
# PSRule module

Set-StrictMode -Version latest;

# Set up some helper variables to make it easier to work with the module
$PSModule = $ExecutionContext.SessionState.Module;
$PSModuleRoot = $PSModule.ModuleBase;

# Import the appropriate nested binary module based on the current PowerShell version
$binModulePath = Join-Path -Path $PSModuleRoot -ChildPath '/core/PSRule.dll';

$binaryModule = Import-Module -Name $binModulePath -PassThru;

# When the module is unloaded, remove the nested binary module that was loaded with it
$PSModule.OnRemove = {
    Remove-Module -ModuleInfo $binaryModule;

[PSRule.Configuration.PSRuleOption]::GetWorkingPath = {
    return Get-Location;

# Localization

# $LocalizedData = data {

# }

Import-LocalizedData -BindingVariable LocalizedData -FileName 'PSRule.Resources.psd1' -ErrorAction SilentlyContinue;

# Public functions

# .ExternalHelp PSRule-Help.xml
function Invoke-PSRule {

    param (
        # A list of paths to check for rule definitions
        [Parameter(Position = 0)]
        [String[]]$Path = $PWD,

        # Filter to rules with the following names
        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $True, ValueFromPipeline = $True)]

        [Parameter(Mandatory = $False)]
        [PSRule.Rules.RuleOutcome]$Outcome = [PSRule.Rules.RuleOutcome]::Processed,

        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $False)]
        [ValidateSet('Detail', 'Summary')]
        [PSRule.Configuration.ResultFormat]$As = [PSRule.Configuration.ResultFormat]::Detail

    begin {
        Write-Verbose -Message "[PSRule] BEGIN::";

        # Get parameter options, which will override options from other sources
        $optionParams = @{ };

        if ($PSBoundParameters.ContainsKey('Option')) {
            $optionParams['Option'] =  $Option;

        # Get an options object
        $Option = New-PSRuleOption @optionParams;

        Write-Verbose -Message "[PSRule][D] -- Scanning for source files: $Path";

        # Discover scripts in the specified paths
        [String[]]$sourceFiles = GetRuleScriptPath -Path $Path -Verbose:$VerbosePreference;

        # Check that some matching script files were found
        if ($Null -eq $sourceFiles) {
            Write-Warning -Message LocalizedData.PathNotFound;

        $isDeviceGuard = IsDeviceGuardEnabled;

        # If DeviceGuard is enabled, force a contrained execution environment
        if ($isDeviceGuard) {
            $Option.Execution.LanguageMode = [PSRule.Configuration.LanguageMode]::ConstrainedLanguage;

        $builder = [PSRule.Pipeline.PipelineBuilder]::Invoke();
        $builder.FilterBy($Name, $Tag);

        if ($PSBoundParameters.ContainsKey('As')) {

        $pipeline = $builder.Build();

    process {

    end {
        if ($As -eq [PSRule.Configuration.ResultFormat]::Summary) {

        Write-Verbose -Message "[PSRule] END::";

# .ExternalHelp PSRule-Help.xml
function Get-PSRule {

    param (
        # A list of paths to check for rule definitions
        [Parameter(Position = 0, Mandatory = $False)]
        [String[]]$Path = $PWD,

        # Filter to rules with the following names
        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $False)]

    begin {
        Write-Verbose -Message "[Get-PSRule]::BEGIN";

        # Get parameter options, which will override options from other sources
        $optionParams = @{ };

        if ($PSBoundParameters.ContainsKey('Option')) {
            $optionParams['Option'] =  $Option;

        # Get an options object
        $Option = New-PSRuleOption @optionParams;

        # Discover scripts in the specified paths
        [String[]]$sourceFiles = GetRuleScriptPath -Path $Path -Verbose:$VerbosePreference;

        Write-Verbose -Message "[Get-PSRule] -- Found $($sourceFiles.Length) script(s)";
        Write-Debug -Message "[Get-PSRule] -- Found scripts: $([String]::Join(' ', $sourceFiles))";

        $isDeviceGuard = IsDeviceGuardEnabled;

