Skip to content

Fix Authenticode checks when switching PowerShell editions - #136

Open
AmirMS (AmelBawa-msft) wants to merge 2 commits into
mainfrom
user/amelbawa/fix-authenticode
Open

AmirMS (AmelBawa-msft) wants to merge 2 commits into
mainfrom
user/amelbawa/fix-authenticode

Conversation

@AmelBawa-msft

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cross-edition signature verification needs Windows validation, and unresolved launcher and regression-harness issues require attention.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Improves Authenticode verification when Windows Dev Config runs across PowerShell editions.

Changes:

  • Prioritizes native modules in bootstrap, elevation, and engine startup.
  • Adds cross-edition checks for signatures, hashing, and permissions.
  • Documents module handling and the Windows regression-check command.
File Description
src/​windows-dev-config/​README.md Documents module prioritization and regression checks.
src/​windows-dev-config/​dev-config.ps1 Prioritizes the running shell’s built-in modules.
src/​windows-dev-config/​bootstrap.ps1 Applies module priority during bootstrap and elevation.
src/​tests/​calm-os/​module-path-checks.ps1 Adds cross-edition module and signature probes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/tests/calm-os/module-path-checks.ps1
Comment thread src/windows-dev-config/bootstrap.ps1

@ranm-msft ranm-msft left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full diff. The C:\Program Files\PowerShell\7\Modules prepend in all three prologues is the right fix: PowerShell resolves modules by first match on PSModulePath, so prepending the host shell's own module root deterministically wins over an inherited path from the other edition. Covering bootstrap.ps1 in both the outer and the elevated-relaunch prologue is the part that is easy to miss, and it is here.

src/tests/calm-os/module-path-checks.ps1 is a genuinely good test: extracting the prologue via AST rather than duplicating it means the test cannot drift from the shipping code, and running it under both 5.1 and pwsh 7 with a deliberately poisoned PSModulePath exercises the actual failure mode. Verifying DevConfig-CustomModules still resolves confirms the prepend did not shadow the repo's own modules.

No findings. Approving.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants