Skip to content

Harden DISM staging and servicing lifecycle recovery - #18

Merged
cmendesvdl merged 1 commit into
mainfrom
copilot/final-lifecycle-audit
Oct 10, 2026
Merged

cmendesvdl merged 1 commit into
mainfrom
copilot/final-lifecycle-audit

Conversation

@cmendesvdl

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to merged PR #17. The final audit identified servicing lifecycle defects not covered by the original passing regressions.

  • Stage DISM executable wrappers in protected, per-operation Program Files directories with trusted ancestry and exclusive file creation.
  • Confirm process exit after asynchronous termination; retain incomplete cancellation and recovery identity instead of reporting success.
  • Keep regular and custom cancellation in the worker holding the process handle, rather than interrupting or racing it from the UI.
  • Run custom completion/stall detection inside the polling loop and block new custom builds while recovery state remains unresolved.
  • Share owned-WIM cleanup between GUI and headless paths, preserving mount records and temporary content on failure.
  • Add lifecycle regression coverage, CI wiring, documentation, and regenerated 20-file checksums.

Validation

  • Pester 6.2.0: 59 passed, zero failures, skips, or not-run cases.
  • All 10 standalone DAT regression harnesses passed.
  • All 20 checksum entries verified against checked-out bytes.
  • Read-only validation of actual local Program Files ancestry passed; native DirectoryInfo traversal has its own regression case.
  • Workspace parser sweep: 158 PowerShell files across 13 checkouts, plus four standalone XAML files, without parse failures.
  • Existing OSD/hub suites passed: disk 69, log copy 146, AD groups 234, archived hub 14.

Review and rollout limits

This is not a blanket clean-static-analysis or production-certification claim. The broader default-rule analyzer sweep has substantial pre-existing warnings and plaintext SecureString conversion findings that need contextual triage; original MSEndpointMgr histories and bundled historical code were preserved rather than mass-refactored.

Live elevated WPF/DISM, real hardware, firmware, ConfigMgr, and Intune validation remains required. The protected directory creation targets Windows PowerShell 5.1/.NET Framework; PowerShell 7 runtime compatibility is not certified. Failed or unverifiable launch/cancellation state remains fail-closed and requires identity-aware recovery.

This follow-up is intentionally submitted for review, not auto-merged under the authorization for the original numbered PRs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cmendesvdl
cmendesvdl merged commit 0906588 into main Oct 10, 2026
1 check passed
@cmendesvdl
cmendesvdl deleted the copilot/final-lifecycle-audit branch October 10, 2026 00:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants