From 7019247655c3319ac4df1f3aef3b02724060f853 Mon Sep 17 00:00:00 2001 From: Raimund Andree Date: Sat, 10 Oct 2026 08:11:07 +0000 Subject: [PATCH] test(lab): justify the plain-text conversions of the kit and say how far Repair reaches The four ConvertTo-SecureString -AsPlainText calls of Probe-EffectiveAccess.ps1 and Run-MatrixLocalSuite.ps1 get a SuppressMessageAttribute with a justification, as the controller already has for the same case: the lab installation password comes from the AutomatedLab lab definition and the passwords of the probe users are random and exist only in memory. The header of Test-MatrixCleanup.ps1 says that Repair matches the prefixes of the kit in the whole domain and on the whole machine, which the security review pointed out, and that an unresolved S-1-5-21-* member of Performance Log Users can be a real principal of a trust that is down. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant --- Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1 | 3 +++ Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1 | 3 +++ Tests/Lab/Acceptance/Test-MatrixCleanup.ps1 | 10 +++++++--- 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1 b/Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1 index 399a1d6..65ab01e 100644 --- a/Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1 +++ b/Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1 @@ -1,3 +1,6 @@ +[Diagnostics.CodeAnalysis.SuppressMessageAttribute( + 'PSAvoidUsingConvertToSecureStringWithPlainText', '', Justification = 'The lab installation password comes from the AutomatedLab lab definition, which stores it as text, and the passwords of the probe users are random and exist only in memory; no credential is written.' +)] [CmdletBinding()] param ( [Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label, diff --git a/Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1 b/Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1 index 9ad4564..93b052f 100644 --- a/Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1 +++ b/Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1 @@ -1,3 +1,6 @@ +[Diagnostics.CodeAnalysis.SuppressMessageAttribute( + 'PSAvoidUsingConvertToSecureStringWithPlainText', '', Justification = 'The lab installation password comes from the AutomatedLab lab definition, which stores it as text; the credential is built in memory and never written.' +)] [CmdletBinding()] param ( [Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label, diff --git a/Tests/Lab/Acceptance/Test-MatrixCleanup.ps1 b/Tests/Lab/Acceptance/Test-MatrixCleanup.ps1 index 5e1b39f..021734e 100644 --- a/Tests/Lab/Acceptance/Test-MatrixCleanup.ps1 +++ b/Tests/Lab/Acceptance/Test-MatrixCleanup.ps1 @@ -17,9 +17,13 @@ param ( # or a global error count. Repair is for a run whose removal failed: with the SIDs of the snapshot, it removes what that run left on the machines # (the memberships, also of orphaned SIDs, which net localgroup deletes by SID; the share; the local group; the folders) and what the kit leaves # (the items in the stage folders, the folders of the account probe, the scheduled tasks NtfsMatrix*, the standard users NtfsProbe* with their -# profiles and their entries in Performance Log Users, and the domain accounts NtfsProbe*), and then reports like Verify. Every unresolved -# S-1-5-21-* member of Performance Log Users counts as an entry of the probe, which is the only writer of that group in these labs and uses the same -# pattern in its own cleanup: on a machine where something else leaves such members, Verify reports them and Repair removes them. +# profiles and their entries in Performance Log Users, and the domain accounts NtfsProbe*), and then reports like Verify. The patterns are the +# prefixes of the kit, matched in the whole domain and on the whole machine, not only in the organizational unit and the folders of the kit: +# every AD object whose sAMAccountName starts with NtfsProbe (a computer account too), the NtfsLive* objects of the domain (their SIDs go to the +# snapshot), every local-group member whose name contains NtfsLive, every scheduled task NtfsMatrix*, every local user NtfsProbe* and its profile +# folder, and every unresolved S-1-5-21-* member of Performance Log Users (a real principal of a trust that is down shows as one). The probe is the +# only writer of that group in these labs and uses the same pattern in its own cleanup. Run Repair only in a lab where nothing else has these +# names or leaves such members: Verify reports them, and Repair removes them. & { $ErrorActionPreference = 'Stop' # -File passes an array as one string, so a list may arrive as 'A,B'.