Browse Source

docs(coverage): report the final measurement and review of Handoff 5

The final commit 61e936e was built once, at 8a625c8, and measured on those
bytes: 1,459 cases per configuration, 3,258 of 3,664 sequence points, 1,090 of
1,168 explicit branch points, and the same 187 unvisited methods, all
classified. The first lab accepts the final build (245 passed, 1 skipped per
edition), the 22 files of the matrix suite pass on Windows Server 2019, 2022,
and 2025 and on Windows 11 in 16 configurations, and both labs are clean.

The report adds the second culture defect that the independent review found
(Get-ChildItem2 -Filter in tr-TR), the review and how each finding was
resolved, the probe that tells which parameter set binds for a piped
AppliesTo, and the corrected description of the branch summary of the tool,
which adds one point per method and is not read. The Runs table lists every
run, the Evidence table hashes the evidence outside git, and the ParameterSets
table cites the lines of the final tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/coverage-unknowns
Raimund Andree 22 hours ago
parent
commit
b25a12770d
  1. 1169
      Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-Evidence.csv
  2. 92
      Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-ParameterSets.csv
  3. 96
      Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-Runs.csv
  4. 706
      Tests/Coverage/Quality-Gate-Unknowns-2026-10-10.md

1169
Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-Evidence.csv

File diff suppressed because it is too large

92
Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-ParameterSets.csv

@ -1,6 +1,6 @@
"Group","Cmdlet","ParameterSet","Default","TestInvocationsScan","LiveInvocationsScan","AmbiguousInvocationsThatMayBindIt","BoundBy","StateAssertion","ErrorAssertion","PipelineInput","Continuation","OutputAssertion","KeyTests","LiveEvidence","Gap","GapKind","Evidence","StatusAfter","NewTests","Remaining","Reason"
"access","Add-NTFSAccess","PathComplex","True","33","6","1","36","Yes","Yes","No","Partly","Yes","Access.Tests.ps1:740 Should write an AddAceError for each item, change nothing, and return nothing with -PassThru | PathErrors.Tests.ps1:178 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | Access.Tests.ps1:807 Should write all entries of the item after the change | PathErrors.Tests.ps1:230 Add-NTFSAccess should take ownership, add the entry, and set the owner back","6: SMB share as delegated and domain accounts - add keeps the owner (#34), add by foreign-domain account name, deny-entry fixtures (Live:253, 877, 927, 987, 1038, 1280)","No test pipes anything into the set (FileInfo/DirectoryInfo, or objects with Account/AccessRights properties), and none combines -PassThru with one failing and one succeeding path: continuation (PathErrors:178, no -PassThru) and no output after a failure (Access:740, all items fail) are asserted in separate tests. Several -Account values, a Deny entry written through -Path (type, no Synchronize) and positional binding are untested.","TestNeeded","Access.Tests.ps1:740-751 asserts ErrorId, category WriteError, TargetObject, ArgumentException, no output and unchanged SDDL for two failing paths; PathErrors.Tests.ps1:178-192 asserts one error with the blocked target, its SDDL unchanged and the next item's entry added; Access.Tests.ps1:807-815 asserts type, entry count and the added entry of -PassThru. BoundBy = scan 33 + PathErrors:108 and :178 (& $Command) + PermissionScopes:86 (splat, Form=Flags, Source=Path); about 14 of the 36 calls are the subject of an assertion, the rest are fixtures.","Partly","ParameterSets.Access.Tests.ps1:61,62 Should add one explicit entry for each path bound through the pipeline, by FullName and by property name, leaving the rest of each item unchanged | ParameterSets.Access.Tests.ps1:91 Should write one AddAceError for the blocked path, leave it unchanged, and return -PassThru entries only for the path it changed","several -Account values in one call; a Deny entry written through -Path checked for AccessControlType=Deny and no auto-added Synchronize; positional binding (Add-NTFSAccess $path $account $rights)","budget (all three; proposal 1c was traded for the pipeline and PassThru-combined tests)"
"access","Add-NTFSAccess","PathSimple","False","6","1","2","8","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | PermissionScopes.Tests.ps1:110 Should apply <Name> only to its intended descendants, including the OneLevel boundary | Access.Tests.ps1:1035 Should name the folder of an inheritable entry, also with -ExcludeExplicit | ObjectApis.Tests.ps1:728 Should name the item of a descriptor and write it to a folder by its path","1: SMB share - Deny ReadPermissions entry with -AppliesTo ThisFolderOnly as a fixture of the unknown-parent case (Live:1039); no assertion on the set itself","No test makes the set fail (missing path, denied write, deny entry without rights), pipes into it, or reads its result back with .NET: every read-back goes through -PassThru or Get-NTFSAccess. -AccessType Deny with -AppliesTo and the exclusion of -AppliesTo with -InheritanceFlags are untested.","TestNeeded","PermissionScopes.Tests.ps1:86-94 asserts type, flags, rights and ConvertToApplyTo of the -PassThru entry for 13 scopes (Form=AppliesTo, Source=Path) and :110-133 asserts which descendants inherit it, both read through the module's own cmdlets. Access.Tests.ps1:1035, Inheritance.Tests.ps1:326/365/474 and ObjectApis.Tests.ps1:728 use the set as a fixture. BoundBy = scan 6 + the splats PermissionScopes:84 and :86 (Source=Path); 2 of the 8 calls are the subject of an assertion.","Partly","ParameterSets.Access.Tests.ps1:113,129 Should report a missing path's error by category and target, still scope the next path's entry, and keep binding -Path through the pipeline once -AppliesTo selects the set | ParameterSets.Access.Tests.ps1:572 Should require -AppliesTo only in the Simple parameter sets, -InheritanceFlags/-PropagationFlags only in the Complex parameter sets, and reject combining -AppliesTo with -InheritanceFlags without changing the item","a denied write for this set; a Deny entry without rights (-AccessType Deny -AccessRights None) for this set; -AccessType Deny combined with -AppliesTo","budget (all three; the write-denial code path is shared with PathComplex and already covered there)"
"access","Add-NTFSAccess","PathSimple","False","6","1","2","8","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | PermissionScopes.Tests.ps1:110 Should apply <Name> only to its intended descendants, including the OneLevel boundary | Access.Tests.ps1:1035 Should name the folder of an inheritable entry, also with -ExcludeExplicit | ObjectApis.Tests.ps1:747 Should name the item of a descriptor and write it to a folder by its path","1: SMB share - Deny ReadPermissions entry with -AppliesTo ThisFolderOnly as a fixture of the unknown-parent case (Live:1039); no assertion on the set itself","No test makes the set fail (missing path, denied write, deny entry without rights), pipes into it, or reads its result back with .NET: every read-back goes through -PassThru or Get-NTFSAccess. -AccessType Deny with -AppliesTo and the exclusion of -AppliesTo with -InheritanceFlags are untested.","TestNeeded","PermissionScopes.Tests.ps1:86-94 asserts type, flags, rights and ConvertToApplyTo of the -PassThru entry for 13 scopes (Form=AppliesTo, Source=Path) and :110-133 asserts which descendants inherit it, both read through the module's own cmdlets. Access.Tests.ps1:1035, Inheritance.Tests.ps1:326/365/474 and ObjectApis.Tests.ps1:747 use the set as a fixture. BoundBy = scan 6 + the splats PermissionScopes:84 and :86 (Source=Path); 2 of the 8 calls are the subject of an assertion.","Partly","ParameterSets.Access.Tests.ps1:113,129 Should report a missing path's error by category and target, still scope the next path's entry, and keep binding -Path through the pipeline once -AppliesTo selects the set | ParameterSets.Access.Tests.ps1:572 Should require -AppliesTo only in the Simple parameter sets, -InheritanceFlags/-PropagationFlags only in the Complex parameter sets, and reject combining -AppliesTo with -InheritanceFlags without changing the item","a denied write for this set; a Deny entry without rights (-AccessType Deny -AccessRights None) for this set; -AccessType Deny combined with -AppliesTo","budget (all three; the write-denial code path is shared with PathComplex and already covered there)"
"access","Add-NTFSAccess","SDSimple","False","2","0","2","4","Partly","No","No","No","Yes","Access.Tests.ps1:898 Add-NTFSAccess should still take -AppliesTo for a security descriptor | PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | SecurityDescriptor.Tests.ps1:355 Should write the descriptor and report a read error for -PassThru, not a write error","0","Only InheritanceFlags for ThisFolderOnly is read back from the descriptor with .NET (Access:898); the 13 scopes are checked through the cmdlet's own -PassThru, and no test pipes descriptors in or passes several. A failing change (for example a deny entry without rights) ends the cmdlet with a terminating error and no test pins it (open item 1).","MaintainerDecision","Access.Tests.ps1:898-902 reads the rule from $sd.SecurityDescriptor with .NET; PermissionScopes.Tests.ps1:86-97 asserts type, flags, rights and, for Source=SecurityDescriptor, that the SDDL on disk is unchanged (13 cases). BoundBy = scan 2 (Access:898; SecurityDescriptor:355 is a fixture) + the splats PermissionScopes:84 and :86 (Source=SecurityDescriptor, Form=AppliesTo).","MaintainerDecision","","all 13 scopes read back with .NET for Source=SecurityDescriptor (only ThisFolderOnly already was, pre-existing); piped descriptors; several descriptors; the failing-change (deny entry without rights) terminating error, not pinned","budget (the 13-scope/pipe/several items, notes proposal (b2)#1 not implemented); MaintainerDecision (the failing-change open item)"
"access","Add-NTFSAccess","SDComplex","False","14","2","1","16","Yes","No","No","No","Yes","Access.Tests.ps1:822 Should write all entries of a security descriptor after the change and leave the item unchanged | Access.Tests.ps1:887 Add-NTFSAccess should apply the entry to the folder, its subfolders, and files by default | SecurityDescriptor.Tests.ps1:81 Should write the entry as the only explicit entry of the item | PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account","2: SMB share - descriptor written back keeps the owner (#34, Live:316) and the fixture of the later-command cases (Live:1151)","No test pipes descriptors into the cmdlet, and arrays of descriptors appear only as fixtures of Set-NTFSSecurityDescriptor (SecurityDescriptor.Tests.ps1:306, :324; PipelineControl.Tests.ps1:211). A failing descriptor (deny entry without rights) ends the cmdlet with a terminating error and no test pins it (open item 1).","MaintainerDecision","Access.Tests.ps1:822-827 asserts that -PassThru writes as many entries as $sd.SecurityDescriptor holds, one new explicit entry, and no Everyone entry on disk; :887-892 reads the default flags back with .NET; SecurityDescriptor.Tests.ps1:81-86 asserts exactly one explicit entry on disk after Set-NTFSSecurityDescriptor. BoundBy = scan 14 + Access:872 (& $_, asserts only no throw) + PermissionScopes:86 (splat); 5 of the 16 calls are the subject of an assertion.","MaintainerDecision","","piped descriptors into the cmdlet; arrays of descriptors used only as Set-NTFSSecurityDescriptor fixtures, not asserted for Add itself; the failing descriptor (deny entry without rights) terminating error, not pinned","budget (the pipe/array items, notes proposal (b2)#2 not implemented); MaintainerDecision (the failing-descriptor open item)"
"access","Remove-NTFSAccess","PathComplex","True","13","2","2","17","Yes","Yes","Yes","Partly","Partly","Access.Tests.ps1:539 Should write a RemoveAceError for each item, change nothing, and return nothing with -PassThru | Access.Tests.ps1:617 Should remove an inherit-only entry that Get-NTFSAccess returned, and nothing else | PathErrors.Tests.ps1:178 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | Access.Tests.ps1:651 Should take only the requested generic right from the entry of the account when another account has an exact entry","2: SMB share - remove keeps the owner (#34, Live:264), remove by foreign-domain account name (Live:886)","No test combines -PassThru with one failing and one succeeding path, none asserts the type or the complete entry list of the -PassThru output, and the pipeline test pipes a single entry per case. Several -Account values and positional binding are untested.","TestNeeded","Access.Tests.ps1:539-550 asserts ErrorId, category, target, ArgumentException, no output and unchanged SDDL for two paths; :616-620 pipes Get-NTFSAccess output (binding by property name) and asserts the exact SDDL minus the entry in 3 cases; PathErrors.Tests.ps1:178-192 asserts the next item's entry is removed after one error. BoundBy = scan 13 + Access:617 (pipeline, resolves to PathComplex), PathErrors:108 and :178 (& $Command), PermissionScopes:99 (splat, Form=AppliesTo, Source=Path); all 17 calls are the subject of an assertion.","Partly","ParameterSets.Access.Tests.ps1:157 Should write one RemoveAceError for the blocked path, leave it unchanged, and return -PassThru entries only for the path it changed","the -PassThru output's count is not checked against the complete entry list of the surviving item (only non-emptiness, type, FullName, and absence of the removed account); the pipeline test still pipes only a single entry per call; several -Account values; positional binding","budget (all four)"
@ -17,49 +17,49 @@
"access","Get-NTFSSimpleAccess","SD","False","1","0","2","2","NA","No","Partly","No","Partly","Access.Tests.ps1:476 Should report the security descriptor of a file | Access.Tests.ps1:260 Should read the entries of a security descriptor","0","Only non-empty output and FullName are asserted; -Account, -ExcludeExplicit, -ExcludeInherited, the reduced rights and several descriptors are untested for the descriptor set, and no failing descriptor is tested.","TestNeeded","Access.Tests.ps1:260-263 reads one descriptor; :476-479 pipes one descriptor of a file: the -Path set skips files (Access:468-473), so a non-empty result can only come from the SD set; both assert FullName only. BoundBy = scan 1 + Access:476 (pipeline, resolves to SD).","Partly","ParameterSets.Access.Tests.ps1:469,470,474,476,477,482 Should filter and partition a descriptor's entries like the equivalent -Path call, and read two descriptors bound through the pipeline","no failing descriptor is tested for this set (no per-item handler)","Limit (same no-per-item-handler situation as the Clear-NTFSAccess SD and Get-NTFSAccess SD rows)"
"access","Get-NTFSEffectiveAccess","Path","True","11","7","1","15","NA","Yes","No","Partly","Partly","Access.Tests.ps1:1140 Should report the native identity error for each <Source> and return no access entry | Access.Tests.ps1:86 Should leave out an account without access when -ExcludeNoneAccessEntries is used | Access.Tests.ps1:145 Should return the result of this computer and warn | PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path","7: SMB share, domain and delegated accounts - rights through domain groups and file-server groups with -ServerName, fallback warning, GetEffectiveAccessError for access denied (Live:419, 428, 438, 456, 478, 486, 895)","No unit test asserts the content of the rights (for example an allow and a deny entry on a file with a protected DACL: ReadData present, WriteData absent), pipes objects in, or shows in one call that a failing path emits nothing while the next path emits only its own result. The ReadEffectivePermissionError handlers cannot be reached because the library hides its failures, and remote and group-based results need the lab.","TestNeeded","Access.Tests.ps1:1140-1153 asserts for two failing paths ErrorId GetEffectiveAccessError, category ReadError, TargetObject, Win32Exception 1332, no output and unchanged SDDL; PathErrors.Tests.ps1:108-115 asserts ReadFileError and output for the next path; Access.Tests.ps1:86-95 asserts the ExcludeNone filter and :145-157 the warning text and equal rights. BoundBy = scan 11 + Access:1140 (splat, Source=Path) + PathErrors:108/:145 + Owner.Tests.ps1:98 (& $cmdlet, no throw only).","Partly","ParameterSets.Access.Tests.ps1:498 Should report an allowed right as present and a denied right as absent for a protected DACL | ParameterSets.Access.Tests.ps1:508 Should return one result per item bound through the pipeline, in order","one call combining a failing path (for example a missing one) with a succeeding one, showing the failing path emits nothing and the next emits only its own result; the ReadEffectivePermissionError handler; remote and group-based results","budget (the failing+succeeding combination); Limit (ReadEffectivePermissionError is unreachable - the library records failures instead of throwing); Limit (remote/group-based results need the lab)"
"access","Get-NTFSEffectiveAccess","SecurityDescriptor","False","2","0","1","3","NA","Yes","No","Partly","Partly","Access.Tests.ps1:1140 Should report the native identity error for each <Source> and return no access entry | Access.Tests.ps1:132 Should name the cause in the error, not the Security privilege | Access.Tests.ps1:107 Should compute the effective access of a security descriptor","0","No test shows that the result follows an entry added to the descriptor in memory (and not the file on disk), pipes descriptors in, or passes a mix of failing and succeeding descriptors; the rights themselves are not asserted.","TestNeeded","Access.Tests.ps1:1140-1153 (Source=SecurityDescriptor, 2 descriptors) asserts the same error triple, Win32Exception 1332 and no output; :132-137 asserts one GetEffectiveAccessError that does not blame the privilege; :107-111 asserts one result with the FullName of the file. BoundBy = scan 2 + Access:1140 (splat, Source=SecurityDescriptor).","Partly","ParameterSets.Access.Tests.ps1:524,530,539 Should follow a descriptor changed only in memory while the -Path result stays on disk, and read two descriptors bound through the pipeline","a mix of a failing and a succeeding descriptor in one call","Limit (the per-item catch exists but is unreachable in a unit sandbox; the library records the Authz failure instead of throwing, per the notes)"
"audit","Add-NTFSAudit","PathComplex","True","27","4","1","30","Yes","Yes","No","Yes","Yes","Audit.Tests.ps1:147 Should write an AddAceError for each item, change nothing, and return nothing with -PassThru | Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:178 Should add the audit entry and keep the owner | PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account","4 (NTFSSecurity.Live.Tests.ps1:348, 385, 1010, 1016): SMB share with domain accounts; owner kept; the delegated account gets an AddAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441)","No test pipes paths or objects into -Path, binds Account/AccessRights/AuditFlags by property name, or adds for several accounts. No test asserts the result of a succeeding path that follows a failing one (PathErrors.Tests.ps1:124 only counts errors), and the owner retry after access denied cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:149-158 asserts AddAceError, WriteError, target, ArgumentException, no -PassThru output and an unchanged SACL (Get-Acl -Audit) for two failing paths; :631-669 and :672-679 assert ReadFileError/OpenError/target, the FullName of the output, the SACL rule, and unchanged DACL/owner SDDL. BoundBy 30 = scan 27 + PermissionScopes:146 (13 of 52 cases) + 2 calls through & $Command that the scan cannot see (Audit.Tests.ps1:629, PathErrors.Tests.ps1:124); 23 of the 27 scanned calls are fixtures.","Partly","ParameterSets.Audit.Tests.ps1:99 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged","AuditFlags not bound by property name; adding for several accounts in one call; the owner retry after access denied","budget; budget; Limit (needs a lab or a remote server)"
"audit","Add-NTFSAudit","PathSimple","False","5","0","2","7","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Inheritance.Tests.ps1:386 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:424 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry","0","No call of this set fails on purpose, passes several paths, or pipes objects, and a conflict of -AppliesTo with -InheritanceFlags is not tested. The added entry is read back only from -PassThru and Get-NTFSAudit, and owner and DACL after the call are not asserted for this set.","TestNeeded","The only call under test is PermissionScopes.Tests.ps1:146 (Source=Path with the -AppliesTo form, 13 of 52 cases): :149-154 assert type, Inheritance/Propagation/AuditFlags and the scope name, and :161-163 that the other account remains. The other calls (PermissionScopes:144, Audit.Tests.ps1:618 and :690, Inheritance.Tests.ps1:386, :424, :503) are fixtures; BoundBy 7 = scan 5 + :144 and :146 resolved from the splat.","Closed","ParameterSets.Audit.Tests.ps1:99 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged | ParameterSets.Audit.Tests.ps1:161 Should reject -AppliesTo combined with -InheritanceFlags with an AmbiguousParameterSet error and change nothing","",""
"audit","Add-NTFSAudit","SDSimple","False","0","0","2","2","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Audit.Tests.ps1:89 Should take -Account at position 2 and -AccessRights at position 3 in the <_> parameter set","0","No test makes this set fail, passes or pipes several descriptors, or reads the changed descriptor with .NET; a descriptor without audit entries is tested only with the complex form. Exceptions of the change itself end the cmdlet (open item 1) and are not to be pinned.","TestNeeded","Only PermissionScopes.Tests.ps1:146 binds it (Source=SecurityDescriptor with -AppliesTo, 13 of 52 cases; the fixture at :144 in 26): :149-154 assert the -PassThru type and flags and :156 that the SACL of the item is unchanged (Get-Acl -Audit). Audit.Tests.ps1:89 checks the positions by reflection only; BoundBy 2 resolves the two splat calls, the scan found 0.","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:127 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it | ParameterSets.Audit.Tests.ps1:176 Should add the entry to the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly","exceptions from the change itself (open item 1)","MaintainerDecision (open item)"
"audit","Add-NTFSAudit","SDComplex","False","5","0","1","8","Yes","Partly","No","No","Yes","Audit.Tests.ps1:107 Should bind an account and access rights that are passed by position | Audit.Tests.ps1:120 Should return the audit entries of a security descriptor, not its access entries | SecurityDescriptor.Tests.ps1:120 Should write an added audit entry and keep the owner | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries","0","Only the ErrorId is asserted for a descriptor without audit entries, not its category (InvalidData) or target, and no test pipes descriptors or passes several (one without audit entries), so pipeline binding and continuation are untested. Exceptions of the change itself are open item 1 and are not to be pinned.","TestNeeded","Audit.Tests.ps1:109-110 reads the in-memory SACL with .NET and :122-136 assert type, Sid, InheritanceEnabled and the unchanged access protection; SecurityDescriptor.Tests.ps1:124-126 asserts after Set-NTFSSecurityDescriptor that the owner is kept and the entry exists; PermissionScopes.Tests.ps1:156 asserts the item is untouched until written. BoundBy 8 = scan 5 + PermissionScopes:146 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only).","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:127 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it","exceptions from the change itself (open item 1)","MaintainerDecision (open item)"
"audit","Remove-NTFSAudit","PathComplex","True","7","2","1","10","Yes","Yes","No","Yes","Yes","Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:361 Should keep an audit entry that does not match exactly, given the path | Audit.Tests.ps1:371 Should remove an audit entry that matches exactly, given the path | Audit.Tests.ps1:384 Should return the audit entries of the item, not its access entries","2 (NTFSSecurity.Live.Tests.ps1:357, 398): SMB share with domain accounts; owner kept; the delegated account gets a RemoveAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441)","No test pipes paths or objects in, removes for several accounts, asserts the result of a succeeding path after a failing one, or removes only some rights (without -RemoveSpecific). An item without SACL is tested for no error only (Audit.Tests.ps1:406), and the owner retry cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:631-669 and :672-679 assert ReadFileError/OpenError/target (RemoveAceError/WriteError/target as a basic user), the SACL changed with no rule left, and unchanged DACL/owner SDDL; :363-365 and :373-374 read back through Get-NTFSAudit. BoundBy 10 = scan 7 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124; :386-388 assert type and the other entry but pass even if nothing was removed.","Partly","ParameterSets.Audit.Tests.ps1:191 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:252 Should narrow an entry that grants more rights than it removes, instead of deleting it","removing for several accounts in one call; state (empty Audit SDDL, unchanged DACL) of an item without a SACL; the owner retry after access denied","budget; budget; Limit (needs a lab or a remote server)"
"audit","Remove-NTFSAudit","PathSimple","False","0","0","1","1","Partly","No","No","No","Partly","PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","Only one data-driven call binds it: no failing item, pipeline input, several items, or owner and DACL check after the call, the objects are checked by Sid only, and it never runs without -RemoveSpecific.","TestNeeded","PermissionScopes.Tests.ps1:159 binds it only when Source=Path and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone from -PassThru, that the other account remains, and that Get-NTFSAudit returns nothing for the account. BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set.","Closed","ParameterSets.Audit.Tests.ps1:191 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:270 Should remove the entry from the path when -Path, -Account, -AccessRights, and -AppliesTo are all named directly","",""
"audit","Remove-NTFSAudit","SDSimple","False","0","0","1","1","Partly","No","No","No","Partly","PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","Only one data-driven call binds it: the changed descriptor is read only through -PassThru and Get-NTFSAudit, the item being untouched after the removal is not asserted, and no test makes it fail, pipes or passes several descriptors, or runs without -RemoveSpecific.","TestNeeded","PermissionScopes.Tests.ps1:159 binds it only when Source=SecurityDescriptor and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone, that the other account remains, and that Get-NTFSAudit returns nothing; the SACL on disk is compared only after the Add (:156). BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set.","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:222 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:287 Should remove the entry from the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly","the item on disk being untouched after the removal, until Set-NTFSSecurityDescriptor writes it","budget"
"audit","Remove-NTFSAudit","SDComplex","False","2","0","1","5","Partly","Partly","No","No","Partly","Audit.Tests.ps1:347 Should keep an audit entry that does not match exactly | Audit.Tests.ps1:353 Should remove an audit entry that matches exactly | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries | PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","The item being untouched after the removal and the result after Set-NTFSSecurityDescriptor are not asserted, the error test lacks category and target, and no test pipes or passes several descriptors, checks the -PassThru type, or asserts a removal without -RemoveSpecific. Exceptions of the change itself are open item 1 and are not to be pinned.","TestNeeded","Audit.Tests.ps1:349 and :355 read the in-memory SACL with .NET (non-matching entry kept, matching entry removed) and :427-432 assert one ReadSecurityError, no output and the SACL still empty; PermissionScopes.Tests.ps1:161-163 assert by Sid only. BoundBy 5 = scan 2 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only).","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:222 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry","the item on disk untouched after the removal and the result after Set-NTFSSecurityDescriptor; the -PassThru output type; exceptions from the change itself (open item 1)","budget; budget; MaintainerDecision (open item)"
"audit","Clear-NTFSAudit","Path","True","3","1","0","5","Yes","Yes","No","Yes","NA","Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:455 Should remove the audit entries and keep the owner | Audit.Tests.ps1:478 Should write no error and leave the access entries unchanged | Audit.Tests.ps1:495 Should write an error and leave the item unchanged","2 (NTFSSecurity.Live.Tests.ps1:652, plus :684 through & $Command that the scan cannot see): SMB share; explicit entry cleared with the inherited entry and the owner kept; the delegated account gets a ClearAclError that names the missing privilege and leaves the SDDL unchanged; the file server checks the SACL (:1453)","-DisableInheritance on a path is passed (Audit.Tests.ps1:629) but its end state (protected SACL, no copied inherited entries) is never asserted, and no test pipes paths or asserts the result of a succeeding path after a failing one. The owner retry after access denied cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:457-459 asserts no error, owner kept (.NET) and no entry left (Get-NTFSAudit); :480-483 and :497-499 assert an unchanged DACL and, without the privilege, a ClearAclError with an unchanged SDDL; :631-669 and :672-679 add category and target. BoundBy 5 = scan 3 + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124.","Partly","ParameterSets.Audit.Tests.ps1:305 Should clear the audit entries of each path taken from the pipeline and leave the DACL of each unchanged | ParameterSets.Audit.Tests.ps1:326 Should protect the SACL and not copy the parent's inherited entry when clearing a child path","the result of a succeeding path that follows a failing one; the owner retry after access denied","budget; Limit (needs a lab or a remote server)"
"audit","Clear-NTFSAudit","SD","False","2","0","0","3","Yes","Partly","No","No","NA","Audit.Tests.ps1:696 Should clear and protect the descriptor SACL without writing the <Type> | SecurityDescriptorSets.Tests.ps1:107 Clear-NTFSAudit should remove the explicit audit entries of the descriptor | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries","0","No test pipes descriptors or passes several (one without audit entries), and the error test asserts the ErrorId but not category or target.","TestNeeded","Audit.Tests.ps1:698-705 asserts the in-memory SACL cleared and protected (.NET), the SACL of the item untouched until Set-NTFSSecurityDescriptor, then the state on disk and an unchanged DACL; SecurityDescriptorSets.Tests.ps1:109-112 asserts the same for the unprotected form. BoundBy 3 = scan 2 + & $Command at Audit.Tests.ps1:425 (error case only).","Closed","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:347 Should clear each piped descriptor that has an audit section and continue past one that does not","",""
"audit","Get-NTFSAudit","Path","False","24","4","2","27","NA","Partly","No","Partly","Partly","Audit.Tests.ps1:529 Should name the folder that an inherited entry comes from, also with -ExcludeExplicit | Audit.Tests.ps1:48 Should write an error without the Security privilege instead of returning nothing | PathErrors.Tests.ps1:124 <Command> should write a ReadFileError for it and continue with the next path | Inheritance.Tests.ps1:387 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged","4 (NTFSSecurity.Live.Tests.ps1:336, 373, 656, 657): SMB share with domain accounts; Sid, AuditFlags and rights of the entry; the delegated account gets a ReadSecurityError that names the missing privilege","No test pipes paths or FileInfo/DirectoryInfo into it, asserts the category of its errors or the target of ReadSecurityError, or (in unit tests) the type, AuditFlags and inheritance flags of the output. No unit test has a failing path followed by a path whose entries are asserted (Audit.Tests.ps1:70-73 documents that the second path of the test at :80 no longer fails), and the PermissionDenied branch cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:50-52 asserts one ReadSecurityError by ErrorId only (basic user); :531-534 and :577-578 assert IsInherited and InheritedFrom; PathErrors.Tests.ps1:130-132 asserts ReadFileError and target for a missing path but discards the output (:124). BoundBy 27 = scan 24 + PermissionScopes:163 (26 of 52 cases) + & $Command at PathErrors.Tests.ps1:124 and Owner.Tests.ps1:98 (no -Path, Should -Not -Throw).","Partly","ParameterSets.Audit.Tests.ps1:376 Should return the entries of the existing path in either position and a ReadFileError, category OpenError, for the missing one | ParameterSets.Audit.Tests.ps1:405 Should return the entries of each path object taken from the pipeline by value | ParameterSets.Audit.Tests.ps1:420 Should write a ReadSecurityError with category OpenError and the path as target without the Security privilege","the PermissionDenied category branch of ReadSecurityError","Limit (needs a lab or a remote server)"
"audit","Get-NTFSAudit","SD","False","1","0","2","3","NA","Partly","Partly","No","Partly","Audit.Tests.ps1:61 Should write an error for a security descriptor that was read without the audit entries | SecurityDescriptorSets.Tests.ps1:160 Get-NTFSAudit should return the audit entries that it returns for the path | PermissionScopes.Tests.ps1:163 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","The output is compared only with the output of the Path set (no expected type, flags or values), at most one descriptor is piped, and no test passes several descriptors (one without audit entries). The error test lacks category and target.","TestNeeded","Audit.Tests.ps1:63-65 asserts no output and one ReadSecurityError; SecurityDescriptorSets.Tests.ps1:160-163 pipes one descriptor and asserts one entry equal to the Path result (Sid, AccessRights, AuditFlags); PermissionScopes.Tests.ps1:163 asserts only emptiness after a removal. BoundBy 3 = scan 1 + SecurityDescriptorSets:160 (piped by value, so SD) + PermissionScopes:163 (26 of 52 cases).","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:434 Should return the entries of the piped descriptor that has an audit section and continue past one that does not","an expected type, flags, or values for the output, independent of comparing it to the Path set's output","budget"
"audit","Get-NTFSOrphanedAudit","Path","False","9","1","2","9","NA","Partly","No","Yes","Yes","Audit.Tests.ps1:228 Should return one object per entry whose account cannot be resolved | Audit.Tests.ps1:250 Should return an inherited entry, and nothing with -ExcludeInherited | Audit.Tests.ps1:279 Should write an error for a path that does not exist and continue with the next path without the Security privilege | Audit.Tests.ps1:304 Should write a ReadSecurityError without the Security privilege instead of returning nothing","1 (NTFSSecurity.Live.Tests.ps1:843): SMB share; the entry of a deleted domain account is returned with its SID, without error or warning","No test pipes paths into it, asserts the category of ReadError or ReadSecurityError, or runs -ExcludeExplicit, and the elevated continuation test passes on an empty result (Audit.Tests.ps1:273).","TestNeeded","Audit.Tests.ps1:230-232, :238-239 and :253-256 assert count, type, Sid and IsInherited; :282-286 (basic user) asserts ReadError for the missing path and a ReadSecurityError with its own target for the next path, which shows that the cmdlet continued, while :270-273 (elevated) asserts one error and then only a ForEach over the result. BoundBy 9 = scan 9.","Partly","ParameterSets.Audit.Tests.ps1:456 Should return the orphaned entries of each path taken from the pipeline and write a ReadError, category OpenError, for one that does not exist","the category of ReadSecurityError without the Security privilege; -ExcludeExplicit","budget; budget"
"audit","Get-NTFSOrphanedAudit","SD","False","0","0","2","2","NA","Partly","Partly","No","Partly","Audit.Tests.ps1:243 Should read the entries of a security descriptor | Audit.Tests.ps1:294 Should write an error for a security descriptor that was read without the audit entries","0","At most one descriptor is piped and none is passed in an array, so continuation is untested; -Account and -Exclude* with a descriptor, the entry type and Sid, and the category and target of the error are not asserted.","TestNeeded","Both calls pipe one descriptor, which PowerShell binds by value to -SecurityDescriptor (the elevated run of :296-298 proves it: a Path binding would return entries): :245-246 assert 2 entries with FullName and :296-298 assert no output and one ReadSecurityError. BoundBy 2 = the two ambiguous piped calls (Audit.Tests.ps1:243 and :294); the scan found 0.","Partly","ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:477 Should return the orphaned entries of the piped descriptor that has an audit section and continue past one that does not | ParameterSets.Audit.Tests.ps1:499 Should return the orphaned entries when -SecurityDescriptor is named directly","-Account and -ExcludeInherited/-ExcludeExplicit filters with a descriptor","budget"
"inheritance","Disable-NTFSAccessInheritance","Path","True","9","1","0","16","Partly","Partly","No","Partly","Yes","Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:301 Disable-NTFSAccessInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:133 <_> should write an error and return nothing when the security descriptor cannot be read","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:281-289: no error, owner Administrators kept, DACL protected by Get-Acl)","Not asserted: the error category (OpenError, WriteError), piped input (documented: Get-ChildItem2 | Disable-NTFSAccessInheritance -PassThru), a .NET readback of the kept or removed inherited entries (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given.","TestNeeded","Inheritance.Tests.ps1:341-360 asserts the -PassThru object (type, FullName, flag) and reads flag, owner and entries back only with Get-NTFSInheritance, Get-NTFSOwner and Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:307-309 and 183-191, DriveRoot.Tests.ps1:113). Errors: PathErrors.Tests.ps1:110-112 and 180-182 assert ErrorId and target, never the category; no test pipes into the cmdlet. BoundBy 16 = scan 9 (6 are fixtures) + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:157 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget"
"inheritance","Disable-NTFSAccessInheritance","SecurityDescriptor","False","1","0","0","2","Yes","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:71 Disable-NTFSAccessInheritance should protect the DACL of the descriptor and keep the inherited entries | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type>","0","Not asserted: -RemoveInheritedAccessRules with a descriptor, the owner after the write, and several descriptors (array or pipeline). The set has no per-item handler, like the sets of open item 1 (which does not name it), but it cannot fail on a descriptor from Get-NTFSSecurityDescriptor.","TestNeeded","SecurityDescriptorSets.Tests.ps1:79-84 asserts the in-memory flag, the item unchanged before the write (Get-Acl), and after Set-NTFSSecurityDescriptor the flag and an explicit count equal to the inherited count (.NET); Inheritance.Tests.ps1:557-562 asserts count, FullName and flag of the -PassThru object. BoundBy 2 = scan 1 + Inheritance:555 (& $Command -SecurityDescriptor).","Partly","ParameterSets.Inheritance.Tests.ps1:234 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","the owner unchanged after the descriptor write","budget"
"inheritance","Enable-NTFSAccessInheritance","Path","True","3","1","0","10","Partly","Partly","No","Partly","Yes","Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:312 Enable-NTFSAccessInheritance should take ownership, let the DACL inherit, and set the owner back | DriveRoot.Tests.ps1:110 Should block and restore the access inheritance of the folder that the drive maps","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:291-299: no error, owner kept, DACL inherits again by Get-Acl)","Not asserted: the error category, piped input (documented: Get-NTFSInheritance output piped into Enable-NTFSAccessInheritance -RemoveExplicitAccessRules), a .NET readback of explicit and inherited entries after the call (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given.","TestNeeded","Inheritance.Tests.ps1:341-360 (Enable cases) asserts the object and reads re-inherited and explicit entries back only with Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:319-321 and 190-191, DriveRoot.Tests.ps1:117). Errors as for Disable: ErrorId and target (PathErrors.Tests.ps1:110-112, 180-182), no category; no piped input. BoundBy 10 = scan 3 + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:157 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget"
"inheritance","Enable-NTFSAccessInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:87 Enable-NTFSAccessInheritance should let the DACL of the descriptor inherit | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type>","0","Not asserted: -RemoveExplicitAccessRules with a descriptor, that an explicit entry survives a plain Enable (the test descriptor has none), and several descriptors (array or pipeline). The set works in memory, so it has no error path or handler to test.","TestNeeded","SecurityDescriptorSets.Tests.ps1:94-99 asserts the in-memory flag, the item still protected, then (.NET) the flag false and inherited entries present after the write; the descriptor has no explicit entry, so kept versus removed is unasserted. Inheritance.Tests.ps1:557-562 (Enable cases) asserts count, FullName and flag. BoundBy 2 = scan 1 + Inheritance:555.","Closed","ParameterSets.Inheritance.Tests.ps1:234 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","",""
"inheritance","Disable-NTFSAuditInheritance","Path","True","7","1","0","15","Partly","Yes","No","Yes","Yes","Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | Inheritance.Tests.ps1:113 <_> should return nothing when the audit change fails","2 (SMB: Admin and ServerAdmin write it and the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:632 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690)","Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit; the lab does, NTFSSecurity.Live.Tests.ps1:1453-1458), no test pipes into the set (documented: Get-ChildItem2 -Directory | Disable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY).","TestNeeded","Audit.Tests.ps1:629-679 runs two paths with -PassThru: as a basic user ModifySdError/WriteError/target then ReadFileError/OpenError/target and an empty result (672-679), elevated the object flag, the explicit SACL rules and the unchanged DACL and owner (631, 654-657). Inheritance.Tests.ps1:401-419 reads the SACL back only through Get-NTFSInheritance and Get-NTFSAudit (the DACL through .NET at 405). BoundBy 15 = scan 7 + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629).","Partly","ParameterSets.Inheritance.Tests.ps1:199 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write","budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target"
