Files
winutil/pester
KristianandChris Titus 92d5a08d49 Fix WaaSMedicSvc restoration using direct registry write (#5096)
* Fix WaaSMedicSvc restoration using direct registry write

Set-Service fails on WaaSMedicSvc with Access Denied since it's a
protected service (LaunchProtected=2). FirstLogon.ps1 silently
swallowed this failure via -ErrorAction SilentlyContinue, permanently
leaving WaaSMedicSvc disabled after setup.

Removes WaaSMedicSvc from the Set-Service restoration loop and
restores it via a direct registry write instead, matching the same
technique already used to disable it in WinUtil-PostInstall.ps1.

Added a test verifying the old Set-Service-based restoration is gone
and the new registry-write fix is present.

Addresses the WaaSMedicSvc portion of #5095; the broader AppX/Store
failure investigation is out of scope for this change.

* Assert exact registry-write contract for WaaSMedicSvc test

Per CodeRabbit review: the previous assertion only checked that
Set-ItemProperty and WaaSMedicSvc appeared near each other, which
would pass even with a wrong -Value or -Type. Now asserts the
complete command including -Value 3 and -Type DWord.

* Surface service restoration failures in FirstLogon.log

BITS, wuauserv, UsoSvc, and WaaSMedicSvc restoration all used
-ErrorAction SilentlyContinue, which suppresses errors before they
reach the output stream FirstLogon.ps1 redirects to its log file
(*>&1 ... >> FirstLogon.log). This meant any restoration failure —
not just the WaaSMedicSvc one already fixed — was invisible even in
the log.

Changed -ErrorAction SilentlyContinue to Continue on both the
Set-Service loop and the WaaSMedicSvc registry write, so failures
still don't halt the script but now actually land in
FirstLogon.log for troubleshooting.

Addresses the logging portion of the reporter's suggestion in #5095.

* Assert -ErrorAction Continue in WaaSMedicSvc test

Per CodeRabbit review: the existing test only checked the
Set-ItemProperty command and value, not the -ErrorAction Continue
change made for logging. Extended the same test to also assert
both the Set-ItemProperty and Set-Service lines use Continue instead
of SilentlyContinue.

* Extend WaaSMedicSvc test to cover full ErrorAction Continue

Per CodeRabbit review: the registry-write assertion stopped at
-Type DWord, so a regression back to -ErrorAction SilentlyContinue
would still pass. Extended the pattern to include -ErrorAction
Continue at the end of the command.

* Exercise FirstLogon service restoration behavior

---------

Co-authored-by: Chris Titus <contact@christitus.com>
2026-09-29 12:46:08 -05:00
..