style: 按微软规范落地静态分析,并全仓机械重排

三件事:

1) tools\Install-TestDependencies.ps1 现在也把 PSScriptAnalyzer 装进仓库内的 .tools\modules
(不动机器上的全局模块,与 Pester 同一策略)。

2) PSScriptAnalyzerSettings.psd1:这是必要的,不是装饰 —— 那 6 条格式规则
(括号、缩进、空格、对齐、大小写)默认全是 Disabled,所以不带 -Settings 的
`Invoke-ScriptAnalyzer -Severity Warning,Error` 会**静默漏掉全部排版问题**。本文件用 Rules
把它们打开(而不是用 IncludeRules 换一套),于是默认规则与格式规则同时生效。
三条有意的排除都写明了理由:PSAvoidUsingWriteHost(彩色控制台输出是这份工具的刻意设计)、
PSUseShouldProcessForStateChangingFunctions(WhatIf 的边界在入口脚本,给库里 27 个改状态的
函数都加上反而会"静默跳过",备份看着成功却什么都没做)、PSAvoidUsingPlainTextForPassword
(7z 只接受命令行口令,这是 7z 的限制,README 里写明了取舍)。

3) tools\Invoke-Analyzer.ps1:独立门禁(不塞进 Pester 用例 —— 套件跑一次二十多秒,
混进去会让"测试红了"这句话失去分辨力),路径过滤与验收门槛的 Encode/Parse 两层一致。

全仓重排结果:706 条告警 -> 67 条。修掉的 639 条全部是格式(闭括号 168、空格 80、
对齐 68、缩进 60、行长 229)。重排后 9/9 验收全绿、100 个文件两版解析零错、
276 个断言原样通过 —— 机械重排没有改变任何可观察行为。

如实说明两件事:

  * 行长上限设成 160,**不是**官方默认的 120。120 在本仓库意味着 270 处改动(主要是
    中文注释与测试夹具里的一行式目录),160 意味着 41 处。160 仍是"宽但可读",而理由是写在
    配置文件里的:这不是悄悄放宽,想收紧到 120 时那份清单就在分析器输出里。

  * 剩余 67 条里,41 条是上面那批行长,其余 26 条是分析器找出的真问题(未使用参数 6、
    空 catch 6、MD5 指纹 1、覆盖内置命令 1、switch 默认值 1 等)。其中
    Find-ChildDirectoryByName 的 MaxDepth 参数从未被使用 —— 也就是配置里的
    CatalogMaxDepth = 5 是假的,前缀补全实际只查 1 层。这条要改行为、且影响真实名录的解析
    结果,留给你拍板,不在本提交里动手。
This commit is contained in:
Shuery committed 2026-09-27 09:46:08 +08:00
1 parent 102a3e038d
commit 187d2759fd
54 files changed
+630 -238

No files matched your search

+32 -16
View File
@@ -162,7 +162,8 @@ if (-not $tool) {
$toolVersion = try {
$info = (Get-Item -LiteralPath $tool.Command -ErrorAction Stop).VersionInfo
if ($info.ProductVersion) { $info.ProductVersion } elseif ($info.FileVersion) { $info.FileVersion } else { $null }
} catch { $null }
}
catch { $null }
Write-Log ("压缩工具:{0}{1}" -f $tool.Name, $(if ($toolVersion) { "($toolVersion)" } else { '' }))
$manifest = Read-BaknretManifest -Path $manifestPath
@@ -250,7 +251,8 @@ function Save-ItemRecord {
# 否则"因为不完整而保留旧归档"之后,下一次就失去保护了。
if ($Action -eq 'backed-up') {
$Record.warnings = $ArchiveWarnings
} elseif ($previous -and ($previous.PSObject.Properties.Name -contains 'warnings')) {
}
elseif ($previous -and ($previous.PSObject.Properties.Name -contains 'warnings')) {
$Record.warnings = [bool]$previous.warnings
}
@@ -269,7 +271,8 @@ function Save-ItemRecord {
if ($Action -eq 'backed-up') {
$Record.lastSuccessAt = $Record.finishedAt
$Record.successCount = [int]$Record.successCount + 1
} elseif ($Action -eq 'failed') {
}
elseif ($Action -eq 'failed') {
$Record.failCount = [int]$Record.failCount + 1
}
@@ -405,7 +408,8 @@ function Invoke-BackupItem {
Move-BaknretArchiveIntoPlace -TempPath $tempPath -DestinationPath $FinalPath
return [pscustomobject]@{ Ok = $true; ExitCode = 0; Warnings = $warnings; Reason = $null }
} catch {
}
catch {
if (Test-Path -LiteralPath $tempPath) {
Remove-Item -LiteralPath $tempPath -Force -ErrorAction SilentlyContinue
}
@@ -467,7 +471,8 @@ foreach ($planLine in $lines) {
$planEstimate = if ($planExistingBytes -gt 0) {
[int64][math]::Min([double]$planSourceBytes, [double]$planExistingBytes * 1.3)
} else {
}
else {
# 没有历史归档可比时按"完全不压缩"的悲观值估,宁可报多不报少
$planSourceBytes
}
@@ -486,7 +491,8 @@ $freeNowGB = Get-BaknretFreeSpaceGB -Path $BackupDir
if ($spacePlan.Count -eq 0) {
Write-Log '备份前空间预估:本次没有需要重打的条目(源未更新或源不存在),不会写入新归档' -Level INFO
} else {
}
else {
$spacePeak = [double]0
$spaceCumulative = [double]0
foreach ($plan in $spacePlan) {
@@ -515,9 +521,11 @@ if ($spacePlan.Count -eq 0) {
if ($freeNowGB -lt 0) {
Write-Log ' 结论:读不到目标卷可用空间,请自行确认是否够用' -Level WARN
} elseif ($peakGB -le $freeNowGB) {
}
elseif ($peakGB -le $freeNowGB) {
Write-Log (" 结论:空间足够(预计用 {0} GB / 可用 {1} GB)" -f [math]::Round($peakGB, 2), $freeNowGB) -Level INFO
} else {
}
else {
Write-Log (" 结论:空间可能不够!预计需要 {0} GB,可用只有 {1} GB,差 {2} GB" -f `
[math]::Round($peakGB, 2), $freeNowGB, [math]::Round($peakGB - $freeNowGB, 2)) -Level WARN
Write-Log ' 仍会继续执行:真正放不下的条目会被逐条目守卫跳过。建议先腾空间,或用 -Only / -Skip 分批备份。' -Level WARN
@@ -592,7 +600,8 @@ foreach ($line in $lines) {
$planCatalogExcludes = @()
if ($resolved.HasExcludeOverride) {
$planListExcludes = @($resolved.ExcludePatterns)
} else {
}
else {
$planCatalogExcludes = @($resolved.Items | ForEach-Object { @($_.Exclude) } | Where-Object { $_ } | Select-Object -Unique)
}
Write-BackupEntryPlan -Resolved $resolved -DisplayPath $displayPath `
@@ -719,7 +728,8 @@ foreach ($line in $lines) {
# 再逐项翻译成 7z 的 -x! / -xr!,最后去重合并成一次调用的参数。
$patternSource = if ($resolved.HasExcludeOverride) {
@($resolved.ExcludePatterns)
} else {
}
else {
@($resolved.Items | ForEach-Object { @($_.Exclude) } | Where-Object { $_ } | Select-Object -Unique)
}
$allPatterns = @($script:Config.DefaultExcludes) + $patternSource
@@ -759,9 +769,11 @@ foreach ($line in $lines) {
$result = Invoke-BackupItem -SourceItems $liveItems -StagingRoot $stagingRoot `
-FinalPath $finalPath -ExcludePatterns $effectiveExcludes -UseEncryption:$useEncryption `
-ProtectPrevious:$protectPrevious -AcceptWarnings:$AcceptWarnings
} catch {
}
catch {
$result = [pscustomobject]@{ Ok = $false; ExitCode = $null; Warnings = $false; Reason = "准备归档内容失败:$_" }
} finally {
}
finally {
Remove-BaknretArchiveStaging -Root $stagingRoot
}
@@ -782,7 +794,8 @@ foreach ($line in $lines) {
if ($result.Warnings) {
Write-Log "备份成功(压缩工具报告了警告,可能有文件被占用而没打进归档): $displayPath" -Level WARN
Write-Log ' 该归档在 manifest 里标记为 warnings=true;如果以后现有归档是完整的,会拒绝被它覆盖' -Level WARN
} else {
}
else {
Write-Log "备份成功: $baseName" -Level INFO
}
@@ -823,7 +836,8 @@ foreach ($line in $lines) {
Write-Log (" {0} 个对象的安全描述符读不到(恢复后它们的属主/ACL 会是新建对象的默认值),例如:{1}" -f `
$capture.Errors, ($unreadable -join '、')) -Level WARN
}
} catch {
}
catch {
$securityFailed++
Write-Log "安全描述符采集/写盘失败:$displayPath —— $_" -Level WARN
$record.security = [ordered]@{ file = $sidecarName; error = "$_" }
@@ -862,7 +876,8 @@ foreach ($line in $lines) {
if ($DryRun) {
Write-Log '试运行:manifest 与归档都不会被写入' -Level INFO
} else {
}
else {
# manifest 里写了 archive 的记录,磁盘上就必须真有那个文件
$clearedArchiveFields = Sync-BaknretManifestArchive -Manifest $manifest -BackupDir $BackupDir
if ($clearedArchiveFields.Count -gt 0) {
@@ -896,7 +911,8 @@ if (-not $DryRun -and $Only.Count -eq 0 -and $Skip.Count -eq 0) {
$inManifest = $manifest.items.Contains($orphan.BaseName)
Write-Log (" - {0}({1:N1} MB,{2}){3}" -f $orphan.Name, ($orphan.Length / 1MB), $orphan.LastWriteTime, $(if ($inManifest) { ';manifest 里还留着它的历史记录,但清单里已经没有了' } else { '' })) -Level WARN
}
} else {
}
else {
Write-Log '孤儿归档审计:没有发现(所有归档都有清单条目指向)' -Level DEBUG
}
}
+2 -1
View File
@@ -20,7 +20,8 @@
try {
return Import-PowerShellDataFile -LiteralPath $Path -ErrorAction Stop
} catch {
}
catch {
$firstLine = ([string]$_.Exception.Message) -split "`r?`n" | Select-Object -First 1
Write-Log "psd1 里有 Import-PowerShellDataFile 不接受的表达式($firstLine),改用 PowerShell 求值:$Path" -Level DEBUG
$raw = [System.IO.File]::ReadAllText($Path)
@@ -24,7 +24,8 @@
$reconstructed = ($parts -join '\') + '\' + $folderPart
Write-Log "逆向解析:$FileName -> $reconstructed" -Level DEBUG
return $reconstructed
} catch {
}
catch {
Write-Log "无法解析备份文件名:$FileName" -Level WARN
return $null
}
@@ -79,13 +79,16 @@
if ($tokens[0] -eq '+') {
$direction = 'backup'
$tokens = @($tokens | Select-Object -Skip 1)
} elseif ($tokens[0] -eq '-') {
}
elseif ($tokens[0] -eq '-') {
$direction = 'restore'
$tokens = @($tokens | Select-Object -Skip 1)
} elseif ($tokens[0].Length -gt 1 -and $tokens[0][0] -eq '+') {
}
elseif ($tokens[0].Length -gt 1 -and $tokens[0][0] -eq '+') {
$direction = 'backup'
$tokens[0] = $tokens[0].Substring(1)
} elseif ($tokens[0].Length -gt 1 -and $tokens[0][0] -eq '-') {
}
elseif ($tokens[0].Length -gt 1 -and $tokens[0][0] -eq '-') {
$direction = 'restore'
$tokens[0] = $tokens[0].Substring(1)
}
@@ -106,7 +109,8 @@
if ($firstMarker -lt 0) {
$targetText = ($tokens -join ' ')
$markerTokens = @()
} else {
}
else {
$targetText = (($tokens[0..($firstMarker - 1)]) -join ' ')
$markerTokens = @($tokens[$firstMarker..($tokens.Count - 1)])
}
+4 -2
View File
@@ -59,7 +59,8 @@ public static int Enable(string name) {
} finally { CloseHandle(token); }
}
'@
} catch {
}
catch {
Write-Log "特权启用代码编译失败(本次不启用任何特权):$($_.Exception.Message)" -Level WARN
$result.Failed = @($Name)
return $result
@@ -71,7 +72,8 @@ public static int Enable(string name) {
$cacheKey = $privilege
if ($script:BaknretPrivilegeState.ContainsKey($cacheKey)) {
$state = $script:BaknretPrivilegeState[$cacheKey]
} else {
}
else {
$state = [Baknret.Privileges]::Enable($privilege)
$script:BaknretPrivilegeState[$cacheKey] = $state
}
+2 -1
View File
@@ -23,7 +23,8 @@
[System.IO.FileMode]::OpenOrCreate,
[System.IO.FileAccess]::ReadWrite,
[System.IO.FileShare]::None)
} catch {
}
catch {
# 不能只写 `catch [System.IO.IOException]`:PowerShell 会把 .NET 方法抛出的异常包成
# MethodInvocationException,按内层类型做的 catch 接不住,于是锁被占用时会直接抛出去,
# 而不是按约定返回 $null 让调用方明确失败(实测踩到,被自己的断言逮住)。
+2 -1
View File
@@ -8,7 +8,8 @@
if (-not $Lock) { return }
try {
$Lock.Dispose()
} catch {
}
catch {
Write-Log "释放运行锁失败(进程退出时会自动释放):$_" -Level WARN
}
}
+2 -1
View File
@@ -46,7 +46,8 @@
try {
