Browse Source

chore(memory-bank): record 5.0.0-rc5 and the quality gate before 5.0.0

Record the release of 5.0.0-rc5, Phase 1 of the quality gate that the
maintainer set before 5.0.0 (Decision 21): the published package passes
the live tests, every test runs in at least one configuration, and the
suite runs 55.9% of the C# lines and 37.4% of the branches. Record the
coverage measurement with AltCover, the GitHub CLI on the third
workstation, and the plan of Phase 2, which ends with 5.0.0-rc6.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/release-5.0.0-rc6
Raimund Andree 4 days ago
parent
commit
2b1e0406d0
  1. 92
      .memory-bank/activeContext.md
  2. 35
      .memory-bank/decisions/0021-quality-gate-before-5.0.0.md
  3. 44
      .memory-bank/progress.md
  4. 3
      .memory-bank/systemPatterns.md
  5. 35
      .memory-bank/techContext.md

92
.memory-bank/activeContext.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-07
last-verified: 2026-10-08
owner: active-agent
source: current task evidence
---
@ -9,50 +9,58 @@ source: current task evidence
## Current focus
5.0.0-rc5, prepared on the branch `ai/release-5.0.0-rc5`: the live tests
in `Tests\Lab` (Decision 20) and the fix of
`Get-NTFSEffectiveAccess -ServerName` that they found. The maintainer
pushes the branch, opens and merges the pull request, and tags
`5.0.0-rc5`; CI publishes it (Decision 12). Then, with the tester feedback
in #34, he decides on 5.0.0. After 5.0.0 the repository is archived in
favor of WindowsAccessControl (Decision 18).
Phase 2 of the quality gate before 5.0.0 (Decision 21), on the branch
`ai/release-5.0.0-rc6`, released as 5.0.0-rc6: tests until every code
path is tested or explained, live tests for the remaining cmdlets, and
test-first fixes of the known defects. The maintainer approved it on
2026-10-08. Then Phase 3 and 5.0.0; after 5.0.0 the repository is archived
in favor of WindowsAccessControl (Decision 18).
## Evidence
- 2026-10-07: the live tests ran in the lab of WindowsAccessControl
(`F1ADC1`, `F1AFile2`, `F1AFile1` in `a.forest1.net`) against the Gallery
packages of 5.0.0-rc2 and 5.0.0-rc4 and against the branch build, in
Windows PowerShell 5.1 and PowerShell 7, with the same results in both:
- Case 1 (#34 over SMB): rc2 fails `Add-NTFSAccess`, `Clear-NTFSAccess`,
and `Set-NTFSSecurityDescriptor` with error 1307, on folders with and
without the auto-inherit flag; the other four cmdlets succeed in rc2
too. rc4 passes all seven and keeps Administrators as the owner.
- Case 2: the administrators of the file server read, add, and remove
audit entries over SMB; the delegated account gets the errors that the
cmdlet pages describe, and the folders stay unchanged. Same in rc2.
- Case 3: with `-ServerName` of the file server, the result includes its
local group, without a warning; without it, only the domain groups
count. With a computer that can't be reached, rc2 and rc4 returned no
access, because error 1722 was swallowed; fixed on the branch.
- Case 4, long paths on the share, and #108 pass; #108 fails in rc2.
- The branch build passes every live test, and the 499 tests of `Tests`
in both editions.
- One `security-reviewer` pass approved the branch with minor findings;
the assertion of the fallback warning and the path guard of the live
tests were hardened. Deferred: the bare `catch` in
`Win32.GetEffectiveAccess`, which still swallows any other error of the
remote initialization (not reproducible: for a user who isn't an
administrator of the file server, the cmdlet writes "Access is denied");
the unchecked `AUTHZ_ACCESS_REPLY.Error`; a fallback warning that names
the server and the error, which would change behavior (Decision 16).
- #34: no report from the tester by 16:00 UTC on 2026-10-07; he announced
results against two file servers, one of them IBM ESS, for that day.
- The lab keeps the accounts, the share, and the folders of the last run;
`Invoke-NTFSSecurityLabTest.ps1 -RemoveFixture` removes them.
- 2026-10-08, Phase 1, measured on 5.0.0-rc5 (`fcb370e`):
- The published package passes the live tests in both editions: 8 role
runs, no failure.
- As a basic user, the 11 tests that CI skips pass in both editions. The
one failure, `Enable-Privileges should write one object per
privilege`, assumes more than one privilege. Every test runs in at
least one of four configurations (elevated or basic user, two
editions), but CI runs only elevated.
- The suite runs 55.9% of the C# lines and 37.4% of the branches
(`techContext.md`, Validation). No line of `Test-Path2` and
`Get-DiskSpace` runs; `Set-NTFSOwner` (46%) runs only as a setup step
of another test; `Clear-NTFSAccess` and the access inheritance cmdlets
run about 43%, `FileSystemSecurity2` 42%. No cmdlet calls the registry
classes, `SimpleFileSystemAuditRule`, `PrivilegeEnabler`, or
`FileSystemEffectivePermissionEntry` (244 lines).
- 19 of the 36 cmdlets never ran over SMB, among them `Get-NTFSOwner`,
`Set-NTFSOwner`, the audit inheritance cmdlets, and `Clear-NTFSAudit`;
no account of another domain or forest ran; both ends of the lab run
Windows Server 2025.
- Known defects from the reviews of #113 and #114 (`progress.md`, open
work 3): `Move-Item2 -PassThru` returns the source item; the conflict
checks of `Copy-Item2` and `Move-Item2` use `File.Exists` also for
folders, maybe the cause of #21; an error while restoring the owner can
hide the original one (R4); `Set-NTFSSecurityDescriptor -PassThru` reads
the item again inside the retry (R5); the access check doesn't read
`AUTHZ_ACCESS_REPLY.Error`, and its buffers aren't initialized. #110
lists seven test follow-ups.
- #34: no reply from the tester by 06:44 UTC on 2026-10-08.
## Next step
The maintainer runs the push and pull request commands of the session of
2026-10-07, merges, and tags `5.0.0-rc5`. Then check the published package
with `Invoke-NTFSSecurityLabTest.ps1 -Version 5.0.0-rc5`, wait for the #34
feedback, and release 5.0.0 as `progress.md` describes.
Phase 2, one step at a time, each with evidence before the next:
1. Tests for the cmdlets without tests of their own: `Test-Path2`,
`Get-DiskSpace`, `Set-NTFSOwner`, the link cmdlets,
`Get-NTFSOrphanedAudit`, and `Get-NTFSSimpleAccess`.
2. The other parameter sets and error paths, such as the
`-SecurityDescriptor` sets of the inheritance cmdlets and of
`Clear-NTFSAccess`.
3. The paths of `Security2` that no test runs, and #110.
4. Test-first fixes of the known defects; behavior changes go to the
maintainer (Decision 16).
5. A CI job as a basic user, live tests for the other cmdlets over SMB and
for accounts of other forests, and a lab run.
6. Measure the coverage again, explain what remains, review, and prepare
5.0.0-rc6.

35
.memory-bank/decisions/0021-quality-gate-before-5.0.0.md

@ -0,0 +1,35 @@
---
status: accepted
date: 2026-10-08
last-verified: 2026-10-08
owner: shared
source: maintainer decision of 2026-10-08
---
# Decision 21: A quality gate before 5.0.0
- Choice: 5.0.0 ships only at the highest quality, with everything tested
(maintainer, 2026-10-08). The gate has three phases:
1. Measure 5.0.0-rc5: done on 2026-10-08 (`progress.md`).
2. Add tests until every code path is tested or explained, live tests
for the remaining cmdlets, and test-first fixes of the known defects;
release them as 5.0.0-rc6. The maintainer approved it on 2026-10-08.
3. Run the live tests on more operating systems, such as a Windows 11
client and Server 2019 and 2022 file servers, then release 5.0.0.
- Exit criteria for 5.0.0, as proposed on 2026-10-08:
- Every cmdlet and parameter set has behavior tests, error paths
included.
- No test is skipped in every configuration that runs.
- The C# coverage is measured, and every path that no test runs is
tested or explained.
- Every known defect is fixed, or accepted by the maintainer and listed
in the release notes.
- The published package passes the live tests on every operating system
of the matrix.
- Rationale: rc5 passed every test that ran, but the tests ran 55.9% of
the code lines and 37.4% of the branches; five cmdlets had no tests of
their own, and 19 cmdlets never ran over SMB.
- Open: behavior changes found on the way stay the maintainer's decision
(Decision 16); so do the 244 lines of classes that no cmdlet calls, the
operating systems of Phase 3, and how to cover file servers that aren't
Windows (#34).

