From 164b2f0af30593696c56c6d9b2ba3111ab5a710a Mon Sep 17 00:00:00 2001 From: Raimund Andree Date: Thu, 8 Oct 2026 09:07:58 +0000 Subject: [PATCH] chore(memory-bank): record the link tests and the review fix round Record in activeContext the link cmdlet tests, the two corrections of the New-NTFSSymbolicLink page with the lab check of Developer Mode, the security review of fcb370e..00c3646 and its fix round, the next step, and the open question about unprivileged symbolic links. Add the milestone to progress, the cleanup rule for privileges to systemPatterns, and the way to check the lab client as an account without administrator rights to techContext. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant --- .memory-bank/activeContext.md | 37 ++++++++++++++++++++++++++++++---- .memory-bank/progress.md | 7 +++++++ .memory-bank/systemPatterns.md | 6 +++++- .memory-bank/techContext.md | 6 +++++- 4 files changed, 50 insertions(+), 6 deletions(-) diff --git a/.memory-bank/activeContext.md b/.memory-bank/activeContext.md index 221c7ae..f386e2e 100644 --- a/.memory-bank/activeContext.md +++ b/.memory-bank/activeContext.md @@ -53,15 +53,37 @@ in favor of WindowsAccessControl (Decision 18). and Security privileges enabled in the session when a later command or a terminating error stopped the pipeline; `Test-Path2` stopped with "Illegal characters in path" in Windows PowerShell for a path such as - `C:\a|b`. The suite (533 tests) passes elevated in both editions. + `C:\a|b`. +- Phase 2, step 1, link cmdlets (2026-10-08, `4d5c8c4`, `09eb337`): 18 new + tests for `New-NTFSHardLink`, `Get-NTFSHardLink`, and + `New-NTFSSymbolicLink` pass elevated and as a basic user in both + editions; no code defect. The page of `New-NTFSSymbolicLink` was wrong + twice: `-PassThru` returns a folder object for a link to a folder since + 5.0.0, and Windows Developer Mode doesn't help, because AlphaFS 2.2.1 + passes only the File or Directory flag to `CreateSymbolicLinkW`. Lab + check on `F1AFile1` as `NtfsLiveServerAdmin` (no administrator): + with Developer Mode on, `mklink` created a link and the cmdlet of + 5.0.0-rc5 failed with error 1314; the setting was restored. +- Security review of `fcb370e..00c3646` (`security-reviewer`, 2026-10-08): + the `Dispose` approach is sound; two Major findings, both one root cause + that 4.2.6 already had: the privilege cleanup decided on the states read + in `BeginProcessing` and stopped at the first failure. Reproduced: a + privilege that another command in the pipeline disabled left the others + enabled (silently after an early stop), and + `Get-NTFSOwner ... | ForEach-Object { Disable-Privileges; $_ }` stopped + with "Priviledge already disabled". Two Minor findings: the early-stop + tests could pass vacuously, and `Test-Path2` gave no reason for `$false`. + The maintainer chose to fix all four; fixed test-first in `578042f` and + `b241441`. The suite (555 tests) passes elevated in both editions + (534/0/21 and 504/0/51), and the changed test files pass as a basic user. ## Next step Phase 2, one step at a time, each with evidence before the next: 1. Tests for the cmdlets without tests of their own: done for - `Set-NTFSOwner`, `Test-Path2`, and `Get-DiskSpace`; open for the link - cmdlets, `Get-NTFSOrphanedAudit`, and `Get-NTFSSimpleAccess`. + `Set-NTFSOwner`, `Test-Path2`, `Get-DiskSpace`, and the link cmdlets; + open for `Get-NTFSOrphanedAudit` and `Get-NTFSSimpleAccess`. 