"inheritance","Disable-NTFSAuditInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type> | Inheritance.Tests.ps1:276 Should add no SACL to a security descriptor that was read without its audit entries","0","Not asserted: -RemoveInheritedAuditRules with a descriptor, an independent SACL readback after the write, the owner and DACL after the write, and several descriptors. The set accepts a descriptor without audit entries silently (pinned for Disable at Inheritance.Tests.ps1:276), unlike Add, Remove and Clear-NTFSAudit; see the notes.","TestNeeded","Inheritance.Tests.ps1:579-585 (elevated only) asserts count, FullName and flag of the object, the SACL SDDL unchanged until Set-NTFSSecurityDescriptor, and the flag after it, all through module cmdlets; :284-286 asserts that no SACL is added to a descriptor read without audit entries. BoundBy 2 = scan 1 (Inheritance:282) + Inheritance:577 (& $Command -SecurityDescriptor).","Partly","ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","-RemoveInheritedAuditRules with a descriptor as its own dedicated state test; the owner and DACL unchanged after the write","budget; budget"
"inheritance","Enable-NTFSAuditInheritance","Path","True","1","1","0","9","Partly","Yes","No","Yes","Yes","Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | PathErrors.Tests.ps1:118 <Command> should write a ReadFileError for it and continue with the next path","2 (SMB: the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:642 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690)","Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit), the result of -RemoveExplicitAuditRules is read back only with Get-NTFSAudit, no test pipes into the set (documented: Get-NTFSInheritance output piped into Enable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY).","TestNeeded","Audit.Tests.ps1:660-662 (elevated) asserts the flag true and the explicit rules removed, and :672-679 the errors as a basic user; Inheritance.Tests.ps1:259-260 and 270-272 cover an item without SACL (flag by Get-NTFSInheritance, DACL by .NET). SACL state is never read with .NET in a unit test. BoundBy 9 = scan 1 (PipelineControl:284) + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629).","Partly","ParameterSets.Inheritance.Tests.ps1:199 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write","budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target"
"inheritance","Enable-NTFSAuditInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:115 Enable-NTFSAuditInheritance should let the SACL of the descriptor inherit | Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type>","0","Not asserted: -RemoveExplicitAuditRules with a descriptor, that an explicit audit entry survives a plain Enable, an independent SACL readback after the write, and several descriptors. Enable with an access-only descriptor is pinned only through Set-NTFSInheritance (Inheritance.Tests.ps1:524-539).","TestNeeded","SecurityDescriptorSets.Tests.ps1:119-126 (elevated) asserts the in-memory flag, the item still protected (Get-NTFSInheritance) and the flag after the write; Inheritance.Tests.ps1:579-585 (Enable cases) asserts count, FullName and flag. Nothing reads the SACL with .NET. BoundBy 2 = scan 1 + Inheritance:577.","Partly","ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","-RemoveExplicitAuditRules with a descriptor as its own dedicated state test; an explicit audit entry surviving a plain Enable","budget; budget"
"inheritance","Get-NTFSInheritance","Path","True","23","4","0","27","NA","Partly","No","Partly","Partly","PathErrors.Tests.ps1:104 <Command> should write a <ErrorId> for it and continue with the next path | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:54 Should report the same state as for the path of the item","4 (SMB: protected DACL with inherited audit flag, NTFSSecurity.Live.Tests.ps1:661-666; null audit state without the Security privilege, :695-700; two of the four calls are read-backs, :636 and :646)","Not asserted: FullName, Name, type or exact count of the output, a protected state created without the module (all protected states come from the module's own cmdlets), the error category, piped input (documented: Get-ChildItem2 | Get-NTFSInheritance), and the result for no -Path (documented: current location; Owner.Tests.ps1:92 asserts -Not -Throw only). [Limit] The documented ownership retry has no success path on a local volume.","TestNeeded","Inheritance.Tests.ps1:58-59, 74-75 and 88-90 assert only the flags (the descriptor result equals the -Path result; audit false after Disable-NTFSAuditInheritance), no FullName, type or count. PathErrors.Tests.ps1:110-115 and 147-152 assert ErrorId, target and non-empty output for the next path, no category. BoundBy 27 = scan 23 + 4 calls through & $Command or & $_ (PathErrors:108,145; Owner:98; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:364 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:543,552 Get-NTFSInheritance should take piped folder objects from Get-ChildItem2 and a piped custom object by its FullName property","the Name property of the output; a protected state created without the module; the result for no -Path; a successful ownership-retry read","budget; budget; budget; Limit, no local volume reaches the success path"
"inheritance","Get-NTFSInheritance","SecurityDescriptor","False","4","0","0","4","NA","NA","No","NA","Partly","Inheritance.Tests.ps1:54 Should report the same state as for the path of the item | Inheritance.Tests.ps1:65 Should report the same state as for the path of a <Type> without audit entries | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:93 Should report the audit inheritance as $null for a security descriptor without the audit entries","0","Not asserted: FullName, Name, type, exact count, several descriptors, a protected descriptor created without the module, and piped descriptors (documented: Get-NTFSSecurityDescriptor | Get-NTFSInheritance). The set works in memory and cannot fail on a readable descriptor.","TestNeeded","Inheritance.Tests.ps1:58-59, 74-75, 88-90 and 100-101 compare the flags with the -Path result and assert a null audit state for an access-only descriptor; none asserts FullName, Name, type, count or several descriptors. BoundBy 4 = scan 4.","Partly","ParameterSets.Inheritance.Tests.ps1:565,575 Get-NTFSInheritance -SecurityDescriptor should take two piped descriptors, one protected, and report both in order","the type of the output (BeOfType); a protected descriptor created without the module","budget; budget"
"inheritance","Set-NTFSInheritance","Path","True","14","1","0","18","Partly","Partly","No","Partly","Partly","Inheritance.Tests.ps1:164 Should keep the inherited access entries as explicit ones when it disables access inheritance | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:324 Set-NTFSInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:422 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:302-309: DACL protected, owner kept)","No test pipes into the set, including the documented round trip (Get-NTFSInheritance output piped into Set-NTFSInheritance, which binds both flags by property name); the SACL and the access-enable direction are read back only through module cmdlets. Also not asserted: the error category, the FullName of the -Path -PassThru object, RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op without -Path.","TestNeeded","Inheritance.Tests.ps1:173-175 (.NET flag and explicit count), 428-433 (object, entries, DACL unchanged by .NET) and PathErrors.Tests.ps1:330-332 and 180-191 (owner, denied item unchanged, next item protected) are the strongest; the SACL and the access-enable direction are read back only with module cmdlets (Inheritance.Tests.ps1:371-373, 431-432). Inheritance.Tests.ps1:127-130 asserts no object after a failed audit change for one item, as a basic user only. BoundBy 18 = scan 14 + 4 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:268; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:588 Set-NTFSInheritance should restore a saved inheritance state through the pipeline by property name","an independent SACL readback of the result; OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget; budget"
"inheritance","Set-NTFSInheritance","SecurityDescriptor","False","5","0","0","5","Partly","NA","No","NA","Yes","Inheritance.Tests.ps1:465 Should set access inheritance enabled=<Enable> on a <Type> only when the descriptor is written | Inheritance.Tests.ps1:494 Should set audit inheritance enabled=<Enable> on a <Type> without changing its DACL or owner | Inheritance.Tests.ps1:524 Should keep audit inheritance unknown when requested enabled=<_> on an access-only descriptor | Inheritance.Tests.ps1:180 Should keep the inherited access entries of a security descriptor","0","Not asserted: several descriptors (array or pipeline), a single call that sets both -AccessInheritanceEnabled and -AuditInheritanceEnabled, and an independent SACL readback after the write (the audit side uses module cmdlets). The set works in memory and cannot fail on a readable descriptor.","TestNeeded","Inheritance.Tests.ps1:481-491 asserts count, FullName, Name, flag, the item unchanged until Set-NTFSSecurityDescriptor, then flag and owner by .NET and the explicit entry; :511-521 (elevated) does the audit side through module cmdlets; :533-539 asserts a null audit state and no SACL for an access-only descriptor. BoundBy 5 = scan 5.","Closed","ParameterSets.Inheritance.Tests.ps1:267 Set-NTFSInheritance -SecurityDescriptor should set both inheritance flags in one call, changing only the in-memory descriptor until it is written | ParameterSets.Inheritance.Tests.ps1:600,617 Set-NTFSInheritance -SecurityDescriptor should protect both descriptors in memory, written only by Set-NTFSSecurityDescriptor, piped and passed directly to the parameter","",""
"inheritance","Get-NTFSOwner","Path","True","22","4","3","26","NA","Partly","Partly","Partly","Yes","Owner.Tests.ps1:47 Should write one permission error and keep the owner | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | DriveRoot.Tests.ps1:45 Get-NTFSOwner should return the owner of the root folder | ObjectApis.Tests.ps1:706 Should name the item and the account of an owner object","4 (SMB: owner Administrators, NTFSSecurity.Live.Tests.ps1:585-589; three calls check that the privileges are disabled after a later command ends the pipeline, :1406, 1411, 1422)","No test asserts ErrorId, category and target together (Owner.Tests.ps1:55-56 id and category, PathErrors.Tests.ps1:148-149 id and target); piping covers one FileInfo only (documented: Get-ChildItem2 -Recurse | Get-NTFSOwner); the next item's output is asserted only as non-empty; the documented 'returns nothing' without -Path is untested.","TestNeeded","Owner.Tests.ps1:53-56 asserts no output, one error, ReadSecurityError and PermissionDenied (basic user only, skipped with the Backup privilege); PathErrors.Tests.ps1:147-151 asserts id, target and non-empty output for the next path; DriveRoot.Tests.ps1:46 compares Owner.Sid with Get-Acl; ObjectApis.Tests.ps1:711-713 (line numbers at HEAD 6696f68; +19 in a work tree with the uncommitted ObjectApis edit) asserts Item, FullName and Account. BoundBy 26 = scan 22 + ambiguous Owner:177 and :185 (both bind Path) + PathErrors:108,145.","Partly","ParameterSets.Inheritance.Tests.ps1:379 Get-NTFSOwner should write a ReadSecurityError with its id, category, and target together for a denied item, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:631 Get-NTFSOwner should take two piped folders from Get-ChildItem2 and return the owner of each, verified with Get-Acl","the documented 'returns nothing' without -Path","budget"
"inheritance","Get-NTFSOwner","SecurityDescriptor","False","0","0","3","1","NA","NA","Partly","NA","Partly","SecurityDescriptorSets.Tests.ps1:146 Get-NTFSOwner should return the owner that it returns for the path","0","One test, one descriptor; the owner is compared with the -Path result of the same cmdlet, with no .NET oracle, no type assertion and no several descriptors. The result for a descriptor read without its Owner section is unexercised (see the notes).","TestNeeded","The scan's ambiguous rows Owner.Tests.ps1:177 (System.IO DirectoryInfo by position) and :185 (System.IO FileInfo piped) bind Path: FileSystemPathTransformation turns a file system object into its path, and those types do not convert to FileSystemSecurity2[]. Only SecurityDescriptorSets.Tests.ps1:149-153 binds the set: a FileSystemSecurity2 piped by value, asserting count 1, Owner.Sid against the -Path result and FullName. BoundBy 1 (scan 0 + that call).","Partly","ParameterSets.Inheritance.Tests.ps1:655,665 Get-NTFSOwner -SecurityDescriptor should return the owner of each descriptor, piped and passed directly to the parameter, verified with Get-Acl","the result for a descriptor read without its Owner section","budget, a read-only probe just now shows it returns the item's real owner, not a crash, so it is safely testable and simply was not written"
"inheritance","Set-NTFSOwner","Path","True","8","4","1","10","Partly","Partly","Yes","Partly","Yes","Owner.Tests.ps1:240 Should set an owner that only the Restore privilege allows | Owner.Tests.ps1:232 Should take the items from the pipeline | Owner.Tests.ps1:270 Should write a SetOwnerError and keep the owner | Owner.Tests.ps1:248 Should write a read error for a path that does not exist and continue with the next path","4 (SMB: take ownership as the account itself, assign another account only with the file server's Restore privilege (SetOwnerError for the delegated account), NTFSSecurity.Live.Tests.ps1:595 and 604; a later command that stops the pipeline leaves the second item's owner unchanged, :1143, 1182)","Not asserted: DACL, SACL and group unchanged after the owner changes; as a basic user the owner already equals the user, so Owner.Tests.ps1:217, 229 and 256 cannot show a change; the error category and target (SetOwnerError); -PassThru with a failing item among several; and the documented no-op without -Path.","TestNeeded","Owner.Tests.ps1:245 (.NET owner is TrustedInstaller, needs the Restore privilege), :225-229 (count, type, FullName, Owner.Sid, .NET owner), :237 (two piped Get-Item2 objects) and :277-279 (SetOwnerError id only, owner unchanged). The scan's ambiguous Owner:235 binds Path (the Get-Item2 objects bind by their FullName property). BoundBy 10 = scan 8 + Owner:235 + PathErrors:108.","Partly","ParameterSets.Inheritance.Tests.ps1:293 Set-NTFSOwner should change only the owner and leave the Access entries and the group unchanged | ParameterSets.Inheritance.Tests.ps1:406,423 Should write <ErrorId> with its category and target for <Scenario>, and keep processing the remaining path","the SACL unchanged after the owner changes; the documented no-op without -Path","budget; budget"
"inheritance","Set-NTFSOwner","SecurityDescriptor","False","2","0","1","2","Partly","NA","No","NA","Partly","Owner.Tests.ps1:284 Should change only the descriptor in memory until Set-NTFSSecurityDescriptor writes it | Owner.Tests.ps1:303 Should write nothing without -PassThru and leave the owner of the item unchanged","0","The persisted-owner test is skipped for basic users (Owner.Tests.ps1:287-290); not asserted: DACL unchanged after the write, FullName and type of the -PassThru object (only the -Path set asserts them), and several descriptors (array or pipeline).","TestNeeded","Owner.Tests.ps1:296-300 asserts count, Owner.Sid, the item's owner unchanged until Set-NTFSSecurityDescriptor and changed after (.NET), but the test is skipped when the user owns new items (:287-290); :312-314 asserts no output without -PassThru, the in-memory owner and the item's owner unchanged. BoundBy 2 = scan 2.","Partly","ParameterSets.Inheritance.Tests.ps1:677,692 Set-NTFSOwner -SecurityDescriptor should change both owners in memory without touching the items, piped and passed directly to the parameter","the DACL unchanged after the write; the type of the -PassThru object (BeOfType)","budget; budget"
"inheritance","Get-NTFSSecurityDescriptor","__AllParameterSets","False","79","5","0","82","NA","Partly","No","Partly","Yes","SecurityDescriptor.Tests.ps1:52 Should report the inherited access entries as inherited | SecurityDescriptor.Tests.ps1:63 Should read the owner and the audit entries with the access entries | DriveRoot.Tests.ps1:39 Get-NTFSSecurityDescriptor should read the DACL of the root folder | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path","5 (SMB read-backs for the descriptor tests, NTFSSecurity.Live.Tests.ps1:315, 965, 1150, and InheritedFrom of a vanished item, :988, 1017)","Untested combinations: piped paths and file or folder objects (documented: Get-ChildItem2 | Get-NTFSSecurityDescriptor), no -Path (current location; Owner.Tests.ps1:92 asserts -Not -Throw only), the error category, and that the next item yields exactly one descriptor. [Limit] The documented ownership retry has no success path on a local volume.","TestNeeded","SecurityDescriptor.Tests.ps1:59-60 (inherited flags against the Get-Acl count) and :70-71 (owner against Get-Acl, audit rules) need the Security privilege; DriveRoot.Tests.ps1:42 compares the DACL SDDL with Get-Acl; PathErrors.Tests.ps1:110-115 and 147-152 assert ReadFileError and ReadSecurityError with target and non-empty output. BoundBy 82 = scan 79 + 3 calls through & $Command or & $_ (PathErrors:108,145; Owner:98).","Partly","ParameterSets.Inheritance.Tests.ps1:364 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:706,717,724 Get-NTFSSecurityDescriptor should take piped folder objects, a standard Get-Item object, and a piped custom object by its Path property","the result for no -Path (current location); a successful ownership-retry read","budget; Limit, no local volume reaches the success path"
"audit","Add-NTFSAudit","PathComplex","True","27","4","1","30","Yes","Yes","No","Yes","Yes","Audit.Tests.ps1:147 Should write an AddAceError for each item, change nothing, and return nothing with -PassThru | Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:178 Should add the audit entry and keep the owner | PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account","4 (NTFSSecurity.Live.Tests.ps1:348, 385, 1010, 1016): SMB share with domain accounts; owner kept; the delegated account gets an AddAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441)","No test pipes paths or objects into -Path, binds Account/AccessRights/AuditFlags by property name, or adds for several accounts. No test asserts the result of a succeeding path that follows a failing one (PathErrors.Tests.ps1:124 only counts errors), and the owner retry after access denied cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:149-158 asserts AddAceError, WriteError, target, ArgumentException, no -PassThru output and an unchanged SACL (Get-Acl -Audit) for two failing paths; :631-669 and :672-679 assert ReadFileError/OpenError/target, the FullName of the output, the SACL rule, and unchanged DACL/owner SDDL. BoundBy 30 = scan 27 + PermissionScopes:146 (13 of 52 cases) + 2 calls through & $Command that the scan cannot see (Audit.Tests.ps1:629, PathErrors.Tests.ps1:124); 23 of the 27 scanned calls are fixtures.","Partly","ParameterSets.Audit.Tests.ps1:123 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged","AuditFlags not bound by property name; adding for several accounts in one call; the owner retry after access denied","budget; budget; Limit (needs a lab or a remote server)"
"audit","Add-NTFSAudit","PathSimple","False","5","0","2","7","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Inheritance.Tests.ps1:386 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:424 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry","0","No call of this set fails on purpose, passes several paths, or pipes objects, and a conflict of -AppliesTo with -InheritanceFlags is not tested. The added entry is read back only from -PassThru and Get-NTFSAudit, and owner and DACL after the call are not asserted for this set.","TestNeeded","The only call under test is PermissionScopes.Tests.ps1:146 (Source=Path with the -AppliesTo form, 13 of 52 cases): :149-154 assert type, Inheritance/Propagation/AuditFlags and the scope name, and :161-163 that the other account remains. The other calls (PermissionScopes:144, Audit.Tests.ps1:618 and :690, Inheritance.Tests.ps1:386, :424, :503) are fixtures; BoundBy 7 = scan 5 + :144 and :146 resolved from the splat.","Closed","ParameterSets.Audit.Tests.ps1:123 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged | ParameterSets.Audit.Tests.ps1:193 Should reject -AppliesTo combined with -InheritanceFlags with an AmbiguousParameterSet error and change nothing","",""
"audit","Add-NTFSAudit","SDSimple","False","0","0","2","2","Partly","No","No","No","Yes","PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Audit.Tests.ps1:89 Should take -Account at position 2 and -AccessRights at position 3 in the <_> parameter set","0","No test makes this set fail, passes or pipes several descriptors, or reads the changed descriptor with .NET; a descriptor without audit entries is tested only with the complex form. Exceptions of the change itself end the cmdlet (open item 1) and are not to be pinned.","TestNeeded","Only PermissionScopes.Tests.ps1:146 binds it (Source=SecurityDescriptor with -AppliesTo, 13 of 52 cases; the fixture at :144 in 26): :149-154 assert the -PassThru type and flags and :156 that the SACL of the item is unchanged (Get-Acl -Audit). Audit.Tests.ps1:89 checks the positions by reflection only; BoundBy 2 resolves the two splat calls, the scan found 0.","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:154 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it | ParameterSets.Audit.Tests.ps1:208 Should add the entry to the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly","exceptions from the change itself (open item 1)","MaintainerDecision (open item)"
"audit","Add-NTFSAudit","SDComplex","False","5","0","1","8","Yes","Partly","No","No","Yes","Audit.Tests.ps1:107 Should bind an account and access rights that are passed by position | Audit.Tests.ps1:120 Should return the audit entries of a security descriptor, not its access entries | SecurityDescriptor.Tests.ps1:120 Should write an added audit entry and keep the owner | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries","0","Only the ErrorId is asserted for a descriptor without audit entries, not its category (InvalidData) or target, and no test pipes descriptors or passes several (one without audit entries), so pipeline binding and continuation are untested. Exceptions of the change itself are open item 1 and are not to be pinned.","TestNeeded","Audit.Tests.ps1:109-110 reads the in-memory SACL with .NET and :122-136 assert type, Sid, InheritanceEnabled and the unchanged access protection; SecurityDescriptor.Tests.ps1:124-126 asserts after Set-NTFSSecurityDescriptor that the owner is kept and the entry exists; PermissionScopes.Tests.ps1:156 asserts the item is untouched until written. BoundBy 8 = scan 5 + PermissionScopes:146 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only).","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:154 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it","exceptions from the change itself (open item 1)","MaintainerDecision (open item)"
"audit","Remove-NTFSAudit","PathComplex","True","7","2","1","10","Yes","Yes","No","Yes","Yes","Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:361 Should keep an audit entry that does not match exactly, given the path | Audit.Tests.ps1:371 Should remove an audit entry that matches exactly, given the path | Audit.Tests.ps1:384 Should return the audit entries of the item, not its access entries","2 (NTFSSecurity.Live.Tests.ps1:357, 398): SMB share with domain accounts; owner kept; the delegated account gets a RemoveAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441)","No test pipes paths or objects in, removes for several accounts, asserts the result of a succeeding path after a failing one, or removes only some rights (without -RemoveSpecific). An item without SACL is tested for no error only (Audit.Tests.ps1:406), and the owner retry cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:631-669 and :672-679 assert ReadFileError/OpenError/target (RemoveAceError/WriteError/target as a basic user), the SACL changed with no rule left, and unchanged DACL/owner SDDL; :363-365 and :373-374 read back through Get-NTFSAudit. BoundBy 10 = scan 7 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124; :386-388 assert type and the other entry but pass even if nothing was removed.","Partly","ParameterSets.Audit.Tests.ps1:225 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:286 Should narrow an entry that grants more rights than it removes, instead of deleting it","removing for several accounts in one call; state (empty Audit SDDL, unchanged DACL) of an item without a SACL; the owner retry after access denied","budget; budget; Limit (needs a lab or a remote server)"
"audit","Remove-NTFSAudit","PathSimple","False","0","0","1","1","Partly","No","No","No","Partly","PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","Only one data-driven call binds it: no failing item, pipeline input, several items, or owner and DACL check after the call, the objects are checked by Sid only, and it never runs without -RemoveSpecific.","TestNeeded","PermissionScopes.Tests.ps1:159 binds it only when Source=Path and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone from -PassThru, that the other account remains, and that Get-NTFSAudit returns nothing for the account. BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set.","Closed","ParameterSets.Audit.Tests.ps1:225 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:304 Should remove the entry from the path when -Path, -Account, -AccessRights, and -AppliesTo are all named directly","",""
"audit","Remove-NTFSAudit","SDSimple","False","0","0","1","1","Partly","No","No","No","Partly","PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","Only one data-driven call binds it: the changed descriptor is read only through -PassThru and Get-NTFSAudit, the item being untouched after the removal is not asserted, and no test makes it fail, pipes or passes several descriptors, or runs without -RemoveSpecific.","TestNeeded","PermissionScopes.Tests.ps1:159 binds it only when Source=SecurityDescriptor and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone, that the other account remains, and that Get-NTFSAudit returns nothing; the SACL on disk is compared only after the Add (:156). BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set.","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:256 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:321 Should remove the entry from the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly","the item on disk being untouched after the removal, until Set-NTFSSecurityDescriptor writes it","budget"
"audit","Remove-NTFSAudit","SDComplex","False","2","0","1","5","Partly","Partly","No","No","Partly","Audit.Tests.ps1:347 Should keep an audit entry that does not match exactly | Audit.Tests.ps1:353 Should remove an audit entry that matches exactly | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries | PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","The item being untouched after the removal and the result after Set-NTFSSecurityDescriptor are not asserted, the error test lacks category and target, and no test pipes or passes several descriptors, checks the -PassThru type, or asserts a removal without -RemoveSpecific. Exceptions of the change itself are open item 1 and are not to be pinned.","TestNeeded","Audit.Tests.ps1:349 and :355 read the in-memory SACL with .NET (non-matching entry kept, matching entry removed) and :427-432 assert one ReadSecurityError, no output and the SACL still empty; PermissionScopes.Tests.ps1:161-163 assert by Sid only. BoundBy 5 = scan 2 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only).","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:256 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry","the item on disk untouched after the removal and the result after Set-NTFSSecurityDescriptor; the -PassThru output type; exceptions from the change itself (open item 1)","budget; budget; MaintainerDecision (open item)"
"audit","Clear-NTFSAudit","Path","True","3","1","0","5","Yes","Yes","No","Yes","NA","Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:455 Should remove the audit entries and keep the owner | Audit.Tests.ps1:478 Should write no error and leave the access entries unchanged | Audit.Tests.ps1:495 Should write an error and leave the item unchanged","2 (NTFSSecurity.Live.Tests.ps1:652, plus :684 through & $Command that the scan cannot see): SMB share; explicit entry cleared with the inherited entry and the owner kept; the delegated account gets a ClearAclError that names the missing privilege and leaves the SDDL unchanged; the file server checks the SACL (:1453)","-DisableInheritance on a path is passed (Audit.Tests.ps1:629) but its end state (protected SACL, no copied inherited entries) is never asserted, and no test pipes paths or asserts the result of a succeeding path after a failing one. The owner retry after access denied cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:457-459 asserts no error, owner kept (.NET) and no entry left (Get-NTFSAudit); :480-483 and :497-499 assert an unchanged DACL and, without the privilege, a ClearAclError with an unchanged SDDL; :631-669 and :672-679 add category and target. BoundBy 5 = scan 3 + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124.","Partly","ParameterSets.Audit.Tests.ps1:339 Should clear the audit entries of each path taken from the pipeline and leave the DACL of each unchanged | ParameterSets.Audit.Tests.ps1:360 Should protect the SACL and not copy the parent's inherited entry when clearing a child path","the result of a succeeding path that follows a failing one; the owner retry after access denied","budget; Limit (needs a lab or a remote server)"
"audit","Clear-NTFSAudit","SD","False","2","0","0","3","Yes","Partly","No","No","NA","Audit.Tests.ps1:696 Should clear and protect the descriptor SACL without writing the <Type> | SecurityDescriptorSets.Tests.ps1:107 Clear-NTFSAudit should remove the explicit audit entries of the descriptor | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries","0","No test pipes descriptors or passes several (one without audit entries), and the error test asserts the ErrorId but not category or target.","TestNeeded","Audit.Tests.ps1:698-705 asserts the in-memory SACL cleared and protected (.NET), the SACL of the item untouched until Set-NTFSSecurityDescriptor, then the state on disk and an unchanged DACL; SecurityDescriptorSets.Tests.ps1:109-112 asserts the same for the unprotected form. BoundBy 3 = scan 2 + & $Command at Audit.Tests.ps1:425 (error case only).","Closed","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:381 Should clear each piped descriptor that has an audit section and continue past one that does not","",""
"audit","Get-NTFSAudit","Path","False","24","4","2","27","NA","Partly","No","Partly","Partly","Audit.Tests.ps1:529 Should name the folder that an inherited entry comes from, also with -ExcludeExplicit | Audit.Tests.ps1:48 Should write an error without the Security privilege instead of returning nothing | PathErrors.Tests.ps1:124 <Command> should write a ReadFileError for it and continue with the next path | Inheritance.Tests.ps1:387 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged","4 (NTFSSecurity.Live.Tests.ps1:336, 373, 656, 657): SMB share with domain accounts; Sid, AuditFlags and rights of the entry; the delegated account gets a ReadSecurityError that names the missing privilege","No test pipes paths or FileInfo/DirectoryInfo into it, asserts the category of its errors or the target of ReadSecurityError, or (in unit tests) the type, AuditFlags and inheritance flags of the output. No unit test has a failing path followed by a path whose entries are asserted (Audit.Tests.ps1:70-73 documents that the second path of the test at :80 no longer fails), and the PermissionDenied branch cannot run on a local volume (Limit).","TestNeeded","Audit.Tests.ps1:50-52 asserts one ReadSecurityError by ErrorId only (basic user); :531-534 and :577-578 assert IsInherited and InheritedFrom; PathErrors.Tests.ps1:130-132 asserts ReadFileError and target for a missing path but discards the output (:124). BoundBy 27 = scan 24 + PermissionScopes:163 (26 of 52 cases) + & $Command at PathErrors.Tests.ps1:124 and Owner.Tests.ps1:98 (no -Path, Should -Not -Throw).","Partly","ParameterSets.Audit.Tests.ps1:410 Should return the entries of the existing path in either position and a ReadFileError, category OpenError, for the missing one | ParameterSets.Audit.Tests.ps1:439 Should return the entries of each path object taken from the pipeline by value | ParameterSets.Audit.Tests.ps1:454 Should write a ReadSecurityError with category OpenError and the path as target without the Security privilege","the PermissionDenied category branch of ReadSecurityError","Limit (needs a lab or a remote server)"
"audit","Get-NTFSAudit","SD","False","1","0","2","3","NA","Partly","Partly","No","Partly","Audit.Tests.ps1:61 Should write an error for a security descriptor that was read without the audit entries | SecurityDescriptorSets.Tests.ps1:160 Get-NTFSAudit should return the audit entries that it returns for the path | PermissionScopes.Tests.ps1:163 Should add and remove <Name> using <Form> on <Source>, preserving the other account","0","The output is compared only with the output of the Path set (no expected type, flags or values), at most one descriptor is piped, and no test passes several descriptors (one without audit entries). The error test lacks category and target.","TestNeeded","Audit.Tests.ps1:63-65 asserts no output and one ReadSecurityError; SecurityDescriptorSets.Tests.ps1:160-163 pipes one descriptor and asserts one entry equal to the Path result (Sid, AccessRights, AuditFlags); PermissionScopes.Tests.ps1:163 asserts only emptiness after a removal. BoundBy 3 = scan 1 + SecurityDescriptorSets:160 (piped by value, so SD) + PermissionScopes:163 (26 of 52 cases).","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:468 Should return the entries of the piped descriptor that has an audit section and continue past one that does not","an expected type, flags, or values for the output, independent of comparing it to the Path set's output","budget"
"audit","Get-NTFSOrphanedAudit","Path","False","9","1","2","9","NA","Partly","No","Yes","Yes","Audit.Tests.ps1:228 Should return one object per entry whose account cannot be resolved | Audit.Tests.ps1:250 Should return an inherited entry, and nothing with -ExcludeInherited | Audit.Tests.ps1:279 Should write an error for a path that does not exist and continue with the next path without the Security privilege | Audit.Tests.ps1:304 Should write a ReadSecurityError without the Security privilege instead of returning nothing","1 (NTFSSecurity.Live.Tests.ps1:843): SMB share; the entry of a deleted domain account is returned with its SID, without error or warning","No test pipes paths into it, asserts the category of ReadError or ReadSecurityError, or runs -ExcludeExplicit, and the elevated continuation test passes on an empty result (Audit.Tests.ps1:273).","TestNeeded","Audit.Tests.ps1:230-232, :238-239 and :253-256 assert count, type, Sid and IsInherited; :282-286 (basic user) asserts ReadError for the missing path and a ReadSecurityError with its own target for the next path, which shows that the cmdlet continued, while :270-273 (elevated) asserts one error and then only a ForEach over the result. BoundBy 9 = scan 9.","Partly","ParameterSets.Audit.Tests.ps1:490 Should return the orphaned entries of each path taken from the pipeline and write a ReadError, category OpenError, for one that does not exist","the category of ReadSecurityError without the Security privilege; -ExcludeExplicit","budget; budget"
"audit","Get-NTFSOrphanedAudit","SD","False","0","0","2","2","NA","Partly","Partly","No","Partly","Audit.Tests.ps1:243 Should read the entries of a security descriptor | Audit.Tests.ps1:294 Should write an error for a security descriptor that was read without the audit entries","0","At most one descriptor is piped and none is passed in an array, so continuation is untested; -Account and -Exclude* with a descriptor, the entry type and Sid, and the category and target of the error are not asserted.","TestNeeded","Both calls pipe one descriptor, which PowerShell binds by value to -SecurityDescriptor (the elevated run of :296-298 proves it: a Path binding would return entries): :245-246 assert 2 entries with FullName and :296-298 assert no output and one ReadSecurityError. BoundBy 2 = the two ambiguous piped calls (Audit.Tests.ps1:243 and :294); the scan found 0.","Partly","ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:511 Should return the orphaned entries of the piped descriptor that has an audit section and continue past one that does not | ParameterSets.Audit.Tests.ps1:533 Should return the orphaned entries when -SecurityDescriptor is named directly","-Account and -ExcludeInherited/-ExcludeExplicit filters with a descriptor","budget"
"inheritance","Disable-NTFSAccessInheritance","Path","True","9","1","0","16","Partly","Partly","No","Partly","Yes","Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:301 Disable-NTFSAccessInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:133 <_> should write an error and return nothing when the security descriptor cannot be read","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:281-289: no error, owner Administrators kept, DACL protected by Get-Acl)","Not asserted: the error category (OpenError, WriteError), piped input (documented: Get-ChildItem2 | Disable-NTFSAccessInheritance -PassThru), a .NET readback of the kept or removed inherited entries (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given.","TestNeeded","Inheritance.Tests.ps1:341-360 asserts the -PassThru object (type, FullName, flag) and reads flag, owner and entries back only with Get-NTFSInheritance, Get-NTFSOwner and Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:307-309 and 183-191, DriveRoot.Tests.ps1:113). Errors: PathErrors.Tests.ps1:110-112 and 180-182 assert ErrorId and target, never the category; no test pipes into the cmdlet. BoundBy 16 = scan 9 (6 are fixtures) + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:178 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget"
"inheritance","Disable-NTFSAccessInheritance","SecurityDescriptor","False","1","0","0","2","Yes","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:71 Disable-NTFSAccessInheritance should protect the DACL of the descriptor and keep the inherited entries | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type>","0","Not asserted: -RemoveInheritedAccessRules with a descriptor, the owner after the write, and several descriptors (array or pipeline). The set has no per-item handler, like the sets of open item 1 (which does not name it), but it cannot fail on a descriptor from Get-NTFSSecurityDescriptor.","TestNeeded","SecurityDescriptorSets.Tests.ps1:79-84 asserts the in-memory flag, the item unchanged before the write (Get-Acl), and after Set-NTFSSecurityDescriptor the flag and an explicit count equal to the inherited count (.NET); Inheritance.Tests.ps1:557-562 asserts count, FullName and flag of the -PassThru object. BoundBy 2 = scan 1 + Inheritance:555 (& $Command -SecurityDescriptor).","Partly","ParameterSets.Inheritance.Tests.ps1:255 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","the owner unchanged after the descriptor write","budget"
"inheritance","Enable-NTFSAccessInheritance","Path","True","3","1","0","10","Partly","Partly","No","Partly","Yes","Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:312 Enable-NTFSAccessInheritance should take ownership, let the DACL inherit, and set the owner back | DriveRoot.Tests.ps1:110 Should block and restore the access inheritance of the folder that the drive maps","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:291-299: no error, owner kept, DACL inherits again by Get-Acl)","Not asserted: the error category, piped input (documented: Get-NTFSInheritance output piped into Enable-NTFSAccessInheritance -RemoveExplicitAccessRules), a .NET readback of explicit and inherited entries after the call (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given.","TestNeeded","Inheritance.Tests.ps1:341-360 (Enable cases) asserts the object and reads re-inherited and explicit entries back only with Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:319-321 and 190-191, DriveRoot.Tests.ps1:117). Errors as for Disable: ErrorId and target (PathErrors.Tests.ps1:110-112, 180-182), no category; no piped input. BoundBy 10 = scan 3 + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:178 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget"
"inheritance","Enable-NTFSAccessInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:87 Enable-NTFSAccessInheritance should let the DACL of the descriptor inherit | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type>","0","Not asserted: -RemoveExplicitAccessRules with a descriptor, that an explicit entry survives a plain Enable (the test descriptor has none), and several descriptors (array or pipeline). The set works in memory, so it has no error path or handler to test.","TestNeeded","SecurityDescriptorSets.Tests.ps1:94-99 asserts the in-memory flag, the item still protected, then (.NET) the flag false and inherited entries present after the write; the descriptor has no explicit entry, so kept versus removed is unasserted. Inheritance.Tests.ps1:557-562 (Enable cases) asserts count, FullName and flag. BoundBy 2 = scan 1 + Inheritance:555.","Closed","ParameterSets.Inheritance.Tests.ps1:255 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","",""
"inheritance","Disable-NTFSAuditInheritance","Path","True","7","1","0","15","Partly","Yes","No","Yes","Yes","Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | Inheritance.Tests.ps1:113 <_> should return nothing when the audit change fails","2 (SMB: Admin and ServerAdmin write it and the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:632 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690)","Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit; the lab does, NTFSSecurity.Live.Tests.ps1:1453-1458), no test pipes into the set (documented: Get-ChildItem2 -Directory | Disable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY).","TestNeeded","Audit.Tests.ps1:629-679 runs two paths with -PassThru: as a basic user ModifySdError/WriteError/target then ReadFileError/OpenError/target and an empty result (672-679), elevated the object flag, the explicit SACL rules and the unchanged DACL and owner (631, 654-657). Inheritance.Tests.ps1:401-419 reads the SACL back only through Get-NTFSInheritance and Get-NTFSAudit (the DACL through .NET at 405). BoundBy 15 = scan 7 + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629).","Partly","ParameterSets.Inheritance.Tests.ps1:220 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write","budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target"
"inheritance","Disable-NTFSAuditInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type> | Inheritance.Tests.ps1:276 Should add no SACL to a security descriptor that was read without its audit entries","0","Not asserted: -RemoveInheritedAuditRules with a descriptor, an independent SACL readback after the write, the owner and DACL after the write, and several descriptors. The set accepts a descriptor without audit entries silently (pinned for Disable at Inheritance.Tests.ps1:276), unlike Add, Remove and Clear-NTFSAudit; see the notes.","TestNeeded","Inheritance.Tests.ps1:579-585 (elevated only) asserts count, FullName and flag of the object, the SACL SDDL unchanged until Set-NTFSSecurityDescriptor, and the flag after it, all through module cmdlets; :284-286 asserts that no SACL is added to a descriptor read without audit entries. BoundBy 2 = scan 1 (Inheritance:282) + Inheritance:577 (& $Command -SecurityDescriptor).","Partly","ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","-RemoveInheritedAuditRules with a descriptor as its own dedicated state test; the owner and DACL unchanged after the write","budget; budget"
