Browse Source

chore(memory-bank): record the 5.0.0-rc2 release

5.0.0-rc2 is on the PowerShell Gallery and in the GitHub releases. The
PRs #99 to #106 were merged in order with merge commits, CI on master
passed, and the tag 5.0.0-rc2 on 7ddda8d published it on the third
attempt of the release run, after GitHub's Actions outage of 2026-10-05.
The open issues got their replies, 16 were closed, and the follow-up
issues #107 to #111 track the open Minor review findings.

- Decision 14: repository hardening is optional; the outdated "pending"
  text is gone.
- Decision 15: merge stacked pull requests in order with merge commits.
- Decision 16: fix only reproducible bugs (the maintainer's decision D6).
- activeContext and progress: the CI fix 629f4e7, the copied inherited
  entries behind #34, the issue state, and the next step (test rc2, then
  5.0.0 or rc3).
- techContext: the current versions, the second workstation, and
  one-line commands for the maintainer.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/112/head
Raimund Andree 6 days ago
parent
commit
87dc71aecb
  1. 71
      .memory-bank/activeContext.md
  2. 23
      .memory-bank/decisions/0014-repository-hardening-optional.md
  3. 19
      .memory-bank/decisions/0015-merge-stacks-with-merge-commits.md
  4. 16
      .memory-bank/decisions/0016-fix-reproducible-bugs-only.md
  5. 93
      .memory-bank/progress.md
  6. 3
      .memory-bank/systemPatterns.md
  7. 39
      .memory-bank/techContext.md

71
.memory-bank/activeContext.md

@ -9,47 +9,42 @@ source: current task evidence
## Current focus
The overnight run of 2026-10-04/05 is finished. 5.0.0-rc2 waits on eight
stacked local branches (see `progress.md`): the maintainer pushes them,
opens one PR each against `master`, merges them in order with merge
commits, and tags `5.0.0-rc2` on the last merge commit once CI on `master`
is green. The run's report lists the commands, the PR descriptions, a
reply for each issue, and the open questions.
## Maintainer decisions for the run (2026-10-04)
- D1: the fixes ship in 5.0.0, under `[Unreleased]`; the behavior changes
of D3 and D4 are listed under `Changed` with the way back.
- D2: `Clear-NTFSAccess -DisableInheritance` keeps leaving an empty DACL.
- D3: `Set-NTFSInheritance` keeps entries like the dedicated cmdlets
(Decision 13).
- D4: `-RemoveInheritedAuditRules` and `-RemoveExplicitAuditRules`, with
the old names as aliases.
- D5: `Get-FileHash2` works in PowerShell 7; `MACTripleDES` is deprecated.
- D6: only reproducible bugs are fixed; other behavior changes are
questions for the maintainer.
- D7: Dependabot for `github-actions` only; AlphaFS 2.2.1 everywhere.
- D8: the manifest `Description` and a version-neutral README.
- D9: merged local branches deleted after the run.
- 2026-10-05: the report's recommendations accepted. #5 and #82 ship in
5.0.0 as breaking changes; #34 for rc3 if a file server is available;
#41 and #90 after 5.0.0; Minor findings become issues; the `pwsh` crash
is watched in CI.
5.0.0-rc2 is published. On 2026-10-05 the PRs #99 to #106 were merged into
`master` in order, each with a merge commit, and the tag `5.0.0-rc2` on the
merge commit of #106 (`7ddda8d`) published the module to the PowerShell
Gallery and created the GitHub prerelease through CI (Decision 12). Next:
test the prerelease, answer the issues, and decide between 5.0.0 and an rc3
for #34 and #67.
## Evidence
- Every branch tip: Release build without new warnings (296 at the top,
305 at the baseline), docs checks clean, package dry run passed.
- Tests at the top branch: Windows PowerShell 423 passed, 26 skipped;
PowerShell 7 394 passed, 55 skipped (449). The baseline had 268 tests.
- Tests that need privileges skip on the workstation and run in CI only;
the PR descriptions list them.
- Reviews: one security review per PR; the Major findings were fixed in
the PR that had them (PR 1: 1, PR 2: 5, PR 4: 2, PR 6: 1, PR 7: 3,
PR 8: 2).
- The first CI runs of #100 to #106 failed an elevated test that had only
skipped on the workstation, and from #104 on a second one. The audit
inheritance cmdlets wrote no section for an item without a SACL, which
Windows answers with "Access is denied"; and a test read a descriptor with
its SACL, for which Windows doesn't mark the inherited entries of a DACL
that isn't in the auto-inherit format. Fixed test-first in `629f4e7` on
#106, red and green in both editions.
- CI of #106 at `629f4e7` and of `master` at `7ddda8d`: Windows PowerShell
5.1 436 passed, 19 skipped; PowerShell 7 407 passed, 48 skipped; no
failures. Before the merges, a simulation showed that each merge leaves
`master` at the tree its pull request tested.
- The package from the Gallery imports in both editions as 5.0.0-rc2 with
36 cmdlets and help, and `Disable-NTFSAuditInheritance` works on a file
without audit entries.
- The merges closed #3, #4, #5, #17, #74, #82, #86, and #88 and deleted the
eight `ai/` branches. Later that day the 37 issues that were open before
the merges got their replies, 16 of them were closed (as completed when
answered or already fixed, as not planned when not reproducible or won't
fix), and the follow-up issues #107 to #111 were created; 18 issues are
open.
- Found while fixing the CI: elevated, `Add-NTFSAccess` and `Add-NTFSAudit`
read the DACL together with the SACL, so the inherited entries of a DACL
without the auto-inherit flag come back as explicit entries, and the write
stores them as explicit copies. Same cause as #34: every section is read
and written; the fix for #34 covers both.
## Next step
The maintainer applies the repository settings, pushes the eight branches,
opens and merges the PRs in order, and tags `5.0.0-rc2` once CI on
`master` is green.
The maintainer tests 5.0.0-rc2, then decides between 5.0.0 and 5.0.0-rc3,
which would fix #34, #67, and the copied inherited entries.