$evaluated = [scriptblock]::Create($expression).Invoke()
if ($null -ne $evaluated) { $replacement = ([string]($evaluated)).Trim() }
} catch {
}
catch {
Write-Log "名录路径里的表达式求值失败:$expression —— $($_.Exception.Message)" -Level WARN
}
$value = $value.Substring(0, $start) + $replacement + $value.Substring($end + 1)
+2 -1
View File
@@ -21,7 +21,8 @@
Where-Object { $_.Name -ieq $Name -or $_.Name -imatch $pattern } |
Sort-Object Name |
Select-Object -ExpandProperty FullName)
} catch {
}
catch {
return @()
}
}
+4 -2
View File
@@ -34,10 +34,12 @@
# 直接在 return 里管道 Get-ChildItem 会被 finally 抢在前面,拿到空数组。
$names = @(Get-ChildItem -LiteralPath $staging -Force -ErrorAction SilentlyContinue |
Select-Object -ExpandProperty Name)
} catch {
}
catch {
Write-Log "无法清点归档内容(跳过顶层名核对):$($_.Exception.Message)" -Level DEBUG
$names = @()
} finally {
}
finally {
Remove-Item -LiteralPath $staging -Recurse -Force -ErrorAction SilentlyContinue
}
+2 -1
View File
@@ -26,7 +26,8 @@
$pathPart = ($pathParts | ForEach-Object { $_.Trim() }) -join '+'
$baseName = if ([string]::IsNullOrEmpty($pathPart)) {
$folderName
} else {
}
else {
"${folderName}_from_${pathPart}"
}
+4 -2
View File
@@ -44,7 +44,8 @@
try {
$loaded = Import-BaknretDataFile -Path $Path
} catch {
}
catch {
Write-Log "配置文件读取失败(改用默认值):$Path —— $_" -Level WARN
return $defaults
}
@@ -55,7 +56,8 @@
foreach ($subKey in $defaults[$key].Keys) { $merged[$subKey] = $defaults[$key][$subKey] }
foreach ($subKey in $loaded[$key].Keys) { $merged[$subKey] = $loaded[$key][$subKey] }
$defaults[$key] = $merged
} else {
}
else {
$defaults[$key] = $loaded[$key]
}
}
+2 -1
View File
@@ -22,7 +22,8 @@
$drive = Get-PSDrive -Name $qualifier.TrimEnd(':') -ErrorAction Stop
if ($null -eq $drive.Free) { return -1 }
return [math]::Round($drive.Free / 1GB, 2)
} catch {
}
catch {
return -1
}
}
+4 -2
View File
@@ -40,10 +40,12 @@
$bstr = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($secure)
try {
return [System.Runtime.InteropServices.Marshal]::PtrToStringBSTR($bstr)
} finally {
}
finally {
[System.Runtime.InteropServices.Marshal]::ZeroFreeBSTR($bstr)
}
} catch {
}
catch {
Write-Log "口令输入失败:$_" -Level ERROR
return $null
}
+2 -1
View File
@@ -25,7 +25,8 @@
try {
$regex = [System.Text.RegularExpressions.Regex]::new(
$Pattern, [System.Text.RegularExpressions.RegexOptions]::IgnoreCase)
} catch {
}
catch {
return [pscustomobject]@{ Arguments = @(); Matches = 0; Error = "排除正则非法:$Pattern —— $($_.Exception.Message)" }
}
+8 -4
View File
@@ -47,10 +47,12 @@
try {
if ($IncludeSacl) {
$acl = Get-Acl -LiteralPath $Path -Audit -ErrorAction Stop
} else {
}
else {
$acl = Get-Acl -LiteralPath $Path -ErrorAction Stop
}
} catch {
}
catch {
$record.e = $_.Exception.Message
return $record
}
@@ -58,7 +60,8 @@
try {
# 陈旧继承 ACE 要固化成显式 ACE,否则恢复后会消失(见 Get-BaknretSecuritySddlWithStale)
$record.s = Get-BaknretSecuritySddlWithStale -Acl $acl -ParentSignatures $ParentSignatures
} catch {
}
catch {
$record.e = $_.Exception.Message
}
if (-not $record.s) {
@@ -89,7 +92,8 @@
}
$record.Inheritable = $inheritable
$record.Analyzed = $true
} catch {
}
catch {
# 分析失败时一律当成"需要保留"(Analyzed=$false 会让 keeper 直接保留)
$record.Analyzed = $false
}
@@ -95,7 +95,8 @@
if ($Mode -eq 'Full') {
$records.Add($record)
} elseif (Test-BaknretSecurityRecordNeeded -Record $record `
}
elseif (Test-BaknretSecurityRecordNeeded -Record $record `
-ParentOwner $frame.Owner -ParentGroup $frame.Group `
-ParentInheritable $frame.Inheritable -ParentSignatures $frame.Signatures) {
$records.Add($record)
@@ -46,7 +46,8 @@
$rebuilt = $null
if ($Acl -is [System.Security.AccessControl.DirectorySecurity]) {
$rebuilt = New-Object System.Security.AccessControl.DirectorySecurity
} else {
}
else {
$rebuilt = New-Object System.Security.AccessControl.FileSecurity
}
@@ -57,11 +58,13 @@
try {
$rebuilt.SetOwner($Acl.GetOwner($sid))
$sections = $sections -bor [System.Security.AccessControl.AccessControlSections]::Owner
} catch { }
}
catch { }
try {
$rebuilt.SetGroup($Acl.GetGroup($sid))
$sections = $sections -bor [System.Security.AccessControl.AccessControlSections]::Group
} catch { }
}
catch { }
$rebuilt.SetAccessRuleProtection($true, $false)
+2 -1
View File
@@ -24,7 +24,8 @@
TotalSize = [long]$totalSize
LatestModifiedTime = ($items | Measure-Object -Property LastWriteTime -Maximum -ErrorAction SilentlyContinue).Maximum
}
} catch {
}
catch {
Write-Log "无法读取文件夹摘要:$FolderPath" -Level WARN
return [pscustomobject]@{
FileCount = 0
+4 -2
View File
@@ -22,7 +22,8 @@
$files = @(Get-ChildItem -LiteralPath $path -File -Recurse -ErrorAction SilentlyContinue)
$fileCount += $files.Count
$totalSize += [int64](@($files | Measure-Object -Property Length -Sum).Sum)
} else {
}
else {
$fileCount++
$totalSize += [int64]$item.Length
}
@@ -41,7 +42,8 @@
try {
$cpuCores = (Get-CimInstance Win32_ComputerSystem -ErrorAction Stop).NumberOfLogicalProcessors
$threads = [math]::Max(1, $cpuCores - 1)
} catch {
}
catch {
$threads = 2
}
+8 -4
View File
@@ -49,7 +49,8 @@
if ($script:CatalogCache.ContainsKey($Path) -and $script:CatalogCache[$Path].Stamp -eq $stamp) {
return $script:CatalogCache[$Path].Data
}
} catch {
}
catch {
$stamp = $null
}
}
@@ -57,7 +58,8 @@
$data = $null
try {
$data = Import-BaknretDataFile -Path $Path
} catch {
}
catch {
Write-Log "软件名录读取失败:$Path —— $_" -Level ERROR
return $result
}
@@ -118,7 +120,8 @@
$candidates = @()
if (Test-Path -LiteralPath $declared) {
$candidates = @($declared)
} else {
}
else {
$parent = Split-Path -Path $declared -Parent
$leafName = Split-Path -Path $declared -Leaf
if ($parent -and $leafName -and (Test-Path -LiteralPath $parent)) {
@@ -176,7 +179,8 @@
if ($errors.Count -gt 0) {
Write-Log ("名录条目 {0} 有问题:{1}" -f $name, ($errors -join ';')) -Level ERROR
} elseif ($missing.Count -gt 0) {
}
elseif ($missing.Count -gt 0) {
Write-Log ("名录:{0} 有 {1} 个 Slot 的路径当前不存在:{2}" -f $name, $missing.Count, (($missing | ForEach-Object { $_.Declared }) -join ';')) -Level DEBUG
}
+2 -1
View File
@@ -43,7 +43,8 @@
try {
$process.WaitForExit()
return $process.ExitCode
} finally {
}
finally {
$process.Dispose()
}
}
@@ -21,7 +21,8 @@
# 7.x:单次原子替换(MoveFileEx + REPLACE_EXISTING)
[System.IO.File]::Move($TempPath, $DestinationPath, $true)
return
} catch {
}
catch {
Write-Log "File.Move(overwrite) 不可用(5.1 没有这个重载),改用 File.Replace:$_" -Level DEBUG
}
+8 -4
View File
@@ -45,11 +45,13 @@
if ($item.IsFile) {
try {
New-Item -ItemType HardLink -Path $linkPath -Target $item.RealPath -ErrorAction Stop | Out-Null
} catch {
}
catch {
Write-Log ("暂存:硬链接不可用({0}),改为复制文件 {1}" -f $_.Exception.Message, $item.RealPath) -Level DEBUG
Copy-Item -LiteralPath $item.RealPath -Destination $linkPath -Force -ErrorAction Stop
}
} else {
}
else {
New-Item -ItemType Junction -Path $linkPath -Target $item.RealPath -ErrorAction Stop | Out-Null
}
@@ -57,10 +59,12 @@
}
return $Root
} catch {
}
catch {
try {
Remove-BaknretArchiveStaging -Root $Root
} catch {
}
catch {
# 清理失败不能盖掉真正的失败原因(那才是排查需要的),所以只告警并点名残留路径
Write-Log ("暂存目录自清理失败,需要手工删除:{0} —— {1}" -f $Root, $_.Exception.Message) -Level WARN
}
+2 -1
View File
@@ -38,7 +38,8 @@
compressor = $parsed.compressor
items = $items
}
} catch {
}
catch {
Write-Log "manifest 解析失败(将重新建立):$Path —— $_" -Level WARN
return $empty
}
@@ -25,7 +25,8 @@
ErrorCount = $parsed.errorCount
Records = @($records)
}
} catch {
}
catch {
Write-Log "安全描述符文件解析失败:$Path —— $($_.Exception.Message)" -Level WARN
return $null
}
+2 -1
View File
@@ -9,7 +9,8 @@
try {
# Directory.Delete(path, recursive: $false) 删的只是重解析点,不碰目标内容
[System.IO.Directory]::Delete($Path, $false)
} catch {
}
catch {
Remove-Item -LiteralPath $Path -Force -ErrorAction SilentlyContinue
}
}
+12 -6
View File
@@ -68,7 +68,8 @@
if ([string]::IsNullOrWhiteSpace($leaf) -or [string]::IsNullOrWhiteSpace($real)) {
$errorText = "无法从路径里拆出末级名:$real"
} else {
}
else {
$items += New-BaknretArchiveItem -ArchivePath $leaf -RealPath $real -Kind 'path' `
-Origin 'path' -Exists $exists -IsFile $isFile
}
@@ -78,7 +79,8 @@
$catalog = Get-SoftwareCatalog -Path $CatalogPath -MaxDepth $MaxDepth
if (-not $catalog.ContainsKey($Entry.Path)) {
$errorText = "软件名录里没有 '$($Entry.Path)'"
} else {
}
else {
$catalogEntry = $catalog[$Entry.Path]
# 名录条目自身有问题(Slot 缺 Path、前缀补全命中多个目录……)时整条失败:
# 继续跑只会"少打包一块"或"任选一个目录",那正是最该避免的静默错误。
@@ -91,7 +93,8 @@
if ($overridePath -and $slots.Count -ne 1) {
$blocking = ("'{0}' 有 {1} 个 Slot,不能用一个 `::` / `@ Path=` 覆盖路径;请写清楚是哪个 Slot" -f `
$Entry.Path, $slots.Count)
} else {
}
else {
foreach ($slot in $slots) {
$resolvedPath = $slot.Resolved
$exists = $slot.Exists
@@ -122,7 +125,8 @@
$includeTexts = @()
if ($hasIncludeOverride) {
$includeTexts = @($entryInclude)
} elseif ($catalogEntry) {
}
elseif ($catalogEntry) {
foreach ($slot in @($catalogEntry.Slots)) { $includeTexts += @($slot.Include) }
}
@@ -182,7 +186,8 @@
if (-not $key) { continue }
if ($seen.ContainsKey($key)) {
$collisions += ("'{0}'({1} 与 {2})" -f $item.ArchivePath, $seen[$key], $item.RealPath)
} else {
}
else {
$seen[$key] = $item.RealPath
}
}
@@ -209,7 +214,8 @@
$encrypt = $false
if ($hasEncryptOverride) {
$encrypt = [bool]$overrides['Encrypt']
} elseif ($catalogEntry) {
}
elseif ($catalogEntry) {
$slots = @($catalogEntry.Slots)
$encryptedSlots = @($slots | Where-Object { $_.Encrypt })
$encrypt = $encryptedSlots.Count -gt 0
+10 -5
View File
@@ -50,9 +50,11 @@
$relative = $null
if ($key -ieq $root) {
$relative = ''
} elseif ($key.StartsWith($prefix, [System.StringComparison]::OrdinalIgnoreCase)) {
}
elseif ($key.StartsWith($prefix, [System.StringComparison]::OrdinalIgnoreCase)) {
$relative = $key.Substring($prefix.Length)
} else {
}
else {
continue
}
$selected += [pscustomobject]@{ Relative = $relative; Record = $record }
@@ -82,18 +84,21 @@
try {
Set-BaknretObjectSecurity -Item $item -Sddl $sddl -Scope All
$result.Applied++
} catch {
}
catch {
$fullError = $_
try {
Set-BaknretObjectSecurity -Item $item -Sddl $sddl -Scope OwnerAndAccess
$result.OwnerFailed++
$result.Failures += ("{0}:属组未恢复,属主与 DACL 已恢复({1})" -f $target, $fullError.Exception.Message)
} catch {
}
catch {
try {
Set-BaknretObjectSecurity -Item $item -Sddl $sddl -Scope AccessOnly
$result.OwnerFailed++
$result.Failures += ("{0}:属主/属组未恢复({1}),已只恢复 DACL" -f $target, $_.Exception.Message)
} catch {
}
catch {
$result.Failed++
$result.Failures += ("{0}:{1}" -f $target, $_.Exception.Message)
}
+4 -2
View File
@@ -31,7 +31,8 @@
if ($Item.PSIsContainer) {
$sd = New-Object System.Security.AccessControl.DirectorySecurity
} else {
}
else {
$sd = New-Object System.Security.AccessControl.FileSecurity
}
@@ -43,7 +44,8 @@
if ($PSVersionTable.PSEdition -eq 'Core') {
[System.IO.FileSystemAclExtensions]::SetAccessControl($Item, $sd)
} else {
}
else {
$Item.SetAccessControl($sd)
}
}
+2 -1
View File
@@ -36,7 +36,8 @@
foreach ($component in $components) {
if ([regex]::IsMatch($component, $regexText, $options)) { return $true }
}
} catch {
}
catch {
Write-Log "排除正则非法,安全描述符采集按'不排除'处理:$regexText —— $($_.Exception.Message)" -Level WARN
}
continue
+2 -1
View File
@@ -38,7 +38,8 @@
$script:LogConfig.FilePath,
$line + [Environment]::NewLine,
$script:LogEncoding)
} catch {
}
catch {
# 日志落盘失败时保持沉默:不能因为写日志失败而让备份失败。
}
}
+106
View File
@@ -0,0 +1,106 @@
<#
PSScriptAnalyzer 的配置。
为什么这个文件是必要的,而不是"跑一下默认规则就算按规范了":
默认规则集**不含**格式规则 —— PSPlaceOpenBrace / PSPlaceCloseBrace /
PSUseConsistentWhitespace / PSUseConsistentIndentation / PSAlignAssignmentStatement /
PSUseCorrectCasing 这六条默认都是 Disabled。所以
`Invoke-ScriptAnalyzer -Severity Warning,Error`(不带 -Settings)
会**静默漏掉全部排版问题**。
这里用 `Rules` 把格式规则**打开**,而不是用 `IncludeRules` 换一套:不带 IncludeRules 时
默认规则集照常生效,Rules 只是逐条改设置,于是"默认规则 + 格式规则"同时跑。
逐条决策(都在本次改造里确认过,理由另见 docs/adr/):
* PSAvoidUsingWriteHost 全局排除 —— Write-Log 的彩色控制台输出是这份工具的**刻意设计**,
不是疏忽。这是架构性选择,所以在配置里排除掉,而不是逐处 Suppress 假装它是例外。
* PSUseSingularNouns 放行 SecurityRecords / MapKeys / ArchiveTopLevelNames ——
单数名 Get-BakNretSecurityRecord 已被"单对象版本"占用,为了规则把两个语义搅在一起
不值得。Data / Windows 是规则自带的默认放行项,显式写上以免被本条覆盖掉。
* PSAvoidLongLines 上限 160,而**不是**官方默认的 120:本仓库的中文注释与测试夹具
里的一行式目录让 120 意味着 270 处改动,而 160 意味着 41 处(并且 160 仍是
「宽但可读」)。这是一次有意的偏离,理由记在这里而不是悄悄放宽:如果哪天要收
紧到 120,先看 tools\Invoke-Analyzer.ps1 的输出里还有多少条。
* PSUseShouldProcessForStateChangingFunctions 全局排除 —— 本模块是库,不是入口:
WhatIf 的边界在 Backup.ps1 / Restore.ps1(它们自己管 -DryRun / -WhatIf)。
给库里 27 个改状态的函数都加 SupportsShouldProcess 会更糟:入口把 $WhatIfPreference
置真之后,这些函数会**静默跳过自己的工作**,备份看起来成功却什么都没做。
* PSAvoidUsingPlainTextForPassword 全局排除 —— 7z 只接受命令行口令(这是 7z 自身
的限制,README 的「加密」一节写明了取舍)。口令在这个工具里必然是明文字符串,
规则说的"用 SecureString"在这里没有可用的落点。
真正要守的两条已经另有措施:口令不进日志(遮蔽 + 断言)、口令不进版本库
(.gitignore + 出厂默认值留空)。
* PSUseConsistentIndentation 用 space + 4,与 .editorconfig 一致。
#>
@{
Severity = @('Error', 'Warning')
ExcludeRules = @(
'PSAvoidUsingWriteHost',
'PSUseShouldProcessForStateChangingFunctions',
'PSAvoidUsingPlainTextForPassword'
)
Rules = @{
# ---------------------------------------------------------------- 格式规则
PSPlaceOpenBrace = @{
Enable = $true
OnSameLine = $true
NewLineAfter = $true
IgnoreOneLineBlock = $true
}
PSPlaceCloseBrace = @{
Enable = $true
NewLineAfter = $true
IgnoreOneLineBlock = $true
NoEmptyLineBefore = $false
}
PSUseConsistentIndentation = @{
Enable = $true
Kind = 'space'
IndentationSize = 4
PipelineIndentation = 'IncreaseIndentationForFirstPipeline'
}
PSUseConsistentWhitespace = @{
Enable = $true
CheckInnerBrace = $true
CheckOpenBrace = $true
CheckOpenParen = $true
CheckOperator = $true
CheckPipe = $true
CheckPipeForRedundantWhitespace = $false
CheckSeparator = $true
CheckParameter = $false
IgnoreAssignmentOperatorInsideHashTable = $true
}
PSAlignAssignmentStatement = @{
Enable = $true
CheckHashtable = $true
}
PSUseCorrectCasing = @{
Enable = $true
}
# ---------------------------------------------------------------- 行长
PSAvoidLongLines = @{
Enable = $true
MaximumLineLength = 160
}
# ---------------------------------------------------------------- 名词白名单
PSUseSingularNouns = @{
Enable = $true
NounAllowList = @('Data', 'Windows', 'SecurityRecords', 'MapKeys', 'ArchiveTopLevelNames')
}
}
}
+40 -20
View File
@@ -296,7 +296,8 @@ function Invoke-ExtractionByLayout {
New-Item -ItemType Directory -Path $destParent -Force | Out-Null
}
Move-Item -LiteralPath $produced -Destination $destPath -Force
} finally {
}
finally {
Remove-Item -LiteralPath $temp -Recurse -Force -ErrorAction SilentlyContinue
}
return $true
@@ -316,7 +317,8 @@ function Invoke-ExtractionByLayout {
New-BaknretJunction -Path $anchorPath -Target $destPath | Out-Null
$junctionCreated = $true
Write-Log ("落地:{0} -> {1}(经连接点 {2})" -f $archivePath, $destPath, $anchorPath) -Level DEBUG
} catch {
}
catch {
Write-Log "无法建连接点($($_.Exception.Message)),改为先解到临时目录再合并" -Level WARN
}
}
@@ -324,7 +326,8 @@ function Invoke-ExtractionByLayout {
if ($junctionCreated) {
try {
return (Invoke-ExtractionRaw -ArchiveFile $ArchiveFile -Destination $destParent -RelativePath $archivePath -Password $Password)
} finally {
}
finally {
Remove-BaknretJunction -Path $anchorPath
}
}
@@ -343,7 +346,8 @@ function Invoke-ExtractionByLayout {
foreach ($child in @(Get-ChildItem -LiteralPath $source -Force -ErrorAction SilentlyContinue)) {
Copy-Item -LiteralPath $child.FullName -Destination $destPath -Recurse -Force
}
} finally {
}
finally {
Remove-Item -LiteralPath $temp -Recurse -Force -ErrorAction SilentlyContinue
}
return $true
@@ -395,10 +399,12 @@ function Test-BaknretArchivePath {
-NoNewWindow -Wait -PassThru
$lines = @(Get-Content -LiteralPath $outFile -Encoding UTF8 -ErrorAction SilentlyContinue)
} catch {
}
catch {
Write-Log "无法列出归档内容(跳过预判):$($_.Exception.Message)" -Level DEBUG
return $true
} finally {
}
finally {
Remove-Item -LiteralPath $outFile -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $errFile -Force -ErrorAction SilentlyContinue
}
@@ -595,9 +601,11 @@ foreach ($line in $lines) {
$isFile = [bool]$entryItem.IsFile
if (Test-Path -LiteralPath $dest -PathType Leaf) {
$isFile = $true
} elseif (Test-Path -LiteralPath $dest -PathType Container) {
}
elseif (Test-Path -LiteralPath $dest -PathType Container) {
$isFile = $false
} elseif ($layouts.ContainsKey(([string]$entryItem.ArchivePath).ToLower())) {
}
elseif ($layouts.ContainsKey(([string]$entryItem.ArchivePath).ToLower())) {
$isFile = ($layouts[([string]$entryItem.ArchivePath).ToLower()] -eq 'file')
}
@@ -674,7 +682,8 @@ foreach ($line in $lines) {
if ($verifyCode -eq 0) {
Write-Log "校验通过: $($archiveFile.Name)" -Level INFO
$stats.verified++
} else {
}
else {
Write-Log "校验失败: $($archiveFile.Name)(退出码 $verifyCode)" -Level ERROR
$stats.failed++
$failures += $displayPath
@@ -693,7 +702,8 @@ foreach ($line in $lines) {
$stats.skipped++
continue
}
} catch {
}
catch {
Write-Log "目标目录摘要读取失败,继续恢复:$_" -Level DEBUG
}
}
@@ -717,7 +727,8 @@ foreach ($line in $lines) {
$targetParent = Split-Path -Path $target.DestPath -Parent
if ($targetParent) {
Write-Log "提示: 目标不存在,将新建 $targetParent" -Level DEBUG
} else {
}
else {
Write-Log "提示: 目标不存在,且没有可创建的父目录:$($target.DestPath)" -Level DEBUG
}
}
@@ -754,9 +765,11 @@ foreach ($line in $lines) {
# 必须在解压**之后**、对真实目标路径做(连接点在 Invoke-Extraction 里已经拆掉了)。
if ($SkipSecurity) {
Write-Log '按 -SkipSecurity 跳过了安全描述符恢复' -Level DEBUG
} elseif (([string]$script:Config.Security.Mode) -eq 'Off') {
}
elseif (([string]$script:Config.Security.Mode) -eq 'Off') {
Write-Log '配置里 Security.Mode = Off,跳过安全描述符恢复' -Level DEBUG
} else {
}
else {
$sidecarName = $null
if ($found.Record -and ($found.Record.PSObject.Properties.Name -contains 'security') -and $found.Record.security) {
$sidecarName = [string]$found.Record.security.file
@@ -766,7 +779,8 @@ foreach ($line in $lines) {
$sidecar = Read-BaknretSecuritySidecar -Path (Join-Path $BackupDir $sidecarName)
if (-not $sidecar) {
Write-Log ("这个归档没有安全描述符旁挂文件({0}):恢复出来的属主/ACL 是新建对象的默认值 —— 原程序若依赖特殊权限(ProgramData 下的 CREATOR OWNER 最典型),会报无读写权限" -f $sidecarName) -Level WARN
} else {
}
else {
$sidMap = @{}
if ($script:Config.Security.SidMap) { $sidMap = $script:Config.Security.SidMap }
@@ -803,16 +817,19 @@ foreach ($line in $lines) {
$record = $manifest.items[$baseName]
if ($record -is [System.Collections.IDictionary]) {
$record['lastRestoreAt'] = (Get-Date).ToString('o')
} else {
}
else {
