Browse Source

test(lab): justify the plain-text conversions of the kit and say how far Repair reaches

The four ConvertTo-SecureString -AsPlainText calls of Probe-EffectiveAccess.ps1
and Run-MatrixLocalSuite.ps1 get a SuppressMessageAttribute with a
justification, as the controller already has for the same case: the lab
installation password comes from the AutomatedLab lab definition and the
passwords of the probe users are random and exist only in memory.

The header of Test-MatrixCleanup.ps1 says that Repair matches the prefixes of
the kit in the whole domain and on the whole machine, which the security review
pointed out, and that an unresolved S-1-5-21-* member of Performance Log Users
can be a real principal of a trust that is down.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/119/head
Raimund Andree 2 days ago
parent
commit
7019247655
  1. 3
      Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1
  2. 3
      Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1
  3. 10
      Tests/Lab/Acceptance/Test-MatrixCleanup.ps1

3
Tests/Lab/Acceptance/Probe-EffectiveAccess.ps1

@ -1,3 +1,6 @@
[Diagnostics.CodeAnalysis.SuppressMessageAttribute(
'PSAvoidUsingConvertToSecureStringWithPlainText', '', Justification = 'The lab installation password comes from the AutomatedLab lab definition, which stores it as text, and the passwords of the probe users are random and exist only in memory; no credential is written.'
)]
[CmdletBinding()] [CmdletBinding()]
param ( param (
[Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label, [Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label,

3
Tests/Lab/Acceptance/Run-MatrixLocalSuite.ps1

@ -1,3 +1,6 @@
[Diagnostics.CodeAnalysis.SuppressMessageAttribute(
'PSAvoidUsingConvertToSecureStringWithPlainText', '', Justification = 'The lab installation password comes from the AutomatedLab lab definition, which stores it as text; the credential is built in memory and never written.'
)]
[CmdletBinding()] [CmdletBinding()]
param ( param (
[Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label, [Parameter(Mandatory)] [ValidatePattern('^[\w-]+$')] [string] $Label,

10
Tests/Lab/Acceptance/Test-MatrixCleanup.ps1

@ -17,9 +17,13 @@ param (
# or a global error count. Repair is for a run whose removal failed: with the SIDs of the snapshot, it removes what that run left on the machines # or a global error count. Repair is for a run whose removal failed: with the SIDs of the snapshot, it removes what that run left on the machines
# (the memberships, also of orphaned SIDs, which net localgroup deletes by SID; the share; the local group; the folders) and what the kit leaves # (the memberships, also of orphaned SIDs, which net localgroup deletes by SID; the share; the local group; the folders) and what the kit leaves
# (the items in the stage folders, the folders of the account probe, the scheduled tasks NtfsMatrix*, the standard users NtfsProbe* with their # (the items in the stage folders, the folders of the account probe, the scheduled tasks NtfsMatrix*, the standard users NtfsProbe* with their
# profiles and their entries in Performance Log Users, and the domain accounts NtfsProbe*), and then reports like Verify. Every unresolved # profiles and their entries in Performance Log Users, and the domain accounts NtfsProbe*), and then reports like Verify. The patterns are the
# S-1-5-21-* member of Performance Log Users counts as an entry of the probe, which is the only writer of that group in these labs and uses the same # prefixes of the kit, matched in the whole domain and on the whole machine, not only in the organizational unit and the folders of the kit:
# pattern in its own cleanup: on a machine where something else leaves such members, Verify reports them and Repair removes them. # every AD object whose sAMAccountName starts with NtfsProbe (a computer account too), the NtfsLive* objects of the domain (their SIDs go to the
# snapshot), every local-group member whose name contains NtfsLive, every scheduled task NtfsMatrix*, every local user NtfsProbe* and its profile
# folder, and every unresolved S-1-5-21-* member of Performance Log Users (a real principal of a trust that is down shows as one). The probe is the
# only writer of that group in these labs and uses the same pattern in its own cleanup. Run Repair only in a lab where nothing else has these
# names or leaves such members: Verify reports them, and Repair removes them.
& { & {
$ErrorActionPreference = 'Stop' $ErrorActionPreference = 'Stop'
# -File passes an array as one string, so a list may arrive as 'A,B'. # -File passes an array as one string, so a list may arrive as 'A,B'.

Loading…
Cancel
Save