Private/Save-OSDAppVerifiedBuiltInDownload.ps1

function Save-OSDAppVerifiedBuiltInDownload {
    <#
    .SYNOPSIS
    Downloads a signed built-in MSI/EXE into a separate candidate, validates
    signature and expected publisher before replacing a cached file.
    .NOTES
    The original file is preserved when download or validation fails.
    This does not apply to outer ZIP containers or downloaded MSIX payloads.
    #>

    [CmdletBinding()]
    param(
        [Parameter(Mandatory)][string]$Id,
        [Parameter(Mandatory)][uri]$Uri,
        [Parameter(Mandatory)][string]$DestinationPath,
        [Parameter(Mandatory)][string]$Activity,
        [int]$ProgressId = 20,
        [int]$ParentProgressId = -1
    )

    if (Test-OSDAppWinPE) {
        throw 'Signed built-in cache synchronization requires full Windows.'
    }
    $directory = Split-Path -Path $DestinationPath -Parent
    $basename = [IO.Path]::GetFileNameWithoutExtension($DestinationPath)
    $extension = [IO.Path]::GetExtension($DestinationPath)
    $token = [guid]::NewGuid().ToString('N')
    $candidate = Join-Path $directory ("$basename.$token.candidate$extension")
    $backup = Join-Path $directory ("$basename.$token.previous$extension")
    $hadPrevious = $false
    $promoted = $false

    try {
        Save-OSDAppDownload -Uri $Uri -DestinationPath $candidate -Activity $Activity -ProgressId $ProgressId -ParentProgressId $ParentProgressId | Out-Null
        Assert-OSDAppBuiltInSignature -Id $Id -FilePath $candidate | Out-Null

        $hadPrevious = Test-Path -LiteralPath $DestinationPath -PathType Leaf
        if ($hadPrevious) {
            Move-Item -LiteralPath $DestinationPath -Destination $backup -ErrorAction Stop
        }
        try {
            Move-Item -LiteralPath $candidate -Destination $DestinationPath -ErrorAction Stop
            $promoted = $true
        }
        catch {
            if ($hadPrevious -and (Test-Path -LiteralPath $backup -PathType Leaf)) {
                Move-Item -LiteralPath $backup -Destination $DestinationPath -ErrorAction Stop
            }
            throw
        }

        [pscustomobject]@{
            Id=$Id
            DestinationPath=$DestinationPath
            SignatureVerified=$true
        }
    }
    finally {
        if (Test-Path -LiteralPath $candidate -PathType Leaf) {
            Remove-Item -LiteralPath $candidate -Force -ErrorAction SilentlyContinue
        }
        # Retain the backup after an incomplete promotion/rollback for recovery.
        if ($promoted -and (Test-Path -LiteralPath $backup -PathType Leaf)) {
            Remove-Item -LiteralPath $backup -Force -ErrorAction SilentlyContinue
        }
    }
}