        # If DeviceGuard is enabled, force a contrained execution environment
        if ($isDeviceGuard) {
            $Option.Execution.LanguageMode = [PSRule.Configuration.LanguageMode]::ConstrainedLanguage;

        $builder = [PSRule.Pipeline.PipelineBuilder]::Get();
        $builder.FilterBy($Name, $Tag);
        $pipeline = $builder.Build();

    process {
        # Get matching rule definitions

    end {
        Write-Verbose -Message "[Get-PSRule]::END";

# .ExternalHelp PSRule-Help.xml
function New-PSRuleOption {

    [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSUseShouldProcessForStateChangingFunctions', '', Justification = 'Creates an in memory object only')]
    param (
        [Parameter(Mandatory = $False)]

        [Parameter(Mandatory = $False)]
        [String]$Path = '.\psrule.yml'

    process {

        if ($PSBoundParameters.ContainsKey('Option')) {
            $Option = $Option.Clone();
        elseif ($PSBoundParameters.ContainsKey('Path')) {

            if (!(Test-Path -Path $Path)) {


            $Path = Resolve-Path -Path $Path;

            $Option = [PSRule.Configuration.PSRuleOption]::FromFile($Path);
        else {
            Write-Verbose -Message "Attempting to read: $Path";

            $Option = [PSRule.Configuration.PSRuleOption]::FromFile($Path, $True);

        return $Option;

# Keywords

Create a rule definition.
Create a rule definition.
A rule definition can be used by the rule analysis engine.

function Rule {
    param (
        # The name of the rule
        [Parameter(Position = 0, Mandatory = $True)]

        # The body of the rule
        [Parameter(Position = 1, Mandatory = $True)]

        # Any dependencies for this rule
        [Parameter(Mandatory = $False)]


    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'Rule keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function AllOf {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'AllOf keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function AnyOf {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'AnyOf keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function Exists {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

        [Parameter(Mandatory = $False)]
        [Switch]$CaseSensitive = $False,

        [Parameter(Mandatory = $False)]
        [Switch]$Not = $False

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'Exists keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function Match {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

        [Parameter(Mandatory = $True, Position = 1)]

        [Parameter(Mandatory = $False)]
        [Switch]$CaseSensitive = $False

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'Match keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function Within {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

        [Parameter(Mandatory = $True, Position = 1)]

        [Parameter(Mandatory = $False)]
        [Switch]$CaseSensitive = $False

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'Within keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

function TypeOf {

    param (
        [Parameter(Mandatory = $True, Position = 0)]

    begin {
        # This is just a stub to improve rule authoring and discovery
        Write-Error -Message 'TypeOf keyword can only be called within PSRule. To call rules use Invoke-PSRule.' -Category InvalidOperation;

# Helper functions

# Get a list of rule script files in the matching paths
function GetRuleScriptPath {

    param (
        [Parameter(Mandatory = $True)]

    process {
        $fileObjects = (Get-ChildItem -Path $Path -Recurse -File -Include '*.rule.ps1' -ErrorAction Stop);

        if ($Null -ne $fileObjects) {

function IsDeviceGuardEnabled {

    param (


    process {

        if ((Get-Variable -Name IsMacOS -ErrorAction Ignore) -or (Get-Variable -Name IsLinux -ErrorAction Ignore)) {
            return $False;

        # PowerShell 6.0.x does not support Device Guard
        if ($PSVersionTable.PSVersion -ge '6.0' -and $PSVersionTable.PSVersion -lt '6.1') {
            return $False;

        return [System.Management.Automation.Security.SystemPolicy]::GetSystemLockdownPolicy() -eq [System.Management.Automation.Security.SystemEnforcementMode]::Enforce;

function InitEditorServices {

    param (


    process {
        if ($Null -ne (Get-Variable -Name psEditor -ErrorAction Ignore)) {
            Export-ModuleMember -Function @(

# Editor services


# Export module

Export-ModuleMember -Function 'Rule','Invoke-PSRule','Get-PSRule','New-PSRuleOption';