"inheritance","Enable-NTFSAuditInheritance","Path","True","1","1","0","9","Partly","Yes","No","Yes","Yes","Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | PathErrors.Tests.ps1:118 <Command> should write a ReadFileError for it and continue with the next path","2 (SMB: the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:642 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690)","Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit), the result of -RemoveExplicitAuditRules is read back only with Get-NTFSAudit, no test pipes into the set (documented: Get-NTFSInheritance output piped into Enable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY).","TestNeeded","Audit.Tests.ps1:660-662 (elevated) asserts the flag true and the explicit rules removed, and :672-679 the errors as a basic user; Inheritance.Tests.ps1:259-260 and 270-272 cover an item without SACL (flag by Get-NTFSInheritance, DACL by .NET). SACL state is never read with .NET in a unit test. BoundBy 9 = scan 1 (PipelineControl:284) + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629).","Partly","ParameterSets.Inheritance.Tests.ps1:220 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru","the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write","budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target"
"inheritance","Enable-NTFSAuditInheritance","SecurityDescriptor","False","1","0","0","2","Partly","NA","No","NA","Yes","SecurityDescriptorSets.Tests.ps1:115 Enable-NTFSAuditInheritance should let the SACL of the descriptor inherit | Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type>","0","Not asserted: -RemoveExplicitAuditRules with a descriptor, that an explicit audit entry survives a plain Enable, an independent SACL readback after the write, and several descriptors. Enable with an access-only descriptor is pinned only through Set-NTFSInheritance (Inheritance.Tests.ps1:524-539).","TestNeeded","SecurityDescriptorSets.Tests.ps1:119-126 (elevated) asserts the in-memory flag, the item still protected (Get-NTFSInheritance) and the flag after the write; Inheritance.Tests.ps1:579-585 (Enable cases) asserts count, FullName and flag. Nothing reads the SACL with .NET. BoundBy 2 = scan 1 + Inheritance:577.","Partly","ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor","-RemoveExplicitAuditRules with a descriptor as its own dedicated state test; an explicit audit entry surviving a plain Enable","budget; budget"
"inheritance","Get-NTFSInheritance","Path","True","23","4","0","27","NA","Partly","No","Partly","Partly","PathErrors.Tests.ps1:104 <Command> should write a <ErrorId> for it and continue with the next path | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:54 Should report the same state as for the path of the item","4 (SMB: protected DACL with inherited audit flag, NTFSSecurity.Live.Tests.ps1:661-666; null audit state without the Security privilege, :695-700; two of the four calls are read-backs, :636 and :646)","Not asserted: FullName, Name, type or exact count of the output, a protected state created without the module (all protected states come from the module's own cmdlets), the error category, piped input (documented: Get-ChildItem2 | Get-NTFSInheritance), and the result for no -Path (documented: current location; Owner.Tests.ps1:92 asserts -Not -Throw only). [Limit] The documented ownership retry has no success path on a local volume.","TestNeeded","Inheritance.Tests.ps1:58-59, 74-75 and 88-90 assert only the flags (the descriptor result equals the -Path result; audit false after Disable-NTFSAuditInheritance), no FullName, type or count. PathErrors.Tests.ps1:110-115 and 147-152 assert ErrorId, target and non-empty output for the next path, no category. BoundBy 27 = scan 23 + 4 calls through & $Command or & $_ (PathErrors:108,145; Owner:98; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:385 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:564,573 Get-NTFSInheritance should take piped folder objects from Get-ChildItem2 and a piped custom object by its FullName property","the Name property of the output; a protected state created without the module; the result for no -Path; a successful ownership-retry read","budget; budget; budget; Limit, no local volume reaches the success path"
"inheritance","Get-NTFSInheritance","SecurityDescriptor","False","4","0","0","4","NA","NA","No","NA","Partly","Inheritance.Tests.ps1:54 Should report the same state as for the path of the item | Inheritance.Tests.ps1:65 Should report the same state as for the path of a <Type> without audit entries | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:93 Should report the audit inheritance as $null for a security descriptor without the audit entries","0","Not asserted: FullName, Name, type, exact count, several descriptors, a protected descriptor created without the module, and piped descriptors (documented: Get-NTFSSecurityDescriptor | Get-NTFSInheritance). The set works in memory and cannot fail on a readable descriptor.","TestNeeded","Inheritance.Tests.ps1:58-59, 74-75, 88-90 and 100-101 compare the flags with the -Path result and assert a null audit state for an access-only descriptor; none asserts FullName, Name, type, count or several descriptors. BoundBy 4 = scan 4.","Partly","ParameterSets.Inheritance.Tests.ps1:586,596 Get-NTFSInheritance -SecurityDescriptor should take two piped descriptors, one protected, and report both in order","the type of the output (BeOfType); a protected descriptor created without the module","budget; budget"
"inheritance","Set-NTFSInheritance","Path","True","14","1","0","18","Partly","Partly","No","Partly","Partly","Inheritance.Tests.ps1:164 Should keep the inherited access entries as explicit ones when it disables access inheritance | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:324 Set-NTFSInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:422 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry","1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:302-309: DACL protected, owner kept)","No test pipes into the set, including the documented round trip (Get-NTFSInheritance output piped into Set-NTFSInheritance, which binds both flags by property name); the SACL and the access-enable direction are read back only through module cmdlets. Also not asserted: the error category, the FullName of the -Path -PassThru object, RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op without -Path.","TestNeeded","Inheritance.Tests.ps1:173-175 (.NET flag and explicit count), 428-433 (object, entries, DACL unchanged by .NET) and PathErrors.Tests.ps1:330-332 and 180-191 (owner, denied item unchanged, next item protected) are the strongest; the SACL and the access-enable direction are read back only with module cmdlets (Inheritance.Tests.ps1:371-373, 431-432). Inheritance.Tests.ps1:127-130 asserts no object after a failed audit change for one item, as a basic user only. BoundBy 18 = scan 14 + 4 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:268; Privileges:123).","Partly","ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:609 Set-NTFSInheritance should restore a saved inheritance state through the pipeline by property name","an independent SACL readback of the result; OpenError category for a path that does not exist; the documented no-op without -Path","budget; budget; budget"
"inheritance","Set-NTFSInheritance","SecurityDescriptor","False","5","0","0","5","Partly","NA","No","NA","Yes","Inheritance.Tests.ps1:465 Should set access inheritance enabled=<Enable> on a <Type> only when the descriptor is written | Inheritance.Tests.ps1:494 Should set audit inheritance enabled=<Enable> on a <Type> without changing its DACL or owner | Inheritance.Tests.ps1:524 Should keep audit inheritance unknown when requested enabled=<_> on an access-only descriptor | Inheritance.Tests.ps1:180 Should keep the inherited access entries of a security descriptor","0","Not asserted: several descriptors (array or pipeline), a single call that sets both -AccessInheritanceEnabled and -AuditInheritanceEnabled, and an independent SACL readback after the write (the audit side uses module cmdlets). The set works in memory and cannot fail on a readable descriptor.","TestNeeded","Inheritance.Tests.ps1:481-491 asserts count, FullName, Name, flag, the item unchanged until Set-NTFSSecurityDescriptor, then flag and owner by .NET and the explicit entry; :511-521 (elevated) does the audit side through module cmdlets; :533-539 asserts a null audit state and no SACL for an access-only descriptor. BoundBy 5 = scan 5.","Closed","ParameterSets.Inheritance.Tests.ps1:288 Set-NTFSInheritance -SecurityDescriptor should set both inheritance flags in one call, changing only the in-memory descriptor until it is written | ParameterSets.Inheritance.Tests.ps1:621,638 Set-NTFSInheritance -SecurityDescriptor should protect both descriptors in memory, written only by Set-NTFSSecurityDescriptor, piped and passed directly to the parameter","",""
"inheritance","Get-NTFSOwner","Path","True","22","4","3","26","NA","Partly","Partly","Partly","Yes","Owner.Tests.ps1:47 Should write one permission error and keep the owner | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | DriveRoot.Tests.ps1:45 Get-NTFSOwner should return the owner of the root folder | ObjectApis.Tests.ps1:725 Should name the item and the account of an owner object","4 (SMB: owner Administrators, NTFSSecurity.Live.Tests.ps1:585-589; three calls check that the privileges are disabled after a later command ends the pipeline, :1406, 1411, 1422)","No test asserts ErrorId, category and target together (Owner.Tests.ps1:55-56 id and category, PathErrors.Tests.ps1:148-149 id and target); piping covers one FileInfo only (documented: Get-ChildItem2 -Recurse | Get-NTFSOwner); the next item's output is asserted only as non-empty; the documented 'returns nothing' without -Path is untested.","TestNeeded","Owner.Tests.ps1:53-56 asserts no output, one error, ReadSecurityError and PermissionDenied (basic user only, skipped with the Backup privilege); PathErrors.Tests.ps1:147-151 asserts id, target and non-empty output for the next path; DriveRoot.Tests.ps1:46 compares Owner.Sid with Get-Acl; ObjectApis.Tests.ps1:730-732 (line numbers at HEAD 6696f68; +19 in a work tree with the uncommitted ObjectApis edit) asserts Item, FullName and Account. BoundBy 26 = scan 22 + ambiguous Owner:177 and :185 (both bind Path) + PathErrors:108,145.","Partly","ParameterSets.Inheritance.Tests.ps1:400 Get-NTFSOwner should write a ReadSecurityError with its id, category, and target together for a denied item, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:652 Get-NTFSOwner should take two piped folders from Get-ChildItem2 and return the owner of each, verified with Get-Acl","the documented 'returns nothing' without -Path","budget"
"inheritance","Get-NTFSOwner","SecurityDescriptor","False","0","0","3","1","NA","NA","Partly","NA","Partly","SecurityDescriptorSets.Tests.ps1:146 Get-NTFSOwner should return the owner that it returns for the path","0","One test, one descriptor; the owner is compared with the -Path result of the same cmdlet, with no .NET oracle, no type assertion and no several descriptors. The result for a descriptor read without its Owner section is unexercised (see the notes).","TestNeeded","The scan's ambiguous rows Owner.Tests.ps1:177 (System.IO DirectoryInfo by position) and :185 (System.IO FileInfo piped) bind Path: FileSystemPathTransformation turns a file system object into its path, and those types do not convert to FileSystemSecurity2[]. Only SecurityDescriptorSets.Tests.ps1:149-153 binds the set: a FileSystemSecurity2 piped by value, asserting count 1, Owner.Sid against the -Path result and FullName. BoundBy 1 (scan 0 + that call).","Partly","ParameterSets.Inheritance.Tests.ps1:676,686 Get-NTFSOwner -SecurityDescriptor should return the owner of each descriptor, piped and passed directly to the parameter, verified with Get-Acl","the result for a descriptor read without its Owner section","budget, a read-only probe just now shows it returns the item's real owner, not a crash, so it is safely testable and simply was not written"
"inheritance","Set-NTFSOwner","Path","True","8","4","1","10","Partly","Partly","Yes","Partly","Yes","Owner.Tests.ps1:240 Should set an owner that only the Restore privilege allows | Owner.Tests.ps1:232 Should take the items from the pipeline | Owner.Tests.ps1:270 Should write a SetOwnerError and keep the owner | Owner.Tests.ps1:248 Should write a read error for a path that does not exist and continue with the next path","4 (SMB: take ownership as the account itself, assign another account only with the file server's Restore privilege (SetOwnerError for the delegated account), NTFSSecurity.Live.Tests.ps1:595 and 604; a later command that stops the pipeline leaves the second item's owner unchanged, :1143, 1182)","Not asserted: DACL, SACL and group unchanged after the owner changes; as a basic user the owner already equals the user, so Owner.Tests.ps1:217, 229 and 256 cannot show a change; the error category and target (SetOwnerError); -PassThru with a failing item among several; and the documented no-op without -Path.","TestNeeded","Owner.Tests.ps1:245 (.NET owner is TrustedInstaller, needs the Restore privilege), :225-229 (count, type, FullName, Owner.Sid, .NET owner), :237 (two piped Get-Item2 objects) and :277-279 (SetOwnerError id only, owner unchanged). The scan's ambiguous Owner:235 binds Path (the Get-Item2 objects bind by their FullName property). BoundBy 10 = scan 8 + Owner:235 + PathErrors:108.","Partly","ParameterSets.Inheritance.Tests.ps1:314 Set-NTFSOwner should change only the owner and leave the Access entries and the group unchanged | ParameterSets.Inheritance.Tests.ps1:427,444 Should write <ErrorId> with its category and target for <Scenario>, and keep processing the remaining path","the SACL unchanged after the owner changes; the documented no-op without -Path","budget; budget"
"inheritance","Set-NTFSOwner","SecurityDescriptor","False","2","0","1","2","Partly","NA","No","NA","Partly","Owner.Tests.ps1:284 Should change only the descriptor in memory until Set-NTFSSecurityDescriptor writes it | Owner.Tests.ps1:303 Should write nothing without -PassThru and leave the owner of the item unchanged","0","The persisted-owner test is skipped for basic users (Owner.Tests.ps1:287-290); not asserted: DACL unchanged after the write, FullName and type of the -PassThru object (only the -Path set asserts them), and several descriptors (array or pipeline).","TestNeeded","Owner.Tests.ps1:296-300 asserts count, Owner.Sid, the item's owner unchanged until Set-NTFSSecurityDescriptor and changed after (.NET), but the test is skipped when the user owns new items (:287-290); :312-314 asserts no output without -PassThru, the in-memory owner and the item's owner unchanged. BoundBy 2 = scan 2.","Partly","ParameterSets.Inheritance.Tests.ps1:698,713 Set-NTFSOwner -SecurityDescriptor should change both owners in memory without touching the items, piped and passed directly to the parameter","the DACL unchanged after the write; the type of the -PassThru object (BeOfType)","budget; budget"
"inheritance","Get-NTFSSecurityDescriptor","__AllParameterSets","False","79","5","0","82","NA","Partly","No","Partly","Yes","SecurityDescriptor.Tests.ps1:52 Should report the inherited access entries as inherited | SecurityDescriptor.Tests.ps1:63 Should read the owner and the audit entries with the access entries | DriveRoot.Tests.ps1:39 Get-NTFSSecurityDescriptor should read the DACL of the root folder | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path","5 (SMB read-backs for the descriptor tests, NTFSSecurity.Live.Tests.ps1:315, 965, 1150, and InheritedFrom of a vanished item, :988, 1017)","Untested combinations: piped paths and file or folder objects (documented: Get-ChildItem2 | Get-NTFSSecurityDescriptor), no -Path (current location; Owner.Tests.ps1:92 asserts -Not -Throw only), the error category, and that the next item yields exactly one descriptor. [Limit] The documented ownership retry has no success path on a local volume.","TestNeeded","SecurityDescriptor.Tests.ps1:59-60 (inherited flags against the Get-Acl count) and :70-71 (owner against Get-Acl, audit rules) need the Security privilege; DriveRoot.Tests.ps1:42 compares the DACL SDDL with Get-Acl; PathErrors.Tests.ps1:110-115 and 147-152 assert ReadFileError and ReadSecurityError with target and non-empty output. BoundBy 82 = scan 79 + 3 calls through & $Command or & $_ (PathErrors:108,145; Owner:98).","Partly","ParameterSets.Inheritance.Tests.ps1:385 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:727,738,745 Get-NTFSSecurityDescriptor should take piped folder objects, a standard Get-Item object, and a piped custom object by its Path property","the result for no -Path (current location); a successful ownership-retry read","budget; Limit, no local volume reaches the success path"
"inheritance","Set-NTFSSecurityDescriptor","__AllParameterSets","False","29","4","0","29","Yes","Yes","Yes","Yes","Yes","SecurityDescriptor.Tests.ps1:299 Should report a denied write, return no failed item, and write the next descriptor | SecurityDescriptor.Tests.ps1:249 Should report RestoreOwnerError for a previous owner that it cannot set back after the write | SecurityDescriptor.Tests.ps1:213 Should return the written descriptor with -PassThru also when it took ownership for the write | SecurityDescriptor.Tests.ps1:133 Should not write back the access entries of an unchanged descriptor","4 (SMB: writes the added entry and keeps the owner, NTFSSecurity.Live.Tests.ps1:317; writes the cleared DACL without RestoreOwnerError, :968; a later command that stops the pipeline leaves the second descriptor unwritten, :1154, 1165)","Untested combinations: positional binding (declared Position 2), the by-property-name pipeline form, and the category and target of the -PassThru ReadSecurityError (only its ErrorId is asserted, SecurityDescriptor.Tests.ps1:361). [Limit] A failing SACL write needs a lab.","None","SecurityDescriptor.Tests.ps1:308-317 pipes two descriptors with -PassThru and asserts WriteSdError, category WriteError, target, the denied item's SDDL unchanged (.NET), one object for the next item and its entry; :259-264 asserts RestoreOwnerError with category and target; :223-226 asserts the -PassThru object after an ownership retry. BoundBy 29 = scan 29 (no calls through variables).","None","","positional binding at Position 2; the by-property-name pipeline form; category and target of the -PassThru ReadSecurityError","would-pin, Position 2 vs siblings' Position 1 looks like an undecided inconsistency per the notes; budget, row judged GapKind None; budget, row judged GapKind None"
"items","Copy-Item2","__AllParameterSets","False","6","4","0","20","Yes","Yes","No","Yes","Partly","ItemCmdlets.Tests.ps1:756 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:785 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:605 <_> should write DestinationFileAlreadyExists for a folder that exists at the destination and change nothing | ItemCmdlets.Tests.ps1:644 Copy-Item2 -Force should copy a folder into an existing folder of the same name and replace the files in both","4: -WhatIf onto an existing file on a share (#108, administrator); copy of a file and a folder as the delegated account; later-command stop on a share","No test pipes paths into it (documented: Get-ChildItem2 | Copy-Item2 -Destination), passes an empty or null -Path, a FileInfo object, a path with brackets, a path over 260 characters or a drive root, and -Force replacing an existing file is covered only through the folder merge. FileNotFound and the file case of DestinationFileAlreadyExists are asserted by error count only, and -PassThru asserts FullName but not the output type or that nothing is written without it.","TestNeeded","ItemCmdlets.Tests.ps1:756-771 and :785-797 assert ErrorId, category, target, exception type, only the second item's result and untouched sources; :605-613 and :644-649 read the folder conflict and the merge back; Owner.Tests.ps1:160-163 reads the copied content. 14 of the 20 call sites are '& $Command' calls in ItemCmdlets.Tests.ps1 (lines 514 to 814) that the scan does not resolve.","Partly","ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location","a path with brackets; a path over 260 characters; a drive root; -Force replacing an existing file (still only covered through the folder merge); the file case of DestinationFileAlreadyExists with category/target (still error count only); -PassThru output type; that nothing is written without -PassThru","budget (all items; none needs a lab, none pins an open maintainer decision)"
"items","Get-ChildItem2","__AllParameterSets","False","34","8","0","36","NA","Yes","No","Yes","Yes","ItemCmdlets.Tests.ps1:98 Should apply <Case> without broadening the other attribute filters | ItemCmdlets.Tests.ps1:137 Should return the exact tree for <Case> | ItemCmdlets.Tests.ps1:282 Should report the denied folder and continue with the next path | ItemCmdlets.Tests.ps1:340 Should report a junction whose target was removed as a DirUnspecifiedError and continue with the next folder","8: over SMB: path over 260 characters (administrator), -Hidden and a listing (delegated account), -Filter cases, later-command stop with a denied nested folder","No test pipes folders or strings into -Path (documented by value and by FullName), asserts the result of omitting -Path or of a relative -Path (Owner.Tests.ps1:98 only asserts no throw), or lists a drive root or a path over 260 characters in a unit test. -Directory with -File, -Attributes with -Force/-Hidden/-System/-ReadOnly (documented: ignored), -Depth without -Recurse and the dir2 alias are unasserted, and FileNotFound and AttributesEmpty are asserted without category (and without target for AttributesEmpty); the -Filter dot rules are pinned already and are the maintainer's, so they are not counted here.","TestNeeded","ItemCmdlets.Tests.ps1:98-100 and :137-140 assert exact name sets for ten attribute-switch cases and for the Recurse/Depth/Directory/File/Filter cases; :282-289 and :340-348 assert ErrorId, category, target (and exception type) and that the next path or sibling is still listed; :44-49 and :402-406 assert the AlphaFS types; PathErrors.Tests.ps1:108-114 covers FileNotFound (ID and target only).","Partly","ParameterSets.Items.Tests.ps1:91 Should accept piped folders by value, write one error for a path that does not exist, and list the items of the other folders | ParameterSets.Items.Tests.ps1:111 Should accept folder objects piped from Get-ChildItem2 -Directory and list only the files directly below them","the result of an omitted -Path; the result of a relative -Path; a drive root in a unit test; a path over 260 characters in a unit test; -Directory with -File together; -Attributes with -Force/-Hidden/-System/-ReadOnly; -Depth without -Recurse; the dir2 alias; AttributesEmpty category and target","budget (all items; the -Filter dot rules are the maintainer's and were already excluded from this Gap)"
"items","Get-Item2","__AllParameterSets","False","17","1","0","19","NA","Partly","No","Partly","Partly","PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path | ItemCmdlets.Tests.ps1:935 Get-Item2 should resolve <Path> against the current location | Owner.Tests.ps1:235 Should take the items from the pipeline | PipelineControl.Tests.ps1:124 <Name> should stop after the first object for Select-Object -First 1 and change nothing else","1: FullName and Length of a file on a share (delegated account)","No test pipes paths into it (documented: 'C:\Data','C:\Data\Reports' | Get-Item2) or omits -Path (documented: the current location), and the output type (FileInfo or DirectoryInfo) and the Mode property are never asserted; bracket paths, paths over 260 characters and a drive root are untested. The FileNotFound category is not asserted and the output for the next path is checked only as non-empty.","TestNeeded","PathErrors.Tests.ps1:108-114 asserts one FileNotFound error with the missing path as target and non-empty output for the next path; ItemCmdlets.Tests.ps1:935-943 asserts HaveCount 1 and FullName for six relative paths. 15 of the 17 scan calls are fixtures that feed descriptors or other cmdlets (Access, Audit, Inheritance, ObjectApis, Owner, SecurityDescriptor).","Partly","ParameterSets.Items.Tests.ps1:133 Should accept piped items by value, return each in order with its output type, and write one error for a path that does not exist","an omitted -Path defaulting to the current location; bracket paths; paths over 260 characters; a drive root","budget (all items)"
"items","Move-Item2","__AllParameterSets","False","7","3","0","21","Yes","Yes","No","Yes","Yes","ItemCmdlets.Tests.ps1:756 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:785 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:621 Move-Item2 -Force should replace an existing file with PassThru=<_> | ItemCmdlets.Tests.ps1:841 Should refuse to move <Kind> folder to another volume and leave it in place","3: -WhatIf onto an existing file on a share (administrator); move of a file as the delegated account; later-command stop on a share","No test pipes paths into it (documented), passes an empty or null -Path, moves a non-empty folder tree, or renames an item inside one folder on the same volume (the cross-volume cases need an elevated admin share), and -Force replacing a folder, bracket or wildcard paths, paths over 260 characters and a drive-root destination are untested. FileNotFound is asserted by error count only.","TestNeeded","ItemCmdlets.Tests.ps1:621-631 asserts the source is gone, the content at the destination and PassThru true and false; :576-592 asserts the moved file and folder (DirectoryInfo) and the removed source folder; :756-771 and :785-797 assert ErrorId, category, target, exception type and the other item's result. The cross-volume tests at :841-878 skip without an elevated admin share.","Partly","ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location","moving a non-empty folder tree; renaming an item in place on the same volume; -Force replacing a folder; bracket or wildcard paths; paths over 260 characters; a drive-root destination","budget (all items)"
"items","Remove-Item2","__AllParameterSets","False","15","2","0","16","Yes","Yes","No","Yes","Partly","Remove-Item2.Tests.ps1:43 Should report DeleteError for a non-empty folder without -Recurse and continue with the next path | Remove-Item2.Tests.ps1:104 Should write DeleteError when a descendant is open without delete sharing, not a successful -PassThru result | Remove-Item2.Tests.ps1:126 Should delete a junction with -Recurse without deleting or changing its target | Remove-Item2.Tests.ps1:77 Should leave a folder tree unchanged with -Recurse -Force -WhatIf and write nothing with -PassThru","2: removal of a file on a share as the delegated account; later-command stop on a share","No test pipes items into it (documented: Get-ChildItem2 ... | Remove-Item2), omits -Path (documented: the cmdlet does nothing), passes an empty or null -Path (the ValidateNotNullOrEmpty guard that keeps it from meaning the current location), passes bracket or wildcard paths (documented: literal) or uses rm2/del2. FileNotFound is asserted by error count only (ItemCmdlets.Tests.ps1:507), the access-denied branch of DeleteError (category NotSpecified) is unasserted, and that a successful removal without -PassThru writes nothing is not asserted.","TestNeeded","Remove-Item2.Tests.ps1:43-52 asserts DeleteError, InvalidData, target, kept content, the removed next item and exactly one result; :104-114 and :152-158 assert DeleteError and no success-shaped result with the content kept; :126-130 asserts the junction is removed and its target content and SDDL are unchanged; :176-184 covers the -PassThur alias.","Partly","ParameterSets.Items.Tests.ps1:157 Should accept piped items by value, write one error for a non-empty folder, remove the files, and keep the folder | ParameterSets.Items.Tests.ps1:185 Remove-Item2 should reject -Path <CaseName> instead of removing the current location","-Path omitted entirely (documented: the cmdlet does nothing); bracket or wildcard paths; the rm2/del2 aliases; FileNotFound category/target (still error count only); the access-denied DeleteError branch (category NotSpecified); that a successful removal without -PassThru writes nothing","budget (all items)"
"items","Test-Path2","__AllParameterSets","False","14","3","0","14","NA","NA","Partly","Yes","Yes","ItemCmdlets.Tests.ps1:967 Should return <Expected> for a <Kind> with -PathType <PathType> | ItemCmdlets.Tests.ps1:1009 Should return $false for a path with the character <_> and continue with the next path | ItemCmdlets.Tests.ps1:1000 Should find a folder whose path is longer than 260 characters | ItemCmdlets.Tests.ps1:981 Should take the items from the pipeline","3: file, folder and missing item with -PathType on a share (delegated account)","The pipeline test pipes one file; no test pipes several items (documented: Get-ChildItem2 -Recurse | Test-Path2 -PathType Leaf) or objects with PathType by property name, or tests a drive root, a UNC path or a bracket path. Errors are NA because the cmdlet writes $false for a missing or invalid path; its PathNotFound handler looks unreachable (see the notes).","TestNeeded","ItemCmdlets.Tests.ps1:967-972 asserts one [bool] with the expected value for file, folder and missing item under all three -PathType values; :1009-1013 asserts no error and 'False,True' for six invalid characters followed by a valid path; :981-983 pipes one FileInfo; :992-1001 covers a folder path over 260 characters.","Open","","piping several items into -Path; -PathType bound by property name; a drive root; a UNC path; a bracket path","budget (deprioritized: PipelineInput was already Partly, not No, so lower priority than the cmdlets with no pipeline test at all)"
"items","Get-FileHash2","__AllParameterSets","False","12","2","0","13","Partly","Partly","Partly","Partly","Yes","FileHash.Tests.ps1:41 Should return the hash of Get-FileHash for <_> | FileHash.Tests.ps1:94 Should skip the folder and hash the files that follow it | FileHash.Tests.ps1:108 Should write an error and no result for the file | FileHash.Tests.ps1:153 Should report both the failed read and the failed owner restoration without returning a hash","2: SHA256 equals Get-FileHash on a share (delegated account); later-command stop at the verbose message","No test pipes FileInfo/DirectoryInfo objects or folders (documented: Get-ChildItem2 -Recurse | Get-FileHash2) or Algorithm by property name, hashes a relative path or a path over 260 characters, or puts the failing path first and asserts the next hash; no error category is asserted. The owner-restore tests run only elevated and read the owner back with Get-NTFSOwner, and the retry that succeeds after taking ownership is untested.","TestNeeded","FileHash.Tests.ps1:41-44 compares Hash and Algorithm with Get-FileHash for five algorithms; :94-98 skips a folder and hashes the next file with the SHA256 default; :108-115 asserts one error and no result for a locked file; :153-160 (elevated only) asserts RestoreOwnerError and GetHashError with target, no result and the restored owner; OutputTypes.Tests.ps1:57 asserts the type name.","Partly","ParameterSets.Items.Tests.ps1:516 Should accept Get-ChildItem2 objects piped by value, skip a folder, and match Get-FileHash for each file | ParameterSets.Items.Tests.ps1:548 Should write GetHashError with its category for a locked file first, hash the file that follows it, and resolve a relative path","-Algorithm bound by property name from the pipeline; a path over 260 characters; the ownership-retry-after-taking-ownership success path","-Algorithm by property name and >260 chars: budget; ownership-retry success: Limit (elevated-only, needs a DACL/owner setup not shown buildable)"
"items","Get-DiskSpace","__AllParameterSets","False","6","0","0","6","NA","Partly","NA","No","Yes","ItemCmdlets.Tests.ps1:1038 Should return the size of the system drive | ItemCmdlets.Tests.ps1:1056 Should return the volumes with a size greater than zero without -DriveLetter | ItemCmdlets.Tests.ps1:1072 Should warn and return nothing for a drive letter without a volume | ItemCmdlets.Tests.ps1:1080 Should reject a drive letter without a colon","0","No test passes several drive letters, so the documented warn-and-continue for a letter without a volume is never combined with a valid letter; lower-case letters, positional binding and the free-space values against an independent source are unasserted. The validation error is asserted by ErrorId only (no category or target).","TestNeeded","ItemCmdlets.Tests.ps1:1038-1043 asserts type, DriveName and TotalNumberOfBytes against System.IO.DriveInfo; :1072-1077 asserts the exact warning text and no output or error for a letter without a volume; :1056-1061 asserts every volume has a size above zero and the system drive is included; :1080-1081 asserts the ErrorId of the validation error.","Partly","ParameterSets.Items.Tests.ps1:459 Should return only the system drive and warn for a drive letter without a volume, regardless of order (<Order>) | ParameterSets.Items.Tests.ps1:480 Should accept a lower-case drive letter positionally and report the same total size as .NET","the free-space values (TotalNumberOfFreeBytes/FreeBytesAvailable) against an independent source (only TotalNumberOfBytes was compared); the validation error's category and target (still ErrorId only)","budget (both items)"
"items","New-NTFSHardLink","__AllParameterSets","False","14","2","0","17","Yes","Yes","Yes","Yes","Yes","Links.Tests.ps1:134 Should write a non-terminating error for each link that it cannot create and continue with the next one | Links.Tests.ps1:170 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:67 Should return every name of the file with -PassThru | Links.Tests.ps1:79 Should give both names the same data","2: link creation on a share (administrator) and -PassThru, which writes GetHardLinkError there","Positional binding (documented example 2), a FileInfo object bound to -Path or -Target and the end of a pipeline by a later command are untested; the -PassThru GetHardLinkError on a share is asserted by ErrorId only (no category or target) and only with an elevated admin share. A hard link across volumes cannot be built on a one-volume host.","TestNeeded","Links.Tests.ps1:134-145 pipes four objects by property name and asserts three errors (ErrorId, categories, targets, message), the created link and unchanged files; :170-179 asserts PermissionDenied, exception type, no output and no link; :36-41, :67-73 and :79-84 read back existence, all names and the shared data. Three of the 17 call sites (Links.Tests.ps1:450, 468, 494) are '& $Command' calls that the scan does not resolve.","Partly","ParameterSets.Items.Tests.ps1:253 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:313 New-NTFSHardLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched","positional binding (documented example 2); a FileInfo object bound to -Path or -Target; the -PassThru GetHardLinkError category and target on an admin share (still ID only)","budget (all items; an elevated admin share is already available on this host, simply not used for this)"
"items","Get-NTFSHardLink","__AllParameterSets","False","9","1","0","10","NA","Partly","Yes","Yes","Partly","Links.Tests.ps1:224 Should write an error for a path that does not exist and continue with the next path | Links.Tests.ps1:236 Should write an error for a folder and continue with the next path | Links.Tests.ps1:214 Should take the files with more than one name from Get-ChildItem2 | Links.Tests.ps1:200 Should return every name of a file with hard links","1: writes GetHardLinkError on a share (administrator)","The output type is never asserted (only FullName and Mode), the error categories (InvalidArgument for a folder, ObjectNotFound, ReadError on a share) are unasserted, and positional binding and strings from the pipeline are untested. The UnauthorizedAccessException handler cannot be reached by a test because Windows lists the names without opening the file (Links.Tests.ps1:262).","TestNeeded","Links.Tests.ps1:224-229 and :236-243 assert one error (FileNotFound; GetHardLinkError with target and message) and exactly the next file; :214-218 pipes AlphaFS file objects and asserts the names of both linked files and not the third; :200-203 asserts all names of a linked file; PathErrors.Tests.ps1:108-114 asserts ID and target for a missing path.","Partly","ParameterSets.Items.Tests.ps1:286 Should accept piped strings by value, write errors with their categories for a folder and a missing path, and return the files in order","the ReadError category on a network share (still ID/target only); the UnauthorizedAccessException handler","ReadError on a share: budget (admin share available elevated, not implemented here); UnauthorizedAccessException handler: Limit (structurally unreachable, Windows lists hard-link names without opening the file)"
"items","New-NTFSSymbolicLink","__AllParameterSets","False","12","2","0","15","Yes","Yes","Yes","Partly","Yes","Links.Tests.ps1:297 Should create a link to a file that reads the data of the file | Links.Tests.ps1:387 Should write a non-terminating error for an existing -Path and continue with the next link | Links.Tests.ps1:420 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:335 Should return a folder object for a link to a folder with -PassThru","2: link to a file and to a folder on a share (administrator); asserts no error only","No test creates a link after a failed one in a pipeline (every piped request fails so that the tests run without the privilege), and a link to a folder is checked only for the Directory attribute and reachability through Test-Path2, not for LinkType and target. The success paths run only with SeCreateSymbolicLinkPrivilege; positional binding and an empty -Target (the value that meant the current folder before rc7, while the tests check only the Mandatory metadata) are untested.","TestNeeded","Links.Tests.ps1:297-302 reads back LinkType, target and data of a file link; :387-393 pipes two objects by property name and asserts two errors (ErrorId, categories) and that no link exists; :420-429 asserts PermissionDenied, exception type and no output; :323-339 assert FileInfo and DirectoryInfo with -PassThru.","Partly","ParameterSets.Items.Tests.ps1:253 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:332 New-NTFSSymbolicLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched | ParameterSets.Items.Tests.ps1:356 Should write one ResourceExists error for an existing -Path and still create the links for the requests that follow it","positional binding; the folder link's LinkType and resolved target (only the file link's LinkType was asserted)","budget (both items)"
"items","Enable-Privileges","__AllParameterSets","False","5","0","0","7","Partly","No","NA","NA","Partly","Privileges.Tests.ps1:61 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:284 Should enable the privileges when the module setting EnablePrivileges is $true | Privileges.Tests.ps1:302 Should enable the privileges in a script of another name also when the module setting EnablePrivileges is $false | Privileges.Tests.ps1:179 Enable-Privileges should keep the privileges enabled also when the pipeline stops early","0","The error path (Enable Privilege Error, SecurityError, 'Could not enable requested privileges' when not all four privileges can be enabled) is never asserted, although OutputTypes.Tests.ps1:86 (in a token without the privileges) and the partial-token child script at Privileges.Tests.ps1:93 run it with errors suppressed. Only the Backup state is read back, only through Get-Privileges and only with all four privileges held, and the states in the -PassThru objects are unasserted.","TestNeeded","Privileges.Tests.ps1:61-62 reads the Backup state after Enable-Privileges; :281-305 run it in child scripts and assert the Backup state and the verbose announcement for the Init script with the setting true and false and for another script name; :179-181 asserts the state stays enabled when the pipeline stops; OutputTypes.Tests.ps1:86-89 compares the -PassThru count with Get-Privileges. All but OutputTypes.Tests.ps1:86 skip unless the token holds the four privileges.","Partly","ParameterSets.Items.Tests.ps1:430 Enable-Privileges should write Enable Privilege Error with SecurityError and AdjustPriviledgeException when it cannot enable all four privileges","the -PassThru privilege states (TakeOwnership/Restore/Backup/Security) with an independent read-back beyond Get-Privileges, only verifiable elevated","budget"
"items","Disable-Privileges","__AllParameterSets","False","19","3","0","20","Partly","No","NA","NA","Partly","Privileges.Tests.ps1:64 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:94 Should not warn about the privileges that the access token does not hold | OutputTypes.Tests.ps1:95 Disable-Privileges should write one object per privilege | Privileges.Tests.ps1:382 Should not fail when Disable-Privileges runs inside the pipeline","3: AfterAll/BeforeEach/AfterEach resets in the privileges-on-share tests; no assertion on the cmdlet itself","The error path (Disable Privilege Error, documented as non-terminating, when none of TakeOwnership, Restore and Backup is enabled) is never asserted although 15 of the 19 scan calls (BeforeEach/AfterEach/AfterAll) run it with errors suppressed; -PassThru asserts only a count above 1 and the type, and the warning for a privilege that cannot be disabled is unasserted.","TestNeeded","Privileges.Tests.ps1:64-67 asserts no warning and the Backup state Disabled through Get-Privileges, :74-76 the verbose message, :94 (child script) no warnings for a token that holds only some privileges, :382-387 that no privilege stays enabled after it runs inside a pipeline; OutputTypes.Tests.ps1:95-98 asserts a count above 1 and the type. All skip unless the token holds the privileges.","Partly","ParameterSets.Items.Tests.ps1:440 Disable-Privileges should write Disable Privilege Error with SecurityError and AdjustPriviledgeException and no output when nothing is enabled","the -PassThru object privilege-state values on the successful disable path (still only count/type asserted); the warning when a privilege cannot be disabled","state values on success path: budget; the warning: Limit (needs a race with another command)"
"items","Get-Privileges","__AllParameterSets","False","18","2","0","19","NA","NA","NA","NA","Partly","ObjectApis.Tests.ps1:210 Should compare boxed and typed privilege values consistently without accepting an attributes enum | OutputTypes.Tests.ps1:88 Enable-Privileges should write one object per privilege | Privileges.Tests.ps1:62 Should disable the privileges that Enable-Privileges enabled | PipelineControl.Tests.ps1:164 <Name> should stop after the first object for Select-Object -First 1 and change nothing else","2: a read helper and the check that the account holds the four file system privileges","The output is never compared with an independent source (whoami /priv or the Win32 token), and no test asserts the objects beyond a count above 0, the Equals contract of the first value and the privilege and state that other cmdlets' tests read back; the Removed state and the PrivilegeAttributes property are unasserted. Errors are NA: the cmdlet has no handler and no designed failure.","TestNeeded","ObjectApis.Tests.ps1:210-214 asserts a count above 0 and the equality contract; OutputTypes.Tests.ps1:88 compares the -PassThru count with the cmdlet itself; Privileges.Tests.ps1:30 (read helper) reads one privilege state for the tests of Enable-Privileges and Disable-Privileges. The other calls are preconditions or read-backs.","Partly","ParameterSets.Items.Tests.ps1:492 Should match whoami /priv for the privileges that whoami and the library name the same way","the Removed PrivilegeState value","budget"
"items","Copy-Item2","__AllParameterSets","False","6","4","0","20","Yes","Yes","No","Yes","Partly","ItemCmdlets.Tests.ps1:786 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:815 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:635 <_> should write DestinationFileAlreadyExists for a folder that exists at the destination and change nothing | ItemCmdlets.Tests.ps1:674 Copy-Item2 -Force should copy a folder into an existing folder of the same name and replace the files in both","4: -WhatIf onto an existing file on a share (#108, administrator); copy of a file and a folder as the delegated account; later-command stop on a share","No test pipes paths into it (documented: Get-ChildItem2 | Copy-Item2 -Destination), passes an empty or null -Path, a FileInfo object, a path with brackets, a path over 260 characters or a drive root, and -Force replacing an existing file is covered only through the folder merge. FileNotFound and the file case of DestinationFileAlreadyExists are asserted by error count only, and -PassThru asserts FullName but not the output type or that nothing is written without it.","TestNeeded","ItemCmdlets.Tests.ps1:786-801 and :815-827 assert ErrorId, category, target, exception type, only the second item's result and untouched sources; :605-613 and :644-649 read the folder conflict and the merge back; Owner.Tests.ps1:160-163 reads the copied content. 14 of the 20 call sites are '& $Command' calls in ItemCmdlets.Tests.ps1 (lines 514 to 814) that the scan does not resolve.","Partly","ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location","a path with brackets; a path over 260 characters; a drive root; -Force replacing an existing file (still only covered through the folder merge); the file case of DestinationFileAlreadyExists with category/target (still error count only); -PassThru output type; that nothing is written without -PassThru","budget (all items; none needs a lab, none pins an open maintainer decision)"
"items","Get-ChildItem2","__AllParameterSets","False","34","8","0","36","NA","Yes","No","Yes","Yes","ItemCmdlets.Tests.ps1:98 Should apply <Case> without broadening the other attribute filters | ItemCmdlets.Tests.ps1:137 Should return the exact tree for <Case> | ItemCmdlets.Tests.ps1:312 Should report the denied folder and continue with the next path | ItemCmdlets.Tests.ps1:370 Should report a junction whose target was removed as a DirUnspecifiedError and continue with the next folder","8: over SMB: path over 260 characters (administrator), -Hidden and a listing (delegated account), -Filter cases, later-command stop with a denied nested folder","No test pipes folders or strings into -Path (documented by value and by FullName), asserts the result of omitting -Path or of a relative -Path (Owner.Tests.ps1:98 only asserts no throw), or lists a drive root or a path over 260 characters in a unit test. -Directory with -File, -Attributes with -Force/-Hidden/-System/-ReadOnly (documented: ignored), -Depth without -Recurse and the dir2 alias are unasserted, and FileNotFound and AttributesEmpty are asserted without category (and without target for AttributesEmpty); the -Filter dot rules are pinned already and are the maintainer's, so they are not counted here.","TestNeeded","ItemCmdlets.Tests.ps1:98-100 and :137-140 assert exact name sets for ten attribute-switch cases and for the Recurse/Depth/Directory/File/Filter cases; :282-289 and :340-348 assert ErrorId, category, target (and exception type) and that the next path or sibling is still listed; :44-49 and :402-406 assert the AlphaFS types; PathErrors.Tests.ps1:108-114 covers FileNotFound (ID and target only).","Partly","ParameterSets.Items.Tests.ps1:91 Should accept piped folders by value, write one error for a path that does not exist, and list the items of the other folders | ParameterSets.Items.Tests.ps1:111 Should accept folder objects piped from Get-ChildItem2 -Directory and list only the files directly below them","the result of an omitted -Path; the result of a relative -Path; a drive root in a unit test; a path over 260 characters in a unit test; -Directory with -File together; -Attributes with -Force/-Hidden/-System/-ReadOnly; -Depth without -Recurse; the dir2 alias; AttributesEmpty category and target","budget (all items; the -Filter dot rules are the maintainer's and were already excluded from this Gap)"
"items","Get-Item2","__AllParameterSets","False","17","1","0","19","NA","Partly","No","Partly","Partly","PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path | ItemCmdlets.Tests.ps1:965 Get-Item2 should resolve <Path> against the current location | Owner.Tests.ps1:235 Should take the items from the pipeline | PipelineControl.Tests.ps1:124 <Name> should stop after the first object for Select-Object -First 1 and change nothing else","1: FullName and Length of a file on a share (delegated account)","No test pipes paths into it (documented: 'C:\Data','C:\Data\Reports' | Get-Item2) or omits -Path (documented: the current location), and the output type (FileInfo or DirectoryInfo) and the Mode property are never asserted; bracket paths, paths over 260 characters and a drive root are untested. The FileNotFound category is not asserted and the output for the next path is checked only as non-empty.","TestNeeded","PathErrors.Tests.ps1:108-114 asserts one FileNotFound error with the missing path as target and non-empty output for the next path; ItemCmdlets.Tests.ps1:965-973 asserts HaveCount 1 and FullName for six relative paths. 15 of the 17 scan calls are fixtures that feed descriptors or other cmdlets (Access, Audit, Inheritance, ObjectApis, Owner, SecurityDescriptor).","Partly","ParameterSets.Items.Tests.ps1:133 Should accept piped items by value, return each in order with its output type, and write one error for a path that does not exist","an omitted -Path defaulting to the current location; bracket paths; paths over 260 characters; a drive root","budget (all items)"
"items","Move-Item2","__AllParameterSets","False","7","3","0","21","Yes","Yes","No","Yes","Yes","ItemCmdlets.Tests.ps1:786 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:815 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:651 Move-Item2 -Force should replace an existing file with PassThru=<_> | ItemCmdlets.Tests.ps1:871 Should refuse to move <Kind> folder to another volume and leave it in place","3: -WhatIf onto an existing file on a share (administrator); move of a file as the delegated account; later-command stop on a share","No test pipes paths into it (documented), passes an empty or null -Path, moves a non-empty folder tree, or renames an item inside one folder on the same volume (the cross-volume cases need an elevated admin share), and -Force replacing a folder, bracket or wildcard paths, paths over 260 characters and a drive-root destination are untested. FileNotFound is asserted by error count only.","TestNeeded","ItemCmdlets.Tests.ps1:651-661 asserts the source is gone, the content at the destination and PassThru true and false; :576-592 asserts the moved file and folder (DirectoryInfo) and the removed source folder; :756-771 and :785-797 assert ErrorId, category, target, exception type and the other item's result. The cross-volume tests at :841-878 skip without an elevated admin share.","Partly","ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location","moving a non-empty folder tree; renaming an item in place on the same volume; -Force replacing a folder; bracket or wildcard paths; paths over 260 characters; a drive-root destination","budget (all items)"
"items","Remove-Item2","__AllParameterSets","False","15","2","0","16","Yes","Yes","No","Yes","Partly","Remove-Item2.Tests.ps1:43 Should report DeleteError for a non-empty folder without -Recurse and continue with the next path | Remove-Item2.Tests.ps1:104 Should write DeleteError when a descendant is open without delete sharing, not a successful -PassThru result | Remove-Item2.Tests.ps1:126 Should delete a junction with -Recurse without deleting or changing its target | Remove-Item2.Tests.ps1:77 Should leave a folder tree unchanged with -Recurse -Force -WhatIf and write nothing with -PassThru","2: removal of a file on a share as the delegated account; later-command stop on a share","No test pipes items into it (documented: Get-ChildItem2 ... | Remove-Item2), omits -Path (documented: the cmdlet does nothing), passes an empty or null -Path (the ValidateNotNullOrEmpty guard that keeps it from meaning the current location), passes bracket or wildcard paths (documented: literal) or uses rm2/del2. FileNotFound is asserted by error count only (ItemCmdlets.Tests.ps1:537), the access-denied branch of DeleteError (category NotSpecified) is unasserted, and that a successful removal without -PassThru writes nothing is not asserted.","TestNeeded","Remove-Item2.Tests.ps1:43-52 asserts DeleteError, InvalidData, target, kept content, the removed next item and exactly one result; :104-114 and :152-158 assert DeleteError and no success-shaped result with the content kept; :126-130 asserts the junction is removed and its target content and SDDL are unchanged; :176-184 covers the -PassThur alias.","Partly","ParameterSets.Items.Tests.ps1:157 Should accept piped items by value, write one error for a non-empty folder, remove the files, and keep the folder | ParameterSets.Items.Tests.ps1:185 Remove-Item2 should reject -Path <CaseName> instead of removing the current location","-Path omitted entirely (documented: the cmdlet does nothing); bracket or wildcard paths; the rm2/del2 aliases; FileNotFound category/target (still error count only); the access-denied DeleteError branch (category NotSpecified); that a successful removal without -PassThru writes nothing","budget (all items)"
"items","Test-Path2","__AllParameterSets","False","14","3","0","14","NA","NA","Partly","Yes","Yes","ItemCmdlets.Tests.ps1:997 Should return <Expected> for a <Kind> with -PathType <PathType> | ItemCmdlets.Tests.ps1:1039 Should return $false for a path with the character <_> and continue with the next path | ItemCmdlets.Tests.ps1:1030 Should find a folder whose path is longer than 260 characters | ItemCmdlets.Tests.ps1:1011 Should take the items from the pipeline","3: file, folder and missing item with -PathType on a share (delegated account)","The pipeline test pipes one file; no test pipes several items (documented: Get-ChildItem2 -Recurse | Test-Path2 -PathType Leaf) or objects with PathType by property name, or tests a drive root, a UNC path or a bracket path. Errors are NA because the cmdlet writes $false for a missing or invalid path; its PathNotFound handler looks unreachable (see the notes).","TestNeeded","ItemCmdlets.Tests.ps1:997-1002 asserts one [bool] with the expected value for file, folder and missing item under all three -PathType values; :1009-1013 asserts no error and 'False,True' for six invalid characters followed by a valid path; :981-983 pipes one FileInfo; :992-1001 covers a folder path over 260 characters.","Open","","piping several items into -Path; -PathType bound by property name; a drive root; a UNC path; a bracket path","budget (deprioritized: PipelineInput was already Partly, not No, so lower priority than the cmdlets with no pipeline test at all)"
"items","Get-FileHash2","__AllParameterSets","False","12","2","0","13","Partly","Partly","Partly","Partly","Yes","FileHash.Tests.ps1:41 Should return the hash of Get-FileHash for <_> | FileHash.Tests.ps1:94 Should skip the folder and hash the files that follow it | FileHash.Tests.ps1:108 Should write an error and no result for the file | FileHash.Tests.ps1:153 Should report both the failed read and the failed owner restoration without returning a hash","2: SHA256 equals Get-FileHash on a share (delegated account); later-command stop at the verbose message","No test pipes FileInfo/DirectoryInfo objects or folders (documented: Get-ChildItem2 -Recurse | Get-FileHash2) or Algorithm by property name, hashes a relative path or a path over 260 characters, or puts the failing path first and asserts the next hash; no error category is asserted. The owner-restore tests run only elevated and read the owner back with Get-NTFSOwner, and the retry that succeeds after taking ownership is untested.","TestNeeded","FileHash.Tests.ps1:41-44 compares Hash and Algorithm with Get-FileHash for five algorithms; :94-98 skips a folder and hashes the next file with the SHA256 default; :108-115 asserts one error and no result for a locked file; :153-160 (elevated only) asserts RestoreOwnerError and GetHashError with target, no result and the restored owner; OutputTypes.Tests.ps1:57 asserts the type name.","Partly","ParameterSets.Items.Tests.ps1:531 Should accept Get-ChildItem2 objects piped by value, skip a folder, and match Get-FileHash for each file | ParameterSets.Items.Tests.ps1:565 Should write GetHashError with its category for a locked file first, hash the file that follows it, and resolve a relative path","-Algorithm bound by property name from the pipeline; a path over 260 characters; the ownership-retry-after-taking-ownership success path","-Algorithm by property name and >260 chars: budget; ownership-retry success: Limit (elevated-only, needs a DACL/owner setup not shown buildable)"
"items","Get-DiskSpace","__AllParameterSets","False","6","0","0","6","NA","Partly","NA","No","Yes","ItemCmdlets.Tests.ps1:1068 Should return the size of the system drive | ItemCmdlets.Tests.ps1:1086 Should return the volumes with a size greater than zero without -DriveLetter | ItemCmdlets.Tests.ps1:1102 Should warn and return nothing for a drive letter without a volume | ItemCmdlets.Tests.ps1:1110 Should reject a drive letter without a colon","0","No test passes several drive letters, so the documented warn-and-continue for a letter without a volume is never combined with a valid letter; lower-case letters, positional binding and the free-space values against an independent source are unasserted. The validation error is asserted by ErrorId only (no category or target).","TestNeeded","ItemCmdlets.Tests.ps1:1068-1073 asserts type, DriveName and TotalNumberOfBytes against System.IO.DriveInfo; :1072-1077 asserts the exact warning text and no output or error for a letter without a volume; :1056-1061 asserts every volume has a size above zero and the system drive is included; :1080-1081 asserts the ErrorId of the validation error.","Partly","ParameterSets.Items.Tests.ps1:470 Should return only the system drive and warn for a drive letter without a volume, regardless of order (<Order>) | ParameterSets.Items.Tests.ps1:491 Should accept a lower-case drive letter positionally and report the same total size as .NET","the free-space values (TotalNumberOfFreeBytes/FreeBytesAvailable) against an independent source (only TotalNumberOfBytes was compared); the validation error's category and target (still ErrorId only)","budget (both items)"
"items","New-NTFSHardLink","__AllParameterSets","False","14","2","0","17","Yes","Yes","Yes","Yes","Yes","Links.Tests.ps1:134 Should write a non-terminating error for each link that it cannot create and continue with the next one | Links.Tests.ps1:170 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:67 Should return every name of the file with -PassThru | Links.Tests.ps1:79 Should give both names the same data","2: link creation on a share (administrator) and -PassThru, which writes GetHardLinkError there","Positional binding (documented example 2), a FileInfo object bound to -Path or -Target and the end of a pipeline by a later command are untested; the -PassThru GetHardLinkError on a share is asserted by ErrorId only (no category or target) and only with an elevated admin share. A hard link across volumes cannot be built on a one-volume host.","TestNeeded","Links.Tests.ps1:134-145 pipes four objects by property name and asserts three errors (ErrorId, categories, targets, message), the created link and unchanged files; :170-179 asserts PermissionDenied, exception type, no output and no link; :36-41, :67-73 and :79-84 read back existence, all names and the shared data. Three of the 17 call sites (Links.Tests.ps1:450, 468, 494) are '& $Command' calls that the scan does not resolve.","Partly","ParameterSets.Items.Tests.ps1:264 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:324 New-NTFSHardLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched","positional binding (documented example 2); a FileInfo object bound to -Path or -Target; the -PassThru GetHardLinkError category and target on an admin share (still ID only)","budget (all items; an elevated admin share is already available on this host, simply not used for this)"
"items","Get-NTFSHardLink","__AllParameterSets","False","9","1","0","10","NA","Partly","Yes","Yes","Partly","Links.Tests.ps1:224 Should write an error for a path that does not exist and continue with the next path | Links.Tests.ps1:236 Should write an error for a folder and continue with the next path | Links.Tests.ps1:214 Should take the files with more than one name from Get-ChildItem2 | Links.Tests.ps1:200 Should return every name of a file with hard links","1: writes GetHardLinkError on a share (administrator)","The output type is never asserted (only FullName and Mode), the error categories (InvalidArgument for a folder, ObjectNotFound, ReadError on a share) are unasserted, and positional binding and strings from the pipeline are untested. The UnauthorizedAccessException handler cannot be reached by a test because Windows lists the names without opening the file (Links.Tests.ps1:262).","TestNeeded","Links.Tests.ps1:224-229 and :236-243 assert one error (FileNotFound; GetHardLinkError with target and message) and exactly the next file; :214-218 pipes AlphaFS file objects and asserts the names of both linked files and not the third; :200-203 asserts all names of a linked file; PathErrors.Tests.ps1:108-114 asserts ID and target for a missing path.","Partly","ParameterSets.Items.Tests.ps1:297 Should accept piped strings by value, write errors with their categories for a folder and a missing path, and return the files in order","the ReadError category on a network share (still ID/target only); the UnauthorizedAccessException handler","ReadError on a share: budget (admin share available elevated, not implemented here); UnauthorizedAccessException handler: Limit (structurally unreachable, Windows lists hard-link names without opening the file)"
"items","New-NTFSSymbolicLink","__AllParameterSets","False","12","2","0","15","Yes","Yes","Yes","Partly","Yes","Links.Tests.ps1:297 Should create a link to a file that reads the data of the file | Links.Tests.ps1:387 Should write a non-terminating error for an existing -Path and continue with the next link | Links.Tests.ps1:420 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:335 Should return a folder object for a link to a folder with -PassThru","2: link to a file and to a folder on a share (administrator); asserts no error only","No test creates a link after a failed one in a pipeline (every piped request fails so that the tests run without the privilege), and a link to a folder is checked only for the Directory attribute and reachability through Test-Path2, not for LinkType and target. The success paths run only with SeCreateSymbolicLinkPrivilege; positional binding and an empty -Target (the value that meant the current folder before rc7, while the tests check only the Mandatory metadata) are untested.","TestNeeded","Links.Tests.ps1:297-302 reads back LinkType, target and data of a file link; :387-393 pipes two objects by property name and asserts two errors (ErrorId, categories) and that no link exists; :420-429 asserts PermissionDenied, exception type and no output; :323-339 assert FileInfo and DirectoryInfo with -PassThru.","Partly","ParameterSets.Items.Tests.ps1:264 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:343 New-NTFSSymbolicLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched | ParameterSets.Items.Tests.ps1:367 Should write one ResourceExists error for an existing -Path and still create the links for the requests that follow it","positional binding; the folder link's LinkType and resolved target (only the file link's LinkType was asserted)","budget (both items)"
"items","Enable-Privileges","__AllParameterSets","False","5","0","0","7","Partly","No","NA","NA","Partly","Privileges.Tests.ps1:61 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:284 Should enable the privileges when the module setting EnablePrivileges is $true | Privileges.Tests.ps1:302 Should enable the privileges in a script of another name also when the module setting EnablePrivileges is $false | Privileges.Tests.ps1:179 Enable-Privileges should keep the privileges enabled also when the pipeline stops early","0","The error path (Enable Privilege Error, SecurityError, 'Could not enable requested privileges' when not all four privileges can be enabled) is never asserted, although OutputTypes.Tests.ps1:86 (in a token without the privileges) and the partial-token child script at Privileges.Tests.ps1:93 run it with errors suppressed. Only the Backup state is read back, only through Get-Privileges and only with all four privileges held, and the states in the -PassThru objects are unasserted.","TestNeeded","Privileges.Tests.ps1:61-62 reads the Backup state after Enable-Privileges; :281-305 run it in child scripts and assert the Backup state and the verbose announcement for the Init script with the setting true and false and for another script name; :179-181 asserts the state stays enabled when the pipeline stops; OutputTypes.Tests.ps1:86-89 compares the -PassThru count with Get-Privileges. All but OutputTypes.Tests.ps1:86 skip unless the token holds the four privileges.","Partly","ParameterSets.Items.Tests.ps1:441 Enable-Privileges should write Enable Privilege Error with SecurityError and AdjustPriviledgeException when it cannot enable all four privileges","the -PassThru privilege states (TakeOwnership/Restore/Backup/Security) with an independent read-back beyond Get-Privileges, only verifiable elevated","budget"
"items","Disable-Privileges","__AllParameterSets","False","19","3","0","20","Partly","No","NA","NA","Partly","Privileges.Tests.ps1:64 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:94 Should not warn about the privileges that the access token does not hold | OutputTypes.Tests.ps1:95 Disable-Privileges should write one object per privilege | Privileges.Tests.ps1:382 Should not fail when Disable-Privileges runs inside the pipeline","3: AfterAll/BeforeEach/AfterEach resets in the privileges-on-share tests; no assertion on the cmdlet itself","The error path (Disable Privilege Error, documented as non-terminating, when none of TakeOwnership, Restore and Backup is enabled) is never asserted although 15 of the 19 scan calls (BeforeEach/AfterEach/AfterAll) run it with errors suppressed; -PassThru asserts only a count above 1 and the type, and the warning for a privilege that cannot be disabled is unasserted.","TestNeeded","Privileges.Tests.ps1:64-67 asserts no warning and the Backup state Disabled through Get-Privileges, :74-76 the verbose message, :94 (child script) no warnings for a token that holds only some privileges, :382-387 that no privilege stays enabled after it runs inside a pipeline; OutputTypes.Tests.ps1:95-98 asserts a count above 1 and the type. All skip unless the token holds the privileges.","Partly","ParameterSets.Items.Tests.ps1:451 Disable-Privileges should write Disable Privilege Error with SecurityError and AdjustPriviledgeException and no output when nothing is enabled","the -PassThru object privilege-state values on the successful disable path (still only count/type asserted); the warning when a privilege cannot be disabled","state values on success path: budget; the warning: Limit (needs a race with another command)"
"items","Get-Privileges","__AllParameterSets","False","18","2","0","19","NA","NA","NA","NA","Partly","ObjectApis.Tests.ps1:229 Should compare boxed and typed privilege values consistently without accepting an attributes enum | OutputTypes.Tests.ps1:88 Enable-Privileges should write one object per privilege | Privileges.Tests.ps1:62 Should disable the privileges that Enable-Privileges enabled | PipelineControl.Tests.ps1:164 <Name> should stop after the first object for Select-Object -First 1 and change nothing else","2: a read helper and the check that the account holds the four file system privileges","The output is never compared with an independent source (whoami /priv or the Win32 token), and no test asserts the objects beyond a count above 0, the Equals contract of the first value and the privilege and state that other cmdlets' tests read back; the Removed state and the PrivilegeAttributes property are unasserted. Errors are NA: the cmdlet has no handler and no designed failure.","TestNeeded","ObjectApis.Tests.ps1:229-233 asserts a count above 0 and the equality contract; OutputTypes.Tests.ps1:88 compares the -PassThru count with the cmdlet itself; Privileges.Tests.ps1:30 (read helper) reads one privilege state for the tests of Enable-Privileges and Disable-Privileges. The other calls are preconditions or read-backs.","Partly","ParameterSets.Items.Tests.ps1:503 Should match whoami /priv for the privileges that whoami and the library name the same way","the Removed PrivilegeState value","budget"

1 Group Cmdlet ParameterSet Default TestInvocationsScan LiveInvocationsScan AmbiguousInvocationsThatMayBindIt BoundBy StateAssertion ErrorAssertion PipelineInput Continuation OutputAssertion KeyTests LiveEvidence Gap GapKind Evidence StatusAfter NewTests Remaining Reason
2 access Add-NTFSAccess PathComplex True 33 6 1 36 Yes Yes No Partly Yes Access.Tests.ps1:740 Should write an AddAceError for each item, change nothing, and return nothing with -PassThru | PathErrors.Tests.ps1:178 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | Access.Tests.ps1:807 Should write all entries of the item after the change | PathErrors.Tests.ps1:230 Add-NTFSAccess should take ownership, add the entry, and set the owner back 6: SMB share as delegated and domain accounts - add keeps the owner (#34), add by foreign-domain account name, deny-entry fixtures (Live:253, 877, 927, 987, 1038, 1280) No test pipes anything into the set (FileInfo/DirectoryInfo, or objects with Account/AccessRights properties), and none combines -PassThru with one failing and one succeeding path: continuation (PathErrors:178, no -PassThru) and no output after a failure (Access:740, all items fail) are asserted in separate tests. Several -Account values, a Deny entry written through -Path (type, no Synchronize) and positional binding are untested. TestNeeded Access.Tests.ps1:740-751 asserts ErrorId, category WriteError, TargetObject, ArgumentException, no output and unchanged SDDL for two failing paths; PathErrors.Tests.ps1:178-192 asserts one error with the blocked target, its SDDL unchanged and the next item's entry added; Access.Tests.ps1:807-815 asserts type, entry count and the added entry of -PassThru. BoundBy = scan 33 + PathErrors:108 and :178 (& $Command) + PermissionScopes:86 (splat, Form=Flags, Source=Path); about 14 of the 36 calls are the subject of an assertion, the rest are fixtures. Partly ParameterSets.Access.Tests.ps1:61,62 Should add one explicit entry for each path bound through the pipeline, by FullName and by property name, leaving the rest of each item unchanged | ParameterSets.Access.Tests.ps1:91 Should write one AddAceError for the blocked path, leave it unchanged, and return -PassThru entries only for the path it changed several -Account values in one call; a Deny entry written through -Path checked for AccessControlType=Deny and no auto-added Synchronize; positional binding (Add-NTFSAccess $path $account $rights) budget (all three; proposal 1c was traded for the pipeline and PassThru-combined tests)
3 access Add-NTFSAccess PathSimple False 6 1 2 8 Partly No No No Yes PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | PermissionScopes.Tests.ps1:110 Should apply <Name> only to its intended descendants, including the OneLevel boundary | Access.Tests.ps1:1035 Should name the folder of an inheritable entry, also with -ExcludeExplicit | ObjectApis.Tests.ps1:728 Should name the item of a descriptor and write it to a folder by its path PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | PermissionScopes.Tests.ps1:110 Should apply <Name> only to its intended descendants, including the OneLevel boundary | Access.Tests.ps1:1035 Should name the folder of an inheritable entry, also with -ExcludeExplicit | ObjectApis.Tests.ps1:747 Should name the item of a descriptor and write it to a folder by its path 1: SMB share - Deny ReadPermissions entry with -AppliesTo ThisFolderOnly as a fixture of the unknown-parent case (Live:1039); no assertion on the set itself No test makes the set fail (missing path, denied write, deny entry without rights), pipes into it, or reads its result back with .NET: every read-back goes through -PassThru or Get-NTFSAccess. -AccessType Deny with -AppliesTo and the exclusion of -AppliesTo with -InheritanceFlags are untested. TestNeeded PermissionScopes.Tests.ps1:86-94 asserts type, flags, rights and ConvertToApplyTo of the -PassThru entry for 13 scopes (Form=AppliesTo, Source=Path) and :110-133 asserts which descendants inherit it, both read through the module's own cmdlets. Access.Tests.ps1:1035, Inheritance.Tests.ps1:326/365/474 and ObjectApis.Tests.ps1:728 use the set as a fixture. BoundBy = scan 6 + the splats PermissionScopes:84 and :86 (Source=Path); 2 of the 8 calls are the subject of an assertion. PermissionScopes.Tests.ps1:86-94 asserts type, flags, rights and ConvertToApplyTo of the -PassThru entry for 13 scopes (Form=AppliesTo, Source=Path) and :110-133 asserts which descendants inherit it, both read through the module's own cmdlets. Access.Tests.ps1:1035, Inheritance.Tests.ps1:326/365/474 and ObjectApis.Tests.ps1:747 use the set as a fixture. BoundBy = scan 6 + the splats PermissionScopes:84 and :86 (Source=Path); 2 of the 8 calls are the subject of an assertion. Partly ParameterSets.Access.Tests.ps1:113,129 Should report a missing path's error by category and target, still scope the next path's entry, and keep binding -Path through the pipeline once -AppliesTo selects the set | ParameterSets.Access.Tests.ps1:572 Should require -AppliesTo only in the Simple parameter sets, -InheritanceFlags/-PropagationFlags only in the Complex parameter sets, and reject combining -AppliesTo with -InheritanceFlags without changing the item a denied write for this set; a Deny entry without rights (-AccessType Deny -AccessRights None) for this set; -AccessType Deny combined with -AppliesTo budget (all three; the write-denial code path is shared with PathComplex and already covered there)
4 access Add-NTFSAccess SDSimple False 2 0 2 4 Partly No No No Yes Access.Tests.ps1:898 Add-NTFSAccess should still take -AppliesTo for a security descriptor | PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account | SecurityDescriptor.Tests.ps1:355 Should write the descriptor and report a read error for -PassThru, not a write error 0 Only InheritanceFlags for ThisFolderOnly is read back from the descriptor with .NET (Access:898); the 13 scopes are checked through the cmdlet's own -PassThru, and no test pipes descriptors in or passes several. A failing change (for example a deny entry without rights) ends the cmdlet with a terminating error and no test pins it (open item 1). MaintainerDecision Access.Tests.ps1:898-902 reads the rule from $sd.SecurityDescriptor with .NET; PermissionScopes.Tests.ps1:86-97 asserts type, flags, rights and, for Source=SecurityDescriptor, that the SDDL on disk is unchanged (13 cases). BoundBy = scan 2 (Access:898; SecurityDescriptor:355 is a fixture) + the splats PermissionScopes:84 and :86 (Source=SecurityDescriptor, Form=AppliesTo). MaintainerDecision all 13 scopes read back with .NET for Source=SecurityDescriptor (only ThisFolderOnly already was, pre-existing); piped descriptors; several descriptors; the failing-change (deny entry without rights) terminating error, not pinned budget (the 13-scope/pipe/several items, notes proposal (b2)#1 not implemented); MaintainerDecision (the failing-change open item)
5 access Add-NTFSAccess SDComplex False 14 2 1 16 Yes No No No Yes Access.Tests.ps1:822 Should write all entries of a security descriptor after the change and leave the item unchanged | Access.Tests.ps1:887 Add-NTFSAccess should apply the entry to the folder, its subfolders, and files by default | SecurityDescriptor.Tests.ps1:81 Should write the entry as the only explicit entry of the item | PermissionScopes.Tests.ps1:86 Should add and remove <Name> using <Form> on <Source>, preserving the other account 2: SMB share - descriptor written back keeps the owner (#34, Live:316) and the fixture of the later-command cases (Live:1151) No test pipes descriptors into the cmdlet, and arrays of descriptors appear only as fixtures of Set-NTFSSecurityDescriptor (SecurityDescriptor.Tests.ps1:306, :324; PipelineControl.Tests.ps1:211). A failing descriptor (deny entry without rights) ends the cmdlet with a terminating error and no test pins it (open item 1). MaintainerDecision Access.Tests.ps1:822-827 asserts that -PassThru writes as many entries as $sd.SecurityDescriptor holds, one new explicit entry, and no Everyone entry on disk; :887-892 reads the default flags back with .NET; SecurityDescriptor.Tests.ps1:81-86 asserts exactly one explicit entry on disk after Set-NTFSSecurityDescriptor. BoundBy = scan 14 + Access:872 (& $_, asserts only no throw) + PermissionScopes:86 (splat); 5 of the 16 calls are the subject of an assertion. MaintainerDecision piped descriptors into the cmdlet; arrays of descriptors used only as Set-NTFSSecurityDescriptor fixtures, not asserted for Add itself; the failing descriptor (deny entry without rights) terminating error, not pinned budget (the pipe/array items, notes proposal (b2)#2 not implemented); MaintainerDecision (the failing-descriptor open item)
6 access Remove-NTFSAccess PathComplex True 13 2 2 17 Yes Yes Yes Partly Partly Access.Tests.ps1:539 Should write a RemoveAceError for each item, change nothing, and return nothing with -PassThru | Access.Tests.ps1:617 Should remove an inherit-only entry that Get-NTFSAccess returned, and nothing else | PathErrors.Tests.ps1:178 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | Access.Tests.ps1:651 Should take only the requested generic right from the entry of the account when another account has an exact entry 2: SMB share - remove keeps the owner (#34, Live:264), remove by foreign-domain account name (Live:886) No test combines -PassThru with one failing and one succeeding path, none asserts the type or the complete entry list of the -PassThru output, and the pipeline test pipes a single entry per case. Several -Account values and positional binding are untested. TestNeeded Access.Tests.ps1:539-550 asserts ErrorId, category, target, ArgumentException, no output and unchanged SDDL for two paths; :616-620 pipes Get-NTFSAccess output (binding by property name) and asserts the exact SDDL minus the entry in 3 cases; PathErrors.Tests.ps1:178-192 asserts the next item's entry is removed after one error. BoundBy = scan 13 + Access:617 (pipeline, resolves to PathComplex), PathErrors:108 and :178 (& $Command), PermissionScopes:99 (splat, Form=AppliesTo, Source=Path); all 17 calls are the subject of an assertion. Partly ParameterSets.Access.Tests.ps1:157 Should write one RemoveAceError for the blocked path, leave it unchanged, and return -PassThru entries only for the path it changed the -PassThru output's count is not checked against the complete entry list of the surviving item (only non-emptiness, type, FullName, and absence of the removed account); the pipeline test still pipes only a single entry per call; several -Account values; positional binding budget (all four)
17 access Get-NTFSSimpleAccess SD False 1 0 2 2 NA No Partly No Partly Access.Tests.ps1:476 Should report the security descriptor of a file | Access.Tests.ps1:260 Should read the entries of a security descriptor 0 Only non-empty output and FullName are asserted; -Account, -ExcludeExplicit, -ExcludeInherited, the reduced rights and several descriptors are untested for the descriptor set, and no failing descriptor is tested. TestNeeded Access.Tests.ps1:260-263 reads one descriptor; :476-479 pipes one descriptor of a file: the -Path set skips files (Access:468-473), so a non-empty result can only come from the SD set; both assert FullName only. BoundBy = scan 1 + Access:476 (pipeline, resolves to SD). Partly ParameterSets.Access.Tests.ps1:469,470,474,476,477,482 Should filter and partition a descriptor's entries like the equivalent -Path call, and read two descriptors bound through the pipeline no failing descriptor is tested for this set (no per-item handler) Limit (same no-per-item-handler situation as the Clear-NTFSAccess SD and Get-NTFSAccess SD rows)
18 access Get-NTFSEffectiveAccess Path True 11 7 1 15 NA Yes No Partly Partly Access.Tests.ps1:1140 Should report the native identity error for each <Source> and return no access entry | Access.Tests.ps1:86 Should leave out an account without access when -ExcludeNoneAccessEntries is used | Access.Tests.ps1:145 Should return the result of this computer and warn | PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path 7: SMB share, domain and delegated accounts - rights through domain groups and file-server groups with -ServerName, fallback warning, GetEffectiveAccessError for access denied (Live:419, 428, 438, 456, 478, 486, 895) No unit test asserts the content of the rights (for example an allow and a deny entry on a file with a protected DACL: ReadData present, WriteData absent), pipes objects in, or shows in one call that a failing path emits nothing while the next path emits only its own result. The ReadEffectivePermissionError handlers cannot be reached because the library hides its failures, and remote and group-based results need the lab. TestNeeded Access.Tests.ps1:1140-1153 asserts for two failing paths ErrorId GetEffectiveAccessError, category ReadError, TargetObject, Win32Exception 1332, no output and unchanged SDDL; PathErrors.Tests.ps1:108-115 asserts ReadFileError and output for the next path; Access.Tests.ps1:86-95 asserts the ExcludeNone filter and :145-157 the warning text and equal rights. BoundBy = scan 11 + Access:1140 (splat, Source=Path) + PathErrors:108/:145 + Owner.Tests.ps1:98 (& $cmdlet, no throw only). Partly ParameterSets.Access.Tests.ps1:498 Should report an allowed right as present and a denied right as absent for a protected DACL | ParameterSets.Access.Tests.ps1:508 Should return one result per item bound through the pipeline, in order one call combining a failing path (for example a missing one) with a succeeding one, showing the failing path emits nothing and the next emits only its own result; the ReadEffectivePermissionError handler; remote and group-based results budget (the failing+succeeding combination); Limit (ReadEffectivePermissionError is unreachable - the library records failures instead of throwing); Limit (remote/group-based results need the lab)
19 access Get-NTFSEffectiveAccess SecurityDescriptor False 2 0 1 3 NA Yes No Partly Partly Access.Tests.ps1:1140 Should report the native identity error for each <Source> and return no access entry | Access.Tests.ps1:132 Should name the cause in the error, not the Security privilege | Access.Tests.ps1:107 Should compute the effective access of a security descriptor 0 No test shows that the result follows an entry added to the descriptor in memory (and not the file on disk), pipes descriptors in, or passes a mix of failing and succeeding descriptors; the rights themselves are not asserted. TestNeeded Access.Tests.ps1:1140-1153 (Source=SecurityDescriptor, 2 descriptors) asserts the same error triple, Win32Exception 1332 and no output; :132-137 asserts one GetEffectiveAccessError that does not blame the privilege; :107-111 asserts one result with the FullName of the file. BoundBy = scan 2 + Access:1140 (splat, Source=SecurityDescriptor). Partly ParameterSets.Access.Tests.ps1:524,530,539 Should follow a descriptor changed only in memory while the -Path result stays on disk, and read two descriptors bound through the pipeline a mix of a failing and a succeeding descriptor in one call Limit (the per-item catch exists but is unreachable in a unit sandbox; the library records the Authz failure instead of throwing, per the notes)
20 audit Add-NTFSAudit PathComplex True 27 4 1 30 Yes Yes No Yes Yes Audit.Tests.ps1:147 Should write an AddAceError for each item, change nothing, and return nothing with -PassThru | Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:178 Should add the audit entry and keep the owner | PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account 4 (NTFSSecurity.Live.Tests.ps1:348, 385, 1010, 1016): SMB share with domain accounts; owner kept; the delegated account gets an AddAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441) No test pipes paths or objects into -Path, binds Account/AccessRights/AuditFlags by property name, or adds for several accounts. No test asserts the result of a succeeding path that follows a failing one (PathErrors.Tests.ps1:124 only counts errors), and the owner retry after access denied cannot run on a local volume (Limit). TestNeeded Audit.Tests.ps1:149-158 asserts AddAceError, WriteError, target, ArgumentException, no -PassThru output and an unchanged SACL (Get-Acl -Audit) for two failing paths; :631-669 and :672-679 assert ReadFileError/OpenError/target, the FullName of the output, the SACL rule, and unchanged DACL/owner SDDL. BoundBy 30 = scan 27 + PermissionScopes:146 (13 of 52 cases) + 2 calls through & $Command that the scan cannot see (Audit.Tests.ps1:629, PathErrors.Tests.ps1:124); 23 of the 27 scanned calls are fixtures. Partly ParameterSets.Audit.Tests.ps1:99 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged ParameterSets.Audit.Tests.ps1:123 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged AuditFlags not bound by property name; adding for several accounts in one call; the owner retry after access denied budget; budget; Limit (needs a lab or a remote server)
21 audit Add-NTFSAudit PathSimple False 5 0 2 7 Partly No No No Yes PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Inheritance.Tests.ps1:386 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:424 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry 0 No call of this set fails on purpose, passes several paths, or pipes objects, and a conflict of -AppliesTo with -InheritanceFlags is not tested. The added entry is read back only from -PassThru and Get-NTFSAudit, and owner and DACL after the call are not asserted for this set. TestNeeded The only call under test is PermissionScopes.Tests.ps1:146 (Source=Path with the -AppliesTo form, 13 of 52 cases): :149-154 assert type, Inheritance/Propagation/AuditFlags and the scope name, and :161-163 that the other account remains. The other calls (PermissionScopes:144, Audit.Tests.ps1:618 and :690, Inheritance.Tests.ps1:386, :424, :503) are fixtures; BoundBy 7 = scan 5 + :144 and :146 resolved from the splat. Closed ParameterSets.Audit.Tests.ps1:99 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged | ParameterSets.Audit.Tests.ps1:161 Should reject -AppliesTo combined with -InheritanceFlags with an AmbiguousParameterSet error and change nothing ParameterSets.Audit.Tests.ps1:123 Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged | ParameterSets.Audit.Tests.ps1:193 Should reject -AppliesTo combined with -InheritanceFlags with an AmbiguousParameterSet error and change nothing
22 audit Add-NTFSAudit SDSimple False 0 0 2 2 Partly No No No Yes PermissionScopes.Tests.ps1:146 Should add and remove <Name> using <Form> on <Source>, preserving the other account | Audit.Tests.ps1:89 Should take -Account at position 2 and -AccessRights at position 3 in the <_> parameter set 0 No test makes this set fail, passes or pipes several descriptors, or reads the changed descriptor with .NET; a descriptor without audit entries is tested only with the complex form. Exceptions of the change itself end the cmdlet (open item 1) and are not to be pinned. TestNeeded Only PermissionScopes.Tests.ps1:146 binds it (Source=SecurityDescriptor with -AppliesTo, 13 of 52 cases; the fixture at :144 in 26): :149-154 assert the -PassThru type and flags and :156 that the SACL of the item is unchanged (Get-Acl -Audit). Audit.Tests.ps1:89 checks the positions by reflection only; BoundBy 2 resolves the two splat calls, the scan found 0. Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:127 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it | ParameterSets.Audit.Tests.ps1:176 Should add the entry to the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:154 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it | ParameterSets.Audit.Tests.ps1:208 Should add the entry to the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly exceptions from the change itself (open item 1) MaintainerDecision (open item)
