PowerShell / PowerShell/PSScriptAnalyzer
`Invoke-ScriptAnalyzer` `-Severity` filters rules rather than diagnostics
Personne n'a encore pris cette issue.
- Langage dominant
- C#
- Étoiles
- 2.2k
- Forks
- 414
- Merge moyen
- 13 h 1 min
- PR mergées (30 j)
- 2
Description
The -Severity parameter of Invoke-ScriptAnalyzer does not do what it says it does.
Parameter help for the -Severity parameter says:
After running Script Analyzer with all rules, this parameter selects rule violations with the specified severity.
...
The parameter filters the rules violations only after running all rules.
...
In reality the parameter filters rules and not diagnostics; both have the concept of Severity (RuleSeverity, and DiagnosticSeverity)
How the -Severity parameter is ultimately used:
-
The user passes
-SeveritytoInvoke-ScriptAnalyzer. Value validated to be one of"Warning", "Error", "Information", "ParseError". -
The
ScriptAnalyzersingleton instance is initialised with this-Severitystring[]value, which is stored as a private member of the singleton object (severity). -
When analyzing a script, the engine determines which rules to run. It uses
IsRuleAllowed()to check each rule. -
IsRuleAllowed()gets a list ofallowedSeverities. It does so by callingGetAllowedSeveritiesInInt().Each
severity(an array of strings) is parsed into the underlyinguintvalue of theDiagnosticSeverityenum type.(I believe this should actually be
RuleSeverityenum. It works as both enums have identical members and underlyinguintvalues).
https://github.com/PowerShell/PSScriptAnalyzer/blob/aba29c31151925bd7180e7dfd578e1bfacdaf2a2/Engine/ScriptAnalyzer.cs#L1929-L1934 -
IsRuleAllowed()then callsIsSeverityAllowed(allowedSeverities, rule)as part of it's decision making on whether to execute a rule. Passing in the list ofallowedSeveritiesand the currentrulebeing considered. -
IsSeverityAllowed(..)then checks ifallowedSeveritiescontains therules severity (callingrule.GetSeverity()and casting it to auint). If it does the rule is allowed to run.
https://github.com/PowerShell/PSScriptAnalyzer/blob/aba29c31151925bd7180e7dfd578e1bfacdaf2a2/Engine/ScriptAnalyzer.cs#L1914-L1921
So there are 2 issues that need to be addressed:
-
There is a disparity between the documentation and implementation. Either:
- The documentation needs updating to match reality OR
- The implementation needs to be updated so
-Severityfilters the output ofDiagnosticRecords.
-
GetAllowedSeveritiesInInt()resolves severities usingDiagnosticSeverityand that is then used to compare torule.GetSeverity()which is aRuleSeverity. It works now as both enums are identical in their definition and are being cast to their underlyinguintvalue. If either was updated this could break. It also does not seem intentional.
@bergmeister - Should we update the documentation as a first pass and revisit behaviour later if it's desired? I will also get the enum corrected to RuleSeverity.
This explains the issue described in #2049 - where a custom rule is emitting error-level DiagnosticRecord but is not showing with -Severity Error, but is with -Severity Warning. -Severity is filtering the rules that are run (by their severity) and all custom rules have Warning severity.
n.b. I have typed the word severity so many times now that it no longer looks like a real word...
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par Engine/Commands/InvokeScriptAnalyzerCommand.cs et Engine/ScriptAnalyzer.cs, en particulier l’initialisation de la gravité et les points d’entrée GetAllowedSeveritiesInInt(), IsSeverityAllowed() et IsRuleAllowed(). Confirmez le comportement attendu pour le filtrage des règles par rapport aux DiagnosticRecords, puis assurez-vous que la documentation et la gestion de la gravité reflètent cette décision de manière cohérente.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- csharp, powershell
- Domaine
- tooling
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 45/100