Browse Source

chore(memory-bank): plan 5.0.0-rc3 and record the archival

The maintainer decided on 2026-10-06 to publish 5.0.0-rc3 before 5.0.0
and to archive NTFSSecurity in favor of WindowsAccessControl.

- Decision 18: the project will be archived; the notes in the README,
  the docs home, and the changelog stay until then.
- activeContext: rc3 is the focus. #34 reproduces locally with rc2, on a
  file owned by TrustedInstaller without the Restore privilege, so CI can
  test the fix without a file server.
- progress: rc3, then 5.0.0, with the version steps of each.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/112/head
Raimund Andree 6 days ago
parent
commit
18a76d07f2
  1. 63
      .memory-bank/activeContext.md
  2. 18
      .memory-bank/decisions/0018-archive-for-windowsaccesscontrol.md
  3. 37
      .memory-bank/progress.md
  4. 1
      .memory-bank/systemPatterns.md

63
.memory-bank/activeContext.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-05
last-verified: 2026-10-06
owner: active-agent
source: current task evidence
---
@ -9,42 +9,37 @@ source: current task evidence
## Current focus
5.0.0-rc2 is published. On 2026-10-05 the PRs #99 to #106 were merged into
`master` in order, each with a merge commit, and the tag `5.0.0-rc2` on the
merge commit of #106 (`7ddda8d`) published the module to the PowerShell
Gallery and created the GitHub prerelease through CI (Decision 12). Next:
test the prerelease, answer the issues, and decide between 5.0.0 and an rc3
for #34 and #67.
5.0.0-rc3, before 5.0.0 (maintainer decision of 2026-10-06): the access and
audit cmdlets read and write only the sections of the security descriptor
that they change, which fixes #34 and the copied inherited entries, and #67
is reproduced and fixed or explained. NTFSSecurity will be archived soon;
the README and the docs point users to WindowsAccessControl (Decision 18).
The maintainer has a handoff for rc3, outside the repository.
## Evidence
- The first CI runs of #100 to #106 failed an elevated test that had only
skipped on the workstation, and from #104 on a second one. The audit
inheritance cmdlets wrote no section for an item without a SACL, which
Windows answers with "Access is denied"; and a test read a descriptor with
its SACL, for which Windows doesn't mark the inherited entries of a DACL
that isn't in the auto-inherit format. Fixed test-first in `629f4e7` on
#106, red and green in both editions.
- CI of #106 at `629f4e7` and of `master` at `7ddda8d`: Windows PowerShell
5.1 436 passed, 19 skipped; PowerShell 7 407 passed, 48 skipped; no
failures. Before the merges, a simulation showed that each merge leaves
`master` at the tree its pull request tested.
- The package from the Gallery imports in both editions as 5.0.0-rc2 with
36 cmdlets and help, and `Disable-NTFSAuditInheritance` works on a file
without audit entries.
- The merges closed #3, #4, #5, #17, #74, #82, #86, and #88 and deleted the
eight `ai/` branches. Later that day the 37 issues that were open before
the merges got their replies, 16 of them were closed (as completed when
answered or already fixed, as not planned when not reproducible or won't
fix), and the follow-up issues #107 to #111 were created; 18 issues are
open. On 2026-10-06 the issues got their labels by Decision 17.
- Found while fixing the CI: elevated, `Add-NTFSAccess` and `Add-NTFSAudit`
read the DACL together with the SACL, so the inherited entries of a DACL
without the auto-inherit flag come back as explicit entries, and the write
stores them as explicit copies. Same cause as #34: every section is read
and written; the fix for #34 covers both.
- #34 reproduces locally with 5.0.0-rc2 (2026-10-06): on a file owned by
`NT SERVICE\TrustedInstaller`, with `EnablePrivileges = $false`,
`Add-NTFSAccess` fails with "(1307) This security ID may not be assigned
as the owner of this object" (`AddAceError`), because it writes the
unchanged owner back; `icacls /grant` and `Remove-NTFSAccess`, which
write only the DACL, succeed, and with the Restore privilege enabled
`Add-NTFSAccess` succeeds. A test can therefore run in CI without a file
server.
- Elevated, `Add-NTFSAccess` and `Add-NTFSAudit` read the DACL together
with the SACL. For a DACL without the auto-inherit flag, Windows then
returns the inherited entries without their inherited flag, and the
write stores them as explicit copies (found 2026-10-05).
- `new FileSystemSecurity2(item)` reads all sections it can, and `Write()`
writes what the descriptor holds. Callers that write: adding access or
audit entries, removing all entries of an account, and
`Set-NTFSSecurityDescriptor` for a descriptor from
`Get-NTFSSecurityDescriptor`. Removing a single entry and the inheritance
cmdlets already read and write one section.
- 5.0.0-rc2 is published (2026-10-05); CI on `master` passed; the issues
are answered, labeled (Decision 17), and tracked as #107 to #111.
## Next step
The maintainer tests 5.0.0-rc2, then decides between 5.0.0 and 5.0.0-rc3,
which would fix #34, #67, and the copied inherited entries.
Implement 5.0.0-rc3 test-first on a topic branch, starting with a failing
test for #34 that uses the reproduction above.

