PowerShell / PowerShell/PSScriptAnalyzer
Function-Based Custom Rule with "Error" Severity Doesn’t Show Under -Severity Error
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- C#
- Star
- 2.2k
- Fork
- 414
- Merge trung bình
- 13 giờ 1 phút
- Pull request đã merge (30 ngày)
- 2
Mô tả
I'm experiencing an issue with function-based custom rules. When a custom rule returns a severity of Error, the results don't appear under the -Severity Error filter. Instead, they show up only when filtering by warnings or when no filter is applied.
I couldn’t find any other reports of a similar issue. The closest I came across was #1237, but it seems unanswered or possibly overlooked.
The use-case here is for demonstration purposes.
Steps to reproduce
Custom Rule (Measure-AvoidCustomInvokeExpression.psm1)
function Measure-AvoidCustomInvokeExpression {
[CmdletBinding()]
[OutputType([Microsoft.Windows.Powershell.ScriptAnalyzer.Generic.DiagnosticRecord[]])]
param (
[Parameter(Mandatory = $true)]
[ValidateNotNullOrEmpty()]
[System.Management.Automation.Language.ScriptBlockAst] $ScriptBlockAst
)
process {
$results = @()
try {
[ScriptBlock]$predicate = {
param (
[System.Management.Automation.Language.Ast] $Ast
)
[bool]$returnValue = $false
if ($Ast -is [System.Management.Automation.Language.CommandAst]) {
[System.Management.Automation.Language.CommandAst]$commandAst = $Ast
if ($commandAst.GetCommandName() -eq 'Invoke-Expression') {
$returnValue = $true
}
}
return $returnValue
}
[System.Management.Automation.Language.Ast[]]$asts = $ScriptBlockAst.FindAll($predicate, $true)
if ($asts.Count -ne 0) {
foreach ($ast in $asts) {
$result = New-Object `
-TypeName "Microsoft.Windows.Powershell.ScriptAnalyzer.Generic.DiagnosticRecord" `
-ArgumentList `
"Stop it!",
$ast.Extent,
"AvoidCustomInvokeExpression",
Error,
$null
$results += $result
}
}
return $results
}
catch {
$PSCmdlet.ThrowTerminatingError($PSItem)
}
}
}
Export-ModuleMember -Function Measure-AvoidCustomInvokeExpression
Test Script (Invoke-GetProcess.ps1)
Invoke-Expression "Get-Process"
Expected behavior
Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Error
RuleName Severity ScriptName Line Message
-------- -------- ---------- ---- -------
Custom Name Error Invoke-Get 1 Stop it!
Process.ps
1
Actual behavior
Used with -Severity Error
Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Error
<nothing>
Used with -Severity Warning
Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Warning
RuleName Severity ScriptName Line Message
-------- -------- ---------- ---- -------
Custom Name Error Invoke-Get 1 Stop it!
Process.ps
1
Environment data
Windows 11
> $PSVersionTable
PSVersion 5.1.22621.4391
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0…}
BuildVersion 10.0.22621.4391
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
> (Get-Module -ListAvailable PSScriptAnalyzer).Version | ForEach-Object { $_.ToString() }
1.23.0
Manjaro 6.6.63-1
> $PSVersionTable
PSVersion 7.4.1
PSEdition Core
GitCommitId 7.4.1-0-g5668713d3c906d63cd68e37d415206a95ac061d0
OS Manjaro Linux
Platform Unix
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0…}
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
WSManStackVersion 3.0
> (Get-Module -ListAvailable PSScriptAnalyzer).Version | ForEach-Object { $_.ToString() }
1.23.0
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Tái hiện vấn đề với Measure-AvoidCustomInvokeExpression.psm1 và Invoke-GetProcess.ps1 bằng PSScriptAnalyzer 1.23.0 và cả hai bộ lọc mức độ nghiêm trọng. Bắt đầu bằng cách theo dõi mức độ nghiêm trọng của chẩn đoán từ quy tắc tùy chỉnh qua điểm vào của chức năng lọc mức độ nghiêm trọng của trình phân tích. Hoàn thành khi một chẩn đoán Error xuất hiện với -Severity Error, đồng thời chức năng lọc mức độ nghiêm trọng hiện có vẫn tiếp tục hoạt động.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- csharp, powershell
- Lĩnh vực
- cli, tooling
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức phù hợp với người mới
- 45/100