Repository navigation
feat(win32): default -Architecture to the device's 64-bit host #30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| function Get-IslHostArchitecture { | ||
| <# | ||
| .SYNOPSIS | ||
| The architecture of this device's 64-bit Windows PowerShell host: x64, or arm64 on Windows on ARM. | ||
|
|
||
| .DESCRIPTION | ||
| The agent runs Win32 detection and requirement scripts in the device's 64-bit host unless | ||
| the rule's "run as 32-bit" option is on. On Windows on ARM that host is the native ARM64 | ||
| one and there is no x64 PowerShell at all (Findings, "Windows on ARM"), so the harness | ||
| commands use this as their default architecture instead of a fixed x64 that an ARM64 | ||
| device refuses. The 32-bit host (x86) exists on both and is never the answer here. | ||
|
|
||
| .EXAMPLE | ||
| Get-IslHostArchitecture | ||
|
|
||
| x64 on an x64 device, arm64 on a Windows on ARM device. | ||
|
|
||
| .OUTPUTS | ||
| System.String. x64 or arm64, as Get-IslHostPath and the -Architecture parameters name them. | ||
| #> | ||
| [CmdletBinding()] | ||
| [OutputType([string])] | ||
| param() | ||
|
|
||
| $osArchitecture = "$([System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture)" | ||
| if ($osArchitecture -eq 'Arm64') { 'arm64' } else { 'x64' } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -11,8 +11,9 @@ function Invoke-IntuneDetectionTest { | |
| [Alias('FullName', 'PSPath')] | ||
| [string]$Path, | ||
|
|
||
| # Left out: the device's 64-bit host (x64, or arm64 on Windows on ARM), the agent's default | ||
| [ValidateSet('x86', 'x64', 'arm64')] | ||
| [string]$Architecture = 'x64', | ||
| [string]$Architecture, | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. No default expression on the parameter, resolved in the body instead, for two reasons. |
||
|
|
||
| [ValidateSet('User', 'System')] | ||
| [string]$Context = 'User', | ||
|
|
@@ -35,6 +36,9 @@ function Invoke-IntuneDetectionTest { | |
| throw '-Credential applies to -Context User; System runs as NT AUTHORITY\SYSTEM' | ||
| } | ||
| Write-Verbose "Starting $($MyInvocation.MyCommand.Name) for $($PSBoundParameters.Keys -join ', ')" | ||
| # The agent's default host is the device's 64-bit one: arm64 on Windows on ARM, where no x64 | ||
| # host exists, and x64 elsewhere | ||
| if (-not $Architecture) { $Architecture = Get-IslHostArchitecture } | ||
|
|
||
| $reasons = [System.Collections.Generic.List[string]]::new() | ||
| $signatureStatus = '' | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -33,8 +33,9 @@ function Invoke-IntuneWin32AppTest { | |
| # uninstalled before this app installs, an update target stays (W32-SUP-OLD-A, W32-SUP-OLD-B) | ||
| [hashtable[]]$Supersedes, | ||
|
|
||
| # Left out: the device's 64-bit host (x64, or arm64 on Windows on ARM), the agent's default | ||
| [ValidateSet('x86', 'x64', 'arm64')] | ||
| [string]$Architecture = 'x64', | ||
| [string]$Architecture, | ||
|
|
||
| [ValidateSet('User', 'System')] | ||
| [string]$Context = 'User', | ||
|
|
@@ -64,6 +65,9 @@ function Invoke-IntuneWin32AppTest { | |
| [switch]$EnforceSignatureCheck | ||
| ) | ||
| Write-Verbose "Starting $($MyInvocation.MyCommand.Name) for $($PSBoundParameters.Keys -join ', ')" | ||
| # The agent's default host is the device's 64-bit one: arm64 on Windows on ARM, where no x64 | ||
| # host exists, and x64 elsewhere | ||
| if (-not $Architecture) { $Architecture = Get-IslHostArchitecture } | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Resolved before |
||
|
|
||
| if (-not $DetectionPath -and -not $DetectionRule) { | ||
| throw 'Give a detection script (-DetectionPath), detection rules (-DetectionRule), or both' | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,30 @@ | ||
| #Requires -Modules @{ ModuleName = 'Pester'; ModuleVersion = '6.2.0' } | ||
|
|
||
| <# | ||
| The default architecture of the Win32 harness commands: the 64-bit host this device has, | ||