18
.memory-bank/decisions/0018-archive-for-windowsaccesscontrol.md

@ -0,0 +1,18 @@
---
status: accepted
date: 2026-10-06
last-verified: 2026-10-06
owner: shared
source: maintainer decision of 2026-10-06
---
# Decision 18: NTFSSecurity will be archived
- Choice: The repository will be archived soon, and its users move to
[WindowsAccessControl](https://github.com/raandree/WindowsAccessControl),
which is on the PowerShell Gallery. The README, the documentation home
(also the wiki home), and the `Deprecated` section of the changelog say
so; keep these notes until the repository is archived.
- Before the archive: 5.0.0-rc3 for #34, #67, and the copied inherited
entries, then 5.0.0. The maintainer decided on 2026-10-06 to publish rc3
before 5.0.0.

37
.memory-bank/progress.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-05
last-verified: 2026-10-06
owner: active-agent
source: repository evidence
---
@ -13,7 +13,8 @@ source: repository evidence
published by CI from the tag `5.0.0-rc2` on `master` (`7ddda8d`) on
2026-10-05 (Decision 12). It contains the 24 code defects of work package
5, the issue fixes of the overnight run of 2026-10-04/05, and the CI fix
`629f4e7`. The stable Gallery version is still 4.2.6.
`629f4e7`. The stable Gallery version is still 4.2.6. NTFSSecurity will be
archived soon; its users move to WindowsAccessControl (Decision 18).
## Recent milestones
@ -37,6 +38,10 @@ published by CI from the tag `5.0.0-rc2` on `master` (`7ddda8d`) on
attempts of the release run before they started. Repository hardening is
optional (Decision 14); the merge rule and the maintainer's rule for
fixes are Decisions 15 and 16.
- 2026-10-06: the issues got their labels (Decision 17). The maintainer
decided to publish 5.0.0-rc3 before 5.0.0 and to archive the project in
favor of WindowsAccessControl (Decision 18); the README, the docs home,
and the changelog announce it.
## Stable capabilities
@ -51,24 +56,26 @@ published by CI from the tag `5.0.0-rc2` on `master` (`7ddda8d`) on
## Open work
1. Test 5.0.0-rc2, then release 5.0.0 through CI (Decision 12): remove the
label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc2` to
`$publishedVersions` in `Tests/Repository.Tests.ps1`, and tag `5.0.0`
(steps in `Docs/Contributing/05-Releasing.md`).
2. Issues: the open issues got their replies on 2026-10-05. Follow-up
1. 5.0.0-rc3 first (maintainer decision of 2026-10-06): #34 and #67. Every
section of the security descriptor is read and written, so the owner
and group are written with each change, and in an elevated session
inherited entries are copied as explicit ones. #34 reproduces locally
(owner `TrustedInstaller`, no Restore privilege), so CI can test the
fix; #67 needs an SMB share. `fix/#34` swallows every error and needs a
redo. For the release: set the label `rc3` and add `5.0.0-rc2` to
`$publishedVersions` in `Tests/Repository.Tests.ps1`.
2. Then release 5.0.0 through CI (Decision 12): remove the label, date
`[Unreleased]` as `[5.0.0]`, add `5.0.0-rc3` to `$publishedVersions`,
and tag `5.0.0` (steps in `Docs/Contributing/05-Releasing.md`).
3. Issues: the open issues got their replies on 2026-10-05. Follow-up
issues for the open Minor review findings: #107 (relative path forms),
#108 (`Copy-Item2` and `Move-Item2`), #109 (error messages), #110
(tests), and #111 (small items); #68 tracks `-WhatIf` and `-Confirm` for
every cmdlet that changes security, and #34 the copied inherited
entries. The labels follow Decision 17; #16, #21, #45, #67, and #89
wait for their reporters (Needs Info).
3. 5.0.0-rc3, if a file server that refuses to assign the owner is
available for a test: #34 and #67. Every section of the security
descriptor is read and written, so the owner and group are written with
each change, and in an elevated session inherited entries are copied as
explicit ones; `fix/#34` swallows every error and needs a redo. After
5.0.0: #41 (a drive root reads the device object) and #90 (a trailing
space in a folder name). Enhancements: #22, #49, #68, #77, #87.
wait for their reporters (Needs Info). Not planned for 5.0.0: #41 (a
drive root reads the device object), #90 (a trailing space in a folder
name), and the enhancements #22, #49, #68, #77, #87.
4. `pwsh` 7.6.1 crashed three times during test runs on the ARM64
workstation (x64 emulation), without module frames; none of the CI runs
on native x64 on 2026-10-05 crashed.

1
.memory-bank/systemPatterns.md

@ -64,6 +64,7 @@ Each Decision record is a file in `decisions/`; read only the relevant ones.
| 15 | [Merge stacked pull requests in order with merge commits](decisions/0015-merge-stacks-with-merge-commits.md) |
| 16 | [Fix only reproducible bugs](decisions/0016-fix-reproducible-bugs-only.md) |
| 17 | [Issue labels](decisions/0017-issue-labels.md) |
| 18 | [NTFSSecurity will be archived](decisions/0018-archive-for-windowsaccesscontrol.md) |
## Patterns

Loading…
Cancel
Save