Backport fixes for 3.3-rc.2 - #1679
Merged
Steve Lee (SteveL-MSFT) merged 3 commits intoAug 18, 2026
Merged
Conversation
* Use JSON Schema defaults in synthetic test get_diff Update get_diff() to accept an optional JSON Schema parameter via the new get_diff_with_schema() function. When a property exists in the expected (desired) state but is missing from the actual state, the function now checks the schema for a 'default' value for that property. If the expected value matches the schema default, it is not reported as differing. This improves synthetic test accuracy for resources that don't return properties whose values match the schema-defined defaults. - Add get_diff_with_schema() with optional schema parameter - Keep get_diff() as a convenience wrapper (no schema) - Update invoke_synthetic_test to retrieve and pass the resource schema - Update DscResource synthetic test path for adapted resources - Add get_schema_default() helper to extract defaults from JSON Schema - Add Test/SchemaDefault test resource and dsctest subcommand - Add Rust unit tests for schema default comparison logic - Add Pester integration tests for end-to-end validation Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR feedback: restrict visibility and avoid redundant serialization - Change get_diff_with_schema from pub to pub(crate) since it is only used within the dsc-lib crate - Read schema from RESOURCE_SCHEMAS cache directly (returns Value) instead of round-tripping through get_schema -> String -> from_str. Only calls get_schema to populate the cache on a miss. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add FirewallRuleList Pester tests for schema default fix (PowerShell#1666) Add tests verifying that unspecifiedRulesAction set to the schema default value 'ignore' is no longer reported as drift in synthetic test. Non-default values ('disable', 'remove') are still correctly flagged. Tests require elevation to create/remove firewall rules and are skipped when not running as Administrator. Fixes PowerShell#1666 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix CI: skip firewall schema default tests when NetSecurity module unavailable Move -Skip to Describe block and check for Get-NetFirewallRule cmdlet availability in BeforeDiscovery. This prevents BeforeAll/AfterAll from running on CI runners without the NetSecurity module. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Mikey Lombardi (He/Him) <michael.t.lombardi@gmail.com> --------- Co-authored-by: Steve Lee (POWERSHELL HE/HIM) (from Dev Box) <slee@ntdev.microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Mikey Lombardi (He/Him) <michael.t.lombardi@gmail.com>
…owerShell#1671) * Add scoped unspecified firewall rules Replace unspecifiedRulesAction with the scoped unspecifiedRules object and allow empty rule lists for authoritative reconciliation. Add Rust and Pester coverage for direction and profile filtering. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address firewall scope review feedback Reject empty unspecified rule profile filters in the schema and runtime, and localize the VariantClear warning. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix platform-specific changed coverage Merge coverage from every platform when measuring changed Rust code while retaining Linux-only data for the full-codebase metric. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix cross-platform coverage reporting Correct the PowerShell coverage artifact predicate and initialize firewall Pester skip conditions before Describe discovery so elevated Windows CI executes the suites. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Guard firewall tests on NetSecurity Skip firewall set and what-if suites when any cmdlet required for setup or cleanup is unavailable. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Reduce firewall formatting churn Keep the scoped unspecified-rule implementation focused on semantic changes so changed-line coverage measures the feature rather than unrelated rustfmt reflow. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Minimize changed firewall coverage lines Keep changed expressions in the existing compact style so line coverage is not diluted by formatting-only line splits. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Steve Lee (POWERSHELL HE/HIM) (from Dev Box) <slee@ntdev.microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Ignore write-only properties in schema diffs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Resolve local refs for write-only properties Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Omit write-only firewall instructions from set output Co-authored-by: SteveL-MSFT <11859881+SteveL-MSFT@users.noreply.github.com> --------- Co-authored-by: Steve Lee (POWERSHELL HE/HIM) (from Dev Box) <slee@ntdev.microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: SteveL-MSFT <11859881+SteveL-MSFT@users.noreply.github.com>
Steve Lee (SteveL-MSFT)
requested review from
Gijs Reijn (Gijsreyn),
Mikey Lombardi (He/Him) (michaeltlombardi) and
Tess Gauthier (tgauth)
and removed request for
Gijs Reijn (Gijsreyn)
August 17, 2026 19:28
Tess Gauthier (tgauth)
approved these changes
Aug 18, 2026
Steve Lee (SteveL-MSFT)
merged commit Aug 18, 2026
2b46fb9
into
PowerShell:release/v3.3
20 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Summary
Backport: