PowerShell / PowerShell/PSScriptAnalyzer

Function-Based Custom Rule with "Error" Severity Doesn’t Show Under -Severity Error

未關閉
#2,049 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

Issue - Bug
主要語言
C#
星號
2.2k
分支
415
平均合併
13 小時 1 分鐘
30 天內合併 PR
2

描述

I'm experiencing an issue with function-based custom rules. When a custom rule returns a severity of Error, the results don't appear under the -Severity Error filter. Instead, they show up only when filtering by warnings or when no filter is applied.

I couldn’t find any other reports of a similar issue. The closest I came across was #1237, but it seems unanswered or possibly overlooked.

The use-case here is for demonstration purposes.

Steps to reproduce

Custom Rule (Measure-AvoidCustomInvokeExpression.psm1)

function Measure-AvoidCustomInvokeExpression {
    [CmdletBinding()]
    [OutputType([Microsoft.Windows.Powershell.ScriptAnalyzer.Generic.DiagnosticRecord[]])]
    param (
        [Parameter(Mandatory = $true)]
        [ValidateNotNullOrEmpty()]
        [System.Management.Automation.Language.ScriptBlockAst] $ScriptBlockAst
    )
    process {
        $results = @()
        
        try {
            [ScriptBlock]$predicate = {
                param (
                    [System.Management.Automation.Language.Ast] $Ast
                )
                [bool]$returnValue = $false
                
                if ($Ast -is [System.Management.Automation.Language.CommandAst]) {
                    [System.Management.Automation.Language.CommandAst]$commandAst = $Ast
                    if ($commandAst.GetCommandName() -eq 'Invoke-Expression') {
                        $returnValue = $true
                    }
                }
                return $returnValue
            }
            
            [System.Management.Automation.Language.Ast[]]$asts = $ScriptBlockAst.FindAll($predicate, $true)
            if ($asts.Count -ne 0) {
                foreach ($ast in $asts) {
                    $result = New-Object `
                        -TypeName "Microsoft.Windows.Powershell.ScriptAnalyzer.Generic.DiagnosticRecord" `
                        -ArgumentList `
                        "Stop it!", 
                        $ast.Extent, 
                        "AvoidCustomInvokeExpression", 
                        Error, 
                        $null
                    
                    $results += $result
                }
            }
            return $results
        }
        catch {
            $PSCmdlet.ThrowTerminatingError($PSItem)
        }
    }
}

Export-ModuleMember -Function Measure-AvoidCustomInvokeExpression

Test Script (Invoke-GetProcess.ps1)

Invoke-Expression "Get-Process"

Expected behavior

Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Error

RuleName                            Severity     ScriptName Line  Message
--------                            --------     ---------- ----  -------
Custom Name                         Error        Invoke-Get 1     Stop it!
                                                 Process.ps
                                                 1

Actual behavior

Used with -Severity Error

Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Error

<nothing>

Used with -Severity Warning

Invoke-ScriptAnalyzer -Path ./Invoke-GetProcess.ps1 -CustomRulePath ./Measure-AvoidCustomInvokeExpression.psm1 -Severity Warning

RuleName                            Severity     ScriptName Line  Message
--------                            --------     ---------- ----  -------
Custom Name                         Error        Invoke-Get 1     Stop it!
                                                 Process.ps
                                                 1

Environment data

Windows 11

> $PSVersionTable
PSVersion                      5.1.22621.4391
PSEdition                      Desktop
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0…}
BuildVersion                   10.0.22621.4391
CLRVersion                     4.0.30319.42000
WSManStackVersion              3.0
PSRemotingProtocolVersion      2.3
SerializationVersion           1.1.0.1

> (Get-Module -ListAvailable PSScriptAnalyzer).Version | ForEach-Object { $_.ToString() }
1.23.0

Manjaro 6.6.63-1

> $PSVersionTable
PSVersion                      7.4.1
PSEdition                      Core
GitCommitId                    7.4.1-0-g5668713d3c906d63cd68e37d415206a95ac061d0
OS                             Manjaro Linux
Platform                       Unix
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0…}
PSRemotingProtocolVersion      2.3
SerializationVersion           1.1.0.1
WSManStackVersion              3.0

> (Get-Module -ListAvailable PSScriptAnalyzer).Version | ForEach-Object { $_.ToString() }
1.23.0

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

使用 PSScriptAnalyzer 1.23.0 和兩個嚴重性篩選器,透過 Measure-AvoidCustomInvokeExpression.psm1 和 Invoke-GetProcess.ps1 重現此問題。首先透過分析器嚴重性篩選的進入點追蹤自訂規則診斷的嚴重性。完成標準是使用 -Severity Error 時出現 Error 診斷,同時現有的嚴重性篩選仍能正常運作。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
csharp, powershell
領域
cli, tooling
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
冷清
描述清晰度
描述清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。