23 audit Add-NTFSAudit SDComplex False 5 0 1 8 Yes Partly No No Yes Audit.Tests.ps1:107 Should bind an account and access rights that are passed by position | Audit.Tests.ps1:120 Should return the audit entries of a security descriptor, not its access entries | SecurityDescriptor.Tests.ps1:120 Should write an added audit entry and keep the owner | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries 0 Only the ErrorId is asserted for a descriptor without audit entries, not its category (InvalidData) or target, and no test pipes descriptors or passes several (one without audit entries), so pipeline binding and continuation are untested. Exceptions of the change itself are open item 1 and are not to be pinned. TestNeeded Audit.Tests.ps1:109-110 reads the in-memory SACL with .NET and :122-136 assert type, Sid, InheritanceEnabled and the unchanged access protection; SecurityDescriptor.Tests.ps1:124-126 asserts after Set-NTFSSecurityDescriptor that the owner is kept and the entry exists; PermissionScopes.Tests.ps1:156 asserts the item is untouched until written. BoundBy 8 = scan 5 + PermissionScopes:146 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only). Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:127 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:154 Should add the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and leave the item on disk unchanged until Set-NTFSSecurityDescriptor writes it exceptions from the change itself (open item 1) MaintainerDecision (open item)
24 audit Remove-NTFSAudit PathComplex True 7 2 1 10 Yes Yes No Yes Yes Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:361 Should keep an audit entry that does not match exactly, given the path | Audit.Tests.ps1:371 Should remove an audit entry that matches exactly, given the path | Audit.Tests.ps1:384 Should return the audit entries of the item, not its access entries 2 (NTFSSecurity.Live.Tests.ps1:357, 398): SMB share with domain accounts; owner kept; the delegated account gets a RemoveAceError that names the missing privilege and leaves the SDDL unchanged; the file server counts the SACL entries (:1441) No test pipes paths or objects in, removes for several accounts, asserts the result of a succeeding path after a failing one, or removes only some rights (without -RemoveSpecific). An item without SACL is tested for no error only (Audit.Tests.ps1:406), and the owner retry cannot run on a local volume (Limit). TestNeeded Audit.Tests.ps1:631-669 and :672-679 assert ReadFileError/OpenError/target (RemoveAceError/WriteError/target as a basic user), the SACL changed with no rule left, and unchanged DACL/owner SDDL; :363-365 and :373-374 read back through Get-NTFSAudit. BoundBy 10 = scan 7 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124; :386-388 assert type and the other entry but pass even if nothing was removed. Partly ParameterSets.Audit.Tests.ps1:191 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:252 Should narrow an entry that grants more rights than it removes, instead of deleting it ParameterSets.Audit.Tests.ps1:225 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:286 Should narrow an entry that grants more rights than it removes, instead of deleting it removing for several accounts in one call; state (empty Audit SDDL, unchanged DACL) of an item without a SACL; the owner retry after access denied budget; budget; Limit (needs a lab or a remote server)
25 audit Remove-NTFSAudit PathSimple False 0 0 1 1 Partly No No No Partly PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account 0 Only one data-driven call binds it: no failing item, pipeline input, several items, or owner and DACL check after the call, the objects are checked by Sid only, and it never runs without -RemoveSpecific. TestNeeded PermissionScopes.Tests.ps1:159 binds it only when Source=Path and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone from -PassThru, that the other account remains, and that Get-NTFSAudit returns nothing for the account. BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set. Closed ParameterSets.Audit.Tests.ps1:191 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:270 Should remove the entry from the path when -Path, -Account, -AccessRights, and -AppliesTo are all named directly ParameterSets.Audit.Tests.ps1:225 Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:304 Should remove the entry from the path when -Path, -Account, -AccessRights, and -AppliesTo are all named directly
26 audit Remove-NTFSAudit SDSimple False 0 0 1 1 Partly No No No Partly PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account 0 Only one data-driven call binds it: the changed descriptor is read only through -PassThru and Get-NTFSAudit, the item being untouched after the removal is not asserted, and no test makes it fail, pipes or passes several descriptors, or runs without -RemoveSpecific. TestNeeded PermissionScopes.Tests.ps1:159 binds it only when Source=SecurityDescriptor and Form=Flags (13 of 52 cases, always with -RemoveSpecific): :161-163 assert that the entry of the account is gone, that the other account remains, and that Get-NTFSAudit returns nothing; the SACL on disk is compared only after the Add (:156). BoundBy 1: the scan found 0 and this ambiguous splat call is the only one that binds the set. Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:222 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:287 Should remove the entry from the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:256 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry | ParameterSets.Audit.Tests.ps1:321 Should remove the entry from the descriptor when -SecurityDescriptor, -Account, -AccessRights, and -AppliesTo are all named directly the item on disk being untouched after the removal, until Set-NTFSSecurityDescriptor writes it budget
27 audit Remove-NTFSAudit SDComplex False 2 0 1 5 Partly Partly No No Partly Audit.Tests.ps1:347 Should keep an audit entry that does not match exactly | Audit.Tests.ps1:353 Should remove an audit entry that matches exactly | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries | PermissionScopes.Tests.ps1:159 Should add and remove <Name> using <Form> on <Source>, preserving the other account 0 The item being untouched after the removal and the result after Set-NTFSSecurityDescriptor are not asserted, the error test lacks category and target, and no test pipes or passes several descriptors, checks the -PassThru type, or asserts a removal without -RemoveSpecific. Exceptions of the change itself are open item 1 and are not to be pinned. TestNeeded Audit.Tests.ps1:349 and :355 read the in-memory SACL with .NET (non-matching entry kept, matching entry removed) and :427-432 assert one ReadSecurityError, no output and the SACL still empty; PermissionScopes.Tests.ps1:161-163 assert by Sid only. BoundBy 5 = scan 2 + PermissionScopes:159 (13 of 52 cases) + & $Command at Audit.Tests.ps1:425 and Access.Tests.ps1:881 (Should -Not -Throw only). Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:222 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:256 Should remove the audit entry for the piped <Set> object that has an audit section, write a ReadSecurityError for the one that does not, and keep the other account's entry the item on disk untouched after the removal and the result after Set-NTFSSecurityDescriptor; the -PassThru output type; exceptions from the change itself (open item 1) budget; budget; MaintainerDecision (open item)
28 audit Clear-NTFSAudit Path True 3 1 0 5 Yes Yes No Yes NA Audit.Tests.ps1:629 <Command> should use a held privilege or report a missing one and continue to the next path | Audit.Tests.ps1:455 Should remove the audit entries and keep the owner | Audit.Tests.ps1:478 Should write no error and leave the access entries unchanged | Audit.Tests.ps1:495 Should write an error and leave the item unchanged 2 (NTFSSecurity.Live.Tests.ps1:652, plus :684 through & $Command that the scan cannot see): SMB share; explicit entry cleared with the inherited entry and the owner kept; the delegated account gets a ClearAclError that names the missing privilege and leaves the SDDL unchanged; the file server checks the SACL (:1453) -DisableInheritance on a path is passed (Audit.Tests.ps1:629) but its end state (protected SACL, no copied inherited entries) is never asserted, and no test pipes paths or asserts the result of a succeeding path after a failing one. The owner retry after access denied cannot run on a local volume (Limit). TestNeeded Audit.Tests.ps1:457-459 asserts no error, owner kept (.NET) and no entry left (Get-NTFSAudit); :480-483 and :497-499 assert an unchanged DACL and, without the privilege, a ClearAclError with an unchanged SDDL; :631-669 and :672-679 add category and target. BoundBy 5 = scan 3 + & $Command at Audit.Tests.ps1:629 and PathErrors.Tests.ps1:124. Partly ParameterSets.Audit.Tests.ps1:305 Should clear the audit entries of each path taken from the pipeline and leave the DACL of each unchanged | ParameterSets.Audit.Tests.ps1:326 Should protect the SACL and not copy the parent's inherited entry when clearing a child path ParameterSets.Audit.Tests.ps1:339 Should clear the audit entries of each path taken from the pipeline and leave the DACL of each unchanged | ParameterSets.Audit.Tests.ps1:360 Should protect the SACL and not copy the parent's inherited entry when clearing a child path the result of a succeeding path that follows a failing one; the owner retry after access denied budget; Limit (needs a lab or a remote server)
29 audit Clear-NTFSAudit SD False 2 0 0 3 Yes Partly No No NA Audit.Tests.ps1:696 Should clear and protect the descriptor SACL without writing the <Type> | SecurityDescriptorSets.Tests.ps1:107 Clear-NTFSAudit should remove the explicit audit entries of the descriptor | Audit.Tests.ps1:425 <Command> should write an error and leave the descriptor without audit entries 0 No test pipes descriptors or passes several (one without audit entries), and the error test asserts the ErrorId but not category or target. TestNeeded Audit.Tests.ps1:698-705 asserts the in-memory SACL cleared and protected (.NET), the SACL of the item untouched until Set-NTFSSecurityDescriptor, then the state on disk and an unchanged DACL; SecurityDescriptorSets.Tests.ps1:109-112 asserts the same for the unprotected form. BoundBy 3 = scan 2 + & $Command at Audit.Tests.ps1:425 (error case only). Closed ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:347 Should clear each piped descriptor that has an audit section and continue past one that does not ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:381 Should clear each piped descriptor that has an audit section and continue past one that does not
30 audit Get-NTFSAudit Path False 24 4 2 27 NA Partly No Partly Partly Audit.Tests.ps1:529 Should name the folder that an inherited entry comes from, also with -ExcludeExplicit | Audit.Tests.ps1:48 Should write an error without the Security privilege instead of returning nothing | PathErrors.Tests.ps1:124 <Command> should write a ReadFileError for it and continue with the next path | Inheritance.Tests.ps1:387 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged 4 (NTFSSecurity.Live.Tests.ps1:336, 373, 656, 657): SMB share with domain accounts; Sid, AuditFlags and rights of the entry; the delegated account gets a ReadSecurityError that names the missing privilege No test pipes paths or FileInfo/DirectoryInfo into it, asserts the category of its errors or the target of ReadSecurityError, or (in unit tests) the type, AuditFlags and inheritance flags of the output. No unit test has a failing path followed by a path whose entries are asserted (Audit.Tests.ps1:70-73 documents that the second path of the test at :80 no longer fails), and the PermissionDenied branch cannot run on a local volume (Limit). TestNeeded Audit.Tests.ps1:50-52 asserts one ReadSecurityError by ErrorId only (basic user); :531-534 and :577-578 assert IsInherited and InheritedFrom; PathErrors.Tests.ps1:130-132 asserts ReadFileError and target for a missing path but discards the output (:124). BoundBy 27 = scan 24 + PermissionScopes:163 (26 of 52 cases) + & $Command at PathErrors.Tests.ps1:124 and Owner.Tests.ps1:98 (no -Path, Should -Not -Throw). Partly ParameterSets.Audit.Tests.ps1:376 Should return the entries of the existing path in either position and a ReadFileError, category OpenError, for the missing one | ParameterSets.Audit.Tests.ps1:405 Should return the entries of each path object taken from the pipeline by value | ParameterSets.Audit.Tests.ps1:420 Should write a ReadSecurityError with category OpenError and the path as target without the Security privilege ParameterSets.Audit.Tests.ps1:410 Should return the entries of the existing path in either position and a ReadFileError, category OpenError, for the missing one | ParameterSets.Audit.Tests.ps1:439 Should return the entries of each path object taken from the pipeline by value | ParameterSets.Audit.Tests.ps1:454 Should write a ReadSecurityError with category OpenError and the path as target without the Security privilege the PermissionDenied category branch of ReadSecurityError Limit (needs a lab or a remote server)
31 audit Get-NTFSAudit SD False 1 0 2 3 NA Partly Partly No Partly Audit.Tests.ps1:61 Should write an error for a security descriptor that was read without the audit entries | SecurityDescriptorSets.Tests.ps1:160 Get-NTFSAudit should return the audit entries that it returns for the path | PermissionScopes.Tests.ps1:163 Should add and remove <Name> using <Form> on <Source>, preserving the other account 0 The output is compared only with the output of the Path set (no expected type, flags or values), at most one descriptor is piped, and no test passes several descriptors (one without audit entries). The error test lacks category and target. TestNeeded Audit.Tests.ps1:63-65 asserts no output and one ReadSecurityError; SecurityDescriptorSets.Tests.ps1:160-163 pipes one descriptor and asserts one entry equal to the Path result (Sid, AccessRights, AuditFlags); PermissionScopes.Tests.ps1:163 asserts only emptiness after a removal. BoundBy 3 = scan 1 + SecurityDescriptorSets:160 (piped by value, so SD) + PermissionScopes:163 (26 of 52 cases). Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:434 Should return the entries of the piped descriptor that has an audit section and continue past one that does not ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:468 Should return the entries of the piped descriptor that has an audit section and continue past one that does not an expected type, flags, or values for the output, independent of comparing it to the Path set's output budget
32 audit Get-NTFSOrphanedAudit Path False 9 1 2 9 NA Partly No Yes Yes Audit.Tests.ps1:228 Should return one object per entry whose account cannot be resolved | Audit.Tests.ps1:250 Should return an inherited entry, and nothing with -ExcludeInherited | Audit.Tests.ps1:279 Should write an error for a path that does not exist and continue with the next path without the Security privilege | Audit.Tests.ps1:304 Should write a ReadSecurityError without the Security privilege instead of returning nothing 1 (NTFSSecurity.Live.Tests.ps1:843): SMB share; the entry of a deleted domain account is returned with its SID, without error or warning No test pipes paths into it, asserts the category of ReadError or ReadSecurityError, or runs -ExcludeExplicit, and the elevated continuation test passes on an empty result (Audit.Tests.ps1:273). TestNeeded Audit.Tests.ps1:230-232, :238-239 and :253-256 assert count, type, Sid and IsInherited; :282-286 (basic user) asserts ReadError for the missing path and a ReadSecurityError with its own target for the next path, which shows that the cmdlet continued, while :270-273 (elevated) asserts one error and then only a ForEach over the result. BoundBy 9 = scan 9. Partly ParameterSets.Audit.Tests.ps1:456 Should return the orphaned entries of each path taken from the pipeline and write a ReadError, category OpenError, for one that does not exist ParameterSets.Audit.Tests.ps1:490 Should return the orphaned entries of each path taken from the pipeline and write a ReadError, category OpenError, for one that does not exist the category of ReadSecurityError without the Security privilege; -ExcludeExplicit budget; budget
33 audit Get-NTFSOrphanedAudit SD False 0 0 2 2 NA Partly Partly No Partly Audit.Tests.ps1:243 Should read the entries of a security descriptor | Audit.Tests.ps1:294 Should write an error for a security descriptor that was read without the audit entries 0 At most one descriptor is piped and none is passed in an array, so continuation is untested; -Account and -Exclude* with a descriptor, the entry type and Sid, and the category and target of the error are not asserted. TestNeeded Both calls pipe one descriptor, which PowerShell binds by value to -SecurityDescriptor (the elevated run of :296-298 proves it: a Path binding would return entries): :245-246 assert 2 entries with FullName and :296-298 assert no output and one ReadSecurityError. BoundBy 2 = the two ambiguous piped calls (Audit.Tests.ps1:243 and :294); the scan found 0. Partly ParameterSets.Audit.Tests.ps1:74 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:477 Should return the orphaned entries of the piped descriptor that has an audit section and continue past one that does not | ParameterSets.Audit.Tests.ps1:499 Should return the orphaned entries when -SecurityDescriptor is named directly ParameterSets.Audit.Tests.ps1:95 <Command> should write a ReadSecurityError with category InvalidData and the descriptor as target for the <Set> set, and change nothing | ParameterSets.Audit.Tests.ps1:511 Should return the orphaned entries of the piped descriptor that has an audit section and continue past one that does not | ParameterSets.Audit.Tests.ps1:533 Should return the orphaned entries when -SecurityDescriptor is named directly -Account and -ExcludeInherited/-ExcludeExplicit filters with a descriptor budget
34 inheritance Disable-NTFSAccessInheritance Path True 9 1 0 16 Partly Partly No Partly Yes Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:301 Disable-NTFSAccessInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:133 <_> should write an error and return nothing when the security descriptor cannot be read 1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:281-289: no error, owner Administrators kept, DACL protected by Get-Acl) Not asserted: the error category (OpenError, WriteError), piped input (documented: Get-ChildItem2 | Disable-NTFSAccessInheritance -PassThru), a .NET readback of the kept or removed inherited entries (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given. TestNeeded Inheritance.Tests.ps1:341-360 asserts the -PassThru object (type, FullName, flag) and reads flag, owner and entries back only with Get-NTFSInheritance, Get-NTFSOwner and Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:307-309 and 183-191, DriveRoot.Tests.ps1:113). Errors: PathErrors.Tests.ps1:110-112 and 180-182 assert ErrorId and target, never the category; no test pipes into the cmdlet. BoundBy 16 = scan 9 (6 are fixtures) + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123). Partly ParameterSets.Inheritance.Tests.ps1:157 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru ParameterSets.Inheritance.Tests.ps1:178 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru OpenError category for a path that does not exist; the documented no-op without -Path budget; budget
35 inheritance Disable-NTFSAccessInheritance SecurityDescriptor False 1 0 0 2 Yes NA No NA Yes SecurityDescriptorSets.Tests.ps1:71 Disable-NTFSAccessInheritance should protect the DACL of the descriptor and keep the inherited entries | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type> 0 Not asserted: -RemoveInheritedAccessRules with a descriptor, the owner after the write, and several descriptors (array or pipeline). The set has no per-item handler, like the sets of open item 1 (which does not name it), but it cannot fail on a descriptor from Get-NTFSSecurityDescriptor. TestNeeded SecurityDescriptorSets.Tests.ps1:79-84 asserts the in-memory flag, the item unchanged before the write (Get-Acl), and after Set-NTFSSecurityDescriptor the flag and an explicit count equal to the inherited count (.NET); Inheritance.Tests.ps1:557-562 asserts count, FullName and flag of the -PassThru object. BoundBy 2 = scan 1 + Inheritance:555 (& $Command -SecurityDescriptor). Partly ParameterSets.Inheritance.Tests.ps1:234 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor ParameterSets.Inheritance.Tests.ps1:255 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor the owner unchanged after the descriptor write budget
36 inheritance Enable-NTFSAccessInheritance Path True 3 1 0 10 Partly Partly No Partly Yes Inheritance.Tests.ps1:318 Should set enabled=<Enable> on a <Type>, remove requested entries=<Remove>, and report the written state | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:312 Enable-NTFSAccessInheritance should take ownership, let the DACL inherit, and set the owner back | DriveRoot.Tests.ps1:110 Should block and restore the access inheritance of the folder that the drive maps 1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:291-299: no error, owner kept, DACL inherits again by Get-Acl) Not asserted: the error category, piped input (documented: Get-NTFSInheritance output piped into Enable-NTFSAccessInheritance -RemoveExplicitAccessRules), a .NET readback of explicit and inherited entries after the call (only Get-NTFSAccess reads them), RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op when no -Path is given. TestNeeded Inheritance.Tests.ps1:341-360 (Enable cases) asserts the object and reads re-inherited and explicit entries back only with Get-NTFSAccess; the .NET readbacks assert flag and owner only (PathErrors.Tests.ps1:319-321 and 190-191, DriveRoot.Tests.ps1:117). Errors as for Disable: ErrorId and target (PathErrors.Tests.ps1:110-112, 180-182), no category; no piped input. BoundBy 10 = scan 3 + 7 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:139,152,339,456; Privileges:123). Partly ParameterSets.Inheritance.Tests.ps1:157 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru ParameterSets.Inheritance.Tests.ps1:178 Should set the DACL protected flag to <Enable> and the explicit/inherited rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl | ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru OpenError category for a path that does not exist; the documented no-op without -Path budget; budget
37 inheritance Enable-NTFSAccessInheritance SecurityDescriptor False 1 0 0 2 Partly NA No NA Yes SecurityDescriptorSets.Tests.ps1:87 Enable-NTFSAccessInheritance should let the DACL of the descriptor inherit | Inheritance.Tests.ps1:543 <Command> should return the changed descriptor state without writing the <Type> 0 Not asserted: -RemoveExplicitAccessRules with a descriptor, that an explicit entry survives a plain Enable (the test descriptor has none), and several descriptors (array or pipeline). The set works in memory, so it has no error path or handler to test. TestNeeded SecurityDescriptorSets.Tests.ps1:94-99 asserts the in-memory flag, the item still protected, then (.NET) the flag false and inherited entries present after the write; the descriptor has no explicit entry, so kept versus removed is unasserted. Inheritance.Tests.ps1:557-562 (Enable cases) asserts count, FullName and flag. BoundBy 2 = scan 1 + Inheritance:555. Closed ParameterSets.Inheritance.Tests.ps1:234 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor ParameterSets.Inheritance.Tests.ps1:255 <Command> -SecurityDescriptor should change the in-memory access entries per -<SwitchName>:<Remove>, applied to the item only after Set-NTFSSecurityDescriptor writes it | ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor
38 inheritance Disable-NTFSAuditInheritance Path True 7 1 0 15 Partly Yes No Yes Yes Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | Inheritance.Tests.ps1:113 <_> should return nothing when the audit change fails 2 (SMB: Admin and ServerAdmin write it and the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:632 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690) Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit; the lab does, NTFSSecurity.Live.Tests.ps1:1453-1458), no test pipes into the set (documented: Get-ChildItem2 -Directory | Disable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY). TestNeeded Audit.Tests.ps1:629-679 runs two paths with -PassThru: as a basic user ModifySdError/WriteError/target then ReadFileError/OpenError/target and an empty result (672-679), elevated the object flag, the explicit SACL rules and the unchanged DACL and owner (631, 654-657). Inheritance.Tests.ps1:401-419 reads the SACL back only through Get-NTFSInheritance and Get-NTFSAudit (the DACL through .NET at 405). BoundBy 15 = scan 7 + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629). Partly ParameterSets.Inheritance.Tests.ps1:199 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru ParameterSets.Inheritance.Tests.ps1:220 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target
39 inheritance Disable-NTFSAuditInheritance SecurityDescriptor False 1 0 0 2 Partly NA No NA Yes Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type> | Inheritance.Tests.ps1:276 Should add no SACL to a security descriptor that was read without its audit entries 0 Not asserted: -RemoveInheritedAuditRules with a descriptor, an independent SACL readback after the write, the owner and DACL after the write, and several descriptors. The set accepts a descriptor without audit entries silently (pinned for Disable at Inheritance.Tests.ps1:276), unlike Add, Remove and Clear-NTFSAudit; see the notes. TestNeeded Inheritance.Tests.ps1:579-585 (elevated only) asserts count, FullName and flag of the object, the SACL SDDL unchanged until Set-NTFSSecurityDescriptor, and the flag after it, all through module cmdlets; :284-286 asserts that no SACL is added to a descriptor read without audit entries. BoundBy 2 = scan 1 (Inheritance:282) + Inheritance:577 (& $Command -SecurityDescriptor). Partly ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor -RemoveInheritedAuditRules with a descriptor as its own dedicated state test; the owner and DACL unchanged after the write budget; budget
40 inheritance Enable-NTFSAuditInheritance Path True 1 1 0 9 Partly Yes No Yes Yes Audit.Tests.ps1:606 <Command> should use a held privilege or report a missing one and continue to the next path | Inheritance.Tests.ps1:378 Should set enabled=<Enable> on a <Type>, remove requested audit entries=<Remove>, and leave the DACL unchanged | Inheritance.Tests.ps1:256 <Command> should set the audit inheritance of a <Type> and keep its access entries | PathErrors.Tests.ps1:118 <Command> should write a ReadFileError for it and continue with the next path 2 (SMB: the file server checks the SACL with Get-Acl -Audit, NTFSSecurity.Live.Tests.ps1:642 and 1453-1458; the delegated account gets ModifySdError naming the missing privilege and the folder stays unchanged, :684-690) Unit tests read the SACL only through module cmdlets (no Get-Acl -Audit), the result of -RemoveExplicitAuditRules is read back only with Get-NTFSAudit, no test pipes into the set (documented: Get-NTFSInheritance output piped into Enable-NTFSAuditInheritance), and the documented no-op without -Path is untested. [Limit] The ownership retry and RestoreOwnerError of a SACL write cannot be provoked on a local volume (rule AUDIT-OWNER-RETRY). TestNeeded Audit.Tests.ps1:660-662 (elevated) asserts the flag true and the explicit rules removed, and :672-679 the errors as a basic user; Inheritance.Tests.ps1:259-260 and 270-272 cover an item without SACL (flag by Get-NTFSInheritance, DACL by .NET). SACL state is never read with .NET in a unit test. BoundBy 9 = scan 1 (PipelineControl:284) + 8 calls through & $Command or & $_ (PathErrors:124; Inheritance:118,152,268,313,399; Privileges:123; Audit:629). Partly ParameterSets.Inheritance.Tests.ps1:199 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:458 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru ParameterSets.Inheritance.Tests.ps1:220 Should set the SACL protected flag to <Enable> and the explicit/inherited audit-rule counts for -Remove=<Remove> on a <Type>, read with Get-Acl -Audit | ParameterSets.Inheritance.Tests.ps1:479 <Command> should take piped folders from Get-ChildItem2 and report the <Scope> inheritance state of each with -PassThru the documented no-op without -Path; a successful ownership-retry/RestoreOwnerError of a SACL write budget; Limit, rule AUDIT-OWNER-RETRY needs a remote/SMB target
41 inheritance Enable-NTFSAuditInheritance SecurityDescriptor False 1 0 0 2 Partly NA No NA Yes SecurityDescriptorSets.Tests.ps1:115 Enable-NTFSAuditInheritance should let the SACL of the descriptor inherit | Inheritance.Tests.ps1:565 <Command> should return the changed audit state without writing the <Type> 0 Not asserted: -RemoveExplicitAuditRules with a descriptor, that an explicit audit entry survives a plain Enable, an independent SACL readback after the write, and several descriptors. Enable with an access-only descriptor is pinned only through Set-NTFSInheritance (Inheritance.Tests.ps1:524-539). TestNeeded SecurityDescriptorSets.Tests.ps1:119-126 (elevated) asserts the in-memory flag, the item still protected (Get-NTFSInheritance) and the flag after the write; Inheritance.Tests.ps1:579-585 (Enable cases) asserts count, FullName and flag. Nothing reads the SACL with .NET. BoundBy 2 = scan 1 + Inheritance:577. Partly ParameterSets.Inheritance.Tests.ps1:492,526 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor ParameterSets.Inheritance.Tests.ps1:513,547 <Command> -SecurityDescriptor should take two piped descriptors and report both in order, written only by Set-NTFSSecurityDescriptor -RemoveExplicitAuditRules with a descriptor as its own dedicated state test; an explicit audit entry surviving a plain Enable budget; budget
42 inheritance Get-NTFSInheritance Path True 23 4 0 27 NA Partly No Partly Partly PathErrors.Tests.ps1:104 <Command> should write a <ErrorId> for it and continue with the next path | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:54 Should report the same state as for the path of the item 4 (SMB: protected DACL with inherited audit flag, NTFSSecurity.Live.Tests.ps1:661-666; null audit state without the Security privilege, :695-700; two of the four calls are read-backs, :636 and :646) Not asserted: FullName, Name, type or exact count of the output, a protected state created without the module (all protected states come from the module's own cmdlets), the error category, piped input (documented: Get-ChildItem2 | Get-NTFSInheritance), and the result for no -Path (documented: current location; Owner.Tests.ps1:92 asserts -Not -Throw only). [Limit] The documented ownership retry has no success path on a local volume. TestNeeded Inheritance.Tests.ps1:58-59, 74-75 and 88-90 assert only the flags (the descriptor result equals the -Path result; audit false after Disable-NTFSAuditInheritance), no FullName, type or count. PathErrors.Tests.ps1:110-115 and 147-152 assert ErrorId, target and non-empty output for the next path, no category. BoundBy 27 = scan 23 + 4 calls through & $Command or & $_ (PathErrors:108,145; Owner:98; Privileges:123). Partly ParameterSets.Inheritance.Tests.ps1:364 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:543,552 Get-NTFSInheritance should take piped folder objects from Get-ChildItem2 and a piped custom object by its FullName property ParameterSets.Inheritance.Tests.ps1:385 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:564,573 Get-NTFSInheritance should take piped folder objects from Get-ChildItem2 and a piped custom object by its FullName property the Name property of the output; a protected state created without the module; the result for no -Path; a successful ownership-retry read budget; budget; budget; Limit, no local volume reaches the success path
43 inheritance Get-NTFSInheritance SecurityDescriptor False 4 0 0 4 NA NA No NA Partly Inheritance.Tests.ps1:54 Should report the same state as for the path of the item | Inheritance.Tests.ps1:65 Should report the same state as for the path of a <Type> without audit entries | Inheritance.Tests.ps1:78 Should report the disabled audit inheritance of a <Type> as for its path | Inheritance.Tests.ps1:93 Should report the audit inheritance as $null for a security descriptor without the audit entries 0 Not asserted: FullName, Name, type, exact count, several descriptors, a protected descriptor created without the module, and piped descriptors (documented: Get-NTFSSecurityDescriptor | Get-NTFSInheritance). The set works in memory and cannot fail on a readable descriptor. TestNeeded Inheritance.Tests.ps1:58-59, 74-75, 88-90 and 100-101 compare the flags with the -Path result and assert a null audit state for an access-only descriptor; none asserts FullName, Name, type, count or several descriptors. BoundBy 4 = scan 4. Partly ParameterSets.Inheritance.Tests.ps1:565,575 Get-NTFSInheritance -SecurityDescriptor should take two piped descriptors, one protected, and report both in order ParameterSets.Inheritance.Tests.ps1:586,596 Get-NTFSInheritance -SecurityDescriptor should take two piped descriptors, one protected, and report both in order the type of the output (BeOfType); a protected descriptor created without the module budget; budget
44 inheritance Set-NTFSInheritance Path True 14 1 0 18 Partly Partly No Partly Partly Inheritance.Tests.ps1:164 Should keep the inherited access entries as explicit ones when it disables access inheritance | PathErrors.Tests.ps1:157 <Command> should keep the denied item unchanged, report <ErrorId>, and process the next item | PathErrors.Tests.ps1:324 Set-NTFSInheritance should take ownership, protect the DACL, and set the owner back | Inheritance.Tests.ps1:422 Set-NTFSInheritance should re-enable audit inheritance on a <_> and keep its explicit audit entry 1 (SMB as the delegated account, NTFSSecurity.Live.Tests.ps1:302-309: DACL protected, owner kept) No test pipes into the set, including the documented round trip (Get-NTFSInheritance output piped into Set-NTFSInheritance, which binds both flags by property name); the SACL and the access-enable direction are read back only through module cmdlets. Also not asserted: the error category, the FullName of the -Path -PassThru object, RestoreOwnerError, -PassThru with a failing item among several, and the documented no-op without -Path. TestNeeded Inheritance.Tests.ps1:173-175 (.NET flag and explicit count), 428-433 (object, entries, DACL unchanged by .NET) and PathErrors.Tests.ps1:330-332 and 180-191 (owner, denied item unchanged, next item protected) are the strongest; the SACL and the access-enable direction are read back only with module cmdlets (Inheritance.Tests.ps1:371-373, 431-432). Inheritance.Tests.ps1:127-130 asserts no object after a failed audit change for one item, as a basic user only. BoundBy 18 = scan 14 + 4 calls through & $Command or & $_ (PathErrors:108,178; Inheritance:268; Privileges:123). Partly ParameterSets.Inheritance.Tests.ps1:324 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:347 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:588 Set-NTFSInheritance should restore a saved inheritance state through the pipeline by property name ParameterSets.Inheritance.Tests.ps1:345 <Command> should report <ErrorId> with category WriteError and target for the denied item, and still return the next item's new state with -PassThru | ParameterSets.Inheritance.Tests.ps1:368 <Command> should report RestoreOwnerError after a successful ownership retry and continue with the next path | ParameterSets.Inheritance.Tests.ps1:609 Set-NTFSInheritance should restore a saved inheritance state through the pipeline by property name an independent SACL readback of the result; OpenError category for a path that does not exist; the documented no-op without -Path budget; budget; budget
45 inheritance Set-NTFSInheritance SecurityDescriptor False 5 0 0 5 Partly NA No NA Yes Inheritance.Tests.ps1:465 Should set access inheritance enabled=<Enable> on a <Type> only when the descriptor is written | Inheritance.Tests.ps1:494 Should set audit inheritance enabled=<Enable> on a <Type> without changing its DACL or owner | Inheritance.Tests.ps1:524 Should keep audit inheritance unknown when requested enabled=<_> on an access-only descriptor | Inheritance.Tests.ps1:180 Should keep the inherited access entries of a security descriptor 0 Not asserted: several descriptors (array or pipeline), a single call that sets both -AccessInheritanceEnabled and -AuditInheritanceEnabled, and an independent SACL readback after the write (the audit side uses module cmdlets). The set works in memory and cannot fail on a readable descriptor. TestNeeded Inheritance.Tests.ps1:481-491 asserts count, FullName, Name, flag, the item unchanged until Set-NTFSSecurityDescriptor, then flag and owner by .NET and the explicit entry; :511-521 (elevated) does the audit side through module cmdlets; :533-539 asserts a null audit state and no SACL for an access-only descriptor. BoundBy 5 = scan 5. Closed ParameterSets.Inheritance.Tests.ps1:267 Set-NTFSInheritance -SecurityDescriptor should set both inheritance flags in one call, changing only the in-memory descriptor until it is written | ParameterSets.Inheritance.Tests.ps1:600,617 Set-NTFSInheritance -SecurityDescriptor should protect both descriptors in memory, written only by Set-NTFSSecurityDescriptor, piped and passed directly to the parameter ParameterSets.Inheritance.Tests.ps1:288 Set-NTFSInheritance -SecurityDescriptor should set both inheritance flags in one call, changing only the in-memory descriptor until it is written | ParameterSets.Inheritance.Tests.ps1:621,638 Set-NTFSInheritance -SecurityDescriptor should protect both descriptors in memory, written only by Set-NTFSSecurityDescriptor, piped and passed directly to the parameter
46 inheritance Get-NTFSOwner Path True 22 4 3 26 NA Partly Partly Partly Yes Owner.Tests.ps1:47 Should write one permission error and keep the owner | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | DriveRoot.Tests.ps1:45 Get-NTFSOwner should return the owner of the root folder | ObjectApis.Tests.ps1:706 Should name the item and the account of an owner object Owner.Tests.ps1:47 Should write one permission error and keep the owner | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path | DriveRoot.Tests.ps1:45 Get-NTFSOwner should return the owner of the root folder | ObjectApis.Tests.ps1:725 Should name the item and the account of an owner object 4 (SMB: owner Administrators, NTFSSecurity.Live.Tests.ps1:585-589; three calls check that the privileges are disabled after a later command ends the pipeline, :1406, 1411, 1422) No test asserts ErrorId, category and target together (Owner.Tests.ps1:55-56 id and category, PathErrors.Tests.ps1:148-149 id and target); piping covers one FileInfo only (documented: Get-ChildItem2 -Recurse | Get-NTFSOwner); the next item's output is asserted only as non-empty; the documented 'returns nothing' without -Path is untested. TestNeeded Owner.Tests.ps1:53-56 asserts no output, one error, ReadSecurityError and PermissionDenied (basic user only, skipped with the Backup privilege); PathErrors.Tests.ps1:147-151 asserts id, target and non-empty output for the next path; DriveRoot.Tests.ps1:46 compares Owner.Sid with Get-Acl; ObjectApis.Tests.ps1:711-713 (line numbers at HEAD 6696f68; +19 in a work tree with the uncommitted ObjectApis edit) asserts Item, FullName and Account. BoundBy 26 = scan 22 + ambiguous Owner:177 and :185 (both bind Path) + PathErrors:108,145. Owner.Tests.ps1:53-56 asserts no output, one error, ReadSecurityError and PermissionDenied (basic user only, skipped with the Backup privilege); PathErrors.Tests.ps1:147-151 asserts id, target and non-empty output for the next path; DriveRoot.Tests.ps1:46 compares Owner.Sid with Get-Acl; ObjectApis.Tests.ps1:730-732 (line numbers at HEAD 6696f68; +19 in a work tree with the uncommitted ObjectApis edit) asserts Item, FullName and Account. BoundBy 26 = scan 22 + ambiguous Owner:177 and :185 (both bind Path) + PathErrors:108,145. Partly ParameterSets.Inheritance.Tests.ps1:379 Get-NTFSOwner should write a ReadSecurityError with its id, category, and target together for a denied item, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:631 Get-NTFSOwner should take two piped folders from Get-ChildItem2 and return the owner of each, verified with Get-Acl ParameterSets.Inheritance.Tests.ps1:400 Get-NTFSOwner should write a ReadSecurityError with its id, category, and target together for a denied item, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:652 Get-NTFSOwner should take two piped folders from Get-ChildItem2 and return the owner of each, verified with Get-Acl the documented 'returns nothing' without -Path budget
47 inheritance Get-NTFSOwner SecurityDescriptor False 0 0 3 1 NA NA Partly NA Partly SecurityDescriptorSets.Tests.ps1:146 Get-NTFSOwner should return the owner that it returns for the path 0 One test, one descriptor; the owner is compared with the -Path result of the same cmdlet, with no .NET oracle, no type assertion and no several descriptors. The result for a descriptor read without its Owner section is unexercised (see the notes). TestNeeded The scan's ambiguous rows Owner.Tests.ps1:177 (System.IO DirectoryInfo by position) and :185 (System.IO FileInfo piped) bind Path: FileSystemPathTransformation turns a file system object into its path, and those types do not convert to FileSystemSecurity2[]. Only SecurityDescriptorSets.Tests.ps1:149-153 binds the set: a FileSystemSecurity2 piped by value, asserting count 1, Owner.Sid against the -Path result and FullName. BoundBy 1 (scan 0 + that call). Partly ParameterSets.Inheritance.Tests.ps1:655,665 Get-NTFSOwner -SecurityDescriptor should return the owner of each descriptor, piped and passed directly to the parameter, verified with Get-Acl ParameterSets.Inheritance.Tests.ps1:676,686 Get-NTFSOwner -SecurityDescriptor should return the owner of each descriptor, piped and passed directly to the parameter, verified with Get-Acl the result for a descriptor read without its Owner section budget, a read-only probe just now shows it returns the item's real owner, not a crash, so it is safely testable and simply was not written
48 inheritance Set-NTFSOwner Path True 8 4 1 10 Partly Partly Yes Partly Yes Owner.Tests.ps1:240 Should set an owner that only the Restore privilege allows | Owner.Tests.ps1:232 Should take the items from the pipeline | Owner.Tests.ps1:270 Should write a SetOwnerError and keep the owner | Owner.Tests.ps1:248 Should write a read error for a path that does not exist and continue with the next path 4 (SMB: take ownership as the account itself, assign another account only with the file server's Restore privilege (SetOwnerError for the delegated account), NTFSSecurity.Live.Tests.ps1:595 and 604; a later command that stops the pipeline leaves the second item's owner unchanged, :1143, 1182) Not asserted: DACL, SACL and group unchanged after the owner changes; as a basic user the owner already equals the user, so Owner.Tests.ps1:217, 229 and 256 cannot show a change; the error category and target (SetOwnerError); -PassThru with a failing item among several; and the documented no-op without -Path. TestNeeded Owner.Tests.ps1:245 (.NET owner is TrustedInstaller, needs the Restore privilege), :225-229 (count, type, FullName, Owner.Sid, .NET owner), :237 (two piped Get-Item2 objects) and :277-279 (SetOwnerError id only, owner unchanged). The scan's ambiguous Owner:235 binds Path (the Get-Item2 objects bind by their FullName property). BoundBy 10 = scan 8 + Owner:235 + PathErrors:108. Partly ParameterSets.Inheritance.Tests.ps1:293 Set-NTFSOwner should change only the owner and leave the Access entries and the group unchanged | ParameterSets.Inheritance.Tests.ps1:406,423 Should write <ErrorId> with its category and target for <Scenario>, and keep processing the remaining path ParameterSets.Inheritance.Tests.ps1:314 Set-NTFSOwner should change only the owner and leave the Access entries and the group unchanged | ParameterSets.Inheritance.Tests.ps1:427,444 Should write <ErrorId> with its category and target for <Scenario>, and keep processing the remaining path the SACL unchanged after the owner changes; the documented no-op without -Path budget; budget
