* Fix WaaSMedicSvc restoration using direct registry write
Set-Service fails on WaaSMedicSvc with Access Denied since it's a
protected service (LaunchProtected=2). FirstLogon.ps1 silently
swallowed this failure via -ErrorAction SilentlyContinue, permanently
leaving WaaSMedicSvc disabled after setup.
Removes WaaSMedicSvc from the Set-Service restoration loop and
restores it via a direct registry write instead, matching the same
technique already used to disable it in WinUtil-PostInstall.ps1.
Added a test verifying the old Set-Service-based restoration is gone
and the new registry-write fix is present.
Addresses the WaaSMedicSvc portion of #5095; the broader AppX/Store
failure investigation is out of scope for this change.
* Assert exact registry-write contract for WaaSMedicSvc test
Per CodeRabbit review: the previous assertion only checked that
Set-ItemProperty and WaaSMedicSvc appeared near each other, which
would pass even with a wrong -Value or -Type. Now asserts the
complete command including -Value 3 and -Type DWord.
* Surface service restoration failures in FirstLogon.log
BITS, wuauserv, UsoSvc, and WaaSMedicSvc restoration all used
-ErrorAction SilentlyContinue, which suppresses errors before they
reach the output stream FirstLogon.ps1 redirects to its log file
(*>&1 ... >> FirstLogon.log). This meant any restoration failure —
not just the WaaSMedicSvc one already fixed — was invisible even in
the log.
Changed -ErrorAction SilentlyContinue to Continue on both the
Set-Service loop and the WaaSMedicSvc registry write, so failures
still don't halt the script but now actually land in
FirstLogon.log for troubleshooting.
Addresses the logging portion of the reporter's suggestion in #5095.
* Assert -ErrorAction Continue in WaaSMedicSvc test
Per CodeRabbit review: the existing test only checked the
Set-ItemProperty command and value, not the -ErrorAction Continue
change made for logging. Extended the same test to also assert
both the Set-ItemProperty and Set-Service lines use Continue instead
of SilentlyContinue.
* Extend WaaSMedicSvc test to cover full ErrorAction Continue
Per CodeRabbit review: the registry-write assertion stopped at
-Type DWord, so a regression back to -ErrorAction SilentlyContinue
would still pass. Extended the pattern to include -ErrorAction
Continue at the end of the command.
* Exercise FirstLogon service restoration behavior
---------
Co-authored-by: Chris Titus <contact@christitus.com>
* Add friendly explanations for common DISM exit codes
Invoke-WinUtilISODism threw only a raw exit code on DISM failure
(e.g. "DISM add-driver failed with exit code 112"), leaving users to
look up what the number means themselves.
Adds a $knownExitCode lookup table mapping common Windows/DISM exit
codes (disk full, access denied, file/path not found, file in use,
timeout, etc.) to plain-English explanations. When a failure's exit
code is recognized, the thrown message now includes the explanation
in parentheses; unrecognized codes fall back to the original
plain-number message.
Verified the script still parses correctly after the change.
* Add missing period to fallback DISM error message
* Add tests for DISM known/unknown exit code error messages
Adds a test verifying a known exit code (112) produces the friendly
explanation in the thrown message, alongside the existing test
verifying an unrecognized code still falls back to the plain
numeric message.
Verified: all 35 tests in win11creator.Tests.ps1 pass.
* Document DISM friendly error messages in Win11 Creator troubleshooting
Adds a Troubleshooting table row explaining the new DISM error
message format (exit code + explanation in parentheses), with
guidance for the most common cases and a link to Microsoft's full
error code reference for anything not explained.
* Fix duplicate DISM calls in unmapped exit code test
The unmapped-code test called Invoke-WinUtilISOScript twice — once
via Should -Throw, once to capture the message for the no-parens
check — causing $script:dismCalls to double-count. Consolidated to
a single call, checking both the exit code and the absence of a
parenthesized explanation against one captured exception message.
Verified: all 36 tests in win11creator.Tests.ps1 pass.
* Fix broken DISM error code reference link in docs
Replaced the dead windows-hardware/manufacture link with Microsoft's
actual System Error Codes reference page, which DISM exit codes
correspond to.
* Strengthen DISM fallback regression coverage
---------
Co-authored-by: Chris Titus <contact@christitus.com>
Invoke-WinUtilISOScript.ps1's PostInstall script set DisableFileSyncNGSC
to 1, which FirstLogon.ps1 (from #4409) then immediately overrides back
to 0. The final value was correct, but only because one script undoes
the other's write on every install.
Removes the redundant PostInstall write so FirstLogon.ps1's existing
0 assignment is the only place setting this value.
Verified the script still parses correctly after the change.