Merged PR 38690: Update MaxVisitCount and MaxHashtableKeyCount if visitor safe value context indicates SkipLimitCheck is true ---- #### AI description (iteration 1) #### PR Classification Bug fix that updates the safe value checks by dynamically adjusting limit values based on the visitor context to improve security. #### PR Summary This pull request refactors the safe value visitor logic to replace hard-coded limit constants with context-driven readonly fields and adjusts the conditional checks accordingly. It also adds a test to verify that insecure psd1 files correctly fail when the -SkipLimitCheck parameter is used. - `src/System.Management.Automation/engine/parser/SafeValues.cs`: Replaces constant limits with dynamic fields (_maxVisitCount and _maxHashtableKeyCount) set based on the safe value context, and updates conditional checks to use these fields. - `test/powershell/Modules/Microsoft.PowerShell.Utility/PowerShellData.tests.ps1`: Adds a test case to ensure that insecure psd1 files trigger an error when -SkipLimitCheck is applied. <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot --> Related work items: #163511
Pester Testing Test Guide
Also see the Writing Pester Tests document.
Running Pester Tests
Go to the top level of the PowerShell repository and run: Start-PSPester
inside a self-hosted copy of PowerShell.
You can use Start-PSPester -Tests SomeTestSuite* to limit the tests run.
Testing new powershell processes
Any launch of a new powershell process must include -noprofile so that
modified user and system profiles do not causes tests to fail. You also must
take care to call the development copy of PowerShell, which is not the first
one on the path.
Example:
$powershell = Join-Path -Path $PsHome -ChildPath "pwsh"
& $powershell -noprofile -command "ExampleCommand" | Should Be "ExampleOutput"
Portability
Some tests simply must be tied to certain platforms. Use Pester's
-Skip directive on an It statement to do this. For instance to run
the test only on Windows:
It "Should do something on Windows" -Skip:($IsLinux -Or $IsMacOS) { ... }
Or only on Linux and OS X:
It "Should do something on Linux" -Skip:$IsWindows { ... }
Pending
When writing a test that should pass, but does not, please do not skip or delete
the test, but use It "Should Pass" -Pending to mark the test as pending, and
file an issue on GitHub.