49 inheritance Set-NTFSOwner SecurityDescriptor False 2 0 1 2 Partly NA No NA Partly Owner.Tests.ps1:284 Should change only the descriptor in memory until Set-NTFSSecurityDescriptor writes it | Owner.Tests.ps1:303 Should write nothing without -PassThru and leave the owner of the item unchanged 0 The persisted-owner test is skipped for basic users (Owner.Tests.ps1:287-290); not asserted: DACL unchanged after the write, FullName and type of the -PassThru object (only the -Path set asserts them), and several descriptors (array or pipeline). TestNeeded Owner.Tests.ps1:296-300 asserts count, Owner.Sid, the item's owner unchanged until Set-NTFSSecurityDescriptor and changed after (.NET), but the test is skipped when the user owns new items (:287-290); :312-314 asserts no output without -PassThru, the in-memory owner and the item's owner unchanged. BoundBy 2 = scan 2. Partly ParameterSets.Inheritance.Tests.ps1:677,692 Set-NTFSOwner -SecurityDescriptor should change both owners in memory without touching the items, piped and passed directly to the parameter ParameterSets.Inheritance.Tests.ps1:698,713 Set-NTFSOwner -SecurityDescriptor should change both owners in memory without touching the items, piped and passed directly to the parameter the DACL unchanged after the write; the type of the -PassThru object (BeOfType) budget; budget
50 inheritance Get-NTFSSecurityDescriptor __AllParameterSets False 79 5 0 82 NA Partly No Partly Yes SecurityDescriptor.Tests.ps1:52 Should report the inherited access entries as inherited | SecurityDescriptor.Tests.ps1:63 Should read the owner and the audit entries with the access entries | DriveRoot.Tests.ps1:39 Get-NTFSSecurityDescriptor should read the DACL of the root folder | PathErrors.Tests.ps1:140 <Command> should write a ReadSecurityError for it and continue with the next path 5 (SMB read-backs for the descriptor tests, NTFSSecurity.Live.Tests.ps1:315, 965, 1150, and InheritedFrom of a vanished item, :988, 1017) Untested combinations: piped paths and file or folder objects (documented: Get-ChildItem2 | Get-NTFSSecurityDescriptor), no -Path (current location; Owner.Tests.ps1:92 asserts -Not -Throw only), the error category, and that the next item yields exactly one descriptor. [Limit] The documented ownership retry has no success path on a local volume. TestNeeded SecurityDescriptor.Tests.ps1:59-60 (inherited flags against the Get-Acl count) and :70-71 (owner against Get-Acl, audit rules) need the Security privilege; DriveRoot.Tests.ps1:42 compares the DACL SDDL with Get-Acl; PathErrors.Tests.ps1:110-115 and 147-152 assert ReadFileError and ReadSecurityError with target and non-empty output. BoundBy 82 = scan 79 + 3 calls through & $Command or & $_ (PathErrors:108,145; Owner:98). Partly ParameterSets.Inheritance.Tests.ps1:364 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:706,717,724 Get-NTFSSecurityDescriptor should take piped folder objects, a standard Get-Item object, and a piped custom object by its Path property ParameterSets.Inheritance.Tests.ps1:385 <Command> should write <ErrorId> with category OpenError for a path that does not exist, and return exactly one object for the next path | ParameterSets.Inheritance.Tests.ps1:727,738,745 Get-NTFSSecurityDescriptor should take piped folder objects, a standard Get-Item object, and a piped custom object by its Path property the result for no -Path (current location); a successful ownership-retry read budget; Limit, no local volume reaches the success path
51 inheritance Set-NTFSSecurityDescriptor __AllParameterSets False 29 4 0 29 Yes Yes Yes Yes Yes SecurityDescriptor.Tests.ps1:299 Should report a denied write, return no failed item, and write the next descriptor | SecurityDescriptor.Tests.ps1:249 Should report RestoreOwnerError for a previous owner that it cannot set back after the write | SecurityDescriptor.Tests.ps1:213 Should return the written descriptor with -PassThru also when it took ownership for the write | SecurityDescriptor.Tests.ps1:133 Should not write back the access entries of an unchanged descriptor 4 (SMB: writes the added entry and keeps the owner, NTFSSecurity.Live.Tests.ps1:317; writes the cleared DACL without RestoreOwnerError, :968; a later command that stops the pipeline leaves the second descriptor unwritten, :1154, 1165) Untested combinations: positional binding (declared Position 2), the by-property-name pipeline form, and the category and target of the -PassThru ReadSecurityError (only its ErrorId is asserted, SecurityDescriptor.Tests.ps1:361). [Limit] A failing SACL write needs a lab. None SecurityDescriptor.Tests.ps1:308-317 pipes two descriptors with -PassThru and asserts WriteSdError, category WriteError, target, the denied item's SDDL unchanged (.NET), one object for the next item and its entry; :259-264 asserts RestoreOwnerError with category and target; :223-226 asserts the -PassThru object after an ownership retry. BoundBy 29 = scan 29 (no calls through variables). None positional binding at Position 2; the by-property-name pipeline form; category and target of the -PassThru ReadSecurityError would-pin, Position 2 vs siblings' Position 1 looks like an undecided inconsistency per the notes; budget, row judged GapKind None; budget, row judged GapKind None
52 items Copy-Item2 __AllParameterSets False 6 4 0 20 Yes Yes No Yes Partly ItemCmdlets.Tests.ps1:756 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:785 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:605 <_> should write DestinationFileAlreadyExists for a folder that exists at the destination and change nothing | ItemCmdlets.Tests.ps1:644 Copy-Item2 -Force should copy a folder into an existing folder of the same name and replace the files in both ItemCmdlets.Tests.ps1:786 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:815 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:635 <_> should write DestinationFileAlreadyExists for a folder that exists at the destination and change nothing | ItemCmdlets.Tests.ps1:674 Copy-Item2 -Force should copy a folder into an existing folder of the same name and replace the files in both 4: -WhatIf onto an existing file on a share (#108, administrator); copy of a file and a folder as the delegated account; later-command stop on a share No test pipes paths into it (documented: Get-ChildItem2 | Copy-Item2 -Destination), passes an empty or null -Path, a FileInfo object, a path with brackets, a path over 260 characters or a drive root, and -Force replacing an existing file is covered only through the folder merge. FileNotFound and the file case of DestinationFileAlreadyExists are asserted by error count only, and -PassThru asserts FullName but not the output type or that nothing is written without it. TestNeeded ItemCmdlets.Tests.ps1:756-771 and :785-797 assert ErrorId, category, target, exception type, only the second item's result and untouched sources; :605-613 and :644-649 read the folder conflict and the merge back; Owner.Tests.ps1:160-163 reads the copied content. 14 of the 20 call sites are '& $Command' calls in ItemCmdlets.Tests.ps1 (lines 514 to 814) that the scan does not resolve. ItemCmdlets.Tests.ps1:786-801 and :815-827 assert ErrorId, category, target, exception type, only the second item's result and untouched sources; :605-613 and :644-649 read the folder conflict and the merge back; Owner.Tests.ps1:160-163 reads the copied content. 14 of the 20 call sites are '& $Command' calls in ItemCmdlets.Tests.ps1 (lines 514 to 814) that the scan does not resolve. Partly ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location a path with brackets; a path over 260 characters; a drive root; -Force replacing an existing file (still only covered through the folder merge); the file case of DestinationFileAlreadyExists with category/target (still error count only); -PassThru output type; that nothing is written without -PassThru budget (all items; none needs a lab, none pins an open maintainer decision)
53 items Get-ChildItem2 __AllParameterSets False 34 8 0 36 NA Yes No Yes Yes ItemCmdlets.Tests.ps1:98 Should apply <Case> without broadening the other attribute filters | ItemCmdlets.Tests.ps1:137 Should return the exact tree for <Case> | ItemCmdlets.Tests.ps1:282 Should report the denied folder and continue with the next path | ItemCmdlets.Tests.ps1:340 Should report a junction whose target was removed as a DirUnspecifiedError and continue with the next folder ItemCmdlets.Tests.ps1:98 Should apply <Case> without broadening the other attribute filters | ItemCmdlets.Tests.ps1:137 Should return the exact tree for <Case> | ItemCmdlets.Tests.ps1:312 Should report the denied folder and continue with the next path | ItemCmdlets.Tests.ps1:370 Should report a junction whose target was removed as a DirUnspecifiedError and continue with the next folder 8: over SMB: path over 260 characters (administrator), -Hidden and a listing (delegated account), -Filter cases, later-command stop with a denied nested folder No test pipes folders or strings into -Path (documented by value and by FullName), asserts the result of omitting -Path or of a relative -Path (Owner.Tests.ps1:98 only asserts no throw), or lists a drive root or a path over 260 characters in a unit test. -Directory with -File, -Attributes with -Force/-Hidden/-System/-ReadOnly (documented: ignored), -Depth without -Recurse and the dir2 alias are unasserted, and FileNotFound and AttributesEmpty are asserted without category (and without target for AttributesEmpty); the -Filter dot rules are pinned already and are the maintainer's, so they are not counted here. TestNeeded ItemCmdlets.Tests.ps1:98-100 and :137-140 assert exact name sets for ten attribute-switch cases and for the Recurse/Depth/Directory/File/Filter cases; :282-289 and :340-348 assert ErrorId, category, target (and exception type) and that the next path or sibling is still listed; :44-49 and :402-406 assert the AlphaFS types; PathErrors.Tests.ps1:108-114 covers FileNotFound (ID and target only). Partly ParameterSets.Items.Tests.ps1:91 Should accept piped folders by value, write one error for a path that does not exist, and list the items of the other folders | ParameterSets.Items.Tests.ps1:111 Should accept folder objects piped from Get-ChildItem2 -Directory and list only the files directly below them the result of an omitted -Path; the result of a relative -Path; a drive root in a unit test; a path over 260 characters in a unit test; -Directory with -File together; -Attributes with -Force/-Hidden/-System/-ReadOnly; -Depth without -Recurse; the dir2 alias; AttributesEmpty category and target budget (all items; the -Filter dot rules are the maintainer's and were already excluded from this Gap)
54 items Get-Item2 __AllParameterSets False 17 1 0 19 NA Partly No Partly Partly PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path | ItemCmdlets.Tests.ps1:935 Get-Item2 should resolve <Path> against the current location | Owner.Tests.ps1:235 Should take the items from the pipeline | PipelineControl.Tests.ps1:124 <Name> should stop after the first object for Select-Object -First 1 and change nothing else PathErrors.Tests.ps1:108 <Command> should write a <ErrorId> for it and continue with the next path | ItemCmdlets.Tests.ps1:965 Get-Item2 should resolve <Path> against the current location | Owner.Tests.ps1:235 Should take the items from the pipeline | PipelineControl.Tests.ps1:124 <Name> should stop after the first object for Select-Object -First 1 and change nothing else 1: FullName and Length of a file on a share (delegated account) No test pipes paths into it (documented: 'C:\Data','C:\Data\Reports' | Get-Item2) or omits -Path (documented: the current location), and the output type (FileInfo or DirectoryInfo) and the Mode property are never asserted; bracket paths, paths over 260 characters and a drive root are untested. The FileNotFound category is not asserted and the output for the next path is checked only as non-empty. TestNeeded PathErrors.Tests.ps1:108-114 asserts one FileNotFound error with the missing path as target and non-empty output for the next path; ItemCmdlets.Tests.ps1:935-943 asserts HaveCount 1 and FullName for six relative paths. 15 of the 17 scan calls are fixtures that feed descriptors or other cmdlets (Access, Audit, Inheritance, ObjectApis, Owner, SecurityDescriptor). PathErrors.Tests.ps1:108-114 asserts one FileNotFound error with the missing path as target and non-empty output for the next path; ItemCmdlets.Tests.ps1:965-973 asserts HaveCount 1 and FullName for six relative paths. 15 of the 17 scan calls are fixtures that feed descriptors or other cmdlets (Access, Audit, Inheritance, ObjectApis, Owner, SecurityDescriptor). Partly ParameterSets.Items.Tests.ps1:133 Should accept piped items by value, return each in order with its output type, and write one error for a path that does not exist an omitted -Path defaulting to the current location; bracket paths; paths over 260 characters; a drive root budget (all items)
55 items Move-Item2 __AllParameterSets False 7 3 0 21 Yes Yes No Yes Yes ItemCmdlets.Tests.ps1:756 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:785 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:621 Move-Item2 -Force should replace an existing file with PassThru=<_> | ItemCmdlets.Tests.ps1:841 Should refuse to move <Kind> folder to another volume and leave it in place ItemCmdlets.Tests.ps1:786 <Command> should write a <ErrorId> for a source that another process has locked and continue with the next path | ItemCmdlets.Tests.ps1:815 <Command> should write a <ErrorId> for each source when the destination folder denies new files | ItemCmdlets.Tests.ps1:651 Move-Item2 -Force should replace an existing file with PassThru=<_> | ItemCmdlets.Tests.ps1:871 Should refuse to move <Kind> folder to another volume and leave it in place 3: -WhatIf onto an existing file on a share (administrator); move of a file as the delegated account; later-command stop on a share No test pipes paths into it (documented), passes an empty or null -Path, moves a non-empty folder tree, or renames an item inside one folder on the same volume (the cross-volume cases need an elevated admin share), and -Force replacing a folder, bracket or wildcard paths, paths over 260 characters and a drive-root destination are untested. FileNotFound is asserted by error count only. TestNeeded ItemCmdlets.Tests.ps1:621-631 asserts the source is gone, the content at the destination and PassThru true and false; :576-592 asserts the moved file and folder (DirectoryInfo) and the removed source folder; :756-771 and :785-797 assert ErrorId, category, target, exception type and the other item's result. The cross-volume tests at :841-878 skip without an elevated admin share. ItemCmdlets.Tests.ps1:651-661 asserts the source is gone, the content at the destination and PassThru true and false; :576-592 asserts the moved file and folder (DirectoryInfo) and the removed source folder; :756-771 and :785-797 assert ErrorId, category, target, exception type and the other item's result. The cross-volume tests at :841-878 skip without an elevated admin share. Partly ParameterSets.Items.Tests.ps1:36 <Command> should accept <InputKind> piped by value and still process the surrounding items | ParameterSets.Items.Tests.ps1:229 <Command> should reject -Path <CaseName> instead of silently using the current location moving a non-empty folder tree; renaming an item in place on the same volume; -Force replacing a folder; bracket or wildcard paths; paths over 260 characters; a drive-root destination budget (all items)
56 items Remove-Item2 __AllParameterSets False 15 2 0 16 Yes Yes No Yes Partly Remove-Item2.Tests.ps1:43 Should report DeleteError for a non-empty folder without -Recurse and continue with the next path | Remove-Item2.Tests.ps1:104 Should write DeleteError when a descendant is open without delete sharing, not a successful -PassThru result | Remove-Item2.Tests.ps1:126 Should delete a junction with -Recurse without deleting or changing its target | Remove-Item2.Tests.ps1:77 Should leave a folder tree unchanged with -Recurse -Force -WhatIf and write nothing with -PassThru 2: removal of a file on a share as the delegated account; later-command stop on a share No test pipes items into it (documented: Get-ChildItem2 ... | Remove-Item2), omits -Path (documented: the cmdlet does nothing), passes an empty or null -Path (the ValidateNotNullOrEmpty guard that keeps it from meaning the current location), passes bracket or wildcard paths (documented: literal) or uses rm2/del2. FileNotFound is asserted by error count only (ItemCmdlets.Tests.ps1:507), the access-denied branch of DeleteError (category NotSpecified) is unasserted, and that a successful removal without -PassThru writes nothing is not asserted. No test pipes items into it (documented: Get-ChildItem2 ... | Remove-Item2), omits -Path (documented: the cmdlet does nothing), passes an empty or null -Path (the ValidateNotNullOrEmpty guard that keeps it from meaning the current location), passes bracket or wildcard paths (documented: literal) or uses rm2/del2. FileNotFound is asserted by error count only (ItemCmdlets.Tests.ps1:537), the access-denied branch of DeleteError (category NotSpecified) is unasserted, and that a successful removal without -PassThru writes nothing is not asserted. TestNeeded Remove-Item2.Tests.ps1:43-52 asserts DeleteError, InvalidData, target, kept content, the removed next item and exactly one result; :104-114 and :152-158 assert DeleteError and no success-shaped result with the content kept; :126-130 asserts the junction is removed and its target content and SDDL are unchanged; :176-184 covers the -PassThur alias. Partly ParameterSets.Items.Tests.ps1:157 Should accept piped items by value, write one error for a non-empty folder, remove the files, and keep the folder | ParameterSets.Items.Tests.ps1:185 Remove-Item2 should reject -Path <CaseName> instead of removing the current location -Path omitted entirely (documented: the cmdlet does nothing); bracket or wildcard paths; the rm2/del2 aliases; FileNotFound category/target (still error count only); the access-denied DeleteError branch (category NotSpecified); that a successful removal without -PassThru writes nothing budget (all items)
57 items Test-Path2 __AllParameterSets False 14 3 0 14 NA NA Partly Yes Yes ItemCmdlets.Tests.ps1:967 Should return <Expected> for a <Kind> with -PathType <PathType> | ItemCmdlets.Tests.ps1:1009 Should return $false for a path with the character <_> and continue with the next path | ItemCmdlets.Tests.ps1:1000 Should find a folder whose path is longer than 260 characters | ItemCmdlets.Tests.ps1:981 Should take the items from the pipeline ItemCmdlets.Tests.ps1:997 Should return <Expected> for a <Kind> with -PathType <PathType> | ItemCmdlets.Tests.ps1:1039 Should return $false for a path with the character <_> and continue with the next path | ItemCmdlets.Tests.ps1:1030 Should find a folder whose path is longer than 260 characters | ItemCmdlets.Tests.ps1:1011 Should take the items from the pipeline 3: file, folder and missing item with -PathType on a share (delegated account) The pipeline test pipes one file; no test pipes several items (documented: Get-ChildItem2 -Recurse | Test-Path2 -PathType Leaf) or objects with PathType by property name, or tests a drive root, a UNC path or a bracket path. Errors are NA because the cmdlet writes $false for a missing or invalid path; its PathNotFound handler looks unreachable (see the notes). TestNeeded ItemCmdlets.Tests.ps1:967-972 asserts one [bool] with the expected value for file, folder and missing item under all three -PathType values; :1009-1013 asserts no error and 'False,True' for six invalid characters followed by a valid path; :981-983 pipes one FileInfo; :992-1001 covers a folder path over 260 characters. ItemCmdlets.Tests.ps1:997-1002 asserts one [bool] with the expected value for file, folder and missing item under all three -PathType values; :1009-1013 asserts no error and 'False,True' for six invalid characters followed by a valid path; :981-983 pipes one FileInfo; :992-1001 covers a folder path over 260 characters. Open piping several items into -Path; -PathType bound by property name; a drive root; a UNC path; a bracket path budget (deprioritized: PipelineInput was already Partly, not No, so lower priority than the cmdlets with no pipeline test at all)
58 items Get-FileHash2 __AllParameterSets False 12 2 0 13 Partly Partly Partly Partly Yes FileHash.Tests.ps1:41 Should return the hash of Get-FileHash for <_> | FileHash.Tests.ps1:94 Should skip the folder and hash the files that follow it | FileHash.Tests.ps1:108 Should write an error and no result for the file | FileHash.Tests.ps1:153 Should report both the failed read and the failed owner restoration without returning a hash 2: SHA256 equals Get-FileHash on a share (delegated account); later-command stop at the verbose message No test pipes FileInfo/DirectoryInfo objects or folders (documented: Get-ChildItem2 -Recurse | Get-FileHash2) or Algorithm by property name, hashes a relative path or a path over 260 characters, or puts the failing path first and asserts the next hash; no error category is asserted. The owner-restore tests run only elevated and read the owner back with Get-NTFSOwner, and the retry that succeeds after taking ownership is untested. TestNeeded FileHash.Tests.ps1:41-44 compares Hash and Algorithm with Get-FileHash for five algorithms; :94-98 skips a folder and hashes the next file with the SHA256 default; :108-115 asserts one error and no result for a locked file; :153-160 (elevated only) asserts RestoreOwnerError and GetHashError with target, no result and the restored owner; OutputTypes.Tests.ps1:57 asserts the type name. Partly ParameterSets.Items.Tests.ps1:516 Should accept Get-ChildItem2 objects piped by value, skip a folder, and match Get-FileHash for each file | ParameterSets.Items.Tests.ps1:548 Should write GetHashError with its category for a locked file first, hash the file that follows it, and resolve a relative path ParameterSets.Items.Tests.ps1:531 Should accept Get-ChildItem2 objects piped by value, skip a folder, and match Get-FileHash for each file | ParameterSets.Items.Tests.ps1:565 Should write GetHashError with its category for a locked file first, hash the file that follows it, and resolve a relative path -Algorithm bound by property name from the pipeline; a path over 260 characters; the ownership-retry-after-taking-ownership success path -Algorithm by property name and >260 chars: budget; ownership-retry success: Limit (elevated-only, needs a DACL/owner setup not shown buildable)
59 items Get-DiskSpace __AllParameterSets False 6 0 0 6 NA Partly NA No Yes ItemCmdlets.Tests.ps1:1038 Should return the size of the system drive | ItemCmdlets.Tests.ps1:1056 Should return the volumes with a size greater than zero without -DriveLetter | ItemCmdlets.Tests.ps1:1072 Should warn and return nothing for a drive letter without a volume | ItemCmdlets.Tests.ps1:1080 Should reject a drive letter without a colon ItemCmdlets.Tests.ps1:1068 Should return the size of the system drive | ItemCmdlets.Tests.ps1:1086 Should return the volumes with a size greater than zero without -DriveLetter | ItemCmdlets.Tests.ps1:1102 Should warn and return nothing for a drive letter without a volume | ItemCmdlets.Tests.ps1:1110 Should reject a drive letter without a colon 0 No test passes several drive letters, so the documented warn-and-continue for a letter without a volume is never combined with a valid letter; lower-case letters, positional binding and the free-space values against an independent source are unasserted. The validation error is asserted by ErrorId only (no category or target). TestNeeded ItemCmdlets.Tests.ps1:1038-1043 asserts type, DriveName and TotalNumberOfBytes against System.IO.DriveInfo; :1072-1077 asserts the exact warning text and no output or error for a letter without a volume; :1056-1061 asserts every volume has a size above zero and the system drive is included; :1080-1081 asserts the ErrorId of the validation error. ItemCmdlets.Tests.ps1:1068-1073 asserts type, DriveName and TotalNumberOfBytes against System.IO.DriveInfo; :1072-1077 asserts the exact warning text and no output or error for a letter without a volume; :1056-1061 asserts every volume has a size above zero and the system drive is included; :1080-1081 asserts the ErrorId of the validation error. Partly ParameterSets.Items.Tests.ps1:459 Should return only the system drive and warn for a drive letter without a volume, regardless of order (<Order>) | ParameterSets.Items.Tests.ps1:480 Should accept a lower-case drive letter positionally and report the same total size as .NET ParameterSets.Items.Tests.ps1:470 Should return only the system drive and warn for a drive letter without a volume, regardless of order (<Order>) | ParameterSets.Items.Tests.ps1:491 Should accept a lower-case drive letter positionally and report the same total size as .NET the free-space values (TotalNumberOfFreeBytes/FreeBytesAvailable) against an independent source (only TotalNumberOfBytes was compared); the validation error's category and target (still ErrorId only) budget (both items)
60 items New-NTFSHardLink __AllParameterSets False 14 2 0 17 Yes Yes Yes Yes Yes Links.Tests.ps1:134 Should write a non-terminating error for each link that it cannot create and continue with the next one | Links.Tests.ps1:170 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:67 Should return every name of the file with -PassThru | Links.Tests.ps1:79 Should give both names the same data 2: link creation on a share (administrator) and -PassThru, which writes GetHardLinkError there Positional binding (documented example 2), a FileInfo object bound to -Path or -Target and the end of a pipeline by a later command are untested; the -PassThru GetHardLinkError on a share is asserted by ErrorId only (no category or target) and only with an elevated admin share. A hard link across volumes cannot be built on a one-volume host. TestNeeded Links.Tests.ps1:134-145 pipes four objects by property name and asserts three errors (ErrorId, categories, targets, message), the created link and unchanged files; :170-179 asserts PermissionDenied, exception type, no output and no link; :36-41, :67-73 and :79-84 read back existence, all names and the shared data. Three of the 17 call sites (Links.Tests.ps1:450, 468, 494) are '& $Command' calls that the scan does not resolve. Partly ParameterSets.Items.Tests.ps1:253 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:313 New-NTFSHardLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched ParameterSets.Items.Tests.ps1:264 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:324 New-NTFSHardLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched positional binding (documented example 2); a FileInfo object bound to -Path or -Target; the -PassThru GetHardLinkError category and target on an admin share (still ID only) budget (all items; an elevated admin share is already available on this host, simply not used for this)
61 items Get-NTFSHardLink __AllParameterSets False 9 1 0 10 NA Partly Yes Yes Partly Links.Tests.ps1:224 Should write an error for a path that does not exist and continue with the next path | Links.Tests.ps1:236 Should write an error for a folder and continue with the next path | Links.Tests.ps1:214 Should take the files with more than one name from Get-ChildItem2 | Links.Tests.ps1:200 Should return every name of a file with hard links 1: writes GetHardLinkError on a share (administrator) The output type is never asserted (only FullName and Mode), the error categories (InvalidArgument for a folder, ObjectNotFound, ReadError on a share) are unasserted, and positional binding and strings from the pipeline are untested. The UnauthorizedAccessException handler cannot be reached by a test because Windows lists the names without opening the file (Links.Tests.ps1:262). TestNeeded Links.Tests.ps1:224-229 and :236-243 assert one error (FileNotFound; GetHardLinkError with target and message) and exactly the next file; :214-218 pipes AlphaFS file objects and asserts the names of both linked files and not the third; :200-203 asserts all names of a linked file; PathErrors.Tests.ps1:108-114 asserts ID and target for a missing path. Partly ParameterSets.Items.Tests.ps1:286 Should accept piped strings by value, write errors with their categories for a folder and a missing path, and return the files in order ParameterSets.Items.Tests.ps1:297 Should accept piped strings by value, write errors with their categories for a folder and a missing path, and return the files in order the ReadError category on a network share (still ID/target only); the UnauthorizedAccessException handler ReadError on a share: budget (admin share available elevated, not implemented here); UnauthorizedAccessException handler: Limit (structurally unreachable, Windows lists hard-link names without opening the file)
62 items New-NTFSSymbolicLink __AllParameterSets False 12 2 0 15 Yes Yes Yes Partly Yes Links.Tests.ps1:297 Should create a link to a file that reads the data of the file | Links.Tests.ps1:387 Should write a non-terminating error for an existing -Path and continue with the next link | Links.Tests.ps1:420 Should write a PermissionDenied error and create no link in a folder that denies new files | Links.Tests.ps1:335 Should return a folder object for a link to a folder with -PassThru 2: link to a file and to a folder on a share (administrator); asserts no error only No test creates a link after a failed one in a pipeline (every piped request fails so that the tests run without the privilege), and a link to a folder is checked only for the Directory attribute and reachability through Test-Path2, not for LinkType and target. The success paths run only with SeCreateSymbolicLinkPrivilege; positional binding and an empty -Target (the value that meant the current folder before rc7, while the tests check only the Mandatory metadata) are untested. TestNeeded Links.Tests.ps1:297-302 reads back LinkType, target and data of a file link; :387-393 pipes two objects by property name and asserts two errors (ErrorId, categories) and that no link exists; :420-429 asserts PermissionDenied, exception type and no output; :323-339 assert FileInfo and DirectoryInfo with -PassThru. Partly ParameterSets.Items.Tests.ps1:253 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:332 New-NTFSSymbolicLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched | ParameterSets.Items.Tests.ps1:356 Should write one ResourceExists error for an existing -Path and still create the links for the requests that follow it ParameterSets.Items.Tests.ps1:264 <Command> should reject <CaseName> instead of creating a link to the current folder | ParameterSets.Items.Tests.ps1:343 New-NTFSSymbolicLink should stop after the first pass-through object for Select-Object -First 1 and leave the second request untouched | ParameterSets.Items.Tests.ps1:367 Should write one ResourceExists error for an existing -Path and still create the links for the requests that follow it positional binding; the folder link's LinkType and resolved target (only the file link's LinkType was asserted) budget (both items)
63 items Enable-Privileges __AllParameterSets False 5 0 0 7 Partly No NA NA Partly Privileges.Tests.ps1:61 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:284 Should enable the privileges when the module setting EnablePrivileges is $true | Privileges.Tests.ps1:302 Should enable the privileges in a script of another name also when the module setting EnablePrivileges is $false | Privileges.Tests.ps1:179 Enable-Privileges should keep the privileges enabled also when the pipeline stops early 0 The error path (Enable Privilege Error, SecurityError, 'Could not enable requested privileges' when not all four privileges can be enabled) is never asserted, although OutputTypes.Tests.ps1:86 (in a token without the privileges) and the partial-token child script at Privileges.Tests.ps1:93 run it with errors suppressed. Only the Backup state is read back, only through Get-Privileges and only with all four privileges held, and the states in the -PassThru objects are unasserted. TestNeeded Privileges.Tests.ps1:61-62 reads the Backup state after Enable-Privileges; :281-305 run it in child scripts and assert the Backup state and the verbose announcement for the Init script with the setting true and false and for another script name; :179-181 asserts the state stays enabled when the pipeline stops; OutputTypes.Tests.ps1:86-89 compares the -PassThru count with Get-Privileges. All but OutputTypes.Tests.ps1:86 skip unless the token holds the four privileges. Partly ParameterSets.Items.Tests.ps1:430 Enable-Privileges should write Enable Privilege Error with SecurityError and AdjustPriviledgeException when it cannot enable all four privileges ParameterSets.Items.Tests.ps1:441 Enable-Privileges should write Enable Privilege Error with SecurityError and AdjustPriviledgeException when it cannot enable all four privileges the -PassThru privilege states (TakeOwnership/Restore/Backup/Security) with an independent read-back beyond Get-Privileges, only verifiable elevated budget
64 items Disable-Privileges __AllParameterSets False 19 3 0 20 Partly No NA NA Partly Privileges.Tests.ps1:64 Should disable the privileges that Enable-Privileges enabled | Privileges.Tests.ps1:94 Should not warn about the privileges that the access token does not hold | OutputTypes.Tests.ps1:95 Disable-Privileges should write one object per privilege | Privileges.Tests.ps1:382 Should not fail when Disable-Privileges runs inside the pipeline 3: AfterAll/BeforeEach/AfterEach resets in the privileges-on-share tests; no assertion on the cmdlet itself The error path (Disable Privilege Error, documented as non-terminating, when none of TakeOwnership, Restore and Backup is enabled) is never asserted although 15 of the 19 scan calls (BeforeEach/AfterEach/AfterAll) run it with errors suppressed; -PassThru asserts only a count above 1 and the type, and the warning for a privilege that cannot be disabled is unasserted. TestNeeded Privileges.Tests.ps1:64-67 asserts no warning and the Backup state Disabled through Get-Privileges, :74-76 the verbose message, :94 (child script) no warnings for a token that holds only some privileges, :382-387 that no privilege stays enabled after it runs inside a pipeline; OutputTypes.Tests.ps1:95-98 asserts a count above 1 and the type. All skip unless the token holds the privileges. Partly ParameterSets.Items.Tests.ps1:440 Disable-Privileges should write Disable Privilege Error with SecurityError and AdjustPriviledgeException and no output when nothing is enabled ParameterSets.Items.Tests.ps1:451 Disable-Privileges should write Disable Privilege Error with SecurityError and AdjustPriviledgeException and no output when nothing is enabled the -PassThru object privilege-state values on the successful disable path (still only count/type asserted); the warning when a privilege cannot be disabled state values on success path: budget; the warning: Limit (needs a race with another command)
65 items Get-Privileges __AllParameterSets False 18 2 0 19 NA NA NA NA Partly ObjectApis.Tests.ps1:210 Should compare boxed and typed privilege values consistently without accepting an attributes enum | OutputTypes.Tests.ps1:88 Enable-Privileges should write one object per privilege | Privileges.Tests.ps1:62 Should disable the privileges that Enable-Privileges enabled | PipelineControl.Tests.ps1:164 <Name> should stop after the first object for Select-Object -First 1 and change nothing else ObjectApis.Tests.ps1:229 Should compare boxed and typed privilege values consistently without accepting an attributes enum | OutputTypes.Tests.ps1:88 Enable-Privileges should write one object per privilege | Privileges.Tests.ps1:62 Should disable the privileges that Enable-Privileges enabled | PipelineControl.Tests.ps1:164 <Name> should stop after the first object for Select-Object -First 1 and change nothing else 2: a read helper and the check that the account holds the four file system privileges The output is never compared with an independent source (whoami /priv or the Win32 token), and no test asserts the objects beyond a count above 0, the Equals contract of the first value and the privilege and state that other cmdlets' tests read back; the Removed state and the PrivilegeAttributes property are unasserted. Errors are NA: the cmdlet has no handler and no designed failure. TestNeeded ObjectApis.Tests.ps1:210-214 asserts a count above 0 and the equality contract; OutputTypes.Tests.ps1:88 compares the -PassThru count with the cmdlet itself; Privileges.Tests.ps1:30 (read helper) reads one privilege state for the tests of Enable-Privileges and Disable-Privileges. The other calls are preconditions or read-backs. ObjectApis.Tests.ps1:229-233 asserts a count above 0 and the equality contract; OutputTypes.Tests.ps1:88 compares the -PassThru count with the cmdlet itself; Privileges.Tests.ps1:30 (read helper) reads one privilege state for the tests of Enable-Privileges and Disable-Privileges. The other calls are preconditions or read-backs. Partly ParameterSets.Items.Tests.ps1:492 Should match whoami /priv for the privileges that whoami and the library name the same way ParameterSets.Items.Tests.ps1:503 Should match whoami /priv for the privileges that whoami and the library name the same way the Removed PrivilegeState value budget

96
Tests/Coverage/Quality-Gate-Unknowns-2026-10-10-Runs.csv

@ -23,3 +23,99 @@
"Live suite, matrix cell OSFile22 with OSWin11E (mx1, instrumented)","PowerShell 7, four roles","229","0","2","231","live-matrix\mx1-OSFile22\mx1-OSFile22-counts.csv"
"Live suite, matrix cell OSFile25 with OSWin11E (mx1, instrumented)","Windows PowerShell 5.1, four roles","229","0","2","231","live-matrix\mx1-OSFile25\mx1-OSFile25-counts.csv"
"Live suite, matrix cell OSFile25 with OSWin11E (mx1, instrumented)","PowerShell 7, four roles","229","0","2","231","live-matrix\mx1-OSFile25\mx1-OSFile25-counts.csv"
"Final validate (b2cb47b, host)","Windows PowerShell 5.1, elevated","1429","0","26","1455","final\validate\elevated-Desktop.xml"
"Final validate (b2cb47b, host)","Windows PowerShell 5.1, basic user","1179","0","276","1455","final\validate\basic-Desktop.xml"
"Final validate (b2cb47b, host)","PowerShell 7, elevated","1398","0","57","1455","final\validate\elevated-Core.xml"
"Final validate (b2cb47b, host)","PowerShell 7, basic user","1148","0","307","1455","final\validate\basic-Core.xml"
"Final coverage (b2cb47b, host)","Windows PowerShell 5.1, elevated","1429","0","26","1455","final\coverage\elevated-Desktop.xml"
"Final coverage (b2cb47b, host)","Windows PowerShell 5.1, basic user","1179","0","276","1455","final\coverage\basic-Desktop.xml"
"Final coverage (b2cb47b, host)","PowerShell 7, elevated","1398","0","57","1455","final\coverage\elevated-Core.xml"
"Final coverage (b2cb47b, host)","PowerShell 7, basic user","1148","0","307","1455","final\coverage\basic-Core.xml"
"Final validate (f1f3d8f, host)","Windows PowerShell 5.1, elevated","1429","0","26","1455","final2\validate\elevated-Desktop.xml"
"Final validate (f1f3d8f, host)","Windows PowerShell 5.1, basic user","1179","0","276","1455","final2\validate\basic-Desktop.xml"
"Final validate (f1f3d8f, host)","PowerShell 7, elevated","1398","0","57","1455","final2\validate\elevated-Core.xml"
"Final validate (f1f3d8f, host)","PowerShell 7, basic user","1148","0","307","1455","final2\validate\basic-Core.xml"
"Final coverage (f1f3d8f, host)","Windows PowerShell 5.1, elevated","1429","0","26","1455","final2\coverage\elevated-Desktop.xml"
"Final coverage (f1f3d8f, host)","Windows PowerShell 5.1, basic user","1179","0","276","1455","final2\coverage\basic-Desktop.xml"
"Final coverage (f1f3d8f, host)","PowerShell 7, elevated","1398","0","57","1455","final2\coverage\elevated-Core.xml"
"Final coverage (f1f3d8f, host)","PowerShell 7, basic user","1148","0","307","1455","final2\coverage\basic-Core.xml"
"Final validate (61e936e, host)","Windows PowerShell 5.1, elevated","1433","0","26","1459","final5\validate\elevated-Desktop.xml"
"Final validate (61e936e, host)","Windows PowerShell 5.1, basic user","1183","0","276","1459","final5\validate\basic-Desktop.xml"
"Final validate (61e936e, host)","PowerShell 7, elevated","1402","0","57","1459","final5\validate\elevated-Core.xml"
"Final validate (61e936e, host)","PowerShell 7, basic user","1152","0","307","1459","final5\validate\basic-Core.xml"
"Final coverage (61e936e, host)","Windows PowerShell 5.1, elevated","1433","0","26","1459","final5\coverage\elevated-Desktop.xml"
"Final coverage (61e936e, host)","Windows PowerShell 5.1, basic user","1183","0","276","1459","final5\coverage\basic-Desktop.xml"
"Final coverage (61e936e, host)","PowerShell 7, elevated","1402","0","57","1459","final5\coverage\elevated-Core.xml"
"Final coverage (61e936e, host)","PowerShell 7, basic user","1152","0","307","1459","final5\coverage\basic-Core.xml"
"Live suite, first lab, build of b2cb47b (fix1, not instrumented)","Windows PowerShell 5.1, four roles","245","0","1","246","live-fix1\fix1-Desktop-counts.csv"
"Live suite, first lab, build of b2cb47b (fix1, not instrumented)","PowerShell 7, four roles","245","0","1","246","live-fix1\fix1-Core-counts.csv"
"Live suite, first lab, intermediate build of 0028ccd (fix3, not instrumented)","Windows PowerShell 5.1, four roles","245","0","1","246","live-fix3\fix3-Desktop-counts.csv"
"Live suite, first lab, intermediate build of 0028ccd (fix3, not instrumented)","PowerShell 7, four roles","245","0","1","246","live-fix3\fix3-Core-counts.csv"
"Live suite, first lab, final build of 8a625c8 (fix4, not instrumented)","Windows PowerShell 5.1, four roles","245","0","1","246","live-fix4\fix4-Desktop-counts.csv"
"Live suite, first lab, final build of 8a625c8 (fix4, not instrumented)","PowerShell 7, four roles","245","0","1","246","live-fix4\fix4-Core-counts.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile25, PowerShell 7, basic user","881","0","271","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile25, PowerShell 7, elevated","1130","1","21","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile25, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile25, Windows PowerShell 5.1, elevated","1132","1","19","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile19, PowerShell 7, basic user","881","0","271","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile19, PowerShell 7, elevated","1130","1","21","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile19, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile19, Windows PowerShell 5.1, elevated","1132","1","19","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile22, PowerShell 7, basic user","881","0","271","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile22, PowerShell 7, elevated","1130","1","21","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile22, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final\fix1-localsuite-summary.csv"
"Unit suite on the file servers (fix1, 22 files, tests of b2cb47b)","OSFile22, Windows PowerShell 5.1, elevated","1132","1","19","1152","localsuite-final\fix1-localsuite-summary.csv"
"Diagnosis of the failing file on the file servers (rep1, one file with prints)","OSFile25, PowerShell 7, elevated","46","1","1","48","repro\rep1-localsuite-summary.csv"
"Diagnosis of the failing file on the file servers (rep1, one file with prints)","OSFile25, Windows PowerShell 5.1, elevated","46","1","1","48","repro\rep1-localsuite-summary.csv"
"Diagnosis of the failing file on the file servers (rep1, one file with prints)","OSFile19, PowerShell 7, elevated","46","1","1","48","repro\rep1-localsuite-summary.csv"
"Diagnosis of the failing file on the file servers (rep1, one file with prints)","OSFile19, Windows PowerShell 5.1, elevated","46","1","1","48","repro\rep1-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile25, PowerShell 7, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile25, Windows PowerShell 5.1, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile19, PowerShell 7, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile19, Windows PowerShell 5.1, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile22, PowerShell 7, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the file servers (rep2, tests of f1f3d8f)","OSFile22, Windows PowerShell 5.1, elevated","76","0","2","78","repro-fixed\rep2-localsuite-summary.csv"
