PowerShell / PowerShell/PSScriptAnalyzer
New Rule: Calling Start-Process without checking ExitCode
Nessuno ha ancora preso questa issue.
- Lingua principale
- C#
- Stelle
- 2.2k
- Fork
- 414
- Merge medio
- 13h 1m
- PR unite (30g)
- 2
Descrizione
Summary of the new feature
I recently got burned by a library not handling the exit code for Microsoft.PowerShell.Management\Start-Process.
This could be broken into two rules:
- Always assign Start-Process to a local variable, and check the result. Caveat: How would this work if invoked from Start-Job and deliberately intended to be asynchronous?
Proposed technical implementation details (optional)
- Find calls to Microsoft.PowerShell.Management\Start-Process
There are several ways this could be called:
Arguments not known at caller. No local way to detect $args sets the -Wait and -NoNewWindow switches on
function Do
{
param(
[hashtable]$StartProcess_params
)
Microsoft.PowerShell.Management\Start-Process @StartProcess_params
}
Trivial case: Direct arguments
Microsoft.PowerShell.Management\Start-Process -FilePath "cmd.exe" -ArgumentList "/C" -Wait -NoNewWindow
Middle case: arguments constructed in same scope - I believe this is called $script scope
$StartProcess_params = @{
FilePath = "cmd.exe"
ArgumentList = "/C"
RedirectStandardError = $tempErrorFile
RedirectStandardOutput = $tempOutputFile
NoNewWindow = $true
Wait = $true
}
Microsoft.PowerShell.Management\Start-Process @StartProcess_params
Using Start-Job
Start-Job -Name DoSomething -ScriptBlock {
& cmd.exe /C
Write-Output $LASTEXITCODE
}
#Do other stuff here
Get-Job -Name DoSomething | Wait-Job | Receive-Job
A clear and concise description of what you want to happen.
Flag as warnings with suggestion to assign call to a PS variable, e.g.:
Microsoft.PowerShell.Management\Start-Process @StartProcess_params
would become:
$process = Microsoft.PowerShell.Management\Start-Process @StartProcess_params
if (-not $process.ExitCode)
{
Write-Error $(Microsoft.PowerShell.Management\Get-Content $tempErrorFile
}
Alternatively, if the user truly wishes to suppress the result, the UI could offer a "No, I really don't care and want to explicitly say so" command, which would re-write the code to be:
$(Microsoft.PowerShell.Management\Start-Process @StartProcess_params) | Out-Null
or
[void]Microsoft.PowerShell.Management\Start-Process @StartProcess_params
According to StackOverflow, Out-Null adds a 60% overhead and therefore is slower than [void], so we should probably suggest [void]Microsoft.PowerShell.Management\Start-Process @StartProcess_params
What is the latest version of PSScriptAnalyzer at the point of writing
1.17.1
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Iniziare esaminando i modelli di chiamata proposti di Microsoft.PowerShell.Management\Start-Process, inclusi gli argomenti diretti, i parametri splattati e l’utilizzo di Start-Job. Stabilire se debbano essere coperte le chiamate asincrone e la soppressione esplicita con [void] o Out-Null, quindi verificare che la regola risultante segnali solo nei casi in cui si intende controllare il risultato dell’uscita.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- powershell
- Ambito
- tooling
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 25/100