Browse Source

chore(memory-bank): record the link tests and the review fix round

Record in activeContext the link cmdlet tests, the two corrections of the
New-NTFSSymbolicLink page with the lab check of Developer Mode, the
security review of fcb370e..00c3646 and its fix round, the next step, and
the open question about unprivileged symbolic links. Add the milestone to
progress, the cleanup rule for privileges to systemPatterns, and the way
to check the lab client as an account without administrator rights to
techContext.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/release-5.0.0-rc6
Raimund Andree 4 days ago
parent
commit
164b2f0af3
  1. 37
      .memory-bank/activeContext.md
  2. 7
      .memory-bank/progress.md
  3. 6
      .memory-bank/systemPatterns.md
  4. 6
      .memory-bank/techContext.md

37
.memory-bank/activeContext.md

@ -53,15 +53,37 @@ in favor of WindowsAccessControl (Decision 18).
and Security privileges enabled in the session when a later command or a
terminating error stopped the pipeline; `Test-Path2` stopped with
"Illegal characters in path" in Windows PowerShell for a path such as
`C:\a|b`. The suite (533 tests) passes elevated in both editions.
`C:\a|b`.
- Phase 2, step 1, link cmdlets (2026-10-08, `4d5c8c4`, `09eb337`): 18 new
tests for `New-NTFSHardLink`, `Get-NTFSHardLink`, and
`New-NTFSSymbolicLink` pass elevated and as a basic user in both
editions; no code defect. The page of `New-NTFSSymbolicLink` was wrong
twice: `-PassThru` returns a folder object for a link to a folder since
5.0.0, and Windows Developer Mode doesn't help, because AlphaFS 2.2.1
passes only the File or Directory flag to `CreateSymbolicLinkW`. Lab
check on `F1AFile1` as `NtfsLiveServerAdmin` (no administrator):
with Developer Mode on, `mklink` created a link and the cmdlet of
5.0.0-rc5 failed with error 1314; the setting was restored.
- Security review of `fcb370e..00c3646` (`security-reviewer`, 2026-10-08):
the `Dispose` approach is sound; two Major findings, both one root cause
that 4.2.6 already had: the privilege cleanup decided on the states read
in `BeginProcessing` and stopped at the first failure. Reproduced: a
privilege that another command in the pipeline disabled left the others
enabled (silently after an early stop), and
`Get-NTFSOwner ... | ForEach-Object { Disable-Privileges; $_ }` stopped
with "Priviledge already disabled". Two Minor findings: the early-stop
tests could pass vacuously, and `Test-Path2` gave no reason for `$false`.
The maintainer chose to fix all four; fixed test-first in `578042f` and
`b241441`. The suite (555 tests) passes elevated in both editions
(534/0/21 and 504/0/51), and the changed test files pass as a basic user.
## Next step
Phase 2, one step at a time, each with evidence before the next:
1. Tests for the cmdlets without tests of their own: done for
`Set-NTFSOwner`, `Test-Path2`, and `Get-DiskSpace`; open for the link
cmdlets, `Get-NTFSOrphanedAudit`, and `Get-NTFSSimpleAccess`.
`Set-NTFSOwner`, `Test-Path2`, `Get-DiskSpace`, and the link cmdlets;
open for `Get-NTFSOrphanedAudit` and `Get-NTFSSimpleAccess`.
2. The other parameter sets and error paths, such as the
`-SecurityDescriptor` sets of the inheritance cmdlets and of
`Clear-NTFSAccess`.
@ -71,4 +93,11 @@ Phase 2, one step at a time, each with evidence before the next:
5. A CI job as a basic user, live tests for the other cmdlets over SMB and
for accounts of other forests, and a lab run.
6. Measure the coverage again, explain what remains, review, and prepare
5.0.0-rc6.
5.0.0-rc6. The final review covers the whole branch, including the fix
round of `578042f` and `b241441`.
Open question for the maintainer, not planned: `New-NTFSSymbolicLink`
could request unprivileged creation with
`SYMBOLIC_LINK_FLAG_ALLOW_UNPRIVILEGED_CREATE`, so that Developer Mode
works. That is a behavior change (Decision 16) and needs a fallback for
Windows versions before 10 1703, which don't know the flag.

7
.memory-bank/progress.md

@ -76,6 +76,13 @@ users move to WindowsAccessControl (Decision 18).
user, so every test runs in at least one configuration, but CI runs only
elevated; the suite runs 55.9% of the C# lines and 37.4% of the branches.
The maintainer approved Phase 2.
- 2026-10-08: Phase 2, step 1 on `ai/release-5.0.0-rc6` (local): tests for
`Set-NTFSOwner`, `Test-Path2`, `Get-DiskSpace`, and the link cmdlets
(suite: 555 tests). Fixed test-first: the privileges stayed enabled after
an early stop; `Test-Path2` stopped for invalid characters in Windows
PowerShell; and, from one `security-reviewer` pass, the privilege cleanup
decided on stale states, a defect since 4.2.6. The page of
`New-NTFSSymbolicLink` was corrected after a lab check of Developer Mode.
## Stable capabilities

6
.memory-bank/systemPatterns.md

@ -39,7 +39,11 @@ NTFSSecurity.dll ── cmdlets ──> Security2.dll (FileSystemAccessRule2,
5.0.0-rc6, in `Dispose`: PowerShell skips `EndProcessing` when a later
command, such as `Select-Object -First`, or a terminating error stops the
pipeline, but calls `Dispose`. `Enable-Privileges` keeps them
(`KeepEnabledPrivileges`).
(`KeepEnabledPrivileges`). The cleanup reads the current state of each
privilege, because another command in the pipeline can have changed it,
and tries every privilege even when one fails: `EndProcessing` warns,
`Dispose` stays silent, because PowerShell ignores exceptions thrown
there and no stream is open anymore.
- `PrivateData` switches: `EnablePrivileges`, `GetInheritedFrom`,
`GetFileSystemModeProperty`, `IdentifyHardLinks`, `ShowAccountSid`.
- Cmdlets accept `-Path` (alias `FullName`) or `-SecurityDescriptor`; the

6
.memory-bank/techContext.md

@ -199,7 +199,11 @@ source: repository evidence
`-Version` for Gallery packages or `-ModulePath` for a build; it writes
the results to `$env:TEMP\NTFSSecurityLab\Results`. A run of two versions
in both editions takes about 30 minutes; `-RemoveFixture` removes its
accounts, share, and folders from the lab.
accounts, share, and folders from the lab. For a check on the client as
an account without administrator rights, use `NtfsLiveServerAdmin`
(Remote Management Users on the client, CredSSP by IP address like the
controller): reset its password on the PDC emulator to a random value
in memory; the next run of the controller sets a new one anyway.
- Markdown lint: `npx markdownlint-cli2` with `MD013` limited to prose
(tables, code, and headings excluded) on the conceptual pages; for
`CHANGELOG.md` also `MD024` with `siblings_only: true`, because every

Loading…
Cancel
Save