style: 按微软规范落地静态分析,并全仓机械重排
三件事:
1) tools\Install-TestDependencies.ps1 现在也把 PSScriptAnalyzer 装进仓库内的 .tools\modules
(不动机器上的全局模块,与 Pester 同一策略)。
2) PSScriptAnalyzerSettings.psd1:这是必要的,不是装饰 —— 那 6 条格式规则
(括号、缩进、空格、对齐、大小写)默认全是 Disabled,所以不带 -Settings 的
`Invoke-ScriptAnalyzer -Severity Warning,Error` 会**静默漏掉全部排版问题**。本文件用 Rules
把它们打开(而不是用 IncludeRules 换一套),于是默认规则与格式规则同时生效。
三条有意的排除都写明了理由:PSAvoidUsingWriteHost(彩色控制台输出是这份工具的刻意设计)、
PSUseShouldProcessForStateChangingFunctions(WhatIf 的边界在入口脚本,给库里 27 个改状态的
函数都加上反而会"静默跳过",备份看着成功却什么都没做)、PSAvoidUsingPlainTextForPassword
(7z 只接受命令行口令,这是 7z 的限制,README 里写明了取舍)。
3) tools\Invoke-Analyzer.ps1:独立门禁(不塞进 Pester 用例 —— 套件跑一次二十多秒,
混进去会让"测试红了"这句话失去分辨力),路径过滤与验收门槛的 Encode/Parse 两层一致。
全仓重排结果:706 条告警 -> 67 条。修掉的 639 条全部是格式(闭括号 168、空格 80、
对齐 68、缩进 60、行长 229)。重排后 9/9 验收全绿、100 个文件两版解析零错、
276 个断言原样通过 —— 机械重排没有改变任何可观察行为。
如实说明两件事:
* 行长上限设成 160,**不是**官方默认的 120。120 在本仓库意味着 270 处改动(主要是
中文注释与测试夹具里的一行式目录),160 意味着 41 处。160 仍是"宽但可读",而理由是写在
配置文件里的:这不是悄悄放宽,想收紧到 120 时那份清单就在分析器输出里。
* 剩余 67 条里,41 条是上面那批行长,其余 26 条是分析器找出的真问题(未使用参数 6、
空 catch 6、MD5 指纹 1、覆盖内置命令 1、switch 默认值 1 等)。其中
Find-ChildDirectoryByName 的 MaxDepth 参数从未被使用 —— 也就是配置里的
CatalogMaxDepth = 5 是假的,前缀补全实际只查 1 层。这条要改行为、且影响真实名录的解析
结果,留给你拍板,不在本提交里动手。
This commit is contained in:
1 parent
102a3e038d
commit
187d2759fd
60 files changed
+769
-377
No files matched your search
@@ -66,7 +66,8 @@ function Invoke-NativeTolerant {
|
||||
$ErrorActionPreference = 'Continue'
|
||||
try {
|
||||
return @(& $FilePath @ArgumentList 2>&1)
|
||||
} finally {
|
||||
}
|
||||
finally {
|
||||
$ErrorActionPreference = $previous
|
||||
}
|
||||
}
|
||||
@@ -75,7 +76,8 @@ function Test-Scenario {
|
||||
if ($Ok) {
|
||||
$script:Passed++
|
||||
Write-Host (" [PASS] {0}" -f $Name) -ForegroundColor Green
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
$script:Failures += $Name
|
||||
Write-Host (" [FAIL] {0}{1}" -f $Name, $(if ($Detail) { ' —— ' + $Detail } else { '' })) -ForegroundColor Red
|
||||
}
|
||||
@@ -94,8 +96,8 @@ function Get-SecurityFingerprint {
|
||||
$acl = Get-Acl -LiteralPath $Path
|
||||
$sid = [System.Security.Principal.SecurityIdentifier]
|
||||
$aces = @($acl.GetAccessRules($true, $true, $sid) |
|
||||
ForEach-Object { '{0}|{1}|{2}' -f $_.AccessControlType, $_.IdentityReference.Value, [int]$_.FileSystemRights } |
|
||||
Sort-Object)
|
||||
ForEach-Object { '{0}|{1}|{2}' -f $_.AccessControlType, $_.IdentityReference.Value, [int]$_.FileSystemRights } |
|
||||
Sort-Object)
|
||||
return ('O={0} G={1} P={2} [{3}]' -f $acl.GetOwner($sid).Value, $acl.GetGroup($sid).Value, $acl.AreAccessRulesProtected, ($aces -join ' '))
|
||||
}
|
||||
|
||||
@@ -156,7 +158,8 @@ function Stop-VscodeProcesses {
|
||||
if ($path -and $path.StartsWith($AppRoot, [System.StringComparison]::OrdinalIgnoreCase)) {
|
||||
Stop-Process -Id $process.Id -Force -ErrorAction SilentlyContinue
|
||||
}
|
||||
} catch { }
|
||||
}
