PowerShell / PowerShell/PSScriptAnalyzer

PSAvoidOverwritingBuiltInCmdlets (core-6.1.0-*) returns warning for Write-Log, which is not a built-in cmdlet

Open
#2,146 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Up-for-Grabs
Dominant language
C#
Stars
2.2k
Forks
414
Avg merge
13h 1m
Merged PRs (30d)
2

Description

Before submitting a bug report:

  • Make sure you are able to repro it on the latest released version
  • Perform a quick search for existing issues to check if this bug has already been reported

Steps to reproduce

Create a file called Write-Log.psm1 in your home directory and populate it with an empty function called Write-Log:

function Write-Log {
}

Install and run PSScriptAnalyzer against the file:

> Install-Module PSScriptAnalyzer

> Invoke-ScriptAnalyzer -Path ~\Write-Log.psm1

Expected behavior

PSScriptAnalyzer returns no findings because Write-Log is not a built-in cmdlet.

Actual behavior

RuleName                         Severity ScriptName     Line Message
--------                         -------- ----------     ---- -------
PSAvoidOverwritingBuiltInCmdlets Warning  Write-Log.psm1 1    'Write-Log' is a cmdlet that is included with PowerShell (version core-6.1.0-windows) whose definition should not be overridden

This behaviour should be reproducible cross-platform.

Troubleshooting

Write-Log was never shipped with any version of PowerShell, but it is erroneously defined as a built-in cmdlet:

https://github.com/PowerShell/PSScriptAnalyzer/blob/e2804796f43eab60f5d105f6bbaea83fb446a13d/Engine/Settings/core-6.1.0-linux-arm.json#L1391-L1395

https://github.com/PowerShell/PSScriptAnalyzer/blob/e2804796f43eab60f5d105f6bbaea83fb446a13d/Engine/Settings/core-6.1.0-linux.json#L1391-L1395

https://github.com/PowerShell/PSScriptAnalyzer/blob/e2804796f43eab60f5d105f6bbaea83fb446a13d/Engine/Settings/core-6.1.0-macos.json#L1391-L1395

https://github.com/PowerShell/PSScriptAnalyzer/blob/e2804796f43eab60f5d105f6bbaea83fb446a13d/Engine/Settings/core-6.1.0-windows.json#L1692-L1696

Probable cause is described in https://github.com/PowerShell/PowerShell/issues/7209 as an upstream issue in PSDesiredStateConfiguration that was reportedly fixed in 2020. However, the PSScriptAnalyzer files affected by that issue were never rebuilt afterwards.

The module that may have caused this problem at the time is https://github.com/microsoft/PowerShellForGitHub, which defines Write-Log and then suppresses PSScriptAnalyzer reports in Helper.ps1#L128. The PR to suppress that finding is recorded in https://github.com/microsoft/PowerShellForGitHub/pull/180. If this module was present in the build environment, then PSScriptAnalyzer would have added Write-Log and possibly other cmdlets to the list of built-in cmdlets even though they do not ship with PowerShell.

As a result, default installations of PSScriptAnalyzer return a false warning for PSAvoidOverwritingBuiltInCmdlets against cmdlets named Write-Log.

It is possible that there may be other cmdlets erroneously included in these files for the same reason.

Environment data

> $PSVersionTable

Name                           Value
----                           -----
PSVersion                      7.5.4
PSEdition                      Core
GitCommitId                    7.5.4
OS                             Microsoft Windows 10.0.22631
Platform                       Win32NT
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0…}
PSRemotingProtocolVersion      2.3
SerializationVersion           1.1.0.1
WSManStackVersion              3.0

> (Get-Module -ListAvailable PSScriptAnalyzer).Version | ForEach-Object { $_.ToString() }

1.24.0

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the core-6.1.0 platform settings files under Engine/Settings, especially the entries around Write-Log, and compare the built-in cmdlet lists across Linux ARM, Linux, macOS, and Windows. Remove or correct entries that are not shipped with PowerShell, then run Invoke-ScriptAnalyzer against the Write-Log.psm1 reproduction and check for similar false warnings.

Written by the indexing model from the issue text.

Assessment

Tech stack
powershell
Domain
tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.