2. The other parameter sets and error paths, such as the `-SecurityDescriptor` sets of the inheritance cmdlets and of `Clear-NTFSAccess`. @@ -71,4 +93,11 @@ Phase 2, one step at a time, each with evidence before the next: 5. A CI job as a basic user, live tests for the other cmdlets over SMB and for accounts of other forests, and a lab run. 6. Measure the coverage again, explain what remains, review, and prepare - 5.0.0-rc6. + 5.0.0-rc6. The final review covers the whole branch, including the fix + round of `578042f` and `b241441`. + +Open question for the maintainer, not planned: `New-NTFSSymbolicLink` +could request unprivileged creation with +`SYMBOLIC_LINK_FLAG_ALLOW_UNPRIVILEGED_CREATE`, so that Developer Mode +works. That is a behavior change (Decision 16) and needs a fallback for +Windows versions before 10 1703, which don't know the flag. diff --git a/.memory-bank/progress.md b/.memory-bank/progress.md index 05fc1ac..c9435e0 100644 --- a/.memory-bank/progress.md +++ b/.memory-bank/progress.md @@ -76,6 +76,13 @@ users move to WindowsAccessControl (Decision 18). user, so every test runs in at least one configuration, but CI runs only elevated; the suite runs 55.9% of the C# lines and 37.4% of the branches. The maintainer approved Phase 2. +- 2026-10-08: Phase 2, step 1 on `ai/release-5.0.0-rc6` (local): tests for + `Set-NTFSOwner`, `Test-Path2`, `Get-DiskSpace`, and the link cmdlets + (suite: 555 tests). Fixed test-first: the privileges stayed enabled after + an early stop; `Test-Path2` stopped for invalid characters in Windows + PowerShell; and, from one `security-reviewer` pass, the privilege cleanup + decided on stale states, a defect since 4.2.6. The page of + `New-NTFSSymbolicLink` was corrected after a lab check of Developer Mode. ## Stable capabilities diff --git a/.memory-bank/systemPatterns.md b/.memory-bank/systemPatterns.md index e0d32ed..44118f5 100644 --- a/.memory-bank/systemPatterns.md +++ b/.memory-bank/systemPatterns.md @@ -39,7 +39,11 @@ NTFSSecurity.dll ── cmdlets ──> Security2.dll (FileSystemAccessRule2, 5.0.0-rc6, in `Dispose`: PowerShell skips `EndProcessing` when a later command, such as `Select-Object -First`, or a terminating error stops the pipeline, but calls `Dispose`. `Enable-Privileges` keeps them - (`KeepEnabledPrivileges`). + (`KeepEnabledPrivileges`). The cleanup reads the current state of each + privilege, because another command in the pipeline can have changed it, + and tries every privilege even when one fails: `EndProcessing` warns, + `Dispose` stays silent, because PowerShell ignores exceptions thrown + there and no stream is open anymore. - `PrivateData` switches: `EnablePrivileges`, `GetInheritedFrom`, `GetFileSystemModeProperty`, `IdentifyHardLinks`, `ShowAccountSid`. - Cmdlets accept `-Path` (alias `FullName`) or `-SecurityDescriptor`; the diff --git a/.memory-bank/techContext.md b/.memory-bank/techContext.md index b7355a2..84e6aaf 100644 --- a/.memory-bank/techContext.md +++ b/.memory-bank/techContext.md @@ -199,7 +199,11 @@ source: repository evidence `-Version` for Gallery packages or `-ModulePath` for a build; it writes the results to `$env:TEMP\NTFSSecurityLab\Results`. A run of two versions in both editions takes about 30 minutes; `-RemoveFixture` removes its - accounts, share, and folders from the lab. + accounts, share, and folders from the lab. For a check on the client as + an account without administrator rights, use `NtfsLiveServerAdmin` + (Remote Management Users on the client, CredSSP by IP address like the + controller): reset its password on the PDC emulator to a random value + in memory; the next run of the controller sets a new one anyway. - Markdown lint: `npx markdownlint-cli2` with `MD013` limited to prose (tables, code, and headings excluded) on the conceptual pages; for `CHANGELOG.md` also `MD024` with `siblings_only: true`, because every