44
.memory-bank/progress.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-07
last-verified: 2026-10-08
owner: active-agent
source: repository evidence
---
@ -9,15 +9,15 @@ source: repository evidence
## Current status
5.0.0-rc4 is on the PowerShell Gallery and in the GitHub releases,
published by CI from the tag `5.0.0-rc4` on `master` (`01d9264`, the merge
of #113) on 2026-10-06 (Decision 12). It adds to 5.0.0-rc3 the fixes of the
issues #41, #108, #109, and #111 and of the leftovers of the rc3 review.
5.0.0-rc5 is prepared on the branch `ai/release-5.0.0-rc5`: the live tests
in a lab (Decision 20) and the fix of `Get-NTFSEffectiveAccess -ServerName`
that they found. The stable Gallery version is still 4.2.6. NTFSSecurity
will be archived soon; its users move to WindowsAccessControl
(Decision 18).
5.0.0-rc5 is on the PowerShell Gallery and in the GitHub releases,
published by CI on 2026-10-08 from the tag `5.0.0-rc5` on `master`
(`fcb370e`, the merge of #114; Decision 12). It adds to 5.0.0-rc4 the live
tests in a lab (Decision 20) and the fix of
`Get-NTFSEffectiveAccess -ServerName` that they found. Before 5.0.0, the
maintainer wants the highest quality with everything tested: the quality
gate of Decision 21, now in Phase 2, which ends with 5.0.0-rc6. The stable
Gallery version is still 4.2.6. NTFSSecurity will be archived soon; its
users move to WindowsAccessControl (Decision 18).
## Recent milestones
@ -68,6 +68,14 @@ will be archived soon; its users move to WindowsAccessControl
to fix it test-first in 5.0.0-rc5; the branch build passes all live tests
and the suite. One `security-reviewer` pass approved it with minor
findings (`activeContext.md`).
- 2026-10-08: #114 merged (`fcb370e`); the tag `5.0.0-rc5` published it to
the Gallery and the GitHub releases, whose `NTFSSecurity.zip` holds the
same 11 files. Phase 1 of the quality gate (Decision 21) measured rc5:
the published package passes the live tests in both editions; the 11
tests that need a session without the Security privilege pass as a basic
user, so every test runs in at least one configuration, but CI runs only
elevated; the suite runs 55.9% of the C# lines and 37.4% of the branches.
The maintainer approved Phase 2.
## Stable capabilities
@ -82,14 +90,14 @@ will be archived soon; its users move to WindowsAccessControl
## Open work
1. Publish 5.0.0-rc5 (merge, then tag), check its package in the lab with
`Tests\Lab\Invoke-NTFSSecurityLabTest.ps1 -Version 5.0.0-rc5`, and then
release 5.0.0 through CI (Decision 12) with the tester feedback in #34:
remove the label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc5` to
`$publishedVersions`, and tag `5.0.0` (steps in
`Docs/Contributing/05-Releasing.md`). #34 stays open with Bug and Help
Wanted until a tester with a file server that refuses the owner
confirms the fix, or until 5.0.0 ships.
1. Quality gate before 5.0.0 (Decision 21): Phase 2 on the branch
`ai/release-5.0.0-rc6` (`activeContext.md`), released as 5.0.0-rc6;
Phase 3 runs the live tests on more operating systems. Then release
5.0.0 through CI (Decision 12): remove the label, date `[Unreleased]` as
`[5.0.0]`, add the last prerelease to `$publishedVersions`, and tag
`5.0.0` (steps in `Docs/Contributing/05-Releasing.md`). #34 stays open
with Bug and Help Wanted until a tester with a file server that refuses
the owner confirms the fix, or until 5.0.0 ships.
2. Issues: #110 (tests) is the open follow-up of the review findings; #68
tracks `-WhatIf` and `-Confirm` for every cmdlet that changes security.
The labels follow Decision 17; #16, #21, #45, and #89 wait for their

3
.memory-bank/systemPatterns.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-07
last-verified: 2026-10-08
owner: active-agent
source: repository evidence
---
@ -67,6 +67,7 @@ Each Decision record is a file in `decisions/`; read only the relevant ones.
| 18 | [NTFSSecurity will be archived](decisions/0018-archive-for-windowsaccesscontrol.md) |
| 19 | [Cmdlets write only the sections that they change](decisions/0019-write-only-changed-sections.md) |
| 20 | [Live tests in a lab live in Tests\Lab](decisions/0020-live-tests-in-tests-lab.md) |
| 21 | [A quality gate before 5.0.0](decisions/0021-quality-gate-before-5.0.0.md) |
## Patterns