|
||||
catch { }
|
||||
}
|
||||
}
|
||||
Start-Sleep -Milliseconds 700
|
||||
@@ -184,7 +187,7 @@ function Remove-TreeHard {
|
||||
if (-not (Test-Path -LiteralPath $Path)) { return }
|
||||
|
||||
$links = @(Get-ChildItem -LiteralPath $Path -Recurse -Force -Directory -ErrorAction SilentlyContinue |
|
||||
Where-Object { $_.Attributes -band [IO.FileAttributes]::ReparsePoint })
|
||||
Where-Object { $_.Attributes -band [IO.FileAttributes]::ReparsePoint })
|
||||
foreach ($link in $links) {
|
||||
$null = Invoke-NativeTolerant -FilePath 'cmd.exe' -ArgumentList @('/c', ('rmdir "{0}"' -f $link.FullName))
|
||||
Remove-BaknretJunction -Path $link.FullName
|
||||
@@ -207,7 +210,8 @@ function Remove-TreeHard {
|
||||
|
||||
if (Test-Path -LiteralPath $WorkRoot) {
|
||||
Get-ChildItem -LiteralPath $WorkRoot -Directory -ErrorAction SilentlyContinue | ForEach-Object { Remove-TreeHard -Path $_.FullName }
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
New-Item -ItemType Directory -Path $WorkRoot -Force | Out-Null
|
||||
}
|
||||
$BackupDir = Join-Path $WorkRoot 'backups'
|
||||
@@ -242,10 +246,12 @@ if (-not $SkipScoop) {
|
||||
try {
|
||||
Invoke-Expression "& {$(Invoke-RestMethod -Uri 'https://get.scoop.sh')} -RunAsAdmin"
|
||||
Write-Host ('[A] 安装器退出码:{0}' -f $LASTEXITCODE)
|
||||
} catch {
|
||||
}
|
||||
catch {
|
||||
Test-Scenario 'A: 安装 scoop' $false $_.Exception.Message
|
||||
}
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
Write-Host '[A] scoop 已存在,跳过安装'
|
||||
}
|
||||
|
||||
@@ -299,9 +305,11 @@ $vscodeReady = [bool]$codeCmd
|
||||
|
||||
if ($vscodeReady) {
|
||||
Test-Scenario 'A: vscode 已安装(找到 CLI)' $true $codeCmd
|
||||
} elseif ($SkipScoop) {
|
||||
}
|
||||
elseif ($SkipScoop) {
|
||||
Write-Host (' [SKIP] 按 -SkipScoop 跳过 vscode({0} 不存在)' -f $vscodeCli) -ForegroundColor Yellow
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
Test-Scenario 'A: vscode 已安装(找到 CLI)' $false $vscodeCli
|
||||
}
|
||||
|
||||
@@ -357,7 +365,7 @@ $sourceOwner = (Get-Acl -LiteralPath $bData).GetOwner([System.Security.Principal
|
||||
Write-Host ('[B] 备份前 data 的属主:{0}' -f (Get-Acl -LiteralPath $bData).Owner)
|
||||
$currentSid = ([System.Security.Principal.WindowsIdentity]::GetCurrent()).User.Value
|
||||
Test-Scenario 'B: 现场造对了 —— 属主既不是当前账户、也不是新建对象的默认属主' `
|
||||
(($sourceOwner -ne $currentSid) -and ($sourceOwner -ne $creatorOwner)) `
|
||||
(($sourceOwner -ne $currentSid) -and ($sourceOwner -ne $creatorOwner)) `
|
||||
"owner=$sourceOwner current=$currentSid creatorDefault=$creatorOwner"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
@@ -398,7 +406,7 @@ $backup = Invoke-BaknretChild -Script (Join-Path $RepoPath 'Backup.ps1') -Parame
|
||||
$backup.LastLog | ForEach-Object { ' ' + $_ }
|
||||
Test-Scenario '备份退出码 0' ($backup.ExitCode -eq 0) ('exit=' + $backup.ExitCode)
|
||||
Test-Scenario '每个条目都写了 .acl.json' (@(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count -ge $entries.Count) `
