Skip to content

Retry Chocolatey operations elevated when a package script demands admin - #5495

Merged
Gabriel Dufresne (GabrielDuf) merged 1 commit into
mainfrom
fix/choco-package-script-elevation
Oct 9, 2026
Merged

Gabriel Dufresne (GabrielDuf) merged 1 commit into
mainfrom
fix/choco-package-script-elevation

Conversation

@GabrielDuf

@GabrielDuf Gabriel Dufresne (GabrielDuf) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Chocolatey updates of python, python3 and python314 always failed in UniGetUI, while choco upgrade python python3 python314 -y works from an elevated console. UniGetUI never retried them as administrator.

Root cause

The python314 package checks for admin rights in its own install script (tools\helpers.ps1). When it isn't elevated, it throws:

ERROR: Installation of python314 to default folder requires Administrative permissions. Please run from elevated prompt.

The Chocolatey operation helper only retries as administrator when the output contains one of a fixed set of phrases. None of them matched this text, so the operation was reported as a plain failure.

Changes

  • requires Administrative permissions and run from elevated prompt now trigger the elevated retry. Each is recognised on its own, so a package script that uses only one of the two sentences is caught too.
  • When "Prohibit any kind of Elevation" is on, the helper reports the failure directly. Before, the "elevated" retry could only re-run the same non-elevated command and fail again, after repeating the whole install.

Notes for reviewers

  • Matching stays case-sensitive on purpose. The warning Chocolatey prints on every non-elevated run contains "Run as Administrator" (capital A). The existing Run as administrator check must not match it, or every failed non-elevated run would be retried elevated. Neither new phrase appears in that warning. A test pins that the warning plus an unrelated error still gives a plain failure.
  • Rejected alternative. I considered stripping that warning and matching case-insensitively, then dropped it. Stderr lines are trimmed and interleaved with stdout, so a partly stripped warning could bring back the blanket retry.
  • The prohibited-elevation check is Chocolatey-only. WinGet, Scoop and PowerShell 5/7 still retry once when elevation is prohibited. Fixing that belongs in the operation layer and is out of scope here.

Testing

  • New tests use the reporter's real choco output. They cover:
    • each phrase on its own;
    • the warning plus an unrelated error, which must stay a plain failure;
    • elevation prohibited.
  • Removing either phrase, or the prohibited-elevation check, makes the matching test fail.
  • All 33 ChocolateyManagerTests pass, and dotnet format whitespace and style are clean.
  • Not tested: a real python314 upgrade. The reporter runs the old Chocolatey copy UniGetUI used to bundle in %LOCALAPPDATA%, where choco itself runs without admin rights. A normal system-wide Chocolatey fails earlier with "Access denied", which was already handled.

Closes #5492

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused implementation matches the reported failure and is covered by appropriate regression tests.

0 open findings

What changed in this PR

Adds reliable elevated retries for Chocolatey packages whose scripts require administrator privileges.

Changes:

  • Detects two additional Chocolatey elevation-error phrases.
  • Honors the global prohibition on elevation retries.
  • Adds coverage for positive, negative, and prohibited-elevation cases.
File Description
ChocolateyManagerTests.cs Tests elevation detection and policy behavior.
ChocolateyPkgOperationHelper.cs Extends elevation matching and respects settings.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@randy-but-a-ro randy-but-a-ro Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Pull request was approved automatically: the AI review is complete and all its review threads are resolved. 🎉

Integration Details
{
	"deliveryId": "1b1917c0-c3f1-11f1-9cd0-a96f5b016884",
	"headSha": "6f83113e57c0d6335446ebe41fba3b69350ba98b",
	"reviewer": "copilot-pull-request-reviewer[bot]"
}

@GabrielDuf
Gabriel Dufresne (GabrielDuf) merged commit f260e6c into main Oct 9, 2026
6 checks passed
@GabrielDuf
Gabriel Dufresne (GabrielDuf) deleted the fix/choco-package-script-elevation branch October 9, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Python packages via chocolatey always fail to update

2 participants