* Fix WaaSMedicSvc restoration using direct registry write
Set-Service fails on WaaSMedicSvc with Access Denied since it's a
protected service (LaunchProtected=2). FirstLogon.ps1 silently
swallowed this failure via -ErrorAction SilentlyContinue, permanently
leaving WaaSMedicSvc disabled after setup.
Removes WaaSMedicSvc from the Set-Service restoration loop and
restores it via a direct registry write instead, matching the same
technique already used to disable it in WinUtil-PostInstall.ps1.
Added a test verifying the old Set-Service-based restoration is gone
and the new registry-write fix is present.
Addresses the WaaSMedicSvc portion of #5095; the broader AppX/Store
failure investigation is out of scope for this change.
* Assert exact registry-write contract for WaaSMedicSvc test
Per CodeRabbit review: the previous assertion only checked that
Set-ItemProperty and WaaSMedicSvc appeared near each other, which
would pass even with a wrong -Value or -Type. Now asserts the
complete command including -Value 3 and -Type DWord.
* Surface service restoration failures in FirstLogon.log
BITS, wuauserv, UsoSvc, and WaaSMedicSvc restoration all used
-ErrorAction SilentlyContinue, which suppresses errors before they
reach the output stream FirstLogon.ps1 redirects to its log file
(*>&1 ... >> FirstLogon.log). This meant any restoration failure —
not just the WaaSMedicSvc one already fixed — was invisible even in
the log.
Changed -ErrorAction SilentlyContinue to Continue on both the
Set-Service loop and the WaaSMedicSvc registry write, so failures
still don't halt the script but now actually land in
FirstLogon.log for troubleshooting.
Addresses the logging portion of the reporter's suggestion in #5095.
* Assert -ErrorAction Continue in WaaSMedicSvc test
Per CodeRabbit review: the existing test only checked the
Set-ItemProperty command and value, not the -ErrorAction Continue
change made for logging. Extended the same test to also assert
both the Set-ItemProperty and Set-Service lines use Continue instead
of SilentlyContinue.
* Extend WaaSMedicSvc test to cover full ErrorAction Continue
Per CodeRabbit review: the registry-write assertion stopped at
-Type DWord, so a regression back to -ErrorAction SilentlyContinue
would still pass. Extended the pattern to include -ErrorAction
Continue at the end of the command.
* Exercise FirstLogon service restoration behavior
---------
Co-authored-by: Chris Titus <contact@christitus.com>
* refactor: simplify Win11 Creator ISO workflow
Keep no-driver ISO generation on the fast copy-only path.
Inject exported drivers with one selected-index WIM mount, one Add-Driver pass, and one commit.
Limit WinPE staging to boot-storage drivers and improve workflow validation coverage.
* refactor: stage Win11 setup script fallback
Copy the prepared setup script payloads into sources/$//Setup/Scripts so setup media does not depend solely on answer-file extension extraction.
Keep the existing autounattend execution path unchanged and cover the fallback files in the Win11 Creator tests.
* refactor: address codex feedback
* refactor: run ISO verification in runspace
Rename the ISO logger to Write-WinUtilISOLog so the shared runspace pool imports it automatically. Run Mount & Verify off the WPF thread with dispatcher-safe UI updates, and add Pester coverage for the runspace and logger contract.
* refactor: address ISO review feedback
Keep the selected ISO stable during background verification. Apply ContentDeliveryManager settings to both the first account and the default profile. Block FAT32 USB creation when install.esd exceeds the supported file size.
* refactor: address ISO setup edge cases
Set BypassNRO before OOBE so local account setup is available during Windows Setup.
Detect registered DISM mounts during driver-injection cleanup so partial mount failures are discarded.
* refactor: address ISO review edge cases
Use the actual FAT32 file limit for install.esd USB checks.
Disable ISO modification while mount verification is running.
Apply unsupported-hardware notice suppression to the first user profile.
* refactor: stage ISO setup safeguards earlier
Set device encryption and reserved-storage registry guards before OOBE.
Enable the OEM configuration-set fallback when setup scripts are staged there.
* Update functions/private/Invoke-WinUtilISOUSB.ps1
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
---------
Co-authored-by: Chris Titus <contact@christitus.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* Tab creation
* scaffold outline for the iso tab
* autounattended creation
* inital modification success
* iso save success
* cleanup and iso improvements
* fix startmenu on new 26h2
* remove old first startup
* Fix run for use
* fix unapproved verb
* Keep step 4 output expanded
* update auto-merge
* Cleanup
* remove out-null and trailing whitespace
* explain modify and creator button
* fix scroll to end
* remove workflow change
* fix home updates
* Tab creation
* scaffold outline for the iso tab
* autounattended creation
* inital modification success
* iso save success
* cleanup and iso improvements
* fix startmenu on new 26h2
* remove old first startup
* Fix run for use
* fix unapproved verb
* Keep step 4 output expanded
* update auto-merge
* Cleanup
* remove out-null and trailing whitespace
* explain modify and creator button
* fix scroll to end
* remove workflow change