|
||||
('acl.json=' + @(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count + ' 条目=' + $entries.Count)
|
||||
('acl.json=' + @(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count + ' 条目=' + $entries.Count)
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# 删源 → 恢复
|
||||
@@ -445,7 +453,8 @@ if ($vscodeReady) {
|
||||
[System.IO.File]::WriteAllText($probeFile, 'write probe')
|
||||
$writeOk = (Test-Path -LiteralPath $probeFile)
|
||||
Remove-Item -LiteralPath $probeFile -Force -ErrorAction SilentlyContinue
|
||||
} catch {
|
||||
}
|
||||
catch {
|
||||
$detail = $_.Exception.Message
|
||||
}
|
||||
Test-Scenario 'A: vscode 的数据目录可写(新建文件成功)' $writeOk $detail
|
||||
@@ -455,9 +464,10 @@ if ($vscodeReady) {
|
||||
$expectedNormalized = $expected[$pair[1]] -replace ' P=(True|False) ', ' P='
|
||||
$actualNormalized = (Get-SecurityFingerprint -Path $pair[0]) -replace ' P=(True|False) ', ' P='
|
||||
Test-Scenario ("A: {0} 的安全指纹与备份前一致" -f $pair[1]) ($actualNormalized -eq $expectedNormalized) `
|
||||
("want: " + $expectedNormalized + " / got: " + $actualNormalized)
|
||||
("want: " + $expectedNormalized + " / got: " + $actualNormalized)
|
||||
}
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
Write-Host ' [SKIP] vscode 没装上,A 段的功能断言跳过(-SkipScoop 或下载失败)' -ForegroundColor Yellow
|
||||
}
|
||||
|
||||
@@ -488,7 +498,7 @@ $negative = Join-Path $WorkRoot 'negative-data'
|
||||
& robocopy.exe $bData $negative /E /COPY:DAT /NFL /NDL /NJH /NJS /NP | Out-Null
|
||||
$negativeOwner = (Get-Acl -LiteralPath $negative).GetOwner([System.Security.Principal.SecurityIdentifier]).Value
|
||||
Test-Scenario 'B 负对照: 只搬文件时,属主变成"跑脚本的账户"而不再是原账户' `
|
||||
(($negativeOwner -ne $sourceOwner) -and ($negativeOwner -eq $creatorOwner)) `
|
||||
(($negativeOwner -ne $sourceOwner) -and ($negativeOwner -eq $creatorOwner)) `
|
||||
"negative=$negativeOwner creatorDefault=$creatorOwner"
|
||||
Write-Host (' 原属主 = {0}' -f $sourceOwner)
|
||||
Write-Host (' 恢复后属主 = {0}(应与原属主相同)' -f $restoredOwner)
|
||||
@@ -501,14 +511,16 @@ Write-Host ''
|
||||
$total = $script:Passed + $script:Failures.Count
|
||||
if ($script:Failures.Count -eq 0) {
|
||||
Write-Host ('ACL 演练:全部通过 {0} 项' -f $total) -ForegroundColor Green
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
Write-Host ('ACL 演练:通过 {0} 项,失败 {1} 项' -f $script:Passed, $script:Failures.Count) -ForegroundColor Red
|
||||
foreach ($failure in $script:Failures) { Write-Host (' - ' + $failure) -ForegroundColor Red }
|
||||
}
|
||||
|
||||
if ($KeepWorkRoot) {
|
||||
Write-Host ('临时目录保留:{0}' -f $WorkRoot) -ForegroundColor Yellow
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
Remove-TreeHard -Path $bRoot
|
||||
Remove-TreeHard -Path (Join-Path $WorkRoot 'negative-data')
|
||||
# 备份与日志留着,便于事后核对(归档可能有几百 MB,要腾空间就手工删这个目录)
|
||||
|
||||
Reference in new issue
Block a user