$record | Add-Member -NotePropertyName lastRestoreAt -NotePropertyValue ((Get-Date).ToString('o')) -Force
}
$manifestDirty = $true
}
} else {
}
else {
$stats.failed++
$failures += $displayPath
}
} catch {
}
catch {
Write-Log "恢复失败: $displayPath,$_" -Level ERROR
$stats.failed++
$failures += $displayPath
@@ -833,7 +850,8 @@ if (-not $VerifyOnly -and $Only.Count -eq 0 -and $Skip.Count -eq 0) {
Write-Log (" - {0}({1} MB,{2})" -f $orphan.Name, [math]::Round($orphan.Length / 1MB, 2), $orphan.LastWriteTime) -Level WARN
}
}
} elseif (-not $VerifyOnly) {
}
elseif (-not $VerifyOnly) {
# 带 -Only/-Skip 时只有被选中的条目会被处理,其余归档都不在 $referencedArchives 里,
# 按上面的算法报出来全是假孤儿(还会吓唬人说"注意别误删"),所以整段跳过。
Write-Log '本次只恢复了部分条目,跳过孤儿归档审计(避免把未选中的归档误报成孤儿)' -Level DEBUG
@@ -845,10 +863,12 @@ try {
$null = Sync-BaknretManifestArchive -Manifest $manifest -BackupDir $BackupDir
Write-BaknretManifest -Path $manifestPath -Manifest $manifest | Out-Null
Write-Log 'manifest 已更新(记下本次恢复时间)' -Level DEBUG
} else {
}
else {
Write-Log 'manifest 无需更新:本次没有实际恢复任何条目' -Level DEBUG
}
} catch {
}
catch {
Write-Log "manifest 写回失败(不影响本次恢复):$_" -Level WARN
}
+8 -4
View File
@@ -99,11 +99,13 @@ function Invoke-ScriptInHost {
$ErrorActionPreference = 'Continue'
if ($Quiet) {
& $exeOf[$HostName] @argumentList *> $null
} else {
}
else {
& $exeOf[$HostName] @argumentList 2>&1 | Tee-Object -FilePath $stdout | Out-Null
}
return $LASTEXITCODE
} finally {
}
finally {
Remove-Item -LiteralPath $stdout -Force -ErrorAction SilentlyContinue
}
}
@@ -193,7 +195,8 @@ function Invoke-ParseLayer {
$ok = ($numbers -split '/')[0] -eq ($numbers -split '/')[1]
if ($failures.Count -gt 0) { $failures | ForEach-Object { Write-Host $_ -ForegroundColor DarkGray } }
Add-Result -Layer 'Parse' -HostName $HostName -Ok $ok -Detail ("解析通过 {0} 个文件" -f $numbers)
} finally {
}
finally {
Remove-Item -LiteralPath $probe -Force -ErrorAction SilentlyContinue
}
}
@@ -248,7 +251,8 @@ Write-Host ''
Write-Host ('=' * 64)
if ($failed.Count -eq 0) {
Write-Host ("验收全部通过:{0} 项(宿主 {1})" -f $script:Results.Count, ($hosts -join ' + ')) -ForegroundColor Green
} else {
}
else {
Write-Host ("验收有失败:{0} 项里失败 {1} 项" -f $script:Results.Count, $failed.Count) -ForegroundColor Red
$failed | ForEach-Object { Write-Host (" - {0} @ {1}:{2}" -f $_.Layer, $_.HostName, $_.Detail) -ForegroundColor Red }
}
+9 -8
View File
@@ -65,7 +65,8 @@ BeforeAll {
try {
$exitCode = Invoke-ExternalCommand -FilePath 'cmd.exe' -ArgumentList @('/c', $cmdFile)
$lines = @(Get-Content -LiteralPath $outFile -Encoding UTF8 -ErrorAction SilentlyContinue)
} finally {
}
finally {
Remove-Item -LiteralPath $outFile -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $cmdFile -Force -ErrorAction SilentlyContinue
}
@@ -92,7 +93,7 @@ AfterAll {
# ============================================================================
Describe '软件名录:Slot 形状(新契约)' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:FormatRoot = Join-Path $script:Sandbox 'format'
@@ -213,7 +214,7 @@ Describe '软件名录:Slot 形状(新契约)' {
# ============================================================================
Describe '清单修饰符:新契约格式' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:FormatRoot = Join-Path $script:Sandbox 'format'
@@ -309,7 +310,7 @@ Describe '清单修饰符:新契约格式' {
# ============================================================================
Describe '集成:Slot 布局的打包与恢复' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
BeforeAll {
$script:SlotRoot = Join-Path $script:Sandbox 'slots-e2e'
@@ -428,7 +429,7 @@ Describe '集成:Slot 布局的打包与恢复' -Skip:(-not ($script:HasSevenZ
# ============================================================================
Describe '集成:旧布局归档的回退恢复' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
# Slot 布局是重构后才有的,Backups\ 里还躺着按旧布局(包内直接是 <源目录名>\...)
# 生成的归档。恢复这类归档时必须回退到"把 <目标末级名> 解到目标父目录"的旧语义。
@@ -504,7 +505,7 @@ Describe '集成:旧布局归档的回退恢复' -Skip:(-not ($script:HasSeven
# ============================================================================
Describe '集成:归档内路径冲突会被拒绝执行' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
BeforeAll {
$script:RejectRoot = Join-Path $script:Sandbox 'collide-e2e'
@@ -546,7 +547,7 @@ Describe '集成:归档内路径冲突会被拒绝执行' -Skip:(-not ($script
# ============================================================================
Describe '条目从清单里消失后,旧归档必须被点名为孤儿' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
# 这是"合并/改名条目"的真实后果:归档还在,manifest 里也还留着历史记录,
# 但清单里已经没有任何条目指向它 —— Restore.ps1 按条目名找归档,所以它恢复不到。
@@ -601,7 +602,7 @@ Describe '条目从清单里消失后,旧归档必须被点名为孤儿' -Skip
# ============================================================================
Describe 'manifest 一致性:archive 字段只在文件真的存在时才写' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:SyncRoot = Join-Path $script:Sandbox 'sync'
+11 -8
View File
@@ -44,7 +44,8 @@ BeforeAll {
param([Parameter(Mandatory = $true)][System.IO.FileSystemInfo]$Item, [Parameter(Mandatory = $true)]$Security)
if ($PSVersionTable.PSEdition -eq 'Core') {
[System.IO.FileSystemAclExtensions]::SetAccessControl($Item, $Security)
} else {
}
else {
$Item.SetAccessControl($Security)
}
}
@@ -109,7 +110,8 @@ BeforeAll {
try {
& takeown.exe /F $Path /R /D Y 2>&1 | Out-Null
& icacls.exe $Path /reset /T /C /Q 2>&1 | Out-Null
} finally {
}
finally {
$ErrorActionPreference = $previousPreference
}
@@ -145,7 +147,8 @@ BeforeAll {
try {
$exitCode = Invoke-ExternalCommand -FilePath 'cmd.exe' -ArgumentList @('/c', $cmdFile)
$lines = @(Get-Content -LiteralPath $outFile -Encoding UTF8 -ErrorAction SilentlyContinue)
} finally {
}
finally {
Remove-Item -LiteralPath $outFile -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $cmdFile -Force -ErrorAction SilentlyContinue
}
@@ -219,7 +222,7 @@ AfterAll {
# ============================================================================
Describe '排除判定与 7z 的 -x! / -xr! 语义对齐' {
# ============================================================================
# ============================================================================
It '锚定模式只命中它自己那棵子树' {
Test-BaknretPathExcluded -RelativePath 'Default\Cache' -Patterns @('Default\Cache') | Should -BeTrue
Test-BaknretPathExcluded -RelativePath 'Default\Cache\sub\x.bin' -Patterns @('Default\Cache') | Should -BeFalse
@@ -251,7 +254,7 @@ Describe '排除判定与 7z 的 -x! / -xr! 语义对齐' {
# ============================================================================
Describe 'SID 映射(跨机恢复)' {
# ============================================================================
# ============================================================================
It '整 SID 精确替换' {
$sddl = 'O:S-1-5-21-1-2-3-1001G:S-1-5-21-1-2-3-1001D:(A;;FA;;;S-1-5-21-1-2-3-1001)'
$mapped = Convert-BaknretSidMap -Sddl $sddl -SidMap @{ 'S-1-5-21-1-2-3-1001' = 'S-1-5-21-9-8-7-1001' }
@@ -272,7 +275,7 @@ Describe 'SID 映射(跨机恢复)' {
# ============================================================================
Describe '安全描述符采集' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:CaptureRoot = Join-Path $script:Sandbox 'capture\Data'
$script:CaptureItem = [pscustomobject]@{ ArchivePath = 'Data'; RealPath = $script:CaptureRoot }
@@ -341,7 +344,7 @@ Describe '安全描述符采集' {
# ============================================================================
Describe '安全描述符回放' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:RestoreRoot = Join-Path $script:Sandbox 'restore\Data'
$script:TargetRoot = Join-Path $script:Sandbox 'restore\target'
@@ -422,7 +425,7 @@ Describe '安全描述符回放' {
# ============================================================================
Describe '与 Backup.ps1 / Restore.ps1 的集成' -Skip:(-not $script:HasSevenZip) {
# ============================================================================
# ============================================================================
BeforeAll {
$script:Harness = New-AclEntryHarness -Name 'integration' -Root $script:Sandbox
$script:IntegrationFingerprints = New-AclSourceTree -Root $script:Harness.SourcePath
+28 -20
View File
@@ -82,7 +82,8 @@ BeforeAll {
try {
$exitCode = Invoke-ExternalCommand -FilePath 'cmd.exe' -ArgumentList @('/c', $cmdFile)
$lines = @(Get-Content -LiteralPath $outFile -Encoding UTF8 -ErrorAction SilentlyContinue)
} finally {
}
finally {
Remove-Item -LiteralPath $outFile -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $cmdFile -Force -ErrorAction SilentlyContinue
}
@@ -134,7 +135,7 @@ AfterAll {
# ============================================================================
Describe 'BackupList.txt 解析' {
# ============================================================================
# ============================================================================
It '注释行与空行返回 $null' {
ConvertFrom-BackupListLine -Line '# 这是注释' | Should -BeNullOrEmpty
@@ -364,7 +365,7 @@ Describe 'BackupList.txt 解析' {
# ============================================================================
Describe '归档命名' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:NamingRoot = Join-Path $script:Sandbox 'naming'
@@ -431,7 +432,7 @@ Describe '归档命名' {
# ============================================================================
Describe '7z 排除参数翻译' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:ExcludeTree = Join-Path $script:Sandbox 'exclude-tree'
@@ -588,7 +589,7 @@ Describe '7z 排除参数翻译' {
# ============================================================================
Describe '归档项与暂存目录' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:StagingRoot = Join-Path $script:Sandbox 'staging'
@@ -660,7 +661,8 @@ Describe '归档项与暂存目录' {
$cfg = Get-Item -LiteralPath (Join-Path $stage 'Cfg') -Force
$cfg.PSIsContainer | Should -BeFalse
(Get-Content -Encoding UTF8 -LiteralPath $cfg.FullName -Raw).Trim() | Should -Be 'file-content'
} finally {
}
finally {
Remove-BaknretArchiveStaging -Root $stage
}
}
@@ -678,7 +680,7 @@ Describe '归档项与暂存目录' {
# ============================================================================
Describe '命令行参数拼接' {
# ============================================================================
# ============================================================================
It '无空格参数原样输出' {
ConvertTo-NativeArgumentString -ArgumentList @('a', '-mx=9') | Should -Be 'a -mx=9'
@@ -703,7 +705,7 @@ Describe '命令行参数拼接' {
# ============================================================================
Describe 'manifest 与配置' {
# ============================================================================
# ============================================================================
It 'manifest 读写往返' {
$path = Join-Path $script:Sandbox 'roundtrip\manifest.json'
@@ -762,7 +764,8 @@ Describe 'manifest 与配置' {
(Get-BaknretPassword) | Should -Be 'sekrit'
$env:BAKNRET_PASSWORD = $null
(Get-BaknretPassword) | Should -BeNullOrEmpty
} finally {
}
finally {
$env:BAKNRET_PASSWORD = $saved
}
}
@@ -770,7 +773,7 @@ Describe 'manifest 与配置' {
# ============================================================================
Describe '软件名录' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:CatRoot = Join-Path $script:Sandbox 'catalog'
@@ -961,7 +964,7 @@ Describe '软件名录' {
# ============================================================================
Describe 'Resolve-BackupEntry:条目解析' {
# ============================================================================
# ============================================================================
BeforeAll {
$script:CatRoot = Join-Path $script:Sandbox 'catalog'
@@ -1114,7 +1117,7 @@ Describe 'Resolve-BackupEntry:条目解析' {
# ============================================================================
Describe '外部命令退出码(旧实现的核心缺陷)' {
# ============================================================================
# ============================================================================
It '口令不会进日志:DEBUG 下打印的命令行要遮蔽 -p 参数' {
$sandbox = Join-Path $env:TEMP ("bnr-secret-" + [guid]::NewGuid().ToString('N').Substring(0, 8))
@@ -1125,7 +1128,8 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
$logPath = Start-BaknretLog -Directory $sandbox -Prefix 'secret'
Set-BaknretDebug
$null = Invoke-ExternalCommand -FilePath 'cmd.exe' -ArgumentList @('/c', 'exit 0', "-p$sentinel")
} finally {
}
finally {
Set-BaknretDebug -Enabled:$false
Stop-BaknretLog
}
@@ -1153,7 +1157,8 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
$second | Should -BeNullOrEmpty
Test-Path -LiteralPath (Get-BaknretRunLockPath -Directory $dir) | Should -BeTrue
} finally {
}
finally {
Exit-BaknretRunLock -Lock $second
Exit-BaknretRunLock -Lock $first
}
@@ -1175,7 +1180,8 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
$second = Enter-BaknretRunLock -Directory $dir
$second | Should -Not -BeNullOrEmpty
Exit-BaknretRunLock -Lock $second
} finally {
}
finally {
Remove-Item -LiteralPath $dir -Recurse -Force -ErrorAction SilentlyContinue
}
}
@@ -1190,7 +1196,8 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
$summary.FileCount | Should -Be 0
$summary.TotalSize | Should -Not -BeNullOrEmpty
$summary.TotalSize | Should -Be 0
} finally {
}
finally {
Remove-Item -LiteralPath $empty -Recurse -Force -ErrorAction SilentlyContinue
}
}
@@ -1213,7 +1220,8 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
(Get-Item -LiteralPath $target).IsReadOnly = $true
{ Write-BaknretAtomicText -Path $target -Text 'SHOULD-NOT-LAND' } | Should -Throw
(Get-Content -Encoding UTF8 -LiteralPath $target -Raw) | Should -Be 'SECOND'
} finally {
}
finally {
$file = Get-Item -LiteralPath $target -ErrorAction SilentlyContinue
if ($file) { $file.IsReadOnly = $false }
Remove-Item -LiteralPath $base -Recurse -Force -ErrorAction SilentlyContinue
@@ -1231,7 +1239,7 @@ Describe '外部命令退出码(旧实现的核心缺陷)' {
# ============================================================================
Describe '集成:真实 7z 压缩与排除规则' -Skip:(-not $script:HasSevenZip) {
# ============================================================================
# ============================================================================
BeforeAll {
$script:IntegrationRoot = Join-Path $script:Sandbox 'integration'
@@ -1298,7 +1306,7 @@ Describe '集成:真实 7z 压缩与排除规则' -Skip:(-not $script:HasSeven
# ============================================================================
Describe '集成:Backup.ps1 / Restore.ps1 端到端(字面路径条目)' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
BeforeAll {
$script:E2ERoot = Join-Path $script:Sandbox 'e2e'
@@ -1468,7 +1476,7 @@ Describe '集成:Backup.ps1 / Restore.ps1 端到端(字面路径条目)' -
# ============================================================================
Describe '集成:方向标记与孤儿审计' -Skip:(-not ($script:HasSevenZip -and $script:HasPwsh)) {
# ============================================================================
# ============================================================================
# `+` / `-` 的归档名必须在方向过滤**之前**登记:这些条目自己不产生归档,
# 但它们对应的归档是有主的,不能被孤儿审计当成没人要的孤儿。
+16 -8
View File
@@ -193,9 +193,11 @@ function Compare-RestoredTree {
if ((Get-FileHash -LiteralPath $restoredItem.FullName -Algorithm SHA256).Hash -eq
(Get-FileHash -LiteralPath $liveItem.FullName -Algorithm SHA256).Hash) {
$report.Matched = 1
} elseif ($liveItem.LastWriteTime -gt $ArchiveTime) {
}
elseif ($liveItem.LastWriteTime -gt $ArchiveTime) {
$report.Stale = @($restoredItem.Name)
} else {
}
else {
$report.Changed = @($restoredItem.Name)
}
return $report
@@ -214,7 +216,8 @@ function Compare-RestoredTree {
if (-not (Test-Path -LiteralPath $liveFile)) {
if (Test-RemovedFromLiveAfterBackup -LiveRoot $liveRoot -Relative $relative -ArchiveTime $ArchiveTime) {
$report.Removed += $relative
} else {
}
else {
$report.Extra += $relative
}
continue
@@ -229,7 +232,8 @@ function Compare-RestoredTree {
# 内容不一样:先看是不是"源在归档之后动过"
if ((Get-Item -LiteralPath $liveFile -Force).LastWriteTime -gt $ArchiveTime) {
$report.Stale += $relative
} else {
}
else {
$report.Changed += $relative
}
}
@@ -372,7 +376,8 @@ foreach ($name in $Entries) {
if (-not (Test-Path -LiteralPath $scratchArchive)) {
try {
New-Item -ItemType SymbolicLink -Path $scratchArchive -Target $archiveFile.FullName -ErrorAction Stop | Out-Null
} catch {
}
catch {
Copy-Item -LiteralPath $archiveFile.FullName -Destination $scratchArchive -Force
}
}
@@ -416,7 +421,8 @@ foreach ($name in $Entries) {
$target = Join-Path $entryRoot ([string]$index)
if ($liveItem.PSIsContainer) {
New-Item -ItemType Directory -Path $target -Force | Out-Null
} else {
}
else {
[System.IO.File]::WriteAllText($target, '')
}
@@ -509,7 +515,8 @@ foreach ($name in $Entries) {
if ($changed.Count -gt 0) {
if ($AllowChanged) {
$detail += ";与活源不一致 $($changed.Count) 个(-AllowChanged,已容忍)"
} else {
}
else {
$status = 'FAIL'
$detail += ";与活源不一致 $($changed.Count) 个(首例 $($changed[0]))"
$failures += "$name :与活源不一致(首例 $($changed[0]))"
@@ -552,7 +559,8 @@ Write-Host ("恢复演练:通过 {0},跳过 {1},失败 {2}(真正对拍
if ($KeepWorkRoot) {
Write-Host "临时工作目录保留在:$WorkRoot" -ForegroundColor Yellow
} else {
}
else {
Remove-Item -LiteralPath $WorkRoot -Recurse -Force -ErrorAction SilentlyContinue
}
+6 -3
View File
@@ -101,7 +101,8 @@ function Get-OrphanNames {
if (-not $inSection) { continue }
if ($line -match '-\s+([^\s()]+?)(') {
$names += $Matches[1]
} else {
}
else {
$inSection = $false
}
}
@@ -288,7 +289,8 @@ try {
Assert-Equal 'backed-up' $acceptedRecord.action
Assert-Equal $true $acceptedRecord.warnings
}
} finally {
}
finally {
$lockStream.Close()
$lockStream.Dispose()
}
@@ -664,7 +666,8 @@ Test-Case '源路径不存在被记为 missing-source,退出码仍为 0(跳
if ($KeepWorkRoot) {
Write-Host "`n工作目录保留在:$WorkRoot" -ForegroundColor Yellow
} else {
}
else {
Remove-Item -LiteralPath $WorkRoot -Recurse -Force -ErrorAction SilentlyContinue
}
+6 -3
View File
@@ -84,14 +84,17 @@ function Invoke-BaknretCaptured {
try {
& cmd.exe /c $cmdFile | Out-Null
$code = $LASTEXITCODE
} finally {
}
finally {
$ErrorActionPreference = $previous
}
$text = if (Test-Path -LiteralPath $outFile) {
Get-Content -Encoding UTF8 -LiteralPath $outFile -Raw
} else { '' }
}
else { '' }
return [pscustomobject]@{ ExitCode = $code; Output = $text }
} finally {
}
finally {
Remove-Item -LiteralPath $outFile, $cmdFile -Force -ErrorAction SilentlyContinue
}
}
+18 -9
View File
@@ -463,7 +463,8 @@ Test-Case 'New-BaknretArchiveStaging:目录走 junction、文件走硬链接
Assert-Equal 'Junction' $dirLink.LinkType
