Skip to content

issue 105 detection script size preflight

Kazushi Kamegawa edited this page Aug 24, 2026 · 1 revision

Issue #105: Detection script size preflight

日本語

Tracking

  • Parent issue: #105
  • Draft PR: #109
  • Repository design source: doc/issues/issue-023-detection-script-size-preflight.md
  • Found during review of #103

Goal

Fail fast — before any Graph write, ideally in validate/package/publish --dry-run — when a Windows detection script is too large for win32LobAppPowerShellScriptRule.scriptContent, instead of only discovering it via a Graph rejection mid-publish.

Design

  • Microsoft Learn does not document a size limit for win32LobAppPowerShellScriptRule.scriptContent itself. The sibling resource family win32LobAppInstallPowerShellScript / win32LobAppUninstallPowerShellScript (mobileAppContentScript.content) documents "a maximum size limit of 100KB". Since both are PowerShell-script-content properties on the same app resource family, use this as a conservative proxy — but state explicitly, in code and in doc/01-manifest-schema.md, that it is not a confirmed limit for the detection-rule property.
  • Default threshold: 100 KB (102,400 bytes) of raw (pre-base64) script content.
  • Placement decided at implementation time between ManifestAssetValidator and WindowsAppPublisher.EnsureMappableAsync/ReadDetectionScriptAsync. EnsureMappableAsync already runs during publish --dry-run, so placing it there gets dry-run coverage for free.
  • Failure message names the file, its actual size, and the limit.

Verification

  • A script under the threshold passes unchanged.
  • A script over the threshold fails with a clear message and no Graph call, in both publish and publish --dry-run.
  • dotnet build / dotnet test.

Scope boundaries

  • No change to base64 encoding or the detection rule shape.
  • No compression or truncation of oversized scripts — fail-fast only.

Clone this wiki locally