23
.memory-bank/decisions/0014-repository-hardening-optional.md

@ -0,0 +1,23 @@
---
status: accepted
date: 2026-10-05
last-verified: 2026-10-05
owner: shared
source: maintainer decision of 2026-10-05
---
# Decision 14: Repository hardening is optional
- Choice: The repository settings proposed on 2026-10-04 stay optional:
required reviewers and a tag-only deployment policy for the environment
`powershell-gallery`, a ruleset for `master` that requires a pull request
and the **Build and test** check, and a rotation of `PSGALLERY_API_KEY`.
None of them is a gate for a merge or a release.
- Rationale: The maintainer is the only developer. The PRs #99 to #106 of
5.0.0-rc2 were merged on 2026-10-05 without these settings.
- Consequences: `master` accepts a merge while checks fail, and the Release
job publishes without an approval. The safeguards are the CI run of the
last pull request of a stack before its merges, the CI run on `master`
before the tag, and the checks of the Release job (Decision 12). Agents
don't press for the settings; the proposal stays with the maintainer,
outside the repository.

19
.memory-bank/decisions/0015-merge-stacks-with-merge-commits.md

@ -0,0 +1,19 @@
---
status: accepted
date: 2026-10-05
last-verified: 2026-10-05
owner: shared
source: maintainer decision of 2026-10-05
---
# Decision 15: Merge stacked pull requests in order with merge commits
- Choice: A stack of pull requests whose branches build on each other is
merged into `master` in order, each with **Create a merge commit**. The
merges wait for the CI run of the last pull request, which contains every
commit of the stack; an earlier one may fail tests that a later one fixes.
- Rationale: Squash and rebase merges rewrite the commits, so every later
pull request would conflict, and the commit IDs in the descriptions and
the changelog would no longer exist on `master`. A merge commit keeps
them, and each merge leaves `master` at the tree its pull request tested.
- Applied: 5.0.0-rc2, the PRs #99 to #106 on 2026-10-05.

16
.memory-bank/decisions/0016-fix-reproducible-bugs-only.md

@ -0,0 +1,16 @@
---
status: accepted
date: 2026-10-04
last-verified: 2026-10-05
owner: shared
source: maintainer decision D6 for the overnight run of 2026-10-04
---
# Decision 16: Fix only reproducible bugs
- Choice: Agents fix a defect only when they can reproduce it. Any other
change of behavior, also one that a review recommends, is a question for
the maintainer.
- Rationale: The maintainer's decision D6 for the overnight run of
2026-10-04. It kept the run's changes to reproduced defects and left the
behavior changes, such as #5 and #82, to his decision of 2026-10-05.

93
.memory-bank/progress.md

@ -9,14 +9,11 @@ source: repository evidence
## Current status
5.0.0-rc2 is ready on eight stacked local branches from the overnight run of
2026-10-04/05; none is pushed. Each is a PR against `master`, merged in
this order with merge commits: `ai/maintenance`, `ai/defects-a`,
`ai/defects-b`, `ai/defects-c`, `ai/defects-d`, `ai/decisions-e`,
`ai/issue-fixes`, `ai/release-5.0.0-rc2`. The tag `5.0.0-rc2` on the last
merge commit then publishes it through CI (Decision 12). `master`
(`e0f5366`) carries 5.0.0-rc1, published on 2026-10-04; the stable Gallery
version is still 4.2.6.
5.0.0-rc2 is on the PowerShell Gallery and in the GitHub releases,
published by CI from the tag `5.0.0-rc2` on `master` (`7ddda8d`) on
2026-10-05 (Decision 12). It contains the 24 code defects of work package
5, the issue fixes of the overnight run of 2026-10-04/05, and the CI fix
`629f4e7`. The stable Gallery version is still 4.2.6.
## Recent milestones
@ -27,20 +24,19 @@ version is still 4.2.6.
- 2026-10-04: #98 (`e0f5366`) added releases on a version tag through CI
(Decision 12). The tag `5.0.0-rc1` published to the Gallery and created
the GitHub prerelease; the installed module passed the full suite.
- 2026-10-05, overnight run (local branches): the 24 code defects of work
package 5 fixed with regression tests, plus what the reviews found: a
failed retry after taking ownership left the owner changed, and
`-PassThru` wrote objects after a failed change or under `-WhatIf`.
Maintainer decisions D2 to D5 (Decision 13), the issues #3, #4, #17, #74,
#86, and #88 fixed, the 37 open issues triaged, `Docs/FAQ.md`, Dependabot for
the actions, and the prerelease label `rc2`. One security review per PR;
every Major finding fixed.
- 2026-10-05, morning: the maintainer accepted the report's
recommendations. #5 (`Get-ChildItem2 -Attributes` matches any listed
attribute; an empty value is an error) and #82 (no `Size` alias) ship in
5.0.0 as breaking changes on `ai/issue-fixes`. Tests at the top branch:
Windows PowerShell 423 passed, 26 skipped; PowerShell 7 394 passed, 55
skipped (449).
- 2026-10-05, overnight run: the 24 code defects of work package 5 and the
issues #3, #4, #5, #17, #74, #82, #86, and #88 fixed with regression
tests, plus what one security review per PR found; the 37 open issues
triaged; `Docs/FAQ.md`, Dependabot for the actions, and the label `rc2`.
#5 and #82 are breaking changes, like the change of Decision 13.
- 2026-10-05: the first CI runs of the eight PRs found a defect that the
workstation had skipped, fixed in `629f4e7` (audit inheritance of an item
without a SACL). The PRs #99 to #106 were merged in order with merge
commits, CI on `master` passed, and the tag `5.0.0-rc2` published the
prerelease; GitHub's Actions outage that day cancelled the first two
attempts of the release run before they started. Repository hardening is
optional (Decision 14); the merge rule and the maintainer's rule for
fixes are Decisions 15 and 16.
## Stable capabilities
@ -48,37 +44,34 @@ version is still 4.2.6.
descriptor (4), privileges (3), long-path items (6), links, hash, and
disk space (5).
- Works in Windows PowerShell 5.1 and PowerShell 7. In PowerShell 7,
`Get-FileHash2` lacks `RIPEMD160` and `MACTripleDES`, which .NET lacks
(on `master` it still fails there for every algorithm).
`Get-FileHash2` lacks `RIPEMD160` and `MACTripleDES`, which .NET lacks.
- Pester tests in `Tests\` run in `$env:TEMP` sandboxes through
`Tests\TestHelpers.psm1`; tests that need privileges skip without them
and run in CI, whose runners are elevated.
## Open work
1. The maintainer pushes the eight branches, opens the PRs, merges them in
order, and tags `5.0.0-rc2` once CI on `master` is green; then tests
rc2.
2. Release 5.0.0 through CI (Decision 12) after the tests: remove the
label, date `[Unreleased]` as `[5.0.0]`, tag `5.0.0` (steps in
`Docs/Contributing/05-Releasing.md`; CI warns when the changelog date
isn't the release day).
3. Repository settings: the hardening proposed on 2026-10-04 isn't applied
yet (checked 2026-10-05); the maintainer applies it before pushing the
stack. The details are with the maintainer, not in the repository.
4. Open bugs from the triage: #34 and #67 (the write includes owner and
group; `fix/#34` swallows every error) for rc3 if a file server to test
against is available; #41 (a drive root reads the device object) and #90
(a trailing space in a folder name) after 5.0.0. Enhancements: #22, #49,
#68, #77, #87.
5. `pwsh` 7.6.1 crashed three times during test runs on the ARM64
workstation (x64 emulation) with an access violation in `coreclr.dll` or
`System.Management.Automation.dll`, without module frames; not
reproducible on demand. Check whether CI on native x64 shows it.
6. Minor review findings that the PRs list but don't fix, for example
`Copy-Item2 -WhatIf` reporting a destination conflict as an error, and
relative path forms that the `*-Item2` cmdlets resolve themselves; the
maintainer tracks the useful ones as issues.
7. Optional for the maintainer: delete the AppVeyor project and revoke its
GitHub authorization, restrict wiki editing to collaborators, and ask
`Sup3rlativ3` to delete the Read the Docs project.
1. Test 5.0.0-rc2, then release 5.0.0 through CI (Decision 12): remove the
label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc2` to
`$publishedVersions` in `Tests/Repository.Tests.ps1`, and tag `5.0.0`
(steps in `Docs/Contributing/05-Releasing.md`).
2. Issues: the open issues got their replies on 2026-10-05. Follow-up
issues for the open Minor review findings: #107 (relative path forms),
#108 (`Copy-Item2` and `Move-Item2`), #109 (error messages), #110
(tests), and #111 (small items); #68 tracks `-WhatIf` and `-Confirm` for
every cmdlet that changes security, and #34 the copied inherited
entries.
3. 5.0.0-rc3, if a file server that refuses to assign the owner is
available for a test: #34 and #67. Every section of the security
descriptor is read and written, so the owner and group are written with
each change, and in an elevated session inherited entries are copied as
explicit ones; `fix/#34` swallows every error and needs a redo. After
5.0.0: #41 (a drive root reads the device object) and #90 (a trailing
space in a folder name). Enhancements: #22, #49, #68, #77, #87.
4. `pwsh` 7.6.1 crashed three times during test runs on the ARM64
workstation (x64 emulation), without module frames; none of the CI runs
on native x64 on 2026-10-05 crashed.
5. Optional for the maintainer: delete the AppVeyor project and revoke its
GitHub authorization, restrict wiki editing to collaborators, ask
`Sup3rlativ3` to delete the Read the Docs project, and delete the branch
`test/transfer`.

3
.memory-bank/systemPatterns.md

@ -60,6 +60,9 @@ Each Decision record is a file in `decisions/`; read only the relevant ones.
| 11 | [CI and the wiki run on GitHub Actions](decisions/0011-github-actions.md) |
| 12 | [Releases are built and published by CI on a version tag](decisions/0012-ci-releases.md) |
| 13 | [Set-NTFSInheritance keeps entries like the dedicated cmdlets](decisions/0013-set-inheritance-keeps-entries.md) |
| 14 | [Repository hardening is optional](decisions/0014-repository-hardening-optional.md) |
| 15 | [Merge stacked pull requests in order with merge commits](decisions/0015-merge-stacks-with-merge-commits.md) |
| 16 | [Fix only reproducible bugs](decisions/0016-fix-reproducible-bugs-only.md) |
## Patterns

39
.memory-bank/techContext.md

@ -54,7 +54,7 @@ source: repository evidence
in PowerShell 7.6 on 2026-10-04. Download the 0.2.0 package from
`https://www.powershellgallery.com/api/v2/package/MarkdownLinkCheck/0.2.0`
into `$env:TEMP`, extract it, and import it by path.
- The workstation is ARM64; PowerShell 7 runs as x64 under emulation.
- The first workstation is ARM64; PowerShell 7 runs as x64 under emulation.
Python 3.12.10 (ARM64) is installed per user with winget, the
maintainer's choice for an MkDocs check that Decision 9 made unnecessary.
- The NuGet cache (`~\.nuget\packages`) holds every build dependency: copy
@ -62,23 +62,30 @@ source: repository evidence
`microsoft.netframework.referenceassemblies.net452\1.0.3` into
`packages\<Id>.<Version>`, and point `CscToolPath` at
`microsoft.net.compilers\4.2.0\tools`.
- The second workstation (x64, used since 2026-10-05) runs the agent
session elevated, so the tests that need privileges run there as in CI.
It has no NuGet cache with these packages: download each from
`https://api.nuget.org/v3-flatcontainer/<id>/<version>/<id>.<version>.nupkg`,
extract the first three into `packages\<Id>.<Version>` and the compilers
into `$env:TEMP`; Pester 5.7.1 comes from the Gallery package API the
same way, its folder first on `$env:PSModulePath` of the test process.
The GitHub CLI is in `C:\Program Files\GitHub CLI`, outside the PATH of
sessions started before its installation.
## Constraints
- `ModuleVersion` on `master` is `5.0.0` with the prerelease label `rc1`
(`ai/release-5.0.0-rc2` sets `rc2`); 5.0.0-rc1 is on the Gallery
(published 2026-10-04 by CI). The latest
stable tag and Gallery release is `4.2.6`. The manifest requires
PowerShell 5.1 and .NET Framework 4.5.2, uses `RootModule`, and lists
exactly 36 cmdlets; `Test-ModuleManifest` passes in Windows PowerShell 5.1
and PowerShell 7.6.
- Besides the shipped help file and its tests (#93), the module source at
`master` differs from tag `4.2.6` by the `Remove-Item2 -PassThur` to
`-PassThru` rename (with a `-PassThur` alias), the manifest changes of
#95, and the assembly versions.
- `ModuleVersion` on `master` is `5.0.0` with the prerelease label `rc2`.
The latest stable tag and Gallery release is `4.2.6`. The manifest
requires PowerShell 5.1 and .NET Framework 4.5.2, uses `RootModule`, and
lists exactly 36 cmdlets; `Test-ModuleManifest` passes in Windows
PowerShell 5.1 and PowerShell 7.6.
- The module source at `master` differs from tag `4.2.6` by the changes
that `CHANGELOG.md` lists under `[Unreleased]`, the release notes of each
5.0.0 prerelease.
- PowerShell Gallery versions (publish dates): 4.0.0 (2015-08-19), 4.2.2
(2016-05-18), 4.2.3 (2016-05-19), 4.2.4 (2018-08-13), 4.2.5 (2019-07-11),
4.2.6 (2019-07-12); none has release notes. Older versions were released
4.2.6 (2019-07-12), none with release notes; 5.0.0-rc1 (2026-10-04) and
5.0.0-rc2 (2026-10-05), published by CI. Older versions were released
on CodePlex only, and their dates are lost. The git history starts on
2016-10-10, when the project moved from CodePlex.
- Releases up to 4.2.6 had no script and no CI deployment: the Gallery
@ -106,7 +113,11 @@ source: repository evidence
inside an agent command has no effect (verified 2026-10-04). The hook
matches the whole command text, so a commit message that quotes such a
command is blocked too. Prepare the commands and descriptions; the
maintainer runs them.
maintainer runs them. Give each command as one line, or as a script with
`-WhatIf`: the agent's question dialog renders Markdown, which joins the
lines of a block, and PowerShell then rejects all of it. Simulated `gh`
commands in offline tests must print what the real ones print, such as
the URL of a new comment.
## Validation

Loading…
Cancel
Save