@@ -288,7 +288,7 @@ fn windows_second_ordinary_account_cannot_read_or_replace_the_namespace()
288288 Ok ( ( ) )
289289}
290290
291- const ORDINARY_ACCOUNT_SCRIPT : & str = r"
291+ const ORDINARY_ACCOUNT_SCRIPT : & str = r# "
292292$ErrorActionPreference = 'Stop'
293293$account = 'tsa' + [Guid]::NewGuid().ToString('N').Substring(0, 16)
294294$password = ConvertTo-SecureString ('Tsa!A1' + [Guid]::NewGuid().ToString('N')) -AsPlainText -Force
@@ -342,6 +342,10 @@ catch [UnauthorizedAccessException] { }
342342exit 0
343343'@
344344 $encoded = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes($childScript))
345+ $file = Join-Path $PSHOME 'powershell.exe'
346+ $arguments = @('-NoProfile', '-NonInteractive', '-EncodedCommand', $encoded)
347+ $commandLength = ('"' + $file + '" ' + ($arguments -join ' ')).Length
348+ Write-Output ('audit-account-stage=29 encoded-length=' + $encoded.Length + ' command-length=' + $commandLength)
345349 $stage = 30
346350 $process = Start-Process -FilePath (Join-Path $PSHOME 'powershell.exe') -ArgumentList @('-NoProfile', '-NonInteractive', '-EncodedCommand', $encoded) -Credential $credential -PassThru -WindowStyle Hidden
347351 $stage = 40
@@ -382,6 +386,22 @@ exit 0
382386 Write-Output ('audit-account-stage=' + $stage + ' depth=' + $depth + ' category=' + $kind + ' hresult=' + $exception.HResult + ' native=' + $native)
383387 $exception = $exception.InnerException
384388 }
389+ if ($stage -eq 30) {
390+ # A short launch is diagnostic only: retain the original failure even
391+ # if it succeeds. Credentials and all other startup parameters match.
392+ try {
393+ $shortEncoded = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes('exit 0'))
394+ $shortArguments = @('-NoProfile', '-NonInteractive', '-EncodedCommand', $shortEncoded)
395+ $shortLength = ('"' + $file + '" ' + ($shortArguments -join ' ')).Length
396+ Write-Output ('audit-account-stage=37 short-command-length=' + $shortLength)
397+ $process = Start-Process -FilePath (Join-Path $PSHOME 'powershell.exe') -ArgumentList $shortArguments -Credential $credential -PassThru -WindowStyle Hidden
398+ [void]$process.Handle
399+ if (-not $process.WaitForExit(30000)) { throw 'short diagnostic helper timeout' }
400+ Write-Output ('audit-account-stage=37 short-exit=' + $process.ExitCode)
401+ } catch {
402+ Write-Output ('audit-account-stage=37 hresult=' + $_.Exception.HResult)
403+ }
404+ }
385405 exit 1
386406} finally {
387407 try {
@@ -416,7 +436,7 @@ exit 0
416436 exit 1
417437 }
418438}
419- " ;
439+ "# ;
420440
421441#[ test]
422442fn windows_empty_or_null_directory_dacl_is_denied_before_candidate_commit ( )
0 commit comments