Skip to content

Cover the app-removal execution paths - #85

Merged
BiosSystem merged 1 commit into
masterfrom
feature/app-removal-execution-tests
Sep 29, 2026
Merged

BiosSystem merged 1 commit into
masterfrom
feature/app-removal-execution-tests

Conversation

@BiosSystem

Copy link
Copy Markdown
Owner

RemoveApps.ps1 and ForceRemoveEdge.ps1 uninstall Store apps via winget and the Appx cmdlets, fall back to DISM on 24H2, schedule RunOnce winget tasks and force-remove Edge. Until now nothing ran these bodies outside the Sandbox suite; the unit tests covered only the app metadata and the verification adapters.

Test-AppRemovalExecution.ps1 runs the removal logic with every OS-touching command mocked, and winget/DISM shadowed by no-op functions so the native tools cannot run even if a mock were missing. Coverage:

  • winget-vs-Appx dispatch from Apps.json metadata, and the array-AppId case in Get-AppRemovalMethod
  • Edge deferred to the end of the loop, never routed through the per-app path
  • cancel short circuit, and the WhatIf preview that removes nothing
  • post-removal verification counters: still-present → failure, gone → removed, unreadable list → verification-unavailable
  • winget/Sysprep RunOnce scheduling, Test-AppStillInstalled, Edge autostart cleanup outcomes
  • ForceRemoveEdge WhatIf/DryRun short circuit

The RunOnce tests lock the security-relevant part: the winget command is Base64-encoded so a hostile app id (containing & or a quote) stays inside the blob instead of reaching the shell, and the value name is sanitized.

ForceRemoveEdge writes to HKLM before any exit-code logic, so only its WhatIf/DryRun path is unit-tested; the rest stays in the Sandbox suite.

Test-only. New file wired into CI. Validation run locally: static validation clean (140 files), full unit suite 312 passed / 0 failed (was 279). Not run locally: the Sandbox mutating suite (unchanged) and CI's pwsh/MTA pass, which runs on the PR.

RemoveApps.ps1 and ForceRemoveEdge.ps1 uninstall Store apps through
winget and the Appx cmdlets, fall back to DISM on 24H2, schedule RunOnce
winget tasks and force-remove Edge. Nothing ran these bodies outside the
Windows Sandbox suite; the unit tests only covered the app metadata and
the verification adapters.

Test-AppRemovalExecution.ps1 runs the removal logic with every
OS-touching command mocked, and winget and DISM shadowed by no-op
functions so the native tools cannot run even if a mock were missing. It
covers the winget-vs-Appx dispatch, the Edge deferral to the end of the
loop, the cancel short circuit, the post-removal verification counters
(failure, removed, and verification-unavailable), the winget/Sysprep
task scheduling, Test-AppStillInstalled, the Edge autostart cleanup and
the ForceRemoveEdge WhatIf/DryRun short circuit.

The RunOnce tests lock the security-relevant part: the winget command is
Base64-encoded so a hostile app id (with & or a quote) stays inside the
blob instead of reaching the shell, and the value name is sanitized.

ForceRemoveEdge writes to HKLM before any exit-code logic, so only its
WhatIf/DryRun path is unit-tested; the rest stays in the Sandbox suite.
@BiosSystem
BiosSystem merged commit 26ba0bc into master Sep 29, 2026
1 check passed
@BiosSystem
BiosSystem deleted the feature/app-removal-execution-tests branch September 29, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant