Browse Source

chore(memory-bank): record 5.0.0-rc5 and the quality gate before 5.0.0

Record the release of 5.0.0-rc5, Phase 1 of the quality gate that the
maintainer set before 5.0.0 (Decision 21): the published package passes
the live tests, every test runs in at least one configuration, and the
suite runs 55.9% of the C# lines and 37.4% of the branches. Record the
coverage measurement with AltCover, the GitHub CLI on the third
workstation, and the plan of Phase 2, which ends with 5.0.0-rc6.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/release-5.0.0-rc6
Raimund Andree 4 days ago
parent
commit
2b1e0406d0
  1. 92
      .memory-bank/activeContext.md
  2. 35
      .memory-bank/decisions/0021-quality-gate-before-5.0.0.md
  3. 44
      .memory-bank/progress.md
  4. 3
      .memory-bank/systemPatterns.md
  5. 35
      .memory-bank/techContext.md

92
.memory-bank/activeContext.md

@ -1,6 +1,6 @@
--- ---
status: current status: current
last-verified: 2026-10-07 last-verified: 2026-10-08
owner: active-agent owner: active-agent
source: current task evidence source: current task evidence
--- ---
@ -9,50 +9,58 @@ source: current task evidence
## Current focus ## Current focus
5.0.0-rc5, prepared on the branch `ai/release-5.0.0-rc5`: the live tests Phase 2 of the quality gate before 5.0.0 (Decision 21), on the branch
in `Tests\Lab` (Decision 20) and the fix of `ai/release-5.0.0-rc6`, released as 5.0.0-rc6: tests until every code
`Get-NTFSEffectiveAccess -ServerName` that they found. The maintainer path is tested or explained, live tests for the remaining cmdlets, and
pushes the branch, opens and merges the pull request, and tags test-first fixes of the known defects. The maintainer approved it on
`5.0.0-rc5`; CI publishes it (Decision 12). Then, with the tester feedback 2026-10-08. Then Phase 3 and 5.0.0; after 5.0.0 the repository is archived
in #34, he decides on 5.0.0. After 5.0.0 the repository is archived in in favor of WindowsAccessControl (Decision 18).
favor of WindowsAccessControl (Decision 18).
## Evidence ## Evidence
- 2026-10-07: the live tests ran in the lab of WindowsAccessControl - 2026-10-08, Phase 1, measured on 5.0.0-rc5 (`fcb370e`):
(`F1ADC1`, `F1AFile2`, `F1AFile1` in `a.forest1.net`) against the Gallery - The published package passes the live tests in both editions: 8 role
packages of 5.0.0-rc2 and 5.0.0-rc4 and against the branch build, in runs, no failure.
Windows PowerShell 5.1 and PowerShell 7, with the same results in both: - As a basic user, the 11 tests that CI skips pass in both editions. The
- Case 1 (#34 over SMB): rc2 fails `Add-NTFSAccess`, `Clear-NTFSAccess`, one failure, `Enable-Privileges should write one object per
and `Set-NTFSSecurityDescriptor` with error 1307, on folders with and privilege`, assumes more than one privilege. Every test runs in at
without the auto-inherit flag; the other four cmdlets succeed in rc2 least one of four configurations (elevated or basic user, two
too. rc4 passes all seven and keeps Administrators as the owner. editions), but CI runs only elevated.
- Case 2: the administrators of the file server read, add, and remove - The suite runs 55.9% of the C# lines and 37.4% of the branches
audit entries over SMB; the delegated account gets the errors that the (`techContext.md`, Validation). No line of `Test-Path2` and
cmdlet pages describe, and the folders stay unchanged. Same in rc2. `Get-DiskSpace` runs; `Set-NTFSOwner` (46%) runs only as a setup step
- Case 3: with `-ServerName` of the file server, the result includes its of another test; `Clear-NTFSAccess` and the access inheritance cmdlets
local group, without a warning; without it, only the domain groups run about 43%, `FileSystemSecurity2` 42%. No cmdlet calls the registry
count. With a computer that can't be reached, rc2 and rc4 returned no classes, `SimpleFileSystemAuditRule`, `PrivilegeEnabler`, or
access, because error 1722 was swallowed; fixed on the branch. `FileSystemEffectivePermissionEntry` (244 lines).
- Case 4, long paths on the share, and #108 pass; #108 fails in rc2. - 19 of the 36 cmdlets never ran over SMB, among them `Get-NTFSOwner`,
- The branch build passes every live test, and the 499 tests of `Tests` `Set-NTFSOwner`, the audit inheritance cmdlets, and `Clear-NTFSAudit`;
in both editions. no account of another domain or forest ran; both ends of the lab run
- One `security-reviewer` pass approved the branch with minor findings; Windows Server 2025.
the assertion of the fallback warning and the path guard of the live - Known defects from the reviews of #113 and #114 (`progress.md`, open
tests were hardened. Deferred: the bare `catch` in work 3): `Move-Item2 -PassThru` returns the source item; the conflict
`Win32.GetEffectiveAccess`, which still swallows any other error of the checks of `Copy-Item2` and `Move-Item2` use `File.Exists` also for
remote initialization (not reproducible: for a user who isn't an folders, maybe the cause of #21; an error while restoring the owner can
administrator of the file server, the cmdlet writes "Access is denied"); hide the original one (R4); `Set-NTFSSecurityDescriptor -PassThru` reads
the unchecked `AUTHZ_ACCESS_REPLY.Error`; a fallback warning that names the item again inside the retry (R5); the access check doesn't read
the server and the error, which would change behavior (Decision 16). `AUTHZ_ACCESS_REPLY.Error`, and its buffers aren't initialized. #110
- #34: no report from the tester by 16:00 UTC on 2026-10-07; he announced lists seven test follow-ups.
results against two file servers, one of them IBM ESS, for that day. - #34: no reply from the tester by 06:44 UTC on 2026-10-08.
- The lab keeps the accounts, the share, and the folders of the last run;
`Invoke-NTFSSecurityLabTest.ps1 -RemoveFixture` removes them.
## Next step ## Next step
The maintainer runs the push and pull request commands of the session of Phase 2, one step at a time, each with evidence before the next:
2026-10-07, merges, and tags `5.0.0-rc5`. Then check the published package
with `Invoke-NTFSSecurityLabTest.ps1 -Version 5.0.0-rc5`, wait for the #34 1. Tests for the cmdlets without tests of their own: `Test-Path2`,
feedback, and release 5.0.0 as `progress.md` describes. `Get-DiskSpace`, `Set-NTFSOwner`, the link cmdlets,
`Get-NTFSOrphanedAudit`, and `Get-NTFSSimpleAccess`.
2. The other parameter sets and error paths, such as the
`-SecurityDescriptor` sets of the inheritance cmdlets and of
`Clear-NTFSAccess`.
3. The paths of `Security2` that no test runs, and #110.
4. Test-first fixes of the known defects; behavior changes go to the
maintainer (Decision 16).
5. A CI job as a basic user, live tests for the other cmdlets over SMB and
for accounts of other forests, and a lab run.
6. Measure the coverage again, explain what remains, review, and prepare
5.0.0-rc6.

35
.memory-bank/decisions/0021-quality-gate-before-5.0.0.md

@ -0,0 +1,35 @@
---
status: accepted
date: 2026-10-08
last-verified: 2026-10-08
owner: shared
source: maintainer decision of 2026-10-08
---
# Decision 21: A quality gate before 5.0.0
- Choice: 5.0.0 ships only at the highest quality, with everything tested
(maintainer, 2026-10-08). The gate has three phases:
1. Measure 5.0.0-rc5: done on 2026-10-08 (`progress.md`).
2. Add tests until every code path is tested or explained, live tests
for the remaining cmdlets, and test-first fixes of the known defects;
release them as 5.0.0-rc6. The maintainer approved it on 2026-10-08.
3. Run the live tests on more operating systems, such as a Windows 11
client and Server 2019 and 2022 file servers, then release 5.0.0.
- Exit criteria for 5.0.0, as proposed on 2026-10-08:
- Every cmdlet and parameter set has behavior tests, error paths
included.
- No test is skipped in every configuration that runs.
- The C# coverage is measured, and every path that no test runs is
tested or explained.
- Every known defect is fixed, or accepted by the maintainer and listed
in the release notes.
- The published package passes the live tests on every operating system
of the matrix.
- Rationale: rc5 passed every test that ran, but the tests ran 55.9% of
the code lines and 37.4% of the branches; five cmdlets had no tests of
their own, and 19 cmdlets never ran over SMB.
- Open: behavior changes found on the way stay the maintainer's decision
(Decision 16); so do the 244 lines of classes that no cmdlet calls, the
operating systems of Phase 3, and how to cover file servers that aren't
Windows (#34).

44
.memory-bank/progress.md

@ -1,6 +1,6 @@
--- ---
status: current status: current
last-verified: 2026-10-07 last-verified: 2026-10-08
owner: active-agent owner: active-agent
source: repository evidence source: repository evidence
--- ---
@ -9,15 +9,15 @@ source: repository evidence
## Current status ## Current status
5.0.0-rc4 is on the PowerShell Gallery and in the GitHub releases, 5.0.0-rc5 is on the PowerShell Gallery and in the GitHub releases,
published by CI from the tag `5.0.0-rc4` on `master` (`01d9264`, the merge published by CI on 2026-10-08 from the tag `5.0.0-rc5` on `master`
of #113) on 2026-10-06 (Decision 12). It adds to 5.0.0-rc3 the fixes of the (`fcb370e`, the merge of #114; Decision 12). It adds to 5.0.0-rc4 the live
issues #41, #108, #109, and #111 and of the leftovers of the rc3 review. tests in a lab (Decision 20) and the fix of
5.0.0-rc5 is prepared on the branch `ai/release-5.0.0-rc5`: the live tests `Get-NTFSEffectiveAccess -ServerName` that they found. Before 5.0.0, the
in a lab (Decision 20) and the fix of `Get-NTFSEffectiveAccess -ServerName` maintainer wants the highest quality with everything tested: the quality
that they found. The stable Gallery version is still 4.2.6. NTFSSecurity gate of Decision 21, now in Phase 2, which ends with 5.0.0-rc6. The stable
will be archived soon; its users move to WindowsAccessControl Gallery version is still 4.2.6. NTFSSecurity will be archived soon; its
(Decision 18). users move to WindowsAccessControl (Decision 18).
## Recent milestones ## Recent milestones
@ -68,6 +68,14 @@ will be archived soon; its users move to WindowsAccessControl
to fix it test-first in 5.0.0-rc5; the branch build passes all live tests to fix it test-first in 5.0.0-rc5; the branch build passes all live tests
and the suite. One `security-reviewer` pass approved it with minor and the suite. One `security-reviewer` pass approved it with minor
findings (`activeContext.md`). findings (`activeContext.md`).
- 2026-10-08: #114 merged (`fcb370e`); the tag `5.0.0-rc5` published it to
the Gallery and the GitHub releases, whose `NTFSSecurity.zip` holds the
same 11 files. Phase 1 of the quality gate (Decision 21) measured rc5:
the published package passes the live tests in both editions; the 11
tests that need a session without the Security privilege pass as a basic
user, so every test runs in at least one configuration, but CI runs only
elevated; the suite runs 55.9% of the C# lines and 37.4% of the branches.
The maintainer approved Phase 2.
## Stable capabilities ## Stable capabilities
@ -82,14 +90,14 @@ will be archived soon; its users move to WindowsAccessControl
## Open work ## Open work
1. Publish 5.0.0-rc5 (merge, then tag), check its package in the lab with 1. Quality gate before 5.0.0 (Decision 21): Phase 2 on the branch
`Tests\Lab\Invoke-NTFSSecurityLabTest.ps1 -Version 5.0.0-rc5`, and then `ai/release-5.0.0-rc6` (`activeContext.md`), released as 5.0.0-rc6;
release 5.0.0 through CI (Decision 12) with the tester feedback in #34: Phase 3 runs the live tests on more operating systems. Then release
remove the label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc5` to 5.0.0 through CI (Decision 12): remove the label, date `[Unreleased]` as
`$publishedVersions`, and tag `5.0.0` (steps in `[5.0.0]`, add the last prerelease to `$publishedVersions`, and tag
`Docs/Contributing/05-Releasing.md`). #34 stays open with Bug and Help `5.0.0` (steps in `Docs/Contributing/05-Releasing.md`). #34 stays open
Wanted until a tester with a file server that refuses the owner with Bug and Help Wanted until a tester with a file server that refuses
confirms the fix, or until 5.0.0 ships. the owner confirms the fix, or until 5.0.0 ships.
2. Issues: #110 (tests) is the open follow-up of the review findings; #68 2. Issues: #110 (tests) is the open follow-up of the review findings; #68
tracks `-WhatIf` and `-Confirm` for every cmdlet that changes security. tracks `-WhatIf` and `-Confirm` for every cmdlet that changes security.
The labels follow Decision 17; #16, #21, #45, and #89 wait for their The labels follow Decision 17; #16, #21, #45, and #89 wait for their

3
.memory-bank/systemPatterns.md

@ -1,6 +1,6 @@
--- ---
status: current status: current
last-verified: 2026-10-07 last-verified: 2026-10-08
owner: active-agent owner: active-agent
source: repository evidence source: repository evidence
--- ---
@ -67,6 +67,7 @@ Each Decision record is a file in `decisions/`; read only the relevant ones.
| 18 | [NTFSSecurity will be archived](decisions/0018-archive-for-windowsaccesscontrol.md) | | 18 | [NTFSSecurity will be archived](decisions/0018-archive-for-windowsaccesscontrol.md) |
| 19 | [Cmdlets write only the sections that they change](decisions/0019-write-only-changed-sections.md) | | 19 | [Cmdlets write only the sections that they change](decisions/0019-write-only-changed-sections.md) |
| 20 | [Live tests in a lab live in Tests\Lab](decisions/0020-live-tests-in-tests-lab.md) | | 20 | [Live tests in a lab live in Tests\Lab](decisions/0020-live-tests-in-tests-lab.md) |
| 21 | [A quality gate before 5.0.0](decisions/0021-quality-gate-before-5.0.0.md) |
## Patterns ## Patterns

35
.memory-bank/techContext.md

@ -1,6 +1,6 @@
--- ---
status: current status: current
last-verified: 2026-10-07 last-verified: 2026-10-08
owner: active-agent owner: active-agent
source: repository evidence source: repository evidence
--- ---
@ -72,16 +72,19 @@ source: repository evidence
- The third workstation (`ExHost`, a Windows Server 2025 VM, x64, used since - The third workstation (`ExHost`, a Windows Server 2025 VM, x64, used since
2026-10-07) runs the agent session elevated and hosts the AutomatedLab lab 2026-10-07) runs the agent session elevated and hosts the AutomatedLab lab
`WindowsAccessControlLab` (Decision 20) with Hyper-V and AutomatedLab `WindowsAccessControlLab` (Decision 20) with Hyper-V and AutomatedLab
5.61.704. It has no NuGet cache, platyPS, or GitHub CLI: check each 5.61.704. It has no NuGet cache or platyPS: check each
nuget.org package against the SHA-512 `packageHash` of its catalog entry nuget.org package against the SHA-512 `packageHash` of its catalog entry
(`https://api.nuget.org/v3/registration5-semver1/<id>/<version>.json`, (`https://api.nuget.org/v3/registration5-semver1/<id>/<version>.json`,
then `catalogEntry`), and each Gallery package against `PackageHash` of then `catalogEntry`), and each Gallery package against `PackageHash` of
`api/v2/Packages(Id='<id>',Version='<version>')`. Pester 5.7.1 is in `api/v2/Packages(Id='<id>',Version='<version>')`. Pester 5.7.1 is in
`V:\Git\WindowsAccessControl\output\RequiredModules`; read issues and pull `V:\Git\WindowsAccessControl\output\RequiredModules`. The GitHub CLI
requests through the GitHub REST API. The lab domains `a.forest1.net` and 2.102.0 is in `C:\Program Files\GitHub CLI`, outside the PATH, and signed
`b.forest1.net` had a maximum password age of 42 days, so the password of in as `raandree` since 2026-10-08; `Block-RemoteMutation` denies its
`install` expired on 2026-09-15 and AutomatedLab got access denied; it mutating commands, so the agent uses it read-only. The lab domains
never expires since 2026-10-07, as in `forest1.net`. `a.forest1.net` and `b.forest1.net` had a maximum password age of 42
days, so the password of `install` expired on 2026-09-15 and AutomatedLab
got access denied; it never expires since 2026-10-07, as in
`forest1.net`.
## Constraints ## Constraints
@ -96,7 +99,8 @@ source: repository evidence
- PowerShell Gallery versions (publish dates): 4.0.0 (2015-08-19), 4.2.2 - PowerShell Gallery versions (publish dates): 4.0.0 (2015-08-19), 4.2.2
(2016-05-18), 4.2.3 (2016-05-19), 4.2.4 (2018-08-13), 4.2.5 (2019-07-11), (2016-05-18), 4.2.3 (2016-05-19), 4.2.4 (2018-08-13), 4.2.5 (2019-07-11),
4.2.6 (2019-07-12), none with release notes; 5.0.0-rc1 (2026-10-04), 4.2.6 (2019-07-12), none with release notes; 5.0.0-rc1 (2026-10-04),
5.0.0-rc2 (2026-10-05), 5.0.0-rc3 and 5.0.0-rc4 (2026-10-06), published 5.0.0-rc2 (2026-10-05), 5.0.0-rc3 and 5.0.0-rc4 (2026-10-06), 5.0.0-rc5
(2026-10-08), published
by CI. Older versions were released on CodePlex only, and their dates are by CI. Older versions were released on CodePlex only, and their dates are
lost. The git history starts on 2016-10-10, when the project moved from lost. The git history starts on 2016-10-10, when the project moved from
CodePlex. CodePlex.
@ -175,6 +179,21 @@ source: repository evidence
session. Run them as a basic user with `runas /trustlevel:0x20000`, and session. Run them as a basic user with `runas /trustlevel:0x20000`, and
give Windows PowerShell its own `PSModulePath`; that token holds one give Windows PowerShell its own `PSModulePath`; that token holds one
privilege, so the `Enable-Privileges -PassThru` count test fails there. privilege, so the `Enable-Privileges -PassThru` count test fails there.
`runas` returns at once, so the script it starts writes its own log.
Pester reports a skipped `-ForEach` test under its template name, such as
`<_> should ...`, and a test that ran under the expanded name: compare
runs by template.
- C# coverage (Decision 21): AltCover 9.0.145 (`tools\net472\AltCover.exe`
of the nuget.org package) instruments a copy of the local Release build,
which has the PDB files that the published package lacks: `--save`,
`--reportFormat=OpenCover`, AlphaFS and `System.Management.Automation`
excluded with `--assemblyFilter`. Put the instrumented module in
`NTFSSecurity\bin\Release` of a `git worktree`, run
`.github\scripts\Invoke-Tests.ps1` elevated and as a basic user in both
editions, then `AltCover.exe runner --collect --recorderDirectory=<the
instrumented folder>`. Baseline of the rc5 tree on 2026-10-08: 55.9% of
the lines (1,943 of 3,476), 37.4% of the branches (700 of 1,873); 60.1%
of the lines without 244 lines in classes that no cmdlet calls.
- Live tests (Decision 20): in an elevated Windows PowerShell 5.1 session - Live tests (Decision 20): in an elevated Windows PowerShell 5.1 session
on the lab host, `Tests\Lab\Invoke-NTFSSecurityLabTest.ps1` with on the lab host, `Tests\Lab\Invoke-NTFSSecurityLabTest.ps1` with
`-Version` for Gallery packages or `-ModulePath` for a build; it writes `-Version` for Gallery packages or `-ModulePath` for a build; it writes

Loading…
Cancel
Save