Skip to content

fix: pass -NoProfile when invoking pwsh in requirement checks - #380

Merged
Julio Carlos Menendez (juliomenendez) merged 1 commit into
mainfrom
users/juliome/fix-pwsh-profile-pollution
Apr 21, 2026
Merged

Julio Carlos Menendez (juliomenendez) merged 1 commit into
mainfrom
users/juliome/fix-pwsh-profile-pollution

Conversation

@juliomenendez

Copy link
Copy Markdown
Contributor

Summary

  • PowerShellModulesRequirementCheck.ExecutePowerShellCommandAsync invoked pwsh with only -Command, so any output written by the user's PowerShell profile (PSReadLine install prompt, posh-git warnings, custom Write-Host, etc.) was prepended to stdout.
  • The availability probe parses stdout as an int via int.TryParse("$PSVersionTable.PSVersion.Major"); profile pollution makes this fail and the CLI reports PowerShell is not available on this system even when pwsh 7+ is installed. Get-Module / Install-Module calls on the same code path silently misbehave for the same reason.
  • Adds -NoProfile -NonInteractive to the pwsh arguments. This matches the existing convention in MicrosoftGraphTokenProvider.BuildPowerShellArguments.

Repro (before fix)

Any PowerShell profile that writes to stdout — for example one that imports posh-git or prompts for PSReadLine. Running a365 setup all (or a365 setup requirements) produces:

ERROR: Fail: PowerShell Modules
  PowerShell is not available on this system
  Install PowerShell 7+ from https://learn.microsoft.com/...

After the fix, the probe returns a clean 7 regardless of profile contents and the check proceeds to module detection.

Test plan

  • dotnet test --filter FullyQualifiedName~PowerShellModulesRequirementCheckTests — 5/5 pass
  • Rebuilt and installed CLI via scripts/cli/install-cli.ps1; a365 setup requirements progresses past the PowerShell check on a machine with a profile that prints to stdout (previously blocked at this step)
  • Manual: pwsh -NoProfile -Command "$PSVersionTable.PSVersion.Major" returns 7 cleanly with the same profile that polluted the unflagged call

…t checks

PowerShellModulesRequirementCheck.ExecutePowerShellCommandAsync launched pwsh
with only -Command. Users whose PowerShell profile writes to stdout (e.g. a
PSReadLine install prompt or posh-git warnings) would see that text prepended
to the command output, causing int.TryParse of "$PSVersionTable.PSVersion.Major"
to fail and the check to report "PowerShell is not available on this system"
even on systems with pwsh 7+ installed. The same path is used for module
detection and auto-install, which would silently misbehave for the same reason.

MicrosoftGraphTokenProvider.BuildPowerShellArguments already uses
"-NoProfile -NonInteractive" for pwsh; aligning this invocation with that
convention.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings April 21, 2026 16:21
@github-actions

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR makes PowerShell requirement checks in the Agent365 CLI deterministic by preventing user PowerShell profile scripts (and interactive prompts) from polluting stdout/stderr during subprocess execution.

Changes:

  • Add -NoProfile -NonInteractive to the pwsh invocation used by PowerShellModulesRequirementCheck so version/module checks aren’t affected by profile output.

@juliomenendez
Julio Carlos Menendez (juliomenendez) merged commit 3b348bc into main Apr 21, 2026
12 checks passed
@juliomenendez
Julio Carlos Menendez (juliomenendez) deleted the users/juliome/fix-pwsh-profile-pollution branch April 21, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants