Skip to content

[release/v7.4.19] Fix the dot-sourcing behavior of pwsh -file for advanced-function scripts - #27760

Merged
Justin Chung (jshigetomi) merged 1 commit into
PowerShell:release/v7.4.19from
SeeminglyScience:backport/release/v7.4.19/27727-463ef4374
Aug 6, 2026
Merged

Justin Chung (jshigetomi) merged 1 commit into
PowerShell:release/v7.4.19from
SeeminglyScience:backport/release/v7.4.19/27727-463ef4374

Conversation

@SeeminglyScience

Copy link
Copy Markdown
Contributor

Backport of #27727 to release/v7.4.19

Triggered by Patrick Meinecke (@SeeminglyScience) on behalf of Dongbo Wang (@daxian-dbw)

Original CL Label: CL-Engine

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Customer Impact

  • Customer reported
  • Found internally

Fixes inconsistent WDAC behavior where signed advanced-function scripts failed under pwsh -file while signed simple scripts succeeded. Aligns both code paths so non-noexit file execution behaves consistently.

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

Validated by original PR scenario coverage for WDAC mode and pwsh -file advanced-function behavior; this backport is a direct cherry-pick with no conflict changes.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

Engine behavior change is narrowly scoped to the language-mode compatibility check path for script invocation and keeps existing -noexit behavior intact.

Copilot AI lite review requested due to automatic review settings August 4, 2026 20:55
@SeeminglyScience Patrick Meinecke (SeeminglyScience) added the CL-Engine Indicates that a PR should be marked as an engine change in the Change Log label Aug 4, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports the engine fix from #27727 to ensure pwsh -file behaves consistently for signed advanced-function scripts vs signed simple scripts in WDAC/CLM scenarios, by aligning the language-mode compatibility validation conditions between the advanced-script and simple-script execution paths.

Changes:

  • Exposes the script cmdlet’s “rethrow exit exception” flag so it can be consulted by the advanced-script command processor path.
  • Updates the advanced-script (CommandProcessor) language-mode compatibility check to skip validation in the same “pwsh -file (non--noexit)” scenario as the simple-script path.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs Adds an internal accessor to expose the script cmdlet’s _rethrowExitException state to other engine components.
src/System.Management.Automation/engine/CommandProcessor.cs Updates the advanced-script dotted-script language-mode validation condition to match the simple-script path behavior for pwsh -file.

@jshigetomi
Justin Chung (jshigetomi) merged commit 6aa3700 into PowerShell:release/v7.4.19 Aug 6, 2026
56 of 64 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-Engine Indicates that a PR should be marked as an engine change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants