Browse Source

docs(memory-bank): record the closed #117 and the branch-deletion order

The branch deletion that followed the merge of #116 removed
ai/release-5.0.0-rc7, the base branch of #117, and GitHub closed #117
unmerged instead of retargeting it (events base_ref_deleted and closed,
three seconds after the merge). Nothing is lost: ai/quality-gate-coverage
is intact at f11ff41, and a simulated merge of the rest of the stack is
conflict-free.

Correct the deployment notes, which relied on a retarget, and record the
order: retarget, merge, and delete head branches last. Update the focus,
the next steps, and the progress for the merged #116 and the draft #119.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/119/head
Raimund Andree 2 days ago
parent
commit
2b8643ff03
  1. 39
      .memory-bank/activeContext.md
  2. 52
      .memory-bank/deployment-notes.md
  3. 28
      .memory-bank/progress.md

39
.memory-bank/activeContext.md

@ -10,11 +10,16 @@ source: current task evidence
## Current focus
The maintainer asked on 2026-10-09 at 21:21 UTC to continue with the release-gate
handoffs and to decide and report later. Handoff 1 (paths) is draft #118
(`83149ee`, CI green; stacked on #117 and #116, all open; rc6 is the latest
published candidate, 4.2.6 the stable Gallery version). Handoff 2 (operating-system
matrix) is the local branch `ai/quality-gate-lab-matrix`, stacked on #118 and not
pushed: the lab `NtfsSecurityOsMatrixLab`, three fixes of the module in two commits
handoffs and to decide and report later. On 2026-10-10 at 09:10 UTC he merged
#116 (rc7, merge commit `8a6be9f`; rc7 is neither tagged nor published). His
`--delete-branch` also deleted the base branch of #117, so GitHub closed #117
unmerged; nothing is lost (`ai/quality-gate-coverage` is intact at `f11ff41`,
and the merge into `master` is conflict-free by simulation), and a new pull
request replaces it (Next step 1). Handoff 1 (paths) is draft #118 (`83149ee`,
CI green, base `ai/quality-gate-coverage`; rc6 is the latest published
candidate, 4.2.6 the stable Gallery version). Handoff 2 (operating-system
matrix) is draft #119 (`49734ef`, CI green, base `ai/quality-gate-paths`): the
lab `NtfsSecurityOsMatrixLab`, three fixes of the module in two commits
that the matrix found (`962887a`, `fdd7a8b`), the kit, the controller changes, and the
record `Tests/Lab/Acceptance-2026-10-10-os-matrix.md` (Decision 24, proposed).
The final local candidate `fdd7a8b` passes the module's suite on five operating
@ -46,8 +51,9 @@ open.
- rc6 Release run `37839669028`, attempt 2, succeeded; GitHub prerelease
with zip appeared 2026-10-09 07:01:34 UTC. First attempt proves HTTP 409
after Gallery publication, not the previously assumed retry chronology.
- #116 is open, base master, head `d25647d`, CI build/wiki passed. rc7
publication is pending. The follow-up does not change that PR's head.
- #116 was merged into `master` on 2026-10-10 at 09:10:12Z (merge commit
`8a6be9f`, head `d25647d`); rc7 isn't tagged or published. #117 was closed
unmerged at 09:10:16Z (events `base_ref_deleted`, `closed`).
- Local changes: deletion/ownership guards (`a97e46f`); all scopes and
inheritance (`e7ee203`); absolute basic-user results (`51dec86`);
exact-package publication recovery (`95b827e`); first-hidden-item fix
@ -150,11 +156,14 @@ open.
## Next step
1. The maintainer pushes `ai/quality-gate-lab-matrix` as a draft PR with base
`ai/quality-gate-paths` and decides which of the module fixes belong to rc7
(two commits: `962887a` holds two fixes, `fdd7a8b` one). He reviews and
integrates the stack: #116, then #117, then #118, then the matrix branch
(Decision 24).
1. The maintainer integrates the rest of the stack (Decision 15; commands in
the deployment notes). A **new** pull request from `ai/quality-gate-coverage`
to `master` replaces #117; then #118 and, if its module fixes go into rc7,
#119 are retargeted with `gh pr edit <n> --base master`, marked ready, and
merged. No `--delete-branch` while another open pull request uses the branch
as its base; the head branches are deleted last. He decides which module
fixes of the matrix branch belong to rc7 (two commits: `962887a` holds two
fixes, `fdd7a8b` one) and reviews them (Decision 24).
2. He decides the open items listed in the paths report: `FileSecurity`
conversions, `RemoveAll` account filters, lazy path overloads, abandoned
`PrivilegeEnabler`, dot patterns of `Get-ChildItem2 -Filter`, the 17
@ -164,9 +173,9 @@ open.
the matrix (`Run-MatrixSequence.ps1 -Version`) before the candidate counts as
accepted; no local upload. The paths fixes were accepted locally (record
above).
4. Retain stacked-PR order (15): #116, then #117, then #118; a local merge
in that order gives exactly the tree of #118. Confirm or change Decision
22.
4. Retain stacked-PR order (15): #116 (merged), the replacement of #117, #118,
then #119; a simulated merge in that order gives exactly the tree of the
matrix branch (`62aa1ae`). Confirm or change Decision 22.
5. #34 stays open (Decision 23): the maintainer chooses between waiting for a
test of the published candidate on the NetApp, EMC, and IBM ESS servers of
the reporters (checklist: `Tests/Lab/Non-Windows-File-Server-Test.md`) and

52
.memory-bank/deployment-notes.md

@ -9,33 +9,55 @@ source: release gates of 5.0.0 (lab acceptance, OS matrix, publication plan), re
## Publish the next prerelease (rc7)
State on 2026-10-09: #116 (rc7, head `d25647d`, base `master`), #117 (head
`f11ff41`, base `ai/release-5.0.0-rc7`), and #118 (draft, head `83149ee`,
base `ai/quality-gate-coverage`) are open and green. A local merge in that
order, each with a merge commit (Decision 15), ends in exactly the tree of
#118 (`b1dc006`), without conflicts. The manifest says `5.0.0` with
State on 2026-10-10 at 09:59 UTC: #116 (rc7, head `d25647d`) is merged into
`master` (merge commit `8a6be9f`, 09:10:12Z). #117 (head `f11ff41`, base
`ai/release-5.0.0-rc7`) was **closed without a merge** at 09:10:16Z: the
`--delete-branch` of `gh pr merge 116` deleted its base branch, and GitHub
closed it (events `base_ref_deleted`, then `closed`) instead of retargeting it.
Nothing is lost: `ai/quality-gate-coverage` is intact at `f11ff41`, and
`master` still lacks its change (25 files). #118 (draft, head `83149ee`, base
`ai/quality-gate-coverage`) and #119 (draft, head `49734ef`, base
`ai/quality-gate-paths`) are open and green. A simulated merge chain
(`git merge-tree --write-tree`, no ref written) with merge commits
(Decision 15) is conflict-free at every step: the coverage branch into `master`
gives the tree of `f11ff41`, #118 then gives `b1dc006`, and #119 gives
`62aa1ae`, the tree of the matrix branch. The manifest says `5.0.0` with
`Prerelease = 'rc7'`, and `$publishedVersions` in `Tests/Repository.Tests.ps1`
lists the versions up to rc6, as it must before rc7 is published.
The branch `ai/quality-gate-lab-matrix` (local until the maintainer pushes it)
is stacked on #118. It holds three fixes of the module in two commits (`962887a`
has two, `fdd7a8b` one). `fdd7a8b` reverts cleanly on its own; `962887a` doesn't
The branch `ai/quality-gate-lab-matrix` (draft #119) is stacked on #118. It
holds three fixes of the module in two commits (`962887a` has two, `fdd7a8b`
one). `fdd7a8b` reverts cleanly on its own; `962887a` doesn't
revert while `fdd7a8b` stays (the two conflict in `Security2/Win32/Lib.cs` and
`CHANGELOG.md`), and its two fixes go together. The branch also holds the kit of the
operating-system matrix, the changes of the live controller, and the record
(Decision 24). rc7 contains the module fixes only if the branch is merged after
#118 and before the tag; otherwise they go to the next prerelease. The
maintainer decides; open it as a draft with base `ai/quality-gate-paths`.
maintainer decides.
1. Merge #116, then #117, then #118 into `master`, each with **Create a merge
commit**. Deleting the merged head branch makes GitHub retarget the next
pull request to `master`; otherwise change its base. Wait for green CI on
the retargeted pull request.
2. Tag the merge commit on `master` with `5.0.0-rc7` and push the tag. The
Do not delete a head branch while another open pull request uses it as its
base. On 2026-10-10 the deletion through `gh pr merge --delete-branch` closed
#117 instead of retargeting it. The open reports `cli/cli#1168` and
`cli/cli#14223` show the same two events and say that GitHub retargets only
when the branch is deleted with the button on the pull request page. The
latter also reports, and this was not tried here, that `gh pr edit --base`
refuses a closed pull request and that `gh pr reopen` refuses while the base
branch is missing. A new pull request from the same head is the repair.
1. Open a new pull request from `ai/quality-gate-coverage` to `master` (it
replaces #117, same head and title), wait for its CI, and merge it with
**Create a merge commit**. Do not delete the branch yet.
2. Retarget #118 (`gh pr edit 118 --base master`), mark it ready, and merge it
the same way. Then do the same for #119 if its module fixes go into rc7.
A retarget doesn't start CI again (`pull_request` in `ci.yml` has the
default event types), and the merge result is the tree that CI tested.
3. Delete the head branches only after the last pull request that uses one as
its base is merged or retargeted.
4. Tag the merge commit on `master` with `5.0.0-rc7` and push the tag. The
`release` job checks the tag against the manifest and builds nothing new:
it publishes the package that the `build` job tested. Approve the
deployment of the `powershell-gallery` environment if it asks.
3. After the publication, add `5.0.0-rc7` to `$publishedVersions` with the
5. After the publication, add `5.0.0-rc7` to `$publishedVersions` with the
next change that goes to `master`.
## Accept a published package

28
.memory-bank/progress.md

@ -1,6 +1,6 @@
---
status: current
last-verified: 2026-10-09
last-verified: 2026-10-10
owner: active-agent
source: repository and validation evidence
---
@ -10,13 +10,15 @@ source: repository and validation evidence
## Current status
5.0.0-rc6 is published on the Gallery and GitHub; its failed Release job
recovered in attempt 2 on 2026-10-09. #116 (rc7, `d25647d`, base `master`)
is open and green, not merged or published. Further quality-gate work is
`ai/quality-gate-coverage` (#117) and `ai/quality-gate-paths` (draft #118),
which classifies every remaining unvisited path; the open items are the
maintainer's decisions. The local branch `ai/quality-gate-lab-matrix` (stacked
on #118, not pushed) holds the operating-system matrix, three fixes of the
module found by it, and the controller changes (Decision 24, proposed).
recovered in attempt 2 on 2026-10-09. #116 (rc7, `d25647d`) was merged into
`master` on 2026-10-10 (`8a6be9f`); rc7 is neither tagged nor published. #117
was closed unmerged when its base branch was deleted, so a new pull request
from `ai/quality-gate-coverage` replaces it. Further quality-gate work is
`ai/quality-gate-paths` (draft #118), which classifies every remaining
unvisited path (the open items are the maintainer's decisions), and
`ai/quality-gate-lab-matrix` (draft #119, stacked on #118): the
operating-system matrix, three fixes of the module found by it, and the
controller changes (Decision 24, proposed).
Stable Gallery version: 4.2.6.
After 5.0.0, archive in favor of WindowsAccessControl (Decision 18).
@ -108,7 +110,15 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18).
Major and four Minors, corrected in `b78784d` and `dbb4bd6`; the built-in
`security-review` agent found no exploitable vulnerability and two LOW items
that are not changed (record, Limits). Record:
`Tests/Lab/Acceptance-2026-10-10-os-matrix.md`; nothing was pushed.
`Tests/Lab/Acceptance-2026-10-10-os-matrix.md`; the agent pushed nothing.
- 2026-10-10: the maintainer merged #116 (`8a6be9f`, 09:10:12Z) with `gh pr
merge --delete-branch` and pushed the matrix branch as draft #119 (`49734ef`).
The deletion removed the base branch of #117, and GitHub closed #117
unmerged three seconds later instead of retargeting it (events
`base_ref_deleted`, `closed`; the same pair is in `cli/cli#14223`). The
earlier guidance, which relied on a retarget, was wrong. Nothing is lost; a
new pull request from `ai/quality-gate-coverage` replaces #117 (deployment
notes).
## Stable capabilities

Loading…
Cancel
Save