| which Get-IslHostPath resolves to System32 rather than refusing. | ||
| #> | ||
|
|
||
| BeforeAll { | ||
| $script:ModuleRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSScriptRoot)) | ||
| Import-Module (Join-Path $script:ModuleRoot 'IntuneScriptLab.psd1') -Force | ||
| $osArchitecture = "$([System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture)" | ||
| $script:Native = if ($osArchitecture -eq 'Arm64') { 'arm64' } else { 'x64' } | ||
| } | ||
|
|
||
| AfterAll { | ||
| Remove-Module IntuneScriptLab -Force -ErrorAction SilentlyContinue | ||
| } | ||
|
|
||
| Describe 'Get-IslHostArchitecture' -Tag 'Unit', 'Private' { | ||
|
|
||
| It 'names the 64-bit host this device has' { | ||
| InModuleScope IntuneScriptLab { Get-IslHostArchitecture } | Should-Be $script:Native | ||
| } | ||
|
|
||
| It 'names a host Get-IslHostPath resolves instead of refusing' { | ||
| $hostInfo = InModuleScope IntuneScriptLab { Get-IslHostPath -Architecture (Get-IslHostArchitecture) } | ||
| $hostInfo.Path | Should-BeLikeString '*\WindowsPowerShell\v1.0\powershell.exe' | ||
| $hostInfo.Path | Should-NotBeLikeString '*SysWOW64*' | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -11,6 +11,8 @@ BeforeAll { | |
| Import-Module (Join-Path $script:ModuleRoot 'IntuneScriptLab.psd1') -Force | ||
| . (Join-Path $script:ModuleRoot 'Tests\TestHelpers\TestHelpers.ps1') | ||
| $script:Detect = 'C:\lab\detect.ps1' | ||
| $osArchitecture = "$([System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture)" | ||
| $script:Native = if ($osArchitecture -eq 'Arm64') { 'arm64' } else { 'x64' } | ||
| } | ||
|
|
||
| AfterAll { | ||
|
|
@@ -98,6 +100,17 @@ Describe 'Invoke-IntuneDetectionTest' -Tag 'Unit', 'Public' { | |
| $result.Architecture | Should-Be 'x86' | ||
| $result.Context | Should-Be 'User' | ||
| } | ||
|
|
||
| It 'defaults to the 64-bit host this device has, the one the agent uses for Win32 detection' { | ||
| Mock Invoke-IslScriptRun -ModuleName IntuneScriptLab { | ||
| [pscustomobject]@{ ExitCode = 0; TimedOut = $false; StdOut = 'x'; StdErr = '' } | ||
| } | ||
| $result = Invoke-IntuneDetectionTest -Path $script:Detect | ||
| Should-Invoke Invoke-IslScriptRun -ModuleName IntuneScriptLab -Exactly -Times 1 -ParameterFilter { | ||
| $Architecture -in 'x64', 'arm64' | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The parameter filter accepts either 64-bit host and the exact value is asserted on the result instead, because the filter runs in the mock's scope where the test file's |
||
| } | ||
| $result.Architecture | Should-Be $script:Native | ||
| } | ||
| } | ||
|
|
||
| Context 'Enforced signature check (W32-DET-SIGCHECK)' { | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -67,13 +67,14 @@ Inside a Pester test. | |
|
|
||
| ### -Architecture | ||
|
|
||
| Host to run in: x64 (Intune's default for Win32 detection), x86 (the "run as 32-bit" | ||
| option), or arm64 on a Windows on ARM device. A Windows on ARM device has no x64 host, so the | ||
| x64 default is refused there: pass arm64, the host the agent uses on ARM64. | ||
| Host to run in: x64, x86 (the "run as 32-bit" option), or arm64. Left out, the device's | ||
| 64-bit host: x64 on an x64 device, arm64 on Windows on ARM, which is the host the agent uses | ||
| for Win32 detection. x64 and arm64 each name a host only its own CPU has, so one is refused | ||
| on the other. | ||
|
|
||
| ```yaml | ||
| Type: System.String | ||
| DefaultValue: x64 | ||
| DefaultValue: '' | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Empty DefaultValue is what |
||
| SupportsWildcards: false | ||
| Aliases: [] | ||
| ParameterSets: | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A separate helper rather than
Get-IslDeviceFact, which already derives the same value: that one also reads free disk space and memory through CIM, which the harness does not need on every launch. The OS architecture is the same testGet-IslHostPathmakes, so the two agree by construction.