From c51a6e38cf2bc7ecf0b667fabe30ac59b0d80ef9 Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Tue, 1 May 2018 17:28:57 -0700 Subject: [PATCH] Fix test and infrastructure blocking code coverage runs (#6790) * Fix Remove-Item test to use a test directory instead of relying on pre-existing directory * Increase timeout as we are regularly going over it. --- .../FileSystem.Tests.ps1 | 40 ++++++++++++++++++- test/tools/OpenCover/OpenCover.psm1 | 8 ++-- 2 files changed, 42 insertions(+), 6 deletions(-) diff --git a/test/powershell/Modules/Microsoft.PowerShell.Management/FileSystem.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Management/FileSystem.Tests.ps1 index 974c69568e..3bc4c059b7 100644 --- a/test/powershell/Modules/Microsoft.PowerShell.Management/FileSystem.Tests.ps1 +++ b/test/powershell/Modules/Microsoft.PowerShell.Management/FileSystem.Tests.ps1 @@ -256,8 +256,7 @@ Describe "Basic FileSystem Provider Tests" -Tags "CI" { @{cmdline = "Get-ChildItem $protectedPath -ErrorAction Stop"; expectedError = "DirUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand"} @{cmdline = "New-Item -Type File -Path $newItemPath -ErrorAction Stop"; expectedError = "NewItemUnauthorizedAccessError,Microsoft.PowerShell.Commands.NewItemCommand"} @{cmdline = "Rename-Item -Path $protectedPath -NewName bar -ErrorAction Stop"; expectedError = "RenameItemIOError,Microsoft.PowerShell.Commands.RenameItemCommand"}, - @{cmdline = "Move-Item -Path $protectedPath -Destination bar -ErrorAction Stop"; expectedError = "MoveDirectoryItemIOError,Microsoft.PowerShell.Commands.MoveItemCommand"}, - @{cmdline = "Remove-Item -Path $protectedPath -ErrorAction Stop"; expectedError = "RemoveItemUnauthorizedAccessError,Microsoft.PowerShell.Commands.RemoveItemCommand"} + @{cmdline = "Move-Item -Path $protectedPath -Destination bar -ErrorAction Stop"; expectedError = "MoveDirectoryItemIOError,Microsoft.PowerShell.Commands.MoveItemCommand"} ) { param ($cmdline, $expectedError) @@ -1388,3 +1387,40 @@ Describe "UNC paths" -Tags 'CI' { } } } + +Describe "Remove-Item UnAuthorized Access" -Tags "CI", "RequireAdminOnWindows" { + BeforeAll { + if ($IsWindows) { + $folder = Join-Path $TestDrive "UnAuthFolder" + $protectedPath = (New-Item $folder -ItemType Directory).FullName + } + } + + It "Access-denied test for removing a folder" -Skip:(-not $IsWindows) { + + # The expected error is returned when there is a empty directory with the user does not have authorization to is deleted. + # It cannot have 'System. 'Hidden' or 'ReadOnly' attribute as well as -Force should not be used. + + $powershell = Join-Path $PSHOME "pwsh" + $errorFile = Join-Path (Get-Item $testdrive).FullName "RemoveItemError.txt" + $cmdline = "$powershell -c Remove-Item -Path $protectedPath -ErrorVariable err ;`$err.FullyQualifiedErrorId | Out-File $errorFile" + + ## Remove inheritance + $acl = Get-Acl $protectedPath + $acl.SetAccessRuleProtection($true, $true) + Set-Acl $protectedPath $acl + + ## Remove ACL + $acl = Get-Acl $protectedPath + $acl.Access | ForEach-Object { $acl.RemoveAccessRule($_) } | Out-Null + + # Add local admin + $rule = [System.Security.AccessControl.FileSystemAccessRule]::new("BUILTIN\Administrators","FullControl", "Allow") + $acl.SetAccessRule($rule) + Set-Acl $protectedPath $acl + + runas.exe /trustlevel:0x20000 "$cmdline" + Wait-FileToBePresent -File $errorFile -TimeoutInSeconds 10 + Get-Content $errorFile | Should -BeExactly 'RemoveItemUnauthorizedAccessError,Microsoft.PowerShell.Commands.RemoveItemCommand' + } +} diff --git a/test/tools/OpenCover/OpenCover.psm1 b/test/tools/OpenCover/OpenCover.psm1 index 8899fb7216..8804ca246b 100644 --- a/test/tools/OpenCover/OpenCover.psm1 +++ b/test/tools/OpenCover/OpenCover.psm1 @@ -711,9 +711,9 @@ function Invoke-OpenCover "$openCoverBin $cmdlineUnelevated" | Out-File -FilePath $unelevatedFile -Force runas.exe /trustlevel:0x20000 "powershell.exe -file $unelevatedFile" # poll for process exit every 60 seconds - # timeout of 6 hours - # Runs currently take about 2.5 - 3 hours, we picked 6 hours to be substantially larger. - $timeOut = ([datetime]::Now).AddHours(6) + # timeout of 12 hours + # Runs currently take about 8-9 hours, we picked 12 hours to be substantially larger. + $timeOut = ([datetime]::Now).AddHours(12) $openCoverExited = $false @@ -732,7 +732,7 @@ function Invoke-OpenCover if(-not $openCoverExited) { - throw "Opencover has not exited in 6 hours" + throw "Opencover has not exited in 12 hours" } } finally