"The two changed test files on the host (hostfix, tests of f1f3d8f)","host, PowerShell 7, basic user","40","0","38","78","repro-host\hostfix-localsuite-summary.csv"
"The two changed test files on the host (hostfix, tests of f1f3d8f)","host, PowerShell 7, elevated","76","0","2","78","repro-host\hostfix-localsuite-summary.csv"
"The two changed test files on the host (hostfix, tests of f1f3d8f)","host, Windows PowerShell 5.1, basic user","40","0","38","78","repro-host\hostfix-localsuite-summary.csv"
"The two changed test files on the host (hostfix, tests of f1f3d8f)","host, Windows PowerShell 5.1, elevated","76","0","2","78","repro-host\hostfix-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile25, PowerShell 7, basic user","881","0","271","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile25, PowerShell 7, elevated","1131","0","21","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile25, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile25, Windows PowerShell 5.1, elevated","1133","0","19","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile19, PowerShell 7, basic user","881","0","271","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile19, PowerShell 7, elevated","1131","0","21","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile19, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile19, Windows PowerShell 5.1, elevated","1133","0","19","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile22, PowerShell 7, basic user","881","0","271","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile22, PowerShell 7, elevated","1131","0","21","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile22, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f)","OSFile22, Windows PowerShell 5.1, elevated","1133","0","19","1152","localsuite-final2\fix2-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f)","OSWin11, PowerShell 7, basic user","881","0","271","1152","localsuite-final2-client\fix2c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f)","OSWin11, PowerShell 7, elevated","1131","0","21","1152","localsuite-final2-client\fix2c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f)","OSWin11, Windows PowerShell 5.1, basic user","883","0","269","1152","localsuite-final2-client\fix2c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f)","OSWin11, Windows PowerShell 5.1, elevated","1133","0","19","1152","localsuite-final2-client\fix2c-localsuite-summary.csv"
"Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b)","host, PowerShell 7, basic user","124","3","7","134","tdd2\red\tdd2red-localsuite-summary.csv"
"Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b)","host, PowerShell 7, elevated","130","3","1","134","tdd2\red\tdd2red-localsuite-summary.csv"
"Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b)","host, Windows PowerShell 5.1, basic user","125","3","6","134","tdd2\red\tdd2red-localsuite-summary.csv"
"Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b)","host, Windows PowerShell 5.1, elevated","131","3","0","134","tdd2\red\tdd2red-localsuite-summary.csv"
"Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8)","host, PowerShell 7, basic user","170","0","30","200","tdd2\green3\tdd2green3-localsuite-summary.csv"
"Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8)","host, PowerShell 7, elevated","198","0","2","200","tdd2\green3\tdd2green3-localsuite-summary.csv"
"Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8)","host, Windows PowerShell 5.1, basic user","171","0","29","200","tdd2\green3\tdd2green3-localsuite-summary.csv"
"Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8)","host, Windows PowerShell 5.1, elevated","199","0","1","200","tdd2\green3\tdd2green3-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile25, PowerShell 7, basic user","885","0","271","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile25, PowerShell 7, elevated","1135","0","21","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile25, Windows PowerShell 5.1, basic user","887","0","269","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile25, Windows PowerShell 5.1, elevated","1137","0","19","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile19, PowerShell 7, basic user","885","0","271","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile19, PowerShell 7, elevated","1135","0","21","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile19, Windows PowerShell 5.1, basic user","887","0","269","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile19, Windows PowerShell 5.1, elevated","1137","0","19","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile22, PowerShell 7, basic user","885","0","271","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile22, PowerShell 7, elevated","1135","0","21","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile22, Windows PowerShell 5.1, basic user","887","0","269","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e)","OSFile22, Windows PowerShell 5.1, elevated","1137","0","19","1156","localsuite-final5\fix5-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e)","OSWin11, PowerShell 7, basic user","885","0","271","1156","localsuite-final5-client\fix5c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e)","OSWin11, PowerShell 7, elevated","1135","0","21","1156","localsuite-final5-client\fix5c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e)","OSWin11, Windows PowerShell 5.1, basic user","887","0","269","1156","localsuite-final5-client\fix5c-localsuite-summary.csv"
"Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e)","OSWin11, Windows PowerShell 5.1, elevated","1137","0","19","1156","localsuite-final5-client\fix5c-localsuite-summary.csv"

1 Run Configuration Passed Failed Skipped Total Source
23 Live suite, matrix cell OSFile22 with OSWin11E (mx1, instrumented) PowerShell 7, four roles 229 0 2 231 live-matrix\mx1-OSFile22\mx1-OSFile22-counts.csv
24 Live suite, matrix cell OSFile25 with OSWin11E (mx1, instrumented) Windows PowerShell 5.1, four roles 229 0 2 231 live-matrix\mx1-OSFile25\mx1-OSFile25-counts.csv
25 Live suite, matrix cell OSFile25 with OSWin11E (mx1, instrumented) PowerShell 7, four roles 229 0 2 231 live-matrix\mx1-OSFile25\mx1-OSFile25-counts.csv
26 Final validate (b2cb47b, host) Windows PowerShell 5.1, elevated 1429 0 26 1455 final\validate\elevated-Desktop.xml
27 Final validate (b2cb47b, host) Windows PowerShell 5.1, basic user 1179 0 276 1455 final\validate\basic-Desktop.xml
28 Final validate (b2cb47b, host) PowerShell 7, elevated 1398 0 57 1455 final\validate\elevated-Core.xml
29 Final validate (b2cb47b, host) PowerShell 7, basic user 1148 0 307 1455 final\validate\basic-Core.xml
30 Final coverage (b2cb47b, host) Windows PowerShell 5.1, elevated 1429 0 26 1455 final\coverage\elevated-Desktop.xml
31 Final coverage (b2cb47b, host) Windows PowerShell 5.1, basic user 1179 0 276 1455 final\coverage\basic-Desktop.xml
32 Final coverage (b2cb47b, host) PowerShell 7, elevated 1398 0 57 1455 final\coverage\elevated-Core.xml
33 Final coverage (b2cb47b, host) PowerShell 7, basic user 1148 0 307 1455 final\coverage\basic-Core.xml
34 Final validate (f1f3d8f, host) Windows PowerShell 5.1, elevated 1429 0 26 1455 final2\validate\elevated-Desktop.xml
35 Final validate (f1f3d8f, host) Windows PowerShell 5.1, basic user 1179 0 276 1455 final2\validate\basic-Desktop.xml
36 Final validate (f1f3d8f, host) PowerShell 7, elevated 1398 0 57 1455 final2\validate\elevated-Core.xml
37 Final validate (f1f3d8f, host) PowerShell 7, basic user 1148 0 307 1455 final2\validate\basic-Core.xml
38 Final coverage (f1f3d8f, host) Windows PowerShell 5.1, elevated 1429 0 26 1455 final2\coverage\elevated-Desktop.xml
39 Final coverage (f1f3d8f, host) Windows PowerShell 5.1, basic user 1179 0 276 1455 final2\coverage\basic-Desktop.xml
40 Final coverage (f1f3d8f, host) PowerShell 7, elevated 1398 0 57 1455 final2\coverage\elevated-Core.xml
41 Final coverage (f1f3d8f, host) PowerShell 7, basic user 1148 0 307 1455 final2\coverage\basic-Core.xml
42 Final validate (61e936e, host) Windows PowerShell 5.1, elevated 1433 0 26 1459 final5\validate\elevated-Desktop.xml
43 Final validate (61e936e, host) Windows PowerShell 5.1, basic user 1183 0 276 1459 final5\validate\basic-Desktop.xml
44 Final validate (61e936e, host) PowerShell 7, elevated 1402 0 57 1459 final5\validate\elevated-Core.xml
45 Final validate (61e936e, host) PowerShell 7, basic user 1152 0 307 1459 final5\validate\basic-Core.xml
46 Final coverage (61e936e, host) Windows PowerShell 5.1, elevated 1433 0 26 1459 final5\coverage\elevated-Desktop.xml
47 Final coverage (61e936e, host) Windows PowerShell 5.1, basic user 1183 0 276 1459 final5\coverage\basic-Desktop.xml
48 Final coverage (61e936e, host) PowerShell 7, elevated 1402 0 57 1459 final5\coverage\elevated-Core.xml
49 Final coverage (61e936e, host) PowerShell 7, basic user 1152 0 307 1459 final5\coverage\basic-Core.xml
50 Live suite, first lab, build of b2cb47b (fix1, not instrumented) Windows PowerShell 5.1, four roles 245 0 1 246 live-fix1\fix1-Desktop-counts.csv
51 Live suite, first lab, build of b2cb47b (fix1, not instrumented) PowerShell 7, four roles 245 0 1 246 live-fix1\fix1-Core-counts.csv
52 Live suite, first lab, intermediate build of 0028ccd (fix3, not instrumented) Windows PowerShell 5.1, four roles 245 0 1 246 live-fix3\fix3-Desktop-counts.csv
53 Live suite, first lab, intermediate build of 0028ccd (fix3, not instrumented) PowerShell 7, four roles 245 0 1 246 live-fix3\fix3-Core-counts.csv
54 Live suite, first lab, final build of 8a625c8 (fix4, not instrumented) Windows PowerShell 5.1, four roles 245 0 1 246 live-fix4\fix4-Desktop-counts.csv
55 Live suite, first lab, final build of 8a625c8 (fix4, not instrumented) PowerShell 7, four roles 245 0 1 246 live-fix4\fix4-Core-counts.csv
56 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile25, PowerShell 7, basic user 881 0 271 1152 localsuite-final\fix1-localsuite-summary.csv
57 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile25, PowerShell 7, elevated 1130 1 21 1152 localsuite-final\fix1-localsuite-summary.csv
58 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile25, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final\fix1-localsuite-summary.csv
59 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile25, Windows PowerShell 5.1, elevated 1132 1 19 1152 localsuite-final\fix1-localsuite-summary.csv
60 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile19, PowerShell 7, basic user 881 0 271 1152 localsuite-final\fix1-localsuite-summary.csv
61 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile19, PowerShell 7, elevated 1130 1 21 1152 localsuite-final\fix1-localsuite-summary.csv
62 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile19, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final\fix1-localsuite-summary.csv
63 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile19, Windows PowerShell 5.1, elevated 1132 1 19 1152 localsuite-final\fix1-localsuite-summary.csv
64 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile22, PowerShell 7, basic user 881 0 271 1152 localsuite-final\fix1-localsuite-summary.csv
65 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile22, PowerShell 7, elevated 1130 1 21 1152 localsuite-final\fix1-localsuite-summary.csv
66 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile22, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final\fix1-localsuite-summary.csv
67 Unit suite on the file servers (fix1, 22 files, tests of b2cb47b) OSFile22, Windows PowerShell 5.1, elevated 1132 1 19 1152 localsuite-final\fix1-localsuite-summary.csv
68 Diagnosis of the failing file on the file servers (rep1, one file with prints) OSFile25, PowerShell 7, elevated 46 1 1 48 repro\rep1-localsuite-summary.csv
69 Diagnosis of the failing file on the file servers (rep1, one file with prints) OSFile25, Windows PowerShell 5.1, elevated 46 1 1 48 repro\rep1-localsuite-summary.csv
70 Diagnosis of the failing file on the file servers (rep1, one file with prints) OSFile19, PowerShell 7, elevated 46 1 1 48 repro\rep1-localsuite-summary.csv
71 Diagnosis of the failing file on the file servers (rep1, one file with prints) OSFile19, Windows PowerShell 5.1, elevated 46 1 1 48 repro\rep1-localsuite-summary.csv
72 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile25, PowerShell 7, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
73 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile25, Windows PowerShell 5.1, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
74 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile19, PowerShell 7, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
75 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile19, Windows PowerShell 5.1, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
76 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile22, PowerShell 7, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
77 The two changed test files on the file servers (rep2, tests of f1f3d8f) OSFile22, Windows PowerShell 5.1, elevated 76 0 2 78 repro-fixed\rep2-localsuite-summary.csv
78 The two changed test files on the host (hostfix, tests of f1f3d8f) host, PowerShell 7, basic user 40 0 38 78 repro-host\hostfix-localsuite-summary.csv
79 The two changed test files on the host (hostfix, tests of f1f3d8f) host, PowerShell 7, elevated 76 0 2 78 repro-host\hostfix-localsuite-summary.csv
80 The two changed test files on the host (hostfix, tests of f1f3d8f) host, Windows PowerShell 5.1, basic user 40 0 38 78 repro-host\hostfix-localsuite-summary.csv
81 The two changed test files on the host (hostfix, tests of f1f3d8f) host, Windows PowerShell 5.1, elevated 76 0 2 78 repro-host\hostfix-localsuite-summary.csv
82 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile25, PowerShell 7, basic user 881 0 271 1152 localsuite-final2\fix2-localsuite-summary.csv
83 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile25, PowerShell 7, elevated 1131 0 21 1152 localsuite-final2\fix2-localsuite-summary.csv
84 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile25, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final2\fix2-localsuite-summary.csv
85 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile25, Windows PowerShell 5.1, elevated 1133 0 19 1152 localsuite-final2\fix2-localsuite-summary.csv
86 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile19, PowerShell 7, basic user 881 0 271 1152 localsuite-final2\fix2-localsuite-summary.csv
87 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile19, PowerShell 7, elevated 1131 0 21 1152 localsuite-final2\fix2-localsuite-summary.csv
88 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile19, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final2\fix2-localsuite-summary.csv
89 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile19, Windows PowerShell 5.1, elevated 1133 0 19 1152 localsuite-final2\fix2-localsuite-summary.csv
90 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile22, PowerShell 7, basic user 881 0 271 1152 localsuite-final2\fix2-localsuite-summary.csv
91 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile22, PowerShell 7, elevated 1131 0 21 1152 localsuite-final2\fix2-localsuite-summary.csv
92 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile22, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final2\fix2-localsuite-summary.csv
93 Unit suite on the file servers (fix2, 22 files, tests of f1f3d8f) OSFile22, Windows PowerShell 5.1, elevated 1133 0 19 1152 localsuite-final2\fix2-localsuite-summary.csv
94 Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f) OSWin11, PowerShell 7, basic user 881 0 271 1152 localsuite-final2-client\fix2c-localsuite-summary.csv
95 Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f) OSWin11, PowerShell 7, elevated 1131 0 21 1152 localsuite-final2-client\fix2c-localsuite-summary.csv
96 Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f) OSWin11, Windows PowerShell 5.1, basic user 883 0 269 1152 localsuite-final2-client\fix2c-localsuite-summary.csv
97 Unit suite on the Windows 11 client (fix2c, 22 files, tests of f1f3d8f) OSWin11, Windows PowerShell 5.1, elevated 1133 0 19 1152 localsuite-final2-client\fix2c-localsuite-summary.csv
98 Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b) host, PowerShell 7, basic user 124 3 7 134 tdd2\red\tdd2red-localsuite-summary.csv
99 Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b) host, PowerShell 7, elevated 130 3 1 134 tdd2\red\tdd2red-localsuite-summary.csv
100 Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b) host, Windows PowerShell 5.1, basic user 125 3 6 134 tdd2\red\tdd2red-localsuite-summary.csv
101 Test of the filter before the fix (tdd2red, ItemCmdlets file, build of b2cb47b) host, Windows PowerShell 5.1, elevated 131 3 0 134 tdd2\red\tdd2red-localsuite-summary.csv
102 Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8) host, PowerShell 7, basic user 170 0 30 200 tdd2\green3\tdd2green3-localsuite-summary.csv
103 Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8) host, PowerShell 7, elevated 198 0 2 200 tdd2\green3\tdd2green3-localsuite-summary.csv
104 Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8) host, Windows PowerShell 5.1, basic user 171 0 29 200 tdd2\green3\tdd2green3-localsuite-summary.csv
105 Tests of the filter after the fix (tdd2green3, three files, build of 8a625c8) host, Windows PowerShell 5.1, elevated 199 0 1 200 tdd2\green3\tdd2green3-localsuite-summary.csv
106 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile25, PowerShell 7, basic user 885 0 271 1156 localsuite-final5\fix5-localsuite-summary.csv
107 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile25, PowerShell 7, elevated 1135 0 21 1156 localsuite-final5\fix5-localsuite-summary.csv
108 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile25, Windows PowerShell 5.1, basic user 887 0 269 1156 localsuite-final5\fix5-localsuite-summary.csv
109 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile25, Windows PowerShell 5.1, elevated 1137 0 19 1156 localsuite-final5\fix5-localsuite-summary.csv
110 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile19, PowerShell 7, basic user 885 0 271 1156 localsuite-final5\fix5-localsuite-summary.csv
111 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile19, PowerShell 7, elevated 1135 0 21 1156 localsuite-final5\fix5-localsuite-summary.csv
112 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile19, Windows PowerShell 5.1, basic user 887 0 269 1156 localsuite-final5\fix5-localsuite-summary.csv
113 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile19, Windows PowerShell 5.1, elevated 1137 0 19 1156 localsuite-final5\fix5-localsuite-summary.csv
114 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile22, PowerShell 7, basic user 885 0 271 1156 localsuite-final5\fix5-localsuite-summary.csv
115 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile22, PowerShell 7, elevated 1135 0 21 1156 localsuite-final5\fix5-localsuite-summary.csv
116 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile22, Windows PowerShell 5.1, basic user 887 0 269 1156 localsuite-final5\fix5-localsuite-summary.csv
117 Unit suite on the file servers (fix5, 22 files, final build and tests of 61e936e) OSFile22, Windows PowerShell 5.1, elevated 1137 0 19 1156 localsuite-final5\fix5-localsuite-summary.csv
118 Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e) OSWin11, PowerShell 7, basic user 885 0 271 1156 localsuite-final5-client\fix5c-localsuite-summary.csv
119 Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e) OSWin11, PowerShell 7, elevated 1135 0 21 1156 localsuite-final5-client\fix5c-localsuite-summary.csv
120 Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e) OSWin11, Windows PowerShell 5.1, basic user 887 0 269 1156 localsuite-final5-client\fix5c-localsuite-summary.csv
121 Unit suite on the Windows 11 client (fix5c, 22 files, final build and tests of 61e936e) OSWin11, Windows PowerShell 5.1, elevated 1137 0 19 1156 localsuite-final5-client\fix5c-localsuite-summary.csv

706
Tests/Coverage/Quality-Gate-Unknowns-2026-10-10.md

@ -18,7 +18,9 @@ is open.
- **The shipped code.** The unit suite of the host visits 3,198 of 3,649
sequence points (87.64%) of rc7 (`fa0701b`) and 1,090 of 1,168 explicit
branch points (93.32%). All 232 unvisited methods are classified.
branch points (93.32%). All 232 unvisited methods are classified. The branch
summary of the tool (64.15%) adds points that no person wrote, and it is not
read here (Coverage of the shipped code).
- **The live tests and the domain member.** The live suite (the first lab and
three cells of the matrix lab) and the unit suite on a domain member give
the counts of the uninstrumented acceptance, and together they add 9
@ -29,15 +31,29 @@ is open.
the gaps of the judged matrix of the 64 parameter sets: 7 sets closed, 51
partly, 1 open, 4 left to the maintainer. The unit suite then visits 45
more sequence points, all getters of parameters with pipeline input, which
corrects an explanation of the paths report. At the final commit `b2cb47b`
the suite has 1,455 cases per configuration without a failure and covers
3,243 sequence points (88.87%).
- **A defect fixed, a defect open.** The comparison of an identity with a name
was wrong in `tr-TR`; it is fixed test-first (`419cfb3`), and the first lab
passes on the fixed build (245 passed, 1 skipped per edition). The hard-link
cmdlets (`New-NTFSHardLink -PassThru`, `Get-NTFSHardLink`) fail for a path
whose root is not the volume root; the defect is reproduced and left to the
maintainer.
corrects an explanation of the paths report. At the final commit `61e936e`
(built once, at `8a625c8`) the suite has 1,459 cases per configuration
without a failure and covers 3,258 of 3,664 sequence points (88.92%); the
same 187 methods stay unvisited, all classified. On the file servers of the
matrix lab, one new test failed in every elevated configuration of the first
run because of its oracle (`Get-Acl -Audit` reads the SACL of an item
without audit entries as protected on a domain member; the module was
right); five assertions now read the SACL alone (`f1f3d8f`), and the final
build with the final tests passes the 22 files of the matrix suite on
Windows Server 2019, 2022, and 2025 and on Windows 11 in all 16
configurations (1,156 cases each).
- **Two defects fixed, one open.** Two comparisons were wrong in `tr-TR`, and
both are fixed test-first: an identity compared with a name by `Equals`
(`419cfb3`), and `Get-ChildItem2 -Filter` (`0028ccd`, `fbe0289`, `8a625c8`),
which the independent review found after the first scan had missed its class
of call. The first lab passes on the final build (245 passed, 1 skipped per
edition). The hard-link cmdlets (`New-NTFSHardLink -PassThru`,
`Get-NTFSHardLink`) fail for a path whose root is not the volume root; the
defect is reproduced and left to the maintainer.
- **The review.** One independent review found four Major findings and several
Minor ones; each was resolved, three of the Major ones after a probe (the
claim about `-eq` was wrong, the filter defect was real, the audit tests of a
piped `AppliesTo` did not bind the set that they named).
- **Environments.** `de-DE` and `tr-TR` are tested; Server Core has a plan;
ARM64, a localized system, and non-Windows servers stay open.
@ -45,10 +61,10 @@ is open.
| File | Content |
| --- | --- |
| [Methods](Quality-Gate-Unknowns-2026-10-10-Methods.csv) | the 232 unvisited methods of `fa0701b` with the rule, the category, the disposition, and what the other sources and the final build visit |
| [Cmdlets](Quality-Gate-Unknowns-2026-10-10-Cmdlets.csv) | per cmdlet, the visited sequence and explicit branch points of each source |
| [Methods](Quality-Gate-Unknowns-2026-10-10-Methods.csv) | the 232 unvisited methods of `fa0701b` with the rule, the category, the disposition, and what the other sources and the build of `b2cb47b` visit |
| [Cmdlets](Quality-Gate-Unknowns-2026-10-10-Cmdlets.csv) | per cmdlet, the visited sequence and explicit branch points of each source (the final column is the build of `b2cb47b`; see Final measurement) |
| [Reconciliation](Quality-Gate-Unknowns-2026-10-10-Reconciliation.csv) | the 232 methods against the 231 of `5a5d58b` |
| [ParameterSets](Quality-Gate-Unknowns-2026-10-10-ParameterSets.csv) | the judged matrix of the 64 sets and its status after the new tests |
| [ParameterSets](Quality-Gate-Unknowns-2026-10-10-ParameterSets.csv) | the judged matrix of the 64 sets and its status after the new tests; the cited file:line references point at the tests of the final commit (mapped through the hunks of `git diff` from `fa0701b`, and for the new files from the commit that added each) |
| [Mutations](Quality-Gate-Unknowns-2026-10-10-Mutations.csv) | the 35 mutations of the new tests |
| [LiveRoles](Quality-Gate-Unknowns-2026-10-10-LiveRoles.csv) | the points that each role of the live suite visits |
| [Cultures](Quality-Gate-Unknowns-2026-10-10-Cultures.csv) | the unit suite in `de-DE` and `tr-TR` |
@ -140,15 +156,23 @@ configurations; no skipped row lacks an executed counterpart.
| Assembly | Sequence points | Sequence coverage | Branch points | Branch coverage |
| --- | ---: | ---: | ---: | ---: |
| NTFSSecurity | 1,912/2,168 | 88.19% | 683/1,094 | 62.43% |
| Security2 | 1,061/1,240 | 85.56% | 509/753 | 67.59% |
| Security2 | 1,061/1,240 | 85.56% | 509/753 | 67.60% |
| ProcessPrivileges | 205/219 | 93.61% | 72/125 | 57.60% |
| PrivilegeControl | 20/22 | 90.91% | 12/17 | 70.59% |
| Aggregate | 3,198/3,649 | 87.64% | 1,276/1,989 | 64.15% |
The ratios are visited sequence or branch points divided by their totals, not
unique source lines. The branch summary counts 821 compiler-generated points
(patterns such as `foreach` and `using`), of which 186 are visited; the
explicit branch points that a person wrote are 1,090/1,168 (93.32%).
unique source lines. The branch summary of the tool is not a count of the
branches that a person wrote: it has 821 points more than the 1,168 explicit
branch points, and they are not patterns such as `foreach` and `using`, as the
paths report described them. The tool adds one point to each of the 198 methods
that have explicit branch points, which it counts as visited when the method
runs (186 of the 198 did), and one point to each of the 623 methods that have
none, which it never counts as visited, although 456 of those methods run
(`inventory-fa0701b\branch-summary-decomposition.txt`, read from the summary of
every method in the report). The summary percentage therefore falls when a
method without a branch is added; this report reads the explicit branch
points, 1,090/1,168 (93.32%).
### Against `5a5d58b`
@ -483,12 +507,13 @@ its shares, folders, and the coverage folder, and the end state was verified.
## Stage C: the reachable gaps
After Stages A and B, no cmdlet reaches an unvisited point that has no
source-backed explanation: the 232 unvisited methods of the host unit suite are
classified (451 sequence points), and 9 of those points are now visited on a
domain member and in the lab. What a point count does not show is whether the
parameter sets are tested as behavior. So this stage tests the matrix, not the
numbers.
After Stages A and B, all 232 unvisited methods of the host unit suite are
classified (451 sequence points); 167 have a source-backed explanation and 65
do not (the 8 methods of the open items of the paths report, and 57 getters of
pipeline parameters that PowerShell reads and that no test supplied), and 9 of
the 451 points are now visited on a domain member and in the lab. What a point
count does not show is whether the parameter sets are tested as behavior. So
this stage tests the matrix, not the numbers.
### The scan of the parameter sets
@ -620,13 +645,16 @@ below.
### What the new tests add to the coverage
The new tests add 45 sequence points and no explicit branch point. At the final
commit the unit suite of the host visits 3,243 of 3,649 sequence points
(88.87%), against 3,198 (87.64%); every one of the 45 points is a getter of a
cmdlet parameter in `NTFSSecurity.dll` (1,912 to 1,957 of 2,168 points, 88.19%
to 90.27%); the explicit branch points stay at 1,090 of 1,168 (93.32%). The
reconciliation of the unvisited methods of the two builds has 187 methods that
are unchanged and 45 that are visited now; no method is changed or new.
The new tests add 45 sequence points and no explicit branch point. At
`b2cb47b`, the build of the tests, the unit suite of the host visits 3,243 of
3,649 sequence points (88.87%), against 3,198 (87.64%) at rc7; every one of the
45 points is a getter of a cmdlet parameter in `NTFSSecurity.dll` (1,912 to
1,957 of 2,168 points, 88.19% to 90.27%); the explicit branch points stay at
1,090 of 1,168 (93.32%). The reconciliation of the unvisited methods of the two
builds has 187 methods that are unchanged and 45 that are visited now; no
method is changed or new. The final build adds the fix of the filter (Final
measurement): 15 more sequence points, all visited, and the same 187 unvisited
methods, so it visits 3,258 of 3,664 sequence points (88.92%).
All 45 getters belong to parameters that take pipeline input. This is the
measured proof of the finding of the judged matrix (45 of 64 sets had no test
@ -676,18 +704,57 @@ finding below.
the path of two cmdlets that opens the file at every call, and it has to
decide which names to return when the path crosses a mount point (the names
under the real volume, or under the root that the caller gave). That is a
change of the output of two cmdlets for the maintainer. The failing call is
the regression test for the fix.
- **A piped property does not select the Simple set.** An object with an
`AppliesTo` property, piped into `Add-NTFSAccess` or `Remove-NTFSAccess`,
does not bind the Simple set: the mandatory parameters of the default
Complex set are already satisfiable from the same object, so PowerShell
resolves the set before it binds the property, and the property is dropped
without a message; the entry gets the default scope of the Complex set. A
call that names `-AppliesTo` selects the Simple set. The judged notes had
assumed the opposite. Not pinned: whether that is intended is the
maintainer's decision, and it is why the getter of `AppliesTo` stays
unvisited.
change of the output of two cmdlets for the maintainer. The failing calls are
the regression test for the fix. With the final package they behave as
follows in both editions (`E\probes\hardlink-root\repro-minimal.ps1`, with
the outputs `repro-minimal-final4-Desktop.txt` and
`repro-minimal-final4-Core.txt`, which equal those of the package of
`b2cb47b`; the first reproduction, `repro.ps1`, ran in the worktree of the
implementer):
```powershell
$folder = Join-Path -Path $env:TEMP -ChildPath 'HardLinkRoot'
$null = New-Item -ItemType Directory -Path $folder
subst.exe Z: $folder
Set-Content -LiteralPath Z:\Target.txt -Value 'Target'
# A terminating FileNotFoundException; the link exists on disk
New-NTFSHardLink -Path Z:\Link.txt -Target Z:\Target.txt -PassThru
# Writes FileNotFound for a file that exists
Get-NTFSHardLink -Path Z:\Target.txt
subst.exe Z: /d
Remove-Item -LiteralPath $folder -Recurse -Force
```
- **A piped property does not select the Simple set of a path.** An object
with the properties `FullName`, `Account`, `AccessRights`, and `AppliesTo`,
piped into `Add-NTFSAccess`, `Remove-NTFSAccess`, `Add-NTFSAudit`, or
`Remove-NTFSAudit`, does not bind `PathSimple`: the mandatory parameters of
the default set `PathComplex` are satisfiable from the same object, so
PowerShell resolves the set before it binds the property, and the property
is dropped without a message; an added entry gets the default scope
(`ContainerInherit, ObjectInherit`). The first probe ran in both editions on
the package of `0028ccd` (`E\probes\review2-*.txt`; the binding code is not
part of the later changes) and told the set for the first three cmdlets; for
`Remove-NTFSAudit` the entries that remained were the same with and without
the property, so it did not tell. A second probe on the final package, in
both editions, uses one audit entry of the default scope, which the two sets
treat differently: removing the scope `ThisFolderOnly` from it leaves the
entry for the subfolders and files (`InheritOnly`), and removing the default
scope removes it whole. The piped property removed it whole, like a call
without `AppliesTo`, so `PathComplex` bound; a named
`-AppliesTo ThisFolderOnly` left the `InheritOnly` entry
(`E\probes\p-remove-audit-appliesto.ps1`, outputs
`remove-audit-appliesto-Desktop.txt` and `-Core.txt`). For a descriptor, the
property does select `SDSimple`, because the default set does not compete (no
path is on the object): both Add cmdlets gave the scope `None`, and
`Remove-NTFSAudit` left the `InheritOnly` entry. The judged
notes had assumed the opposite for paths, and the first audit tests named
rows `PathSimple` that piped the property, so they bound `PathComplex` and
could not tell the sets; the independent review caught the contradiction with
the access tests, and the rows now name `-AppliesTo` and assert the scope
(`61e936e`). Not pinned: whether the dropped property is intended is the
maintainer's decision, and it is why the getter of `AppliesTo` of the access
cmdlets stays unvisited.
- **The `-SecurityDescriptor` cmdlets and the pipeline.** See the mutation
`Set-NTFSOwner` above: a test that only pipes descriptors cannot show that a
cmdlet always acts on the first one.
@ -719,13 +786,15 @@ its reason is [the ParameterSets CSV](Quality-Gate-Unknowns-2026-10-10-Parameter
| Items and links (14) | 0 | 13 | 1 | 0 | 0 |
| **Total (64)** | **7** | **51** | **1** | **4** | **1** |
The remaining items of the 52 sets that are not closed carry one of four
reasons, counted by mention: 68 `budget` (the implementer stopped at the
The remaining items of the 57 sets that are not closed (51 partly closed, 1
open, 4 `MaintainerDecision`, and 1 `None`) carry one of four reasons, counted
by mention: 68 `budget` (the implementer stopped at the
target of 15 to 20 blocks per file; plain test work that needs no decision and
no lab), 16 `Limit` (a remote file server or a lab is needed, such as the owner
retry of an audit write or a `PermissionDenied` category), 7
`MaintainerDecision` (open item 1 of the paths report), and 3 `would-pin` (a
test would pin a behavior that a maintainer may change). 32 sets have only
test would pin a behavior that a maintainer may change). Of the 52 partly
closed or open sets alone the mentions are 62, 16, 3, and 2. 32 sets have only
`budget` items left. Such items are the long paths over 260 characters,
bracket paths and drive roots for the item cmdlets, several accounts or a Deny
entry without Synchronize for `Add-NTFSAccess`, and the `-ExcludeExplicit`,
@ -740,11 +809,16 @@ them; nothing is called harmless.
The C# calls whose result depends on the culture of the thread, found by a
text scan of the four projects (`ToLower`, `ToUpper`, `Compare`, `CompareTo`,
`StartsWith`, `EndsWith`, and `IndexOf` without a `StringComparison`; `Parse`;
`Convert`; number and date formatting):
`Convert`; number and date formatting). The first scan missed one class of
call, a case-insensitive `WildcardPattern` or `Regex` without `CultureInvariant`;
the independent review found the one that matters (below), and a second scan
for `WildcardPattern`, `Regex`, `IgnoreCase`, and `CultureInfo` found no other:
| Where | Call | Verdict |
| --- | --- | --- |
| `Security2\IdentityReference2.cs`, `Equals(object)` | `ntAccount.Value.ToLower() == value.ToLower()` | a defect in `tr-TR`, fixed in `419cfb3` (below) |
| `NTFSSecurity\ItemCmdlets\GetChildItem2.cs`, the filter | `new WildcardPattern(..., IgnoreCase)`, and the enumeration of AlphaFS 2.2, which matches the filter with a case-insensitive regular expression | a defect in `tr-TR`, found by the review, fixed in `0028ccd`, `fbe0289`, and `8a625c8` (below) |
| `Security2\IdentityReference2.cs`, line 9 | `new Regex("(S-1-)[0-9-]+", RegexOptions.IgnoreCase)` | ASCII digits and hyphens: no difference |
| `NTFSSecurity\BaseCmdlets.cs`, path prefixes | `StartsWith("..\\")`, `".\\"`, `"./"`, `"\\"` | the culture overload, on ASCII punctuation: no difference in `de-DE` and `tr-TR`; characters that a culture ignores in a comparison (such as U+200B) were not probed |
| `AddAccess`, `RemoveAccess`, `AddAudit`, `RemoveAudit` | `ParameterSetName.StartsWith("Path")`, `EndsWith("Simple")` | the culture overload on ASCII names; the sets do not hold an uppercase `I`; no difference |
| `Security2\Win32\Lib.cs`, `Win32Lib.cs` | `AncestorName.StartsWith(@"\\?\")` | the culture overload on ASCII punctuation: no difference |
@ -768,16 +842,19 @@ The six failures of `de-DE` in PowerShell 7 are assertions on English message
text, not defects of the module: PowerShell 7 localizes its message for a
failed parameter validation and quotes the parameter name as „Filter“, where
the tests match `'Filter'` or `'Title'` with ASCII quotes. They are the null
`-Filter` of `Get-ChildItem2` (`ItemCmdlets.Tests.ps1`, line 235) and the five
refused titles of `Invoke-TestsAsBasicUser.ps1` (`Repository.Tests.ps1`, lines
128 and 133). Each of them also asserts the error ID, which passes. The tests
`-Filter` of `Get-ChildItem2` (`ItemCmdlets.Tests.ps1`, line 235 at `fa0701b`)
and the five refused titles of `Invoke-TestsAsBasicUser.ps1`
(`Repository.Tests.ps1`, lines 128 and 133). The test of the null `-Filter`
also asserts the error ID, which passes; the five refused titles assert only
the message, and the log shows the same validation error. The tests
stay as they are: CI runs the culture of its image, and weakening an assertion
to make a localized run green is not a gain.
The suite found no failure in `tr-TR`, but that does not say the culture is
safe: no test compared a name that holds an uppercase `I` with the same name in
another case. A probe did (`p-culture-identity.ps1`, both editions, a new
process each):
another case, and none filtered by such a name. A probe did for the identity
(`p-culture-identity.ps1`, both editions, a new process each); the independent
review found the filter (below):
| Name | Culture | Equals exact | Equals lowercase | Equals uppercase |
| --- | --- | --- | --- | --- |
@ -786,11 +863,21 @@ process each):
| `NT AUTHORITY\SYSTEM` | `tr-TR` | True | **False** | True |
| `NT AUTHORITY\INTERACTIVE` | `tr-TR` | True | **False** | True |
`$entry.Account -eq 'builtin\administrators'` is true in `en-US` and false in
`tr-TR`: the comparison lowercases both names with the culture of the thread,
and `tr-TR` turns `I` into U+0131. The cmdlets compare identities by SID, so
they are not affected; a script that compares the account of an entry with a
name is. The defect is reproducible, so by Decision 16 it is fixed: the test
`$entry.Account.Equals('builtin\administrators')` is true in `en-US` and false
in `tr-TR`: the method lowercases both names with the culture of the thread, and
`tr-TR` turns `I` into U+0131. The operators are not affected. The first
version of this report and of the changelog entry named `-eq`, which the
independent review doubted; a probe on the previous build under `tr-TR`
(`E\probes\review-prefix-Desktop.txt` and `-Core.txt`) shows that `-eq`,
`-contains`, and `-in` return True for the exact, the lowercase, and the
uppercase name: PowerShell converts the name to an identity (`-as` gives a
`Security2.IdentityReference2`) and compares the two identities, which is
culture independent (`E\probes\p-eq-mechanism.ps1`, run on the bytes of rc7,
which have the code from before the fix; the outputs are
`eq-mechanism-Desktop.txt` and `-Core.txt`). The cmdlets compare identities by
SID, so they are not affected either; a script or a program that calls
`Equals` with a name is. The defect is reproducible, so by Decision 16 it is
fixed: the test
`Should compare a name with the account ignoring case in Turkish, where I and i
are different letters` in `ObjectApis.Tests.ps1` sets the culture of the thread
to `tr-TR` and compares the system account with its name in three cases. Before
@ -799,9 +886,56 @@ the fix it fails in all four configurations (1 failed of 110 rows in each,
it passes in all four (`E\tdd\green`). The change is a production change after
the tag, so it belongs to a new candidate that the maintainer decides on.
### A second defect, found by the independent review
The scan listed the string functions and not the case-insensitive pattern
classes, so it missed `Get-ChildItem2 -Filter`. The reviewer read
`GetChildItem2.cs`, where a `WildcardPattern` compares each name with the filter
with `IgnoreCase` and without `CultureInvariant`, and asked for a probe. Under
`tr-TR` the previous build drops the items whose names differ from the filter in
the case of an `I`, in both editions (`E\probes\review-prefix-*.txt`;
`Get-ChildItem` is the reference):
| `-Filter` | `Get-ChildItem2` | `Get-ChildItem` |
| --- | --- | --- |
| `index*` | nothing | `Index.txt` |
| `INDEX*` | `Index.txt` | `Index.txt` |
| `*.ini` | `desktop.ini` | `desktop.ini`, `SETTINGS.INI` |
| `*.INI` | `SETTINGS.INI` | `desktop.ini`, `SETTINGS.INI` |
The defect is reproducible and not an open item (the dot rules of `-Filter` are
a different question), so by Decision 16 it is fixed test-first. The test
`Should match -Filter <Filter> ignoring case in Turkish, where I and i are
different letters` in `ItemCmdlets.Tests.ps1` sets the culture of the thread to
`tr-TR` and lists a folder with `Index.txt`, `desktop.ini`, `SETTINGS.INI`, and
`Other.txt`. On the previous build it fails in the four configurations (3 of 134
cases: `index*`, `*.ini`, and `*.INI`; `INDEX*` is the control; `E\tdd2\red`).
The first fix was not enough, which the probes showed. `0028ccd` made the
pattern of the cmdlet culture invariant (`WildcardOptions.CultureInvariant`: a
`WildcardPattern` without the option does not match `Index.txt` with `index*` in
`tr-TR`, and with it does, in both editions; `E\probes\wildcard-culture-*.txt`),
and the test still failed on that build. The enumeration also compares with the
culture: AlphaFS 2.2 matches the filter with a regular expression that takes the
culture of the thread, and `Directory.EnumerateFileSystemEntries` of AlphaFS
returns nothing for `index*` under `tr-TR`, where .NET returns `Index.txt`
(`E\probes\alphafs-filter-*.txt`; the same call in `en-US` agrees with .NET).
The fix has two parts: the pattern of the cmdlet is culture invariant, and the
enumeration, that is the creation of the enumerator and every `MoveNext`, runs
with the invariant culture (`fbe0289` and `8a625c8`), which is restored before
an item reaches the pipeline, so that no later command sees it. No other cmdlet
passes a pattern of the user to AlphaFS. On the fixed build `Get-ChildItem2`
returns the same names as `Get-ChildItem` for the four filters and two more, in
both editions, in `tr-TR` and in `en-US` (`E\probes\review-final4-*.txt`), and
the test passes in the four configurations (`E\tdd2\green3`: 200 cases of three
files, elevated and as a basic user).
Not tested: a localized operating system (no such image exists: the ISO files
are English), the names of built-in accounts in other languages, and the
localized texts of Windows errors.
localized texts of Windows errors. The review found one test that depends on a
localized text, the comparison of `Get-Privileges` with the State column of
`whoami /priv` in `ParameterSets.Items.Tests.ps1`; it compares the state now
only where `whoami` prints the English words.
### Server Core
@ -863,26 +997,61 @@ item 5). It stays open.
## Final measurement
The code and the tests of the work are frozen at the commit
`b2cb47b5a0b21c8390aef7a71b82b86610296d56` of `ai/coverage-unknowns` (the fix
`419cfb3`, the four test files, one change of the list of the suite of the
matrix lab, and one of a test). It was measured like `fa0701b`, in a new
frozen worktree and with the same commands (`Run-Frozen.ps1`: Build, Validate,
then Coverage), and its skip eligibility was checked on a second, uninstrumented
tree that holds the same bytes (every file hash-equal to the pristine copy of
the build). Against `fa0701b` the production code differs in one statement
(`IdentityReference2.Equals`), and the tests grew by 141 rows.
- Build: Release, 0 errors, 317 warnings (296 of CS1591, 19 of CS1574, one of
CS0169, one of CS0618), the same as at `fa0701b`.
- Validate (no instrumentation): 1,455 cases in each of the four
configurations, no failure.
`61e936e80fd307cdc341a893c4afbbd155986756` of `ai/coverage-unknowns`; the
commits after it change documents only. Against `fa0701b` the production code
differs in two classes (`IdentityReference2.Equals`, and the filter of
`Get-ChildItem2`), and the tests grew by 145 rows. The measurement was made
three times, in a new frozen worktree each time and with the same commands:
1. **`b2cb47b`** (`b2cb47b5a0b21c8390aef7a71b82b86610296d56`: the fix
`419cfb3`, the four test files, one change of the list of the suite of the
matrix lab, and one of a test) was built and measured like `fa0701b`
(`Run-Frozen.ps1`: Build, Validate, then Coverage). Its skip eligibility was
checked on a second, uninstrumented tree that holds the same bytes (every
file hash-equal to the pristine copy of the build). The first lab
acceptance of the fixed build (`fix1`) and the first run of the unit suite
on the file servers used the pristine package of this build.
2. **`f1f3d8f`** (`f1f3d8f0789f830f991c927197863456f74bf0fa`, the change of the
oracle of five assertions that the file servers made necessary) was measured
again on the same bytes, without a new build (`Chain-Remeasure.ps1`): a
Release build is not byte-reproducible, and a new build would no longer be
the build that the lab accepted. The 20 files of the pristine Release folder
were copied into a new frozen worktree and a new eligibility worktree of the
commit (all hashes equal), and the script refuses to run when a file outside
the tests and the documents differs from `b2cb47b` (it does not). Validate,
Coverage, and the skip eligibility were run again with the same commands.
3. **`61e936e`, the final measurement.** The independent review found the
second culture defect (Stage D) after the two measurements above, and its
fix changed the production code, so the build changed. The fix was built once
at `8a625c8` (`E\final4`: Release, the same warnings; every file of the
extracted package equals the pristine copy), and the test files of `61e936e`
were measured on those bytes without another build (`Chain-Remeasure.ps1`,
`E\final5`, the script again refusing to run if a file outside the tests and
the documents differed from `8a625c8`; it does not). The first lab
acceptance and the unit suite on the file servers and on the client at the
end of this report ran on the package of this build; `fix1` to `fix3`, and
the first run of the suite on the file servers, ran on the builds named with
them.
The first two measurements gave the same results: 3,243 of 3,649 sequence
points, and of the 4,817 points (with the explicit branch points) none is
visited by one run and not by the other (`merge\final-vs-final2-points.csv`).
The final measurement differs from them in the code of one class, and is
shown here:
- Build (of `8a625c8`): Release, 0 errors, 317 warnings (296 of CS1591, 19 of
CS1574, one of CS0169, one of CS0618), the same as at `fa0701b` and at
`b2cb47b`.
- Validate (no instrumentation): 1,459 cases in each of the four
configurations, no failure (1,455 at the first two measurements; the four new
cases are the rows of the filter test).
| Configuration | Passed | Failed | Skipped | Total |
| --- | ---: | ---: | ---: | ---: |
| Windows PowerShell 5.1, elevated | 1,429 | 0 | 26 | 1,455 |
| Windows PowerShell 5.1, basic user | 1,179 | 0 | 276 | 1,455 |
| PowerShell 7, elevated | 1,398 | 0 | 57 | 1,455 |
| PowerShell 7, basic user | 1,148 | 0 | 307 | 1,455 |
| Windows PowerShell 5.1, elevated | 1,433 | 0 | 26 | 1,459 |
| Windows PowerShell 5.1, basic user | 1,183 | 0 | 276 | 1,459 |
| PowerShell 7, elevated | 1,402 | 0 | 57 | 1,459 |
| PowerShell 7, basic user | 1,152 | 0 | 307 | 1,459 |
- Skip eligibility, by row: 666 skipped rows of 165 distinct tests (582 and
138 at `fa0701b`); every skipped row executes in two other configurations,
@ -891,61 +1060,106 @@ the build). Against `fa0701b` the production code differs in one statement
Security, Restore, or symbolic-link privilege, or an owner that a basic user
does not hold by default) and 4 rows of the two elevated ones (the test of
the error without the Security privilege, and the test of a denied read that
the Backup privilege would bypass).
the Backup privilege would bypass). The skips are those of `b2cb47b` (666
rows of 165 tests again, and no skip state changed): the four rows of the
filter test are new and execute in all four configurations, and four audit
rows have other data (they pass `-AppliesTo` by name now) with the same skip
state (skipped as a basic user).
- The instrumented runs gave the same counts. The measured assemblies:
| Assembly | SHA-256 |
| --- | --- |
| `NTFSSecurity.dll` | `DB725D529E6F89BD207DE673BE4A655FF1F1988DFB23981BC33117C52821D312` |
| `Security2.dll` | `487DBEF7690B33A85285F27D9596A924EFE9A8292ED02FE5F6B6F456CD323D6D` |
| `ProcessPrivileges.dll` | `19B35D2A9180BB5E09F078DCCDB6E47F5817DAF2929A972E17C1312475D1AC3A` |
| `PrivilegeControl.dll` | `37A6527173D5DE05E3D81D733951742A1D788DBA632239A01158F22F0FB524E3` |
| `NTFSSecurity.dll` | `6A3F42391F7A2247EF0B722804DBFE09B7D52739275FE6D56D3E0448E381F806` |
| `Security2.dll` | `417FB25C40734FB20A686469C1A6BC1F0F3F5EE83F06BC7E4F447C53FF039542` |
| `ProcessPrivileges.dll` | `A3834E173905CCC664803B9642DE48C1D8AA0C97D25B3FE2AC02F4460EBFCBB9` |
| `PrivilegeControl.dll` | `826C0E6A643578E0739B8A7A0635482022E932172196F2F62A33D397E0ACBF0B` |
| Assembly | Sequence points | Sequence coverage | Branch points | Branch coverage |
| --- | ---: | ---: | ---: | ---: |
| NTFSSecurity | 1,957/2,168 | 90.27% | 683/1,094 | 62.43% |
| Security2 | 1,061/1,240 | 85.56% | 509/753 | 67.59% |
| NTFSSecurity | 1,972/2,183 | 90.33% | 683/1,097 | 62.26% |
| Security2 | 1,061/1,240 | 85.56% | 509/753 | 67.60% |
| ProcessPrivileges | 205/219 | 93.61% | 72/125 | 57.60% |
| PrivilegeControl | 20/22 | 90.91% | 12/17 | 70.59% |
| Aggregate | 3,243/3,649 | 88.87% | 1,276/1,989 | 64.15% |
| Aggregate | 3,258/3,664 | 88.92% | 1,276/1,992 | 64.06% |
The explicit branch points that a person wrote are 1,090/1,168 (93.32%), as at
`fa0701b`. The 45 added sequence points are the getters described in Stage C.
The per cmdlet table ([the Cmdlets CSV](Quality-Gate-Unknowns-2026-10-10-Cmdlets.csv),
the unit suite of the host at `fa0701b`, the domain member, the first lab, the
final unit suite, and all sources together) has 19 cmdlets with more visited
points at the final commit; every cmdlet has 76.5% or more of its sequence
points visited by the sources together (72.5% for the unit suite of `fa0701b`),
and the lowest are `Clear-NTFSAudit` and the two audit inheritance cmdlets,
whose ownership-retry closures stay unvisited.
`fa0701b`. The final build visits 60 sequence points more than rc7: 45 are the
getters described in Stage C, and 15 are points of the new code of the filter
fix (the culture scope and its calls), all visited, so the denominator grew by
15. The branch summary grew by three points, one for each of the three new
methods, which it never counts as visited (Coverage of the shipped code: it
adds one point to a method without a branch), so its percentage fell from
64.15% to 64.06% while the explicit branch points did not change. All the new
points are in `GetChildItem2`: 148 of its 160 sequence points are visited (133
of 145 at `b2cb47b`), and 69 of its 70 explicit branch points (the same one as
at `fa0701b`, in the folder check of `WriteFileSystem`); the 12 unvisited
sequence points are the getters of its pipeline parameters.
The final build is another build of the same source and has other hashes than
the build of Stage A (the Release build is not byte-reproducible), so the two
measurements are compared by method and by position, not by hash.
the build of Stage A (the Release build is not byte-reproducible), so the
measurements are compared by method and by position, not by hash. Compared
with `f1f3d8f` by position (`merge\final2-vs-final5-points.csv`), none of the
4,602 points outside `GetChildItem2` is visited by one run and not by the other
and none is missing from one; the points of `GetChildItem2` cannot be aligned,
because its code changed and its lines moved (178 and 163 of the 393 positions
exist in one build only).
The merged tables of the sources, [Methods](Quality-Gate-Unknowns-2026-10-10-Methods.csv)
and [Cmdlets](Quality-Gate-Unknowns-2026-10-10-Cmdlets.csv) (the unit suite of
the host at `fa0701b`, the domain member, the first lab, the final unit suite,
and all sources together), are those of the measurement of `b2cb47b`: the other
sources ran the code of `fa0701b`, and the points of a method whose code
changed cannot be aligned by position with them, so the final column was not
rebuilt for the one changed class; it is given above. The table has 19 cmdlets
with more visited points at the final commit; every cmdlet has 76.5% or more
of its sequence points visited by the sources together (72.5% for the unit
suite of `fa0701b`), and the lowest are `Clear-NTFSAudit` and the two audit
inheritance cmdlets, whose ownership-retry closures stay unvisited.
The unvisited inventory of the final build has 187 methods, 406 sequence
points, and 78 explicit branch points; each of the 187 is classified (none is
unclassified), 167 as explained and 20 as open (the 8 methods that the paths
report left to the maintainer, and 12 getters of pipeline parameters).
points, and 78 explicit branch points, the same 187 methods as at `b2cb47b` and
at `f1f3d8f` (`GetChildItem2.WriteFileSystem` has 47 sequence points, all
visited, where it had 41); each is classified (none is unclassified), 167 as
explained and 20 as open (the 8 methods that the paths report left to the
maintainer, and 12 getters of pipeline parameters), with no row of the
classification changed (`classification-final5.csv`).
The measurement of `f1f3d8f` equals that of `b2cb47b`. Of the 4,817 points
(3,649 sequence points and 1,168 explicit branch points), none is visited by
one run and not by the other (`merge\final-vs-final2-points.csv`); the three
files of the inventory of the unvisited methods are byte-identical; and the
discovered rows and their skips are equal but for the line numbers of the rows
in the two edited test files. The coverage reports of two runs differ in hash,
as two runs do.
## Lab acceptance of the fixed build
A defect that is not an open item is fixed, and the lab acceptance of the
affected behavior is repeated on the fixed build (the handoff, as the paths
work did). The affected behavior is the comparison of an identity with a name.
No cmdlet uses it (the cmdlets compare identities by SID, and no line of the C#
of the cmdlets compares an identity with a string) and no live test does, so
this run is evidence that the fix changes nothing in the lab. It is not a
release acceptance: a new candidate needs its own (open item 6).
- Module: the extracted package of the measured final build
(`E\final\package\NTFSSecurity`, packaged like CI by `New-ModulePackage.ps1`
from the pristine copy). The hashes of its four assemblies, logged at the
start of the run, are those of the final measurement. It was passed with
`-ModulePath` to the unmodified controller and live tests of the repository
(Git blobs `635bf162…` and `efe36e50…`), without instrumentation.
- Lab: `WindowsAccessControlLab` (client `F1AFile1`, file server `F1AFile2`,
four domains, the trusts), one call per edition, run `fix1`,
`Run-LiveAcceptance.ps1`.
work did). It ran for each build that carried a fix, in the same way: the
unmodified controller and live tests of the repository (Git blobs `635bf162…`
and `efe36e50…`), the extracted package of the build (packaged like CI by
`New-ModulePackage.ps1` from the pristine copy and passed with `-ModulePath`),
no instrumentation, one call per edition (`Run-LiveAcceptance.ps1`) in
`WindowsAccessControlLab` (client `F1AFile1`, file server `F1AFile2`, four
domains, the trusts). Each run logs the hashes of the four assemblies at its
start.
| Run | Build (`NTFSSecurity.dll`) | Code that the fix changed | Clean end state |
| --- | --- | --- | --- |
| `fix1` | `b2cb47b` (`DB725D52…`) | the comparison of an identity with a name; no cmdlet uses it (the cmdlets compare identities by SID, and no line of the C# of the cmdlets compares an identity with a string) and no live test does | 21:30:18Z |
| `fix3` | `0028ccd` (`C0D10ED6…`), the first and incomplete fix of the filter; evidence, not final | the matcher of `Get-ChildItem2 -Filter` | 23:40:04Z |
| `fix4` | `8a625c8` (`6A3F4239…`), the final build, the bytes of the final measurement | the filter, complete: the culture scope around AlphaFS | 00:00:35Z |
The first run is evidence that the identity fix changes nothing in the lab. The
live tests do call `Get-ChildItem2` (a long path, `-Hidden`, the listing of a
share folder, a folder that the account cannot read, and `-Filter` on a share
folder), so `fix3` and `fix4` run the changed code in the three client roles,
over SMB, in `en-US`. They cannot show the `tr-TR` defect, which the unit tests
show; they show that the culture scope around the enumeration changes nothing
there. None of the runs is a release acceptance: a new candidate needs its own
(open item 6).
Per role (the same in all three runs and in both editions):
| Role | Account | Passed | Failed | Skipped | Exit code |
| --- | --- | ---: | ---: | ---: | ---: |
@ -954,11 +1168,125 @@ release acceptance: a new candidate needs its own (open item 6).
| Admin | `A\NtfsLiveAdmin` | 64 | 0 | 0 | 0 |
| Server | `A\install` | 76 | 0 | 1 | 0 |
Both editions gave the same counts: 245 passed, 0 failed, 1 skipped
(`LIVE_RESULT_VERIFIED`), the counts of the rc7 acceptance and of the
All three runs gave the same counts in both editions: 245 passed, 0 failed, 1
skipped (`LIVE_RESULT_VERIFIED`), the counts of the rc7 acceptance and of the
instrumented runs. The removal of the fixture and the independent check of the
end state found no account, share, folder, profile, task, or group member left
in the four domains and on both machines (`CLEAN`, 21:30:18Z).
in the four domains and on both machines (`CLEAN` at the times above).
**The end state of both labs after the last run** (00:41 to 00:43Z,
`E\verify-final`). A read-only check of one lab after the other, with the
`Test-MatrixCleanup.ps1 -Mode Verify` of the kit and the SIDs of the last
fixtures, found no fixture, scheduled task, stage item, probe account, or
profile left: the matrix lab (the domain controller `OSDC1` and the file
servers `OSFile19`, `OSFile22`, and `OSFile25`) and the first lab (the four
domains, `F1AFile1`, and `F1AFile2`) are `CLEAN`. The Windows 11 client
`OSWin11`, which the kit does not check, was read with `Verify-Client.ps1`: no
scheduled task `NtfsMatrix*`, no stage item, no probe user or profile, no
share, and no folder or user of the fixture. `OSWin11E` was not started and
nothing in this work ran in it after the runs of Stage B.
## The suite on the machines of the matrix lab
The unit suite ran on the three file servers of the matrix lab (Windows Server
2019, 2022, and 2025, domain members) and on its Windows 11 client, as the 22
behavior files that `Run-MatrixLocalSuite.ps1` stages, the four new files among
them, elevated and as a basic user, in both editions. The first run of the
package of this work found a failing test of this work; the section tells how
it was found and fixed, and the full runs after the fixes are at its end. The
first run was `fix1` (21:30 to 22:10Z, 1,152 cases, the pristine package of
`b2cb47b` and its test files; `E\localsuite-final`). The three machines gave
the same counts:
| Configuration | Passed | Failed | Skipped | Total |
| --- | ---: | ---: | ---: | ---: |
| Windows PowerShell 5.1, elevated | 1,132 | 1 | 19 | 1,152 |
| Windows PowerShell 5.1, basic user | 883 | 0 | 269 | 1,152 |
| PowerShell 7, elevated | 1,130 | 1 | 21 | 1,152 |
| PowerShell 7, basic user | 881 | 0 | 271 | 1,152 |
The six basic-user runs passed. The six elevated runs failed the same test, a
new one of this work in `ParameterSets.Inheritance.Tests.ps1`:
`Disable-NTFSAuditInheritance -SecurityDescriptor should take two piped
descriptors and report both in order, written only by Set-NTFSSecurityDescriptor`
fails with `Expected $false, but got $true` at the check that the file on disk
is unchanged by the in-memory change. The host passes it in all four
configurations.
**Cause: the oracle of the test, not the module.** The check read the SACL of
a fresh file with `Get-Acl -Audit`, which reads it together with the other
sections. A diagnostic run of the same file with prints (run `rep1`, elevated,
both editions, on `OSFile25` and `OSFile19`; `E\repro`) shows the reads side
by side for a file without audit entries:
| State of the file | `Get-Acl -Audit` | SACL read alone (.NET) | `Get-NTFSInheritance -Path` |
| --- | --- | --- | --- |
| fresh, and after `Get-NTFSSecurityDescriptor` | protected | not protected | audit inheritance enabled |
| after the piped call of the descriptor, before `Set-NTFSSecurityDescriptor` | protected | not protected | audit inheritance enabled |
| after `Disable-NTFSAuditInheritance -Path` | protected | protected | audit inheritance disabled |
The file on disk was not changed by the in-memory call, as the test intends;
only the oracle read "protected" before and after it.
`Security2\FileSystem\FileSystemSecurity2.cs` and the
[acceptance of the matrix](../Lab/Acceptance-2026-10-10-os-matrix.md) already
describe this difference for Windows Server 2022 and 2025 and Windows 11, and
the module reads the SACL alone for that reason. The diagnostic adds Windows
Server 2019, where the baseline of that acceptance had not been run, and shows
the same in both editions.
**The fix** (`f1f3d8f`): five assertions of two new files read the SACL alone
through .NET (`Get-TestAuditAcl`), as the module does. One of them failed. Four
more expected "protected" for an item that ends without audit entries
(`Set-NTFSInheritance -SecurityDescriptor` after the write, the `Disable` rows
of two piped tests, and `Clear-NTFSAudit -DisableInheritance`); on a domain
member the combined read gives that answer whether or not the flag was
written, so they could not fail there, and they are strengthened too. The
assertions that read the flag of an item with explicit audit entries or compare
an SDDL before and after are unchanged, as are the older files: they read the
flag from an in-memory descriptor or, in the live test, from folders that hold
explicit audit entries.
**Verification of the fix.** The two changed files (78 cases) ran again with
the pristine package on the three file servers, elevated, in both editions (run
`rep2`, `E\repro-fixed`): 76 passed, 0 failed, 2 skipped on each. On the host
(run `hostfix`, `E\repro-host`) they passed in the four configurations:
elevated 76, 0, 2; basic user 40, 0, 38 (passed, failed, skipped). The 35
mutations of Stage C ran on the host before this change; both versions of the
oracle pass on the host, so the mutation table is stated as measured and was
not repeated.
**The full suite after the fixes.** Two full runs followed, each on the three
file servers and on the Windows 11 client (build 28000.1836, reached with its
local installation account):
- `fix2` (22:32 to 23:12Z, `E\localsuite-final2`) and `fix2c` (22:45 to
22:55Z, `E\localsuite-final2-client`) ran the test files of `f1f3d8f` on the
package of `b2cb47b`: 1,152 cases in each configuration, and all 16
configurations passed (1,133, 883, 1,131, and 881 passed; 19, 269, 21, and
271 skipped, in the order of the table below).
- `fix5` (00:00 to 00:41Z, `E\localsuite-final5`) and `fix5c` (00:02 to
00:13Z, `E\localsuite-final5-client`) ran the test files of `61e936e` on the
package of the final build (`8a625c8`; the log of each run starts with the
hash of `NTFSSecurity.dll`, `6A3F4239…`, and with the hashes of the 23 staged
files, which equal those of the commit): 1,156 cases in each configuration,
the 1,152 and the four rows of the filter test. All 16 configurations
passed, and the four machines gave the same counts:
| Configuration | Passed | Failed | Skipped | Total |
| --- | ---: | ---: | ---: | ---: |
| Windows PowerShell 5.1, elevated | 1,137 | 0 | 19 | 1,156 |
| Windows PowerShell 5.1, basic user | 887 | 0 | 269 | 1,156 |
| PowerShell 7, elevated | 1,135 | 0 | 21 | 1,156 |
| PowerShell 7, basic user | 885 | 0 | 271 | 1,156 |
The four rows of the filter test execute in all four configurations on all four
machines, and the skips are the same on every machine and in `fix2` (19 and 21
elevated, 269 and 271 as a basic user). So the final build passes the 22 files
on Windows Server 2019, 2022, and 2025 and on Windows 11, the operating systems
of the matrix, where the first run found the failure of the oracle. The runner
removes its scheduled tasks and its stage folder on each machine at the end of
a run; an independent check of the end state of the labs followed (the end of
the section Lab acceptance of the fixed build).
## Decisions made
@ -1000,7 +1328,8 @@ the maintainer can reverse every one of them.
10. **The hard-link defect is not fixed** (Stage C): the fix chooses which
names two cmdlets return and adds code to their path, which is a decision.
11. **Not pinned:** the four `MaintainerDecision` sets, and the behavior that a
piped `AppliesTo` property does not select the Simple set.
piped `AppliesTo` property is dropped for a path instead of selecting the
Simple set.
12. **Stage C stopped** at 79 `It` blocks, the target of 15 to 20 per file;
every remaining gap is in the ParameterSets table. The 12 getters were not
tested, to keep the measured commit stable for the lab acceptance.
@ -1014,6 +1343,41 @@ the maintainer can reverse every one of them.
16. **A rehearsal** of the final run on `ef45b38` (three of the four files)
was stopped in the mode Coverage after Build and Validate had passed (1,407
cases in each configuration), and replaced by the final run.
17. **The audit protection flag is read from the SACL alone in the new tests**
(`f1f3d8f`, section "The suite on the machines of the matrix lab"). The
oracle was wrong on a domain member and the module already reads the SACL
alone, so the test changes and the module does not. The change follows the
measured commit; the final measurement was repeated on it.
18. **The second culture defect is fixed, and the first fix was incomplete.**
The review found `Get-ChildItem2 -Filter` in `tr-TR` (the class of
Decision 8), so the rule of the handoff applies: a failing test, the fix,
and the acceptance of the fixed build. `0028ccd` fixed the comparison of the
cmdlet; the probes showed that AlphaFS 2.2 also matches the filter with the
culture of the thread, so `fbe0289` runs the enumeration with the invariant
culture. The thread culture changes only around the creation of the
enumerator and each `MoveNext`, never across a `WriteObject`. The alternative
without the switch, enumerating everything with `*` and matching only in the
cmdlet, changes the dot rules of `-Filter` (an open decision of the paths
report) and the cost of a filtered listing of a share, so it was not taken.
19. **The final measurement and the acceptance are repeated on the build of
`8a625c8`,** because the product code changed after the build that the first
acceptance used. The builds of `b2cb47b` (and of `f1f3d8f`, the same bytes)
and of `0028ccd` (accepted in the first lab, run `fix3`, and not final) stay
as evidence. The merged tables of the sources (Methods and Cmdlets) are those
of `b2cb47b`: the other sources must run the same code, and `GetChildItem2`
changed since, so its final row is measured on its own.
20. **One independent review, not two.** The review (the built-in `code-review`
agent, 44 minutes, read-only) found four Major findings and several Minor
ones; each was resolved or answered with a probe, a test, or a text change
(section Review). The changes made to resolve them were not reviewed by a
second agent: runs verified them (red and green tests, probes, the lab
acceptance), and the handoff asks for one review.
21. **The cells of the matrix lab were not run again for the final build.** The
change after the acceptance that the matrix gave to rc7 is one class,
`GetChildItem2`, which the live suite of the first lab exercises and the
unit suite ran on the three file servers and the client. The cells are the
acceptance of a new candidate (open item 6), and they cost the matrix lab's
time (an evaluation client that shuts down every hour).
## Open items for the maintainer
@ -1026,28 +1390,33 @@ of the effective-access check, Decisions 22 and 24, and #34) stay as they are.
1. **Hard-link names under a root that is not the volume root.** A defect with
a reproduction (Stage C). Options: the names under the real volume root
(a final path of a handle), the names under the root that the caller gave,
or a documented limit. The call of `repro.ps1` is the regression test.
or a documented limit. The commands in Stage C are the regression test.
2. **`AUDIT-OWNER-RETRY` and `AUDIT-READ-DENIED`** (47 plus 6 sequence points)
have no trigger on a Windows file server. Closing them needs an answer of a
file server that is not a Windows server (#34), or a seam that injects the
exception (a design change).
3. **A piped property `AppliesTo`** does not select the Simple set of
`Add-NTFSAccess` and `Remove-NTFSAccess` and is dropped without a message.
Intended or not?
3. **A piped property `AppliesTo`** is dropped for a path, without a message:
the default set `PathComplex` binds, and the property does not select the
Simple set (probed for all four cmdlets: `Add-NTFSAccess`,
`Remove-NTFSAccess`, `Add-NTFSAudit`, and `Remove-NTFSAudit`). For a
descriptor it selects `SDSimple`. Intended or not?
4. **Twelve getters of pipeline parameters** that take pipeline input by
property name and that no test supplies on a piped object (Stage C lists
them): tests close them.
5. **The remaining gaps of 52 sets** in the ParameterSets table (68 `budget`,
16 `Limit`, 3 `would-pin`), and the four `MaintainerDecision` sets with the
open item 1 of the paths report. The `-SecurityDescriptor` sets other than
three were not tested with a direct call that passes several descriptors.
6. **A new candidate.** The fix `419cfb3` and the tests are changes after the
tag; a new candidate, if he takes them, needs the acceptance (matrix cells
and first lab) on its own bytes. The acceptance of the fixed build below is
evidence for the behavior, not for a release.
5. **The remaining gaps of 52 sets** in the ParameterSets table (62 `budget`,
16 `Limit`, 2 `would-pin`, and 3 `MaintainerDecision` mentions), and the four
`MaintainerDecision` sets with the open item 1 of the paths report. The
`-SecurityDescriptor` sets other than three were not tested with a direct
call that passes several descriptors.
6. **A new candidate.** The fixes `419cfb3`, `0028ccd`, `fbe0289`, and
`8a625c8` and the tests are changes after the tag; a new candidate, if he
takes them, needs the acceptance (matrix cells and first lab) on its own
bytes. The acceptance of the fixed build below is evidence for the behavior,
not for a release.
7. **Server Core** (the plan of Stage D; it widens the proposed Decision 24),
**ARM64**, **a localized operating system** (names of built-in accounts and
error texts), and **non-Windows file servers**.
**ARM64**, **a localized operating system** (names of built-in accounts,
error texts, and any other comparison that AlphaFS or Windows does with the
culture), and **non-Windows file servers**.
8. **A trivial observation:** `RemoveAudit.cs` converts the scope of an
`-AppliesTo` twice for the set `PathSimple` (at the top of `ProcessRecord`
and again in the loop). It is idempotent and has no effect.
@ -1059,14 +1428,52 @@ of the effective-access check, Decisions 22 and 24, and #34) stay as they are.
| Coverage of the shipped code (rc7, `fa0701b`) | Closed | Stage A: 3,198/3,649 sequence points (87.64%), 1,090/1,168 explicit branch points; 232 methods classified, none unclassified; the Methods, Cmdlets, and Reconciliation tables |
| Coverage of the live tests | Closed | Stage B: first lab and three matrix cells, 245 and 229 passed per edition, the counts of the uninstrumented acceptance; 1,861 sequence points each, 9 sequence and 4 explicit branch points more than the host unit suite; the cells add nothing to the first lab |
| The unit suite on a domain member | Closed | `OSFile25`, four configurations, the counts of the rc7 acceptance; 9 sequence and 3 explicit branch points more than the host |
| The unit suite of the final build on the other operating systems | Closed | the 22 behavior files on Windows Server 2019, 2022, 2025 and Windows 11 (build 28000), elevated and as a basic user, both editions: 1,156 cases in each of the 16 configurations, no failure (`fix5`, `fix5c`); the first run (`fix1`) found one failing test, caused by its oracle and fixed in the test (`f1f3d8f`); both labs verified clean afterwards |
| The code of `fdd7a8b` | Closed, with one branch visited by nothing | the ServerAdmin tests (lines 478 and 486) and the basic-user runs on the domain member visit the fall back; the answer "RPC server unavailable" of the context initialization is visited by nothing (explained) |
| `AUDIT-OWNER-RETRY`, `AUDIT-READ-DENIED` | Open | no test visits them; no trigger on a Windows file server (probe of 48 calls); closing needs a non-Windows server (#34) or a seam |
| The reachable gaps, the judged matrix of the 64 parameter sets | Partly closed | 79 `It` blocks (140 rows), 33 of 35 mutations caught; 7 sets closed, 51 partly, 1 open, 4 `MaintainerDecision`, 1 `None`; 12 getters of pipeline parameters open; one defect (hard-link names) and one behavior (piped `AppliesTo`) for the maintainer |
| Other cultures | Closed for `de-DE` and `tr-TR` | one defect found and fixed test-first (`419cfb3`); six `de-DE` failures are assertions on English text; localized names and texts untested |
| The reachable gaps, the judged matrix of the 64 parameter sets | Partly closed | 79 `It` blocks (140 rows), 33 of 35 mutations caught; 7 sets closed, 51 partly, 1 open, 4 `MaintainerDecision`, 1 `None`; 12 getters of pipeline parameters open; one defect (hard-link names) and one behavior (piped `AppliesTo` for a path) for the maintainer |
| Other cultures | Closed for `de-DE` and `tr-TR`, after two defects | two defects found and fixed test-first: the comparison of an identity with a name (`419cfb3`) and `Get-ChildItem2 -Filter` (`0028ccd`, `fbe0289`, `8a625c8`), the second found by the independent review after the scan had missed its class of call; six `de-DE` failures are assertions on English text; localized names and texts untested |
| Windows Server Core | Open | a plan with the image index, disk, time, and commands; deploying needs the maintainer's word |
| ARM64 | Open | no reproduction |
| The final commit | Closed | `b2cb47b`: 1,455 cases per configuration, no failure; 3,243/3,649 sequence points (88.87%); eligibility by row; 187 unvisited methods classified |
| The lab acceptance of the fixed build | Closed for the first lab | the measured final package, both editions, 245 passed, 0 failed, 1 skipped each, clean end state; the matrix cells were not repeated (a new candidate needs them) |
| The final commit | Closed | `61e936e`, built once at `8a625c8` and measured on those bytes: 1,459 cases per configuration, no failure; 3,258/3,664 sequence points (88.92%), 1,090/1,168 explicit branch points; skip eligibility by row (666 skipped rows, none without an executed counterpart); the same 187 unvisited methods as at `b2cb47b`, all classified; the merged tables of the sources are those of `b2cb47b` (Final measurement) |
| The lab acceptance of the fixed build | Closed for the first lab | three runs on three builds (`b2cb47b`, `0028ccd`, and the final build `8a625c8`), both editions, 245 passed, 0 failed, 1 skipped each, clean end state; the matrix cells were not run again (a new candidate needs them) |
## Review
One independent review, as the handoff asks: the built-in `code-review` agent
(the custom `security-reviewer` cannot start), read-only, one pass of 44 minutes
over `6696f68..bea855e`, which covered the production fix, the new tests, the
numbers of this report, the Memory Bank, and the change of the matrix runner.
It found four Major and several Minor findings, and no Blocker. Each was
resolved or answered with evidence:
| # | Severity | Finding | Resolution |
| --- | --- | --- | --- |
| 1 | Major | The `-eq` example of the changelog entry and of this report is not shown by any evidence and likely does not fail | Probed on the previous build under `tr-TR`: `-eq`, `-contains`, and `-in` return True; only `Equals` failed. The entry and the text now name `Equals` (`0028ccd`) |
| 2 | Major | The culture scan missed the case-insensitive `WildcardPattern` of `Get-ChildItem2`, so "Other cultures: Closed" overclaimed | Reproduced in both editions; fixed test-first (`0028ccd`, `fbe0289`, `8a625c8`; the first fix was incomplete, see Stage D); second scan found no other; acceptance repeated |
| 3 | Major | The test of `Get-Privileges` compares the localized State text of `whoami /priv` | The state is compared only where `whoami` prints the English words (`61e936e`) |
| 4 | Major | The finding on a piped `AppliesTo` contradicts the coverage data of the audit cmdlets | Traced with probes in both editions: a path drops the property for access and audit alike, a descriptor binds it. The audit rows named `PathSimple` bound `PathComplex`; they name `-AppliesTo` now and assert the scope (`61e936e`); text and open item corrected |
| 5 | Minor | Two Items rows "array with an empty element" passed a plain empty string | They pass an array (`61e936e`) |
| 6 | Minor | The empty-path rows of Copy-Item2 and Move-Item2 run with the sandbox as current location | They run in an empty folder of their own (`61e936e`) |
| 7 | Minor | The on-disk proof that an audit entry was written is only that the SDDL differs | The entry is asserted in the descriptor and on disk (`61e936e`) |
| 8 | Minor | Numbers and wording: 67.59% (it is 67.60%); the counts of the 52 sets (they are of the 57 not closed); "each of them asserts the error ID" (only the filter test does); the Runs table (it lacked the final runs); a sentence that no cmdlet reaches an unexplained point (65 methods have no explanation) | All corrected here; the Runs table lists every run |
| 9 | Minor | `b2cb47b` is still called the final commit, and the Memory Bank has the same wording and one overstatement | Updated with the final measurement |
The reviewer checked and found clean: the production fix of the identity
comparison (null and empty arguments, `GetHashCode`, the operators, the red and
green logs, the restoration of the thread culture, the changelog group);
PSScriptAnalyzer on the new files; the Pester 5 pitfalls (the use of
`BeforeDiscovery` variables, `Set-ItResult -Skipped` with `return`); the
restoration of `EnablePrivileges`, the balance of `Push-Location`, and the
confinement of every destructive call to the sandbox; the remaining reads of the
SACL with `Get-Acl -Audit` (they hold audit entries); about 40 numbers of this
report against the tables; the change of `Run-MatrixLocalSuite.ps1`; and the
agreement of the Memory Bank with the report.
The review saw `bea855e`. Everything after it, the second culture defect, the
test changes, the new measurement, and the acceptance, was verified by runs
(Stage D, and the sections on the final measurement and the acceptance) and not
by a second review.
## Checks not run, and limits
@ -1075,6 +1482,10 @@ of the effective-access check, Decisions 22 and 24, and #34) stay as they are.
ones whose named gaps are asserted. The coverage of the unit suite barely
moved (+45 points, all getters), because the gaps were assertions and not
lines.
- The 35 mutations ran before the later test changes (`f1f3d8f`, the oracle of
five assertions, and `61e936e`, the rows of the review) and were not
repeated. On the host the old and the new oracle pass; whether each mutation
that one of the changed assertions caught is still caught was not measured.
- The live coverage ran on one first lab and three cells of the matrix lab
with one client (`OSWin11E`); the matrix cells added no point, so the claim
that the operating system does not change the code that the tests run
@ -1083,18 +1494,24 @@ of the effective-access check, Decisions 22 and 24, and #34) stay as they are.
`Run-MatrixLocalSuite.ps1` stages (1,011 of 1,314 cases), not in the files
that check the repository, the manifest, the help, the wiki, and the release
scripts, which need the repository.
- Not run: a hard link through a volume mounted into a folder or through a
junction to another volume (the defect is reproduced with a substituted
drive only); the 12 getters; the matrix suite on `OSWin11E` and `OSWin11`
with the new files; Windows Server Core; ARM64; a localized operating
system; a file server that is not a Windows server.
- The culture scan covers the C# of the four projects and the filter that
`Get-ChildItem2` passes to AlphaFS; the rest of AlphaFS, a third-party
library, was not scanned.
- Not run: the live suite of the matrix cells (`Run-MatrixSequence.ps1`) on
the final build (the first lab ran it, and the unit suite ran on every
machine of the matrix; open item 6); a hard link through a volume mounted
into a folder or through a junction to another volume (the defect is
reproduced with a substituted drive only); the 12 getters; the matrix suite
on `OSWin11E` with the new files (`OSWin11` ran it); Windows Server Core;
ARM64; a localized operating system; a file server that is not a Windows
server.
- The Release build is not byte-reproducible: a hash identifies the measured
files, not the source. Different code has different denominators; the
measurements of `5a5d58b`, `fa0701b`, and `b2cb47b` are not increments of
one source, and the comparison is by method and position.
- The custom `security-reviewer` cannot start (its model is unavailable), and
no model setting was overridden; the independent review below is the
read-only built-in `code-review` agent.
no model setting was overridden; the independent review (section Review) is
the read-only built-in `code-review` agent.
- Nothing was pushed, merged, tagged, or published. The stable 5.0.0 stays
gated by the other gates, and a percentage never closes a gate.
@ -1110,9 +1527,14 @@ lists its files with size and SHA-256; the folders are:
| `fa0701b`, `eligibility-fa0701b`, `inventory-fa0701b`, `classification-fa0701b.csv`, `reconciliation-fa0701b.csv` | Stage A: the frozen worktree, the reports and logs of the four configurations, the pristine and saved assemblies with hashes, the skip rows, and the inventory |
| `live-inst2`, `live-fl1b`, `live-fl2`, `localsuite-osfile25`, `live-matrix`, `probe-auditdenied` | Stage B: the instrumented module and its zero-hit report, the rejected first design, the first lab, the unit suite on the domain member, the matrix cells, and the audit probe, each with the report, the snapshots per process, the validation, and the logs |
| `paramsets`, `impl` | Stage C: the scan, the judged tables and notes, the status tables, and the run logs of the implementers |
| `cultures`, `probes`, `tdd` | Stage D and the fix of the identity comparison: the four culture runs, the probes (`hardlink-root` has the reproduction), and the red and green runs |
| `final`, `eligibility-final`, `inventory-final`, `classification-final.csv` | the final measurement and its package |
| `live-fix1`, `localsuite-final`, `chain-fix.log` | the lab acceptance of the fixed build |
| `cultures`, `probes`, `tdd`, `tdd2` | Stage D and the two culture defects: the four culture runs, the probes (`hardlink-root` has the reproduction, `alphafs-*` the enumeration of AlphaFS, `review-*`, `eq-mechanism-*`, and `remove-audit-appliesto-*` the findings of the review), and the red and green runs of the identity comparison (`tdd`) and of the filter (`tdd2`) |
| `final`, `eligibility-final`, `inventory-final`, `classification-final.csv` | the measurement of `b2cb47b` and its package |
| `final2`, `eligibility-final2`, `inventory-final2`, `chain-final2.log`, `merge\final-vs-final2-*` | the measurement of `f1f3d8f` on the same bytes, and its comparison with the first by position |
| `final3`, `live-fix3` | the build of `0028ccd` (the first, incomplete fix of the filter) and its acceptance in the first lab |
| `final4`, `final5`, `eligibility-final5`, `inventory-final5`, `classification-final5.csv`, `chain-final5.log`, `merge\final2-vs-final5-*` | the final build of `8a625c8` with its package, the final measurement of `61e936e` on its bytes (`inventory-*\branch-summary-decomposition.txt` holds the split of the branch summary, for rc7 and for the final build), and the comparison with the measurement of `f1f3d8f` by position |
| `live-fix1`, `localsuite-final`, `chain-fix.log` | the lab acceptance of the build of `b2cb47b` and the first run of the unit suite on the file servers |
| `live-fix4`, `localsuite-final5`, `localsuite-final5-client`, `verify-pre`, `verify-final` | the lab acceptance of the final build, the unit suite of the final build on the file servers (`fix5`) and on the Windows 11 client (`fix5c`), and the read-only checks of both labs before the work and after the last run |
| `repro`, `repro-fixed`, `repro-host`, `repro-root`, `localsuite-final2`, `localsuite-final2-client` | the diagnosis of the failing oracle (`rep1`), the runs after the fix on the file servers (`rep2`) and the host (`hostfix`), the test roots of the diagnosis, and the full unit suite at `f1f3d8f` on the file servers (`fix2`) and the client (`fix2c`) |
| `merge`, `scripts` | the merged points by position, and every script of the method |
Nothing in the evidence holds a password; the controller keeps them in memory.

Loading…
Cancel
Save