Cover the app-removal execution paths - #85
Merged
Merged
Conversation
RemoveApps.ps1 and ForceRemoveEdge.ps1 uninstall Store apps through winget and the Appx cmdlets, fall back to DISM on 24H2, schedule RunOnce winget tasks and force-remove Edge. Nothing ran these bodies outside the Windows Sandbox suite; the unit tests only covered the app metadata and the verification adapters. Test-AppRemovalExecution.ps1 runs the removal logic with every OS-touching command mocked, and winget and DISM shadowed by no-op functions so the native tools cannot run even if a mock were missing. It covers the winget-vs-Appx dispatch, the Edge deferral to the end of the loop, the cancel short circuit, the post-removal verification counters (failure, removed, and verification-unavailable), the winget/Sysprep task scheduling, Test-AppStillInstalled, the Edge autostart cleanup and the ForceRemoveEdge WhatIf/DryRun short circuit. The RunOnce tests lock the security-relevant part: the winget command is Base64-encoded so a hostile app id (with & or a quote) stays inside the blob instead of reaching the shell, and the value name is sanitized. ForceRemoveEdge writes to HKLM before any exit-code logic, so only its WhatIf/DryRun path is unit-tested; the rest stays in the Sandbox suite.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
RemoveApps.ps1andForceRemoveEdge.ps1uninstall Store apps via winget and the Appx cmdlets, fall back to DISM on 24H2, schedule RunOnce winget tasks and force-remove Edge. Until now nothing ran these bodies outside the Sandbox suite; the unit tests covered only the app metadata and the verification adapters.Test-AppRemovalExecution.ps1runs the removal logic with every OS-touching command mocked, andwinget/DISMshadowed by no-op functions so the native tools cannot run even if a mock were missing. Coverage:Apps.jsonmetadata, and the array-AppIdcase inGet-AppRemovalMethodTest-AppStillInstalled, Edge autostart cleanup outcomesForceRemoveEdgeWhatIf/DryRun short circuitThe RunOnce tests lock the security-relevant part: the winget command is Base64-encoded so a hostile app id (containing
&or a quote) stays inside the blob instead of reaching the shell, and the value name is sanitized.ForceRemoveEdgewrites to HKLM before any exit-code logic, so only its WhatIf/DryRun path is unit-tested; the rest stays in the Sandbox suite.Test-only. New file wired into CI. Validation run locally: static validation clean (140 files), full unit suite 312 passed / 0 failed (was 279). Not run locally: the Sandbox mutating suite (unchanged) and CI's pwsh/MTA pass, which runs on the PR.