35
.memory-bank/techContext.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-07
last-verified: 2026-10-08
owner: active-agent
source: repository evidence
---
@ -72,16 +72,19 @@ source: repository evidence
- The third workstation (`ExHost`, a Windows Server 2025 VM, x64, used since
2026-10-07) runs the agent session elevated and hosts the AutomatedLab lab
`WindowsAccessControlLab` (Decision 20) with Hyper-V and AutomatedLab
5.61.704. It has no NuGet cache, platyPS, or GitHub CLI: check each
5.61.704. It has no NuGet cache or platyPS: check each
nuget.org package against the SHA-512 `packageHash` of its catalog entry
(`https://api.nuget.org/v3/registration5-semver1/<id>/<version>.json`,
then `catalogEntry`), and each Gallery package against `PackageHash` of
`api/v2/Packages(Id='<id>',Version='<version>')`. Pester 5.7.1 is in
`V:\Git\WindowsAccessControl\output\RequiredModules`; read issues and pull
requests through the GitHub REST API. The lab domains `a.forest1.net` and
`b.forest1.net` had a maximum password age of 42 days, so the password of
`install` expired on 2026-09-15 and AutomatedLab got access denied; it
never expires since 2026-10-07, as in `forest1.net`.
`V:\Git\WindowsAccessControl\output\RequiredModules`. The GitHub CLI
2.102.0 is in `C:\Program Files\GitHub CLI`, outside the PATH, and signed
in as `raandree` since 2026-10-08; `Block-RemoteMutation` denies its
mutating commands, so the agent uses it read-only. The lab domains
`a.forest1.net` and `b.forest1.net` had a maximum password age of 42
days, so the password of `install` expired on 2026-09-15 and AutomatedLab
got access denied; it never expires since 2026-10-07, as in
`forest1.net`.
## Constraints
@ -96,7 +99,8 @@ source: repository evidence
- PowerShell Gallery versions (publish dates): 4.0.0 (2015-08-19), 4.2.2
(2016-05-18), 4.2.3 (2016-05-19), 4.2.4 (2018-08-13), 4.2.5 (2019-07-11),
4.2.6 (2019-07-12), none with release notes; 5.0.0-rc1 (2026-10-04),
5.0.0-rc2 (2026-10-05), 5.0.0-rc3 and 5.0.0-rc4 (2026-10-06), published
5.0.0-rc2 (2026-10-05), 5.0.0-rc3 and 5.0.0-rc4 (2026-10-06), 5.0.0-rc5
(2026-10-08), published
by CI. Older versions were released on CodePlex only, and their dates are
lost. The git history starts on 2016-10-10, when the project moved from
CodePlex.
@ -175,6 +179,21 @@ source: repository evidence
session. Run them as a basic user with `runas /trustlevel:0x20000`, and
give Windows PowerShell its own `PSModulePath`; that token holds one
privilege, so the `Enable-Privileges -PassThru` count test fails there.
`runas` returns at once, so the script it starts writes its own log.
Pester reports a skipped `-ForEach` test under its template name, such as
`<_> should ...`, and a test that ran under the expanded name: compare
runs by template.
- C# coverage (Decision 21): AltCover 9.0.145 (`tools\net472\AltCover.exe`
of the nuget.org package) instruments a copy of the local Release build,
which has the PDB files that the published package lacks: `--save`,
`--reportFormat=OpenCover`, AlphaFS and `System.Management.Automation`
excluded with `--assemblyFilter`. Put the instrumented module in
`NTFSSecurity\bin\Release` of a `git worktree`, run
`.github\scripts\Invoke-Tests.ps1` elevated and as a basic user in both
editions, then `AltCover.exe runner --collect --recorderDirectory=<the
instrumented folder>`. Baseline of the rc5 tree on 2026-10-08: 55.9% of
the lines (1,943 of 3,476), 37.4% of the branches (700 of 1,873); 60.1%
of the lines without 244 lines in classes that no cmdlet calls.
- Live tests (Decision 20): in an elevated Windows PowerShell 5.1 session
on the lab host, `Tests\Lab\Invoke-NTFSSecurityLabTest.ps1` with
`-Version` for Gallery packages or `-ModulePath` for a build; it writes

Loading…
Cancel
Save