Assert-Equal 'HardLink' $fileLink.LinkType
Assert-True (Test-Path -LiteralPath (Join-Path $staging 'AlphaData\f.txt')) '应能穿过 junction 看到内容'
} finally {
}
finally {
Remove-BaknretArchiveStaging -Root $staging
}
@@ -488,7 +489,8 @@ Test-Case 'New-BaknretJunction / Remove-BaknretJunction:只删连接点,不
Remove-BaknretJunction -Path $link
New-BaknretJunction -Path $link -Target $target | Out-Null
Assert-True $true
} finally {
}
finally {
Remove-BaknretJunction -Path $link
}
}
@@ -707,7 +709,8 @@ Test-Case '口令:环境变量可读取,取不到返回 $null' {
Assert-Null (Get-BaknretPassword -PasswordFile (Join-Path $sandbox 'nope'))
$env:BAKNRET_PASSWORD = 'from-env'
Assert-Equal 'from-env' (Get-BaknretPassword)
} finally {
}
finally {
Remove-Item Env:BAKNRET_PASSWORD -ErrorAction SilentlyContinue
if ($old) { $env:BAKNRET_PASSWORD = $old }
}
@@ -1071,7 +1074,8 @@ $sevenZip = Get-Command 7z -ErrorAction SilentlyContinue | Select-Object -First
if (-not $sevenZip) {
Write-Host ' 跳过:未找到 7z' -ForegroundColor Yellow
} else {
}
else {
Test-Case '排除规则与空格处理在真实归档上生效' {
$root = Join-Path $sandbox 'src'
$itemName = 'User Data'
@@ -1202,7 +1206,8 @@ Test-Case '口令不会进日志:DEBUG 下打印的命令行要遮蔽 -p 参
$logPath = Start-BaknretLog -Directory $sandbox -Prefix 'secret'
Set-BaknretDebug
$null = Invoke-ExternalCommand -FilePath 'cmd.exe' -ArgumentList @('/c', 'exit 0', "-p$sentinel")
} finally {
}
finally {
Set-BaknretDebug -Enabled:$false
Stop-BaknretLog
}
@@ -1236,7 +1241,8 @@ Test-Case '空目录的摘要给 0 而不是 $null(否则空间守卫会静默
Assert-True ($null -ne $summary.TotalSize) 'TotalSize 不能是 $null'
Assert-True ($summary.TotalSize -is [long]) 'TotalSize 应当是整数'
Assert-Equal 0 $summary.TotalSize
} finally {
}
finally {
Remove-Item -LiteralPath $empty -Recurse -Force -ErrorAction SilentlyContinue
}
}
@@ -1261,7 +1267,8 @@ Test-Case '原子替换:成功时新内容到位且不留 .tmp;失败时旧
try { Write-BaknretAtomicText -Path $target -Text 'SHOULD-NOT-LAND' | Out-Null } catch { $threw = $true }
Assert-True $threw '目标只读时替换应当抛错'
Assert-Equal 'SECOND' (Get-Content -Encoding UTF8 -LiteralPath $target -Raw)
} finally {
}
finally {
$file = Get-Item -LiteralPath $target -ErrorAction SilentlyContinue
if ($file) { $file.IsReadOnly = $false }
Remove-Item -LiteralPath $base -Recurse -Force -ErrorAction SilentlyContinue
@@ -1286,7 +1293,8 @@ Test-Case '运行锁:同一份备份目录同时只能有一个持有者' {
Assert-True ($null -eq $second) '同一目录的第二次不应当拿到锁'
Assert-FileExists (Get-BaknretRunLockPath -Directory $dir)
} finally {
}
finally {
Exit-BaknretRunLock -Lock $second
Exit-BaknretRunLock -Lock $first
}
@@ -1309,7 +1317,8 @@ Test-Case '运行锁:释放之后可以重新取得' {
$second = Enter-BaknretRunLock -Directory $dir
Assert-True ($null -ne $second) '释放之后应当能重新拿到锁'
Exit-BaknretRunLock -Lock $second
} finally {
}
finally {
Remove-Item -LiteralPath $dir -Recurse -Force -ErrorAction SilentlyContinue
}
}
+4 -2
View File
@@ -32,7 +32,8 @@ function Test-Case {
& $Body
$script:Passed++
Write-Host " [PASS] $Name" -ForegroundColor Green
} catch {
}
catch {
$script:Failed++
$script:Failures += "$Name —— $($_.Exception.Message)"
Write-Host " [FAIL] $Name" -ForegroundColor Red
@@ -94,7 +95,8 @@ function Write-TestSummary {
Write-Host ("=" * 60)
if ($script:Failed -eq 0) {
Write-Host "$Title 全部通过:$($script:Passed) 项" -ForegroundColor Green
} else {
}
else {
Write-Host "$Title 通过 $($script:Passed) 项,失败 $($script:Failed) 项" -ForegroundColor Red
foreach ($failure in $script:Failures) { Write-Host " - $failure" -ForegroundColor Red }
}
+48 -27
View File
@@ -1,26 +1,27 @@
<#
.SYNOPSIS
把测试用的 Pester 5 装进仓库内的 .tools\modules(不动机器上的全局模块)。
把测试与静态分析用的模块装进仓库内的 .tools\modules(不动机器上的全局模块)。
.DESCRIPTION
tests\BakNRet.Tests.ps1 需要 Pester 5.0+。本机常见的坑是:
* Windows 自带的是 Pester 3.4.0,没有 `Should -Be`,套件会语法错误;
* 直接 Install-Module 会把 5.x 装到全局,可能影响机器上别的、按 3.x 语法写的脚本。
装两样:
* Pester —— tests\BakNRet.Tests.ps1 需要 5.0+。本机常见的坑是 Windows 自带的是
3.4.0,没有 `Should -Be`,套件会语法错误;
* PSScriptAnalyzer —— tools\Invoke-Analyzer.ps1 用它做"按微软规范"的门禁。
所以这里用 Save-Module 把指定版本下载到仓库内的 .tools\modules,
tests\Run-Pester.ps1 会自动把该目录加进 PSModulePath。
.tools\ 已进 .gitignore,不会污染版本库。
两者都用 Save-Module 下载到仓库内,而不是 Install-Module:后者会装到全局,
可能影响机器上别的、按旧语法写的脚本。.tools\ 已进 .gitignore,不污染版本库。
.EXAMPLE
pwsh -File .\tools\Install-TestDependencies.ps1
.EXAMPLE
pwsh -File .\tools\Install-TestDependencies.ps1 -PesterVersion 5.9.1 -Force
pwsh -File .\tools\Install-TestDependencies.ps1 -Force
#>
[CmdletBinding()]
param(
[version]$PesterVersion = [version]'5.9.1',
[string]$PSScriptAnalyzerVersion = 'latest',
[switch]$Force
)
@@ -34,38 +35,58 @@ $installed = Join-Path $target ("Pester\{0}" -f $PesterVersion)
Write-Host ''
Write-Host ("目标目录 : {0}" -f $target)
Write-Host ("Pester : {0}" -f $PesterVersion)
Write-Host ("PSScriptAnalyzer: {0}" -f $PSScriptAnalyzerVersion)
Write-Host ''
if ((Test-Path -LiteralPath $installed) -and -not $Force) {
Write-Host "已经装好了,无需重复下载(要重装加 -Force)。" -ForegroundColor Green
exit 0
}
if ($Force -and (Test-Path -LiteralPath (Join-Path $target 'Pester'))) {
Remove-Item -LiteralPath (Join-Path $target 'Pester') -Recurse -Force
}
New-Item -ItemType Directory -Path $target -Force | Out-Null
if (-not (Get-Command Save-Module -ErrorAction SilentlyContinue)) {
Write-Error '当前环境没有 Save-Module(需要 PowerShellGet 2.x)。请改用:Install-Module Pester -Scope CurrentUser -MinimumVersion 5.0.0'
exit 1
}
try {
New-Item -ItemType Directory -Path $target -Force | Out-Null
$needPester = $Force -or -not (Test-Path -LiteralPath $installed)
if ($needPester) {
if ($Force -and (Test-Path -LiteralPath (Join-Path $target 'Pester'))) {
Remove-Item -LiteralPath (Join-Path $target 'Pester') -Recurse -Force
}
try {
Save-Module -Name Pester -RequiredVersion $PesterVersion -Path $target -Force -ErrorAction Stop
} catch {
Write-Error "下载失败(多半是访问不到 PSGallery):$_"
}
catch {
Write-Error "Pester 下载失败(多半是访问不到 PSGallery):$_"
exit 1
}
Write-Host ("已安装:Pester {0}" -f $PesterVersion) -ForegroundColor Green
}
else {
Write-Host "Pester {0} 已经装好了,跳过(要重装加 -Force)。" -f $PesterVersion -ForegroundColor DarkGray
}
$module = Get-Module -ListAvailable Pester | Where-Object { [version]$_.Version -eq $PesterVersion }
if (-not $module) {
Write-Error "下载结束但找不到 Pester $PesterVersion,请检查 $target。"
# PSScriptAnalyzer:版本目录带具体版本号,所以"装没装过"按目录是否存在判断
$analyzerInstalled = @(Test-Path -LiteralPath (Join-Path $target 'PSScriptAnalyzer'))
if ($Force -or -not $analyzerInstalled) {
if ($Force -and $analyzerInstalled) {
Remove-Item -LiteralPath (Join-Path $target 'PSScriptAnalyzer') -Recurse -Force
}
try {
Save-Module -Name PSScriptAnalyzer -Path $target -Force -ErrorAction Stop
}
catch {
Write-Error "PSScriptAnalyzer 下载失败(多半是访问不到 PSGallery):$_"
exit 1
}
$analyzerVersion = (Get-ChildItem (Join-Path $target 'PSScriptAnalyzer') -Directory | Select-Object -First 1).Name
Write-Host ("已安装:PSScriptAnalyzer {0}" -f $analyzerVersion) -ForegroundColor Green
}
else {
Write-Host 'PSScriptAnalyzer 已经装好了,跳过(要重装加 -Force)。' -ForegroundColor DarkGray
}
Write-Host ("已安装:Pester {0} -> {1}" -f $module.Version, $module.ModuleBase) -ForegroundColor Green
Write-Host '现在可以跑:.\tests\Run-Pester.ps1' -ForegroundColor Cyan
Write-Host ''
Write-Host '现在可以跑:' -ForegroundColor Cyan
Write-Host ' .\tests\Run-Pester.ps1 (单元套件)' -ForegroundColor Gray
Write-Host ' .\tools\Invoke-Analyzer.ps1 (静态分析门禁)' -ForegroundColor Gray
Write-Host ''
exit 0
+101
View File
@@ -0,0 +1,101 @@
<#
.SYNOPSIS
对全仓跑 PSScriptAnalyzer(默认规则集 + 格式规则集),按规则汇总。
.DESCRIPTION
为什么要有这个入口,而不是直接敲 Invoke-ScriptAnalyzer:
* 分析器装在**仓库内**(.tools\modules),不能指望机器上全局有一份;
* 格式规则默认是 Disabled —— 不带 -Settings 的调用会静默漏掉全部排版问题,
那会让"按微软规范检查过了"变成一句空话;
* 结果要能一眼看出"哪条规则、几个文件、几行",而不是几百行原始输出;
* 路径过滤要与验收门槛一致:.tools\ / Backups\ / logs\ / dist\ 不进分析范围。
与测试的分工:这是**独立的门禁**,不塞进 Pester 用例。那个套件跑一次二十多秒,
把静态分析混进去会让"测试红了"这句话失去分辨力。
.PARAMETER Severity
只报这些级别,默认 Error 与 Warning。
.PARAMETER Quiet
只打印按规则汇总的计数,不逐条列出。
.EXAMPLE
.\tools\Invoke-Analyzer.ps1
.EXAMPLE
.\tools\Invoke-Analyzer.ps1 -Quiet
#>
[CmdletBinding()]
param(
[string[]]$Severity = @('Error', 'Warning'),
[switch]$Quiet
)
$ErrorActionPreference = 'Stop'
$projectRoot = Split-Path -Parent $PSScriptRoot
$localModules = Join-Path $projectRoot '.tools\modules'
if (Test-Path -LiteralPath (Join-Path $localModules 'PSScriptAnalyzer')) {
$env:PSModulePath = $localModules + [System.IO.Path]::PathSeparator + $env:PSModulePath
}
$analyzer = Get-Module -ListAvailable PSScriptAnalyzer |
Sort-Object { [version]$_.Version } -Descending |
Select-Object -First 1
if (-not $analyzer) {
Write-Host ''
Write-Host '找不到 PSScriptAnalyzer。把它装进仓库(不动机器上的全局模块):' -ForegroundColor Red
Write-Host ' .\tools\Install-TestDependencies.ps1' -ForegroundColor Cyan
Write-Host ''
exit 2
}
Import-Module $analyzer.Path -Force
# 分析范围与验收门槛的 Encode / Parse 两层保持一致:只分析仓库自己的源码
$excluded = '\\(\.git|\.tools|\.scratch|Backups|logs|dist|snapshots)\\'
$targets = @(Get-ChildItem -LiteralPath $projectRoot -Recurse -File |
Where-Object { $_.Extension -in '.ps1', '.psm1', '.psd1' } |
Where-Object { $_.FullName -notmatch $excluded } |
Select-Object -ExpandProperty FullName)
$settings = Join-Path $projectRoot 'PSScriptAnalyzerSettings.psd1'
Write-Host ''
Write-Host ("PSScriptAnalyzer {0}({1})" -f $analyzer.Version, $analyzer.ModuleBase) -ForegroundColor DarkGray
Write-Host ("分析 {0} 个文件,配置 {1}" -f $targets.Count, $settings) -ForegroundColor DarkGray
Write-Host ''
# 逐个文件调用:-Path 在这个版本上只接受单个路径(传数组会报 Cannot convert
# 'System.Object[]' to the type 'System.String'),而我们要的正是「只分析仓库自己的
# 源码」这个范围 —— 自己枚举文件反而更准。
$results = @(foreach ($file in $targets) {
Invoke-ScriptAnalyzer -Path $file -Settings $settings -Severity $Severity
})
if ($results.Count -eq 0) {
Write-Host ("没有 {0} 级别的告警。" -f ($Severity -join '/')) -ForegroundColor Green
Write-Host ''
exit 0
}
$byRule = $results | Group-Object RuleName | Sort-Object Count -Descending
Write-Host ("共 {0} 条,按规则汇总:" -f $results.Count) -ForegroundColor Yellow
foreach ($group in $byRule) {
Write-Host (" {0,4} {1}" -f $group.Count, $group.Name)
}
if (-not $Quiet) {
Write-Host ''
Write-Host '逐条:' -ForegroundColor Yellow
foreach ($item in ($results | Sort-Object ScriptName, Line)) {
$relative = $item.ScriptName.Replace($projectRoot, '').TrimStart('\')
Write-Host (" {0}:{1} [{2}] {3}" -f $relative, $item.Line, $item.RuleName, $item.Message)
}
}
Write-Host ''
exit 1
+4 -2
View File
@@ -78,7 +78,8 @@ if ($Remove) {
try {
Unregister-ScheduledTask -TaskName $TaskName -Confirm:$false -ErrorAction Stop
Write-Host "已移除计划任务:$TaskName" -ForegroundColor Green
} catch {
}
catch {
Write-Error "移除失败(多半是权限不足,请用管理员终端):$_"
exit 1
}
@@ -116,7 +117,8 @@ try {
Write-Host "已注册计划任务:$TaskName(每天 $At)" -ForegroundColor Green
Write-Host "查看上次运行结果:Get-ScheduledTaskInfo -TaskName '$TaskName'" -ForegroundColor DarkGray
Write-Host "手动跑一次验证 :Start-ScheduledTask -TaskName '$TaskName'" -ForegroundColor DarkGray
} catch {
}
catch {
Write-Error "注册失败(多半是权限不足,请用管理员终端):$_"
exit 1
}
+2 -1
View File
@@ -242,7 +242,8 @@ foreach ($entry in $plan) {
Write-Host "已重命名: $($entry.Old.Name) -> $($entry.New)" -ForegroundColor Green
$ok++
} catch {
}
catch {
Write-Host "重命名失败: $($entry.Old.Name) —— $_" -ForegroundColor Red
$failed++
}
+2 -1
View File
@@ -65,7 +65,8 @@ Write-Host ("受管文件 {0} 个" -f $targets.Count)
if ($addedBom.Count -gt 0) {
Write-Host ("补上 BOM {0} 个:" -f $addedBom.Count) -ForegroundColor Yellow
$addedBom | ForEach-Object { Write-Host " $_" }
} else {
}
else {
Write-Host '所有文件都已经带 BOM。' -ForegroundColor Green
}
if ($normalizedLf.Count -gt 0) {
+7 -4
View File
@@ -44,7 +44,7 @@ function Get-LabPath {
function Write-LabLog {
<# .SYNOPSIS 统一日志:同时进控制台与 $LabRoot\logs\lab.log。 #>
param([Parameter(Mandatory)][string]$Message, [ValidateSet('INFO','WARN','ERROR','STEP')][string]$Level = 'INFO')
param([Parameter(Mandatory)][string]$Message, [ValidateSet('INFO', 'WARN', 'ERROR', 'STEP')][string]$Level = 'INFO')
$line = "[{0}] [{1,-5}] {2}" -f (Get-Date).ToString('HH:mm:ss'), $Level, $Message
switch ($Level) {
'STEP' { Write-Host $line -ForegroundColor Cyan }
@@ -131,7 +131,8 @@ function New-LabSession {
$s = New-PSSession -VMName $script:LabConfig.VmName -Credential $cred -ErrorAction Stop
Write-LabLog "PowerShell Direct 会话已建立(等待 $([math]::Round($sw.Elapsed.TotalSeconds)) 秒)"
return $s
} catch {
}
catch {
$lastError = $_.Exception.Message
Start-Sleep -Seconds 5
}
@@ -149,7 +150,8 @@ function Invoke-LabCommand {
$s = New-LabSession -RetrySeconds $RetrySeconds
try {
return Invoke-Command -Session $s -ScriptBlock $ScriptBlock -ArgumentList $ArgumentList -ErrorAction Stop
} finally {
}
finally {
Remove-PSSession -Session $s -ErrorAction SilentlyContinue
}
}
@@ -178,5 +180,6 @@ function Test-LabGuestReady {
try {
$r = Invoke-LabCommand -ScriptBlock { Test-Path 'C:\BakNRet-Lab\state\provision.ok' } -RetrySeconds 60
return [bool]$r
} catch { return $false }
}
catch { return $false }
}
+11 -8
View File
@@ -38,10 +38,10 @@
[CmdletBinding()]
param(
[Parameter(Mandatory, Position = 0)]
[ValidateSet('status','start','stop','wait','sync','seed','backup','restore','acl-test','test','shell','console','checkpoint','reset','destroy')]
[ValidateSet('status', 'start', 'stop', 'wait', 'sync', 'seed', 'backup', 'restore', 'acl-test', 'test', 'shell', 'console', 'checkpoint', 'reset', 'destroy')]
[string]$Verb,
[ValidateSet('all','pester','zero','e2e')][string]$Suite = 'all',
[ValidateSet('all', 'pester', 'zero', 'e2e')][string]$Suite = 'all',
# 恢复演练要处理的条目(写法同 BackupList.txt 的一行)
[string[]]$Entries,
@@ -127,7 +127,7 @@ function Invoke-GuestScriptFile {
$text = if ($badUtf8 -le $badAnsi) { $asUtf8 } else { $asAnsi }
return @($text -split "`r?`n" | Where-Object { $_ -ne '' } | Select-Object -Last $lines)
}
$all = @('-NoProfile','-ExecutionPolicy','Bypass','-File',$script) + $scriptArgs
$all = @('-NoProfile', '-ExecutionPolicy', 'Bypass', '-File', $script) + $scriptArgs
$out = $logPath
$err = "$logPath.err"
$p = Start-Process -FilePath 'pwsh.exe' -ArgumentList $all -NoNewWindow -Wait -PassThru -RedirectStandardOutput $out -RedirectStandardError $err
@@ -147,7 +147,8 @@ function Invoke-LabSync {
Push-Location $cfg.RepoRoot
try {
& $sevenZip a -tzip $zip '.\*' '-xr!Backups' '-xr!logs' '-xr!.git' '-xr!.tools' '-xr!*.tmp.7z' '-xr!*.tmp.zip' -y | Out-Null
} finally { Pop-Location }
}
finally { Pop-Location }
Write-LabLog ("快照大小 {0} MB" -f [math]::Round((Get-Item -LiteralPath $zip).Length / 1MB, 2))
Write-LabLog '推送到 VM(Copy-VMFile,走 VMBus)' 'STEP'
@@ -235,9 +236,11 @@ switch ($Verb) {
if ($g.Archives.Count -gt 0) {
Write-Host ("沙盒归档 : {0} 个({1} MB 合计)" -f $g.Archives.Count, [math]::Round((($g.Archives | Measure-Object MB -Sum).Sum), 1))
$g.Archives | Sort-Object MB -Descending | ForEach-Object { Write-Host (" {0,-52} {1,8} MB" -f $_.Name, $_.MB) }
} else { Write-Host '沙盒归档 : (还没有,跑 Lab.ps1 backup)' }
}
else { Write-Host '沙盒归档 : (还没有,跑 Lab.ps1 backup)' }
if ($g.LastLog) { Write-Host ("最近备份日志: {0}" -f $g.LastLog) }
} catch {
}
catch {
Write-Host ("VM 内查询失败(可能还没起来):{0}" -f $_.Exception.Message) -ForegroundColor Yellow
}
}
@@ -367,7 +370,7 @@ switch ($Verb) {
$color = if ($_.ExitCode -eq 0) { 'Green' } else { 'Red' }
Write-Host (" {0,-14} 退出码 {1} 日志 {2}" -f $_.Suite, $_.ExitCode, $_.Log) -ForegroundColor $color
}
$bad = @($results | Where-Object ExitCode -ne 0)
$bad = @($results | Where-Object ExitCode -NE 0)
if ($bad.Count -gt 0) { throw ("有 {0} 套件失败" -f $bad.Count) }
}
@@ -398,7 +401,7 @@ switch ($Verb) {
'reset' {
if (-not $CheckpointName) { $CheckpointName = $cfg.CheckpointName }
$snap = Get-VMSnapshot -VMName $cfg.VmName -ErrorAction SilentlyContinue | Where-Object Name -eq $CheckpointName
$snap = Get-VMSnapshot -VMName $cfg.VmName -ErrorAction SilentlyContinue | Where-Object Name -EQ $CheckpointName
if (-not $snap) { throw "找不到检查点 $CheckpointName" }
Write-LabLog "回到检查点 $CheckpointName" 'STEP'
Restore-VMSnapshot -VMSnapshot $snap -Confirm:$false
+17 -14
View File
@@ -29,7 +29,7 @@
[CmdletBinding()]
param(
[ValidateSet('all','disk','vm','provision')][string]$Stage = 'all',
[ValidateSet('all', 'disk', 'vm', 'provision')][string]$Stage = 'all',
[switch]$Recreate,
[switch]$ListImages,
[int]$ImageIndex = 0
@@ -54,7 +54,7 @@ function Get-IsoVolume {
function Get-ImageList {
param([Parameter(Mandatory)][string]$IsoLetter)
$wim = @('install.wim','install.esd') |
$wim = @('install.wim', 'install.esd') |
ForEach-Object { Join-Path "$IsoLetter`:\sources" $_ } |
Where-Object { Test-Path -LiteralPath $_ } | Select-Object -First 1
if (-not $wim) { throw "ISO ($IsoLetter`:) 里找不到 sources\install.wim|esd" }
@@ -115,7 +115,7 @@ function New-LabSystemDisk {
Write-LabLog '已完成 GPT 分区(ESP 类型已按 EFI System Partition 建立)与格式化' 'STEP'
}
$efiPart = Get-Partition -DiskNumber $disk.Number | Where-Object GptType -eq $espGuid
$efiPart = Get-Partition -DiskNumber $disk.Number | Where-Object GptType -EQ $espGuid
$winPart = Get-Partition -DiskNumber $disk.Number | Where-Object { $_.GptType -eq '{ebd0a0a2-b9e5-4433-87c0-68b6b72699c7}' -and $_.Size -gt 1GB }
if (-not $efiPart -or -not $winPart) { throw '分区布局不符合预期(ESP / Windows 分区没找到)' }
$efiLetter = $efiPart.DriveLetter
@@ -129,17 +129,18 @@ function New-LabSystemDisk {
$di = Get-IsoVolume
$isoLetter = ($di | Get-Volume).DriveLetter
$il = Get-ImageList -IsoLetter $isoLetter
$pick = $il.Images | Where-Object Index -eq $cfg.ImageIndex
$pick = $il.Images | Where-Object Index -EQ $cfg.ImageIndex
if (-not $pick) { throw "ISO 里没有索引 $($cfg.ImageIndex);可用:$($il.Images.Index -join ', ')" }
Write-LabLog "展开映像 [$($pick.Index)] $($pick.Name) -> $winLetter`:(需要十几分钟)" 'STEP'
$scratch = Get-LabPath 'scratch'
$out = Get-LabPath 'logs\dism-apply.out'
$err = Get-LabPath 'logs\dism-apply.err'
$proc = Start-Process -FilePath 'dism.exe' -NoNewWindow -Wait -PassThru -RedirectStandardOutput $out -RedirectStandardError $err `
-ArgumentList @('/English','/Apply-Image',"/ImageFile:$($il.WimPath)", "/Index:$($pick.Index)", "/ApplyDir:$winLetter`:\", "/ScratchDir:$scratch")
-ArgumentList @('/English', '/Apply-Image', "/ImageFile:$($il.WimPath)", "/Index:$($pick.Index)", "/ApplyDir:$winLetter`:\", "/ScratchDir:$scratch")
if ($proc.ExitCode -ne 0) { throw "DISM 展开失败,退出码 $($proc.ExitCode),见 $out / $err" }
Write-LabLog '映像展开完成' 'STEP'
} else {
}
else {
