Invoke-PSBuildModuleSigning has no test that calls it
評估
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 新手友好度
- 76/100
- Issue 類型
- 重構
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- powershell
- 領域
- testing-qa
研究方向
從 tests/Invoke-PSBuildModuleSigning.tests.ps1 和 Invoke-PSBuildModuleSigning.ps1 函式本體開始。替換或修改兩個檔案探索測試,使其呼叫該函式,並使用 issue 中描述的具範圍的 Set-AuthenticodeSignature mock 模式。執行測試檔案,並驗證涵蓋範圍包括探索、參數轉送,以及為每個探索到的檔案簽署。
由索引模型根據 Issue 內容生成。
描述
tests/Invoke-PSBuildModuleSigning.tests.ps1 has eleven passing tests and none of them call Invoke-PSBuildModuleSigning. The function's body has never executed.
What happens
Two tests are named as though they exercise the function's file discovery:
It 'Searches for files matching Include patterns' {
...
Mock Set-AuthenticodeSignature { [PSCustomObject]@{ Status = 'Valid'; Path = $InputObject } }
# We need to skip this test if we can't create a real cert, or just verify file discovery
# Instead of mocking cert, just count the files that would be signed
$files = Get-ChildItem -Path $testDir -Recurse -Include '*.psd1', '*.psm1', '*.ps1'
$files.Count | Should -Be 3 # Should not include .txt file
}
The Get-ChildItem call is in the test body. It asserts that Get-ChildItem filters by -Include, which is a fact about PowerShell, not about this module. Uses custom Include patterns when specified does the same thing with a one-element pattern list.
The Mock Set-AuthenticodeSignature in the first of the two is declared and then never used. It is also unscoped — no -ModuleName 'PowerShellBuild' — so it could not have reached the call inside the function even if the function had been called. That is the same defect as the six mocks in the sibling certificate test file.
The remaining nine tests inspect Get-Command metadata: that the command is exported, that its help has a synopsis and an example, that Path and Certificate are mandatory, that HashAlgorithm has the expected ValidateSet. Useful, but none of them run the function.
Measured
Code coverage over Invoke-PSBuildModuleSigning.ps1 with the whole file running:
11 tests passed, 0 failed
5 of 17 commands covered
All five covered commands are the ValidateScript on the Path parameter, which runs during parameter binding — reached by Validates that Path must be a directory, the one test that does bind against the command:
Line Command
60 if (-not (Test-Path -Path $_ -PathType Container)) { throw ... }
60 Test-Path -Path $_ -PathType Container
61 throw ($LocalizedData.PathArgumentMustBeAFolder)
Everything past the param() block is unexecuted:
$files = Get-ChildItem -Path $Path -Recurse -Include $Include
Write-Verbose ($LocalizedData.SigningModuleFiles -f $files.Count, ($Include -join ', '), $Path)
$sigParams = @{
Certificate = $Certificate
TimestampServer = $TimestampServer
HashAlgorithm = $HashAlgorithm
}
$files | Set-AuthenticodeSignature @sigParams
Why it matters
This is the function that signs a consumer's shipped module. Nothing currently checks that:
- the
Includepatterns the consumer configured are the ones passed toGet-ChildItem, or that-Recurseis passed at all; TimestampServerandHashAlgorithmreachSet-AuthenticodeSignaturerather than being accepted and dropped — the tests assert only that the parameters exist;$Certificateis the certificate used;- every discovered file is signed, rather than only the first.
Any of those could be broken by a refactor with the suite staying green. $PSBPreference.Sign.HashAlgorithm could silently stop being honoured the same way $PSBPreference.Sign.SkipCertificateValidation silently stopped being honoured in #193, and there is no test here that would notice.
The gap is easy to close, because Set-AuthenticodeSignature is the only thing in the body that touches the outside world. Mocked with -ModuleName 'PowerShellBuild', the function can be driven end to end against files in $TestDrive with no certificate and no signing.
Options
- Call the function with a mocked
Set-AuthenticodeSignature. APSCustomObjectstands in for the certificate, since the parameter is typedX509Certificate2— which needs either a real certificate or a small[X509Certificate2]::new()from generated bytes to satisfy the binder. ThenShould -Invoke -ModuleName 'PowerShellBuild' Set-AuthenticodeSignature -Times 3 -Exactlywith a-ParameterFilteronTimestampServerandHashAlgorithmcovers the whole body and every forwarding question above. This is the shape the retry-loop tests inTest-PSBuildScriptAnalysis.tests.ps1already use, and they are the strongest tests in the suite. - Rewrite the two misnamed tests rather than adding to them.
Searches for files matching Include patternsandUses custom Include patterns when specifiedshould either call the function or be deleted; leaving them as they are means the file reports coverage of behaviour it does not have. - Remove the unused
Mock Set-AuthenticodeSignature, or scope it and use it. As written it reads like protection against accidentally signing something during a test run, and it is not.
(1) subsumes (2) and (3). The Certificate parameter's type is the only real obstacle, and a self-signed certificate generated into $TestDrive or a PSCustomObject cast through a looser parameter type both solve it.
Related: #103 (Publish-PSBuildModule had the same zero-coverage shape and the same consequence — a real defect, #203, sat undetected behind passing tests). Shares its mock-scoping defect and its remediation with #216, which has the same unscoped Mock problem in tests/Get-PSBuildCertificate.tests.ps1.
- 主要語言
- PowerShell
- 星號
- 145
- 分支
- 26
- PR 合併指標
- 30 天內沒有已合併 PR
環境準備
在瀏覽器裡用你自己的 GitHub 帳號啟動這個專案的開發容器。
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
psake/PowerShellBuild 的其他 Issue
-
bug
難度 2/5 1-3 小時 新手友好度 72/100
psake/PowerShellBuild#218 · 1 則留言 ·
-
Staging flattens a culture directory's .psd1 into the output root可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 2/5 1-3 小時 新手友好度 74/100
psake/PowerShellBuild#211 · 1 則留言 ·
-
CI: Install the built module from a local repository to verify install-time dependency behaviour可能已有人在做 @tablackburn 於 35 天前認領。 未關閉enhancement github_actions
難度 4/5 3-5 天 新手友好度 68/100
psake/PowerShellBuild#229 ·
-
Test-PSBuildPester unloads a module it never imported可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 3/5 1-2 天 新手友好度 55/100
psake/PowerShellBuild#222 ·
-
Build-PSBuildMarkdown unloads a module the caller had loaded可能已有人在做 @tablackburn 於 42 天前認領。 未關閉bug
難度 4/5 3-5 天 新手友好度 68/100
psake/PowerShellBuild#221 ·
查看 psake/PowerShellBuild 的全部 Issue
相似的 Issue
-
難度 1/5 1 小時以內 新手友好度 82/100
zerocracy/judges-action#2743 ·
維護者通常 8 天內回覆
-
[Good First Issue]: Add unit tests for NetworkVersionInfo可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉Good First Issue hacktoberfest
難度 2/5 1-3 小時 新手友好度 85/100
hiero-ledger/hiero-sdk-js#4489 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 88/100
crazy-goat/rabbit-stream#830 ·
維護者通常 1 天內回覆
-
area:connector bug
難度 2/5 1-3 小時 新手友好度 72/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 62/100
CopilotKit/openmuse#176 ·
維護者通常 1 天內回覆