh 7 with a deliberately poisoned PSModulePath exercises the actual failure mode. Verifying DevConfig-CustomModules still resolves confirms the prepend did not shadow the repo's own modules.
No findings. Approving.

No description provided.