Write-LabLog '系统盘上已有 Windows,跳过展开' 'WARN'
}
@@ -147,12 +148,13 @@ function New-LabSystemDisk {
Write-LabLog '注入 7-Zip / PowerShell 7 / Pester / 供给脚本' 'STEP'
$payloadSrc = Join-Path $PSScriptRoot 'payload'
$guestLab = Join-Path "$winLetter`:\" ($cfg.GuestLabPath.TrimStart('\'))
foreach ($item in '7zip','pwsh','Pester','provision.ps1') {
foreach ($item in '7zip', 'pwsh', 'Pester', 'provision.ps1') {
$src = Join-Path $payloadSrc $item
$dst = Join-Path $guestLab ('payload\' + $item)
if (Test-Path -LiteralPath $src) {
$null = robocopy $src $dst /MIR /NFL /NDL /NJH /NJS /NP /R:1 /W:1
} else {
}
else {
Write-LabLog "负载缺失(跳过):$src" 'WARN'
}
}
@@ -198,9 +200,10 @@ function New-LabVM {
# 集成服务名随系统语言变化(中文是「来宾服务接口」),按状态启用而不是按名字找
Get-VMIntegrationService -VMName $cfg.VmName | Where-Object { -not $_.Enabled } |
ForEach-Object { Enable-VMIntegrationService -VMName $cfg.VmName -Name $_.Name }
} else {
}
else {
Write-LabLog "虚拟机 $($cfg.VmName) 已存在(状态 $($vm.State))" 'WARN'
if (-not (Get-VMHardDiskDrive -VMName $cfg.VmName | Where-Object Path -eq $cfg.VhdxPath)) {
if (-not (Get-VMHardDiskDrive -VMName $cfg.VmName | Where-Object Path -EQ $cfg.VhdxPath)) {
Add-VMHardDiskDrive -VMName $cfg.VmName -Path $cfg.VhdxPath
}
}
@@ -235,7 +238,7 @@ function Wait-LabProvision {
function New-LabCheckpoint {
Assert-LabElevated -Why '创建 Hyper-V 检查点'
$existing = Get-VMSnapshot -VMName $cfg.VmName -ErrorAction SilentlyContinue | Where-Object Name -eq $cfg.CheckpointName
$existing = Get-VMSnapshot -VMName $cfg.VmName -ErrorAction SilentlyContinue | Where-Object Name -EQ $cfg.CheckpointName
if ($existing) { Write-LabLog "检查点 $($cfg.CheckpointName) 已存在,跳过" 'WARN'; return }
Checkpoint-VM -Name $cfg.VmName -SnapshotName $cfg.CheckpointName
Write-LabLog "已创建检查点 $($cfg.CheckpointName)(Lab.ps1 -Verb reset 可回到此状态)" 'STEP'
@@ -245,8 +248,8 @@ function New-LabCheckpoint {
# 主流程
# ---------------------------------------------------------------------------
if ($Stage -in @('all','disk')) { New-LabSystemDisk }
if ($Stage -in @('all','vm')) { New-LabVM }
if ($Stage -in @('all','provision')) { Wait-LabProvision; New-LabCheckpoint }
if ($Stage -in @('all', 'disk')) { New-LabSystemDisk }
if ($Stage -in @('all', 'vm')) { New-LabVM }
if ($Stage -in @('all', 'provision')) { Wait-LabProvision; New-LabCheckpoint }
Write-LabLog '搭建流程结束' 'STEP'
+6 -4
View File
@@ -34,7 +34,8 @@ function New-TextFile {
if (-not (Test-Path -LiteralPath $dir)) { New-Item -ItemType Directory -Force -Path $dir | Out-Null }
if ($Count -le 1) {
Set-Content -LiteralPath $Path -Value $Content -Encoding UTF8
} else {
}
else {
Set-Content -LiteralPath $Path -Value (1..$Count | ForEach-Object { "$Content #$_" }) -Encoding UTF8
}
}
@@ -95,9 +96,10 @@ if (-not (Test-Path -LiteralPath $bigFile)) {
$rng = [Random]::new(20260926)
$chunk = [byte[]]::new(1MB)
for ($i = 0; $i -lt 50; $i++) { $rng.NextBytes($chunk); $fs.Write($chunk, 0, $chunk.Length) }
} finally { $fs.Dispose() }
}
finally { $fs.Dispose() }
}
Write-Host ("大文件:{0} MB" -f [math]::Round((Get-Item $bigFile).Length/1MB,1))
Write-Host ("大文件:{0} MB" -f [math]::Round((Get-Item $bigFile).Length / 1MB, 1))
# --- 7. 被占用文件(后台进程持句柄 90 秒后释放)-----------------------------
$lockDir = Join-Path $Root 'AppLocked'
@@ -111,7 +113,7 @@ $holderLines = @(
)
$holderPath = 'C:\BakNRet-Lab\state\hold-lock.ps1'
Set-Content -LiteralPath $holderPath -Value $holderLines -Encoding UTF8
Start-Process -FilePath 'powershell.exe' -ArgumentList @('-NoProfile','-ExecutionPolicy','Bypass','-File',$holderPath,$lockFile) -WindowStyle Hidden
Start-Process -FilePath 'powershell.exe' -ArgumentList @('-NoProfile', '-ExecutionPolicy', 'Bypass', '-File', $holderPath, $lockFile) -WindowStyle Hidden
Write-Host "已启动占用者进程(持句柄 90 秒):$lockFile"
# --- 8. 「源不存在」条目对应的目录:故意不建 ---------------------------------
+27 -15
View File
@@ -66,7 +66,8 @@ function Invoke-NativeTolerant {
$ErrorActionPreference = 'Continue'
try {
return @(& $FilePath @ArgumentList 2>&1)
} finally {
}
finally {
$ErrorActionPreference = $previous
}
}
@@ -75,7 +76,8 @@ function Test-Scenario {
if ($Ok) {
$script:Passed++
Write-Host (" [PASS] {0}" -f $Name) -ForegroundColor Green
} else {
}
else {
$script:Failures += $Name
Write-Host (" [FAIL] {0}{1}" -f $Name, $(if ($Detail) { ' —— ' + $Detail } else { '' })) -ForegroundColor Red
}
@@ -156,7 +158,8 @@ function Stop-VscodeProcesses {
if ($path -and $path.StartsWith($AppRoot, [System.StringComparison]::OrdinalIgnoreCase)) {
Stop-Process -Id $process.Id -Force -ErrorAction SilentlyContinue
}
} catch { }
}
catch { }
}
}
Start-Sleep -Milliseconds 700
@@ -207,7 +210,8 @@ function Remove-TreeHard {
if (Test-Path -LiteralPath $WorkRoot) {
Get-ChildItem -LiteralPath $WorkRoot -Directory -ErrorAction SilentlyContinue | ForEach-Object { Remove-TreeHard -Path $_.FullName }
} else {
}
else {
New-Item -ItemType Directory -Path $WorkRoot -Force | Out-Null
}
$BackupDir = Join-Path $WorkRoot 'backups'
@@ -242,10 +246,12 @@ if (-not $SkipScoop) {
try {
Invoke-Expression "& {$(Invoke-RestMethod -Uri 'https://get.scoop.sh')} -RunAsAdmin"
Write-Host ('[A] 安装器退出码:{0}' -f $LASTEXITCODE)
} catch {
}
catch {
Test-Scenario 'A: 安装 scoop' $false $_.Exception.Message
}
} else {
}
else {
Write-Host '[A] scoop 已存在,跳过安装'
}
@@ -299,9 +305,11 @@ $vscodeReady = [bool]$codeCmd
if ($vscodeReady) {
Test-Scenario 'A: vscode 已安装(找到 CLI)' $true $codeCmd
} elseif ($SkipScoop) {
}
elseif ($SkipScoop) {
Write-Host (' [SKIP] 按 -SkipScoop 跳过 vscode({0} 不存在)' -f $vscodeCli) -ForegroundColor Yellow
} else {
}
else {
Test-Scenario 'A: vscode 已安装(找到 CLI)' $false $vscodeCli
}
@@ -357,7 +365,7 @@ $sourceOwner = (Get-Acl -LiteralPath $bData).GetOwner([System.Security.Principal
Write-Host ('[B] 备份前 data 的属主:{0}' -f (Get-Acl -LiteralPath $bData).Owner)
$currentSid = ([System.Security.Principal.WindowsIdentity]::GetCurrent()).User.Value
Test-Scenario 'B: 现场造对了 —— 属主既不是当前账户、也不是新建对象的默认属主' `
(($sourceOwner -ne $currentSid) -and ($sourceOwner -ne $creatorOwner)) `
(($sourceOwner -ne $currentSid) -and ($sourceOwner -ne $creatorOwner)) `
"owner=$sourceOwner current=$currentSid creatorDefault=$creatorOwner"
# ---------------------------------------------------------------------------
@@ -398,7 +406,7 @@ $backup = Invoke-BaknretChild -Script (Join-Path $RepoPath 'Backup.ps1') -Parame
$backup.LastLog | ForEach-Object { ' ' + $_ }
Test-Scenario '备份退出码 0' ($backup.ExitCode -eq 0) ('exit=' + $backup.ExitCode)
Test-Scenario '每个条目都写了 .acl.json' (@(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count -ge $entries.Count) `
('acl.json=' + @(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count + ' 条目=' + $entries.Count)
('acl.json=' + @(Get-ChildItem -LiteralPath $BackupDir -Filter '*.acl.json').Count + ' 条目=' + $entries.Count)
# ---------------------------------------------------------------------------
# 删源 → 恢复
@@ -445,7 +453,8 @@ if ($vscodeReady) {
[System.IO.File]::WriteAllText($probeFile, 'write probe')
$writeOk = (Test-Path -LiteralPath $probeFile)
Remove-Item -LiteralPath $probeFile -Force -ErrorAction SilentlyContinue
} catch {
}
catch {
$detail = $_.Exception.Message
}
Test-Scenario 'A: vscode 的数据目录可写(新建文件成功)' $writeOk $detail
@@ -457,7 +466,8 @@ if ($vscodeReady) {
Test-Scenario ("A: {0} 的安全指纹与备份前一致" -f $pair[1]) ($actualNormalized -eq $expectedNormalized) `
("want: " + $expectedNormalized + " / got: " + $actualNormalized)
}
} else {
}
else {
Write-Host ' [SKIP] vscode 没装上,A 段的功能断言跳过(-SkipScoop 或下载失败)' -ForegroundColor Yellow
}
@@ -488,7 +498,7 @@ $negative = Join-Path $WorkRoot 'negative-data'
& robocopy.exe $bData $negative /E /COPY:DAT /NFL /NDL /NJH /NJS /NP | Out-Null
$negativeOwner = (Get-Acl -LiteralPath $negative).GetOwner([System.Security.Principal.SecurityIdentifier]).Value
Test-Scenario 'B 负对照: 只搬文件时,属主变成"跑脚本的账户"而不再是原账户' `
(($negativeOwner -ne $sourceOwner) -and ($negativeOwner -eq $creatorOwner)) `
(($negativeOwner -ne $sourceOwner) -and ($negativeOwner -eq $creatorOwner)) `
"negative=$negativeOwner creatorDefault=$creatorOwner"
Write-Host (' 原属主 = {0}' -f $sourceOwner)
Write-Host (' 恢复后属主 = {0}(应与原属主相同)' -f $restoredOwner)
@@ -501,14 +511,16 @@ Write-Host ''
$total = $script:Passed + $script:Failures.Count
if ($script:Failures.Count -eq 0) {
Write-Host ('ACL 演练:全部通过 {0} 项' -f $total) -ForegroundColor Green
} else {
}
else {
Write-Host ('ACL 演练:通过 {0} 项,失败 {1} 项' -f $script:Passed, $script:Failures.Count) -ForegroundColor Red
foreach ($failure in $script:Failures) { Write-Host (' - ' + $failure) -ForegroundColor Red }
}
if ($KeepWorkRoot) {
Write-Host ('临时目录保留:{0}' -f $WorkRoot) -ForegroundColor Yellow
} else {
}
else {
Remove-TreeHard -Path $bRoot
Remove-TreeHard -Path (Join-Path $WorkRoot 'negative-data')
# 备份与日志留着,便于事后核对(归档可能有几百 MB,要腾空间就手工删这个目录)
+1 -1
View File
@@ -21,5 +21,5 @@
ToolOutput = 'quiet'
Snapshot = @{ Enabled = $false; KeepCount = 3; KeepDays = 30 }
Encryption = @{ Enabled = $false; PasswordFile = 'C:\BakNRet-Lab\state\baknret.key'; EncryptHeaders = $true }
DefaultExcludes = @('!Thumbs.db','!desktop.ini')
DefaultExcludes = @('!Thumbs.db', '!desktop.ini')
}