From 4e8ff81998b780ac32967a2e51a7ac79ea595148 Mon Sep 17 00:00:00 2001 From: BiosSystem <63607038+BiosSystem@users.noreply.github.com> Date: Thu, 24 Sep 2026 17:03:30 +0300 Subject: [PATCH] Document where the unelevated -Verify test can run refuses to verify without elevation only runs in an unelevated session, and both the CI runner and Windows Sandbox are elevated, so it never ran. Say that a workstation run of the ReadOnly tag is where it executes. Run that way it passes, which completes coverage of the integration suite: every test has now passed at least once. --- Tests/Integration/README.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/Tests/Integration/README.md b/Tests/Integration/README.md index a0ebbf0..36c0435 100644 --- a/Tests/Integration/README.md +++ b/Tests/Integration/README.md @@ -30,6 +30,12 @@ Read-only checks, safe on a workstation: .\Tests\Integration\Invoke-IntegrationTests.ps1 ``` +Run this from a normal, non-elevated PowerShell as well as from an elevated one. +One test, `refuses to verify without elevation`, only runs unelevated, and the +CI runner and Windows Sandbox are both elevated, so a workstation run is the only +place it executes. Unelevated, Winnow stops at its admin check without a UAC +prompt, because the test runs it with input redirected. + Adding the dry-run checks, on a machine you can throw away: ```powershell