Browse Source

chore(memory-bank): record the 5.0.0-rc4 release

- progress and activeContext: 5.0.0-rc4 published from 01d9264; #41,
  #108, #109, and #111 closed as completed, #90 and #107 as not planned;
  the deferred review findings are listed in #113; 5.0.0 is next.
- techContext: the label rc4 and the Gallery versions; AlphaFS reaches the
  device object for a drive or volume root through DirectoryInfo and the
  root folder through the path methods; stale lines shortened.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/114/head
Raimund Andree 5 days ago
parent
commit
c7c3e11ebe
  1. 28
      .memory-bank/activeContext.md
  2. 50
      .memory-bank/progress.md
  3. 24
      .memory-bank/techContext.md

28
.memory-bank/activeContext.md

@ -9,30 +9,30 @@ source: current task evidence
## Current focus
5.0.0-rc3 is released and recorded. Next is 5.0.0, when the maintainer
5.0.0-rc4 is released and recorded. Next is 5.0.0, when the maintainer
decides; then the repository is archived in favor of WindowsAccessControl
(Decision 18). Issue #34 is open with Bug and Help Wanted and waits for a
tester with a file server that refuses the owner; #67 is closed as not
planned.
(Decision 18). Issue #34 is open with Bug and Help Wanted; a user there
planned to test 5.0.0-rc3 against an IBM ESS file server.
## Evidence
- 2026-10-06: the tag `5.0.0-rc3` on `914e8da`, the merge commit of #112,
- 2026-10-06: the tag `5.0.0-rc4` on `01d9264`, the merge commit of #113,
published the prerelease to the PowerShell Gallery and to GitHub. The
Gallery package and `NTFSSecurity.zip` hold identical module files and
import as 5.0.0-rc3 in both editions; CI passed for #112 and on `master`.
- The replies to #34 and #67 are posted. The merge of #112 closed #34,
because the PR description said "fixes #34"; the maintainer reopened it.
- The cmdlets write only the sections that they change (Decision 19); the
manifest `Description` announces the archive (Decision 18).
Gallery package and `NTFSSecurity.zip` hold identical module files; the
package imports as 5.0.0-rc4 in both editions and passes the smoke tests
of #41 and #34. CI passed for #113 and on `master`.
- The rc4 replies are posted: #41, #108, #109, and #111 are closed as
completed, #90 and #107 got WontFix and are closed as not planned. The
findings that the rc4 review deferred are listed in #113.
- Without the Security privilege, the tests that change the audit entries
of a descriptor from `Get-NTFSSecurityDescriptor` skip; a basic-user run
fails only the `Enable-Privileges -PassThru` count test (techContext).
- Hand commands to the maintainer as fenced code blocks at the end of the
reply, and end the turn there; never put them in the question dialog,
which also covers a reply before it. A pull request names an issue
without a closing keyword unless the merge should close it (techContext).
A handoff outside the repository fixes the hand-over in the user-level
Customizations.
## Next step
Before 5.0.0, read #34 for feedback from a tester. Then release 5.0.0 as
Before 5.0.0, read #34 for feedback from the tester. Then release 5.0.0 as
`progress.md` describes.

50
.memory-bank/progress.md

@ -9,13 +9,12 @@ source: repository evidence
## Current status
5.0.0-rc3 is on the PowerShell Gallery and in the GitHub releases,
published by CI from the tag `5.0.0-rc3` on `master` (`914e8da`, the merge
of #112) on 2026-10-06 (Decision 12). It adds to 5.0.0-rc2 the fix of #34
and of the copied inherited entries: the cmdlets write only the sections
that they change (Decision 19). The stable Gallery version is still 4.2.6.
NTFSSecurity will be archived soon; its users move to WindowsAccessControl
(Decision 18).
5.0.0-rc4 is on the PowerShell Gallery and in the GitHub releases,
published by CI from the tag `5.0.0-rc4` on `master` (`01d9264`, the merge
of #113) on 2026-10-06 (Decision 12). It adds to 5.0.0-rc3 the fixes of the
issues #41, #108, #109, and #111 and of the leftovers of the rc3 review.
The stable Gallery version is still 4.2.6. NTFSSecurity will be archived
soon; its users move to WindowsAccessControl (Decision 18).
## Recent milestones
@ -50,6 +49,13 @@ NTFSSecurity will be archived soon; its users move to WindowsAccessControl
explained in `Docs/FAQ.md`, and was closed as not planned. One
`security-reviewer` pass approved the branch. The PR description said
"fixes #34", so the merge closed #34; it was reopened for a tester.
- 2026-10-06: 5.0.0-rc4 (#113), test-first: drive and volume roots read
and change their root folder, not the device (#41); the audit cmdlets
reject a descriptor without the audit entries (#109); `-WhatIf` previews
`Copy-Item2` and `Move-Item2` despite an existing destination (#108);
small items (#111). One `security-reviewer` pass approved it; its Minor
findings R1, R2, R6, and R8 were fixed before the merge. #41, #108,
#109, and #111 closed as completed, #90 and #107 as not planned.
## Stable capabilities
@ -65,31 +71,25 @@ NTFSSecurity will be archived soon; its users move to WindowsAccessControl
## Open work
1. Release 5.0.0 through CI (Decision 12) when the maintainer decides:
remove the label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc3` to
remove the label, date `[Unreleased]` as `[5.0.0]`, add `5.0.0-rc4` to
`$publishedVersions`, and tag `5.0.0` (steps in
`Docs/Contributing/05-Releasing.md`). #34 stays open with Bug and Help
Wanted until a tester with a file server that refuses the owner
confirms the fix, or until 5.0.0 ships.
2. Issues: the open issues got their replies on 2026-10-05. Follow-up
issues for the open Minor review findings: #107 (relative path forms),
#108 (`Copy-Item2` and `Move-Item2`), #109 (error messages), #110
(tests), and #111 (small items); #68 tracks `-WhatIf` and `-Confirm` for
every cmdlet that changes security. The labels follow Decision 17; #16,
#21, #45, and #89 wait for their reporters (Needs Info). Not planned for
5.0.0: #41 (a drive root reads the device object), #90 (a trailing space
in a folder name), and the enhancements #22, #49, #68, #77, #87.
3. Review findings of rc3, not filed: an extra DACL read and four SDDL
snapshots on read paths, and a duplicate SACL check. Older:
`Remove-NTFSAudit` fails for an item without a SACL;
`FileSystemSecurity2.Write(FileSystemInfo)` and `Write(string)` write
every section; the owner retry of `Set-NTFSSecurityDescriptor` lacks a
`finally`; `RemoveFileSystemAccessRuleAll` and
`RemoveFileSystemAuditRuleAll` ignore their accounts filter, which no
cmdlet passes.
2. Issues: #110 (tests) is the open follow-up of the review findings; #68
tracks `-WhatIf` and `-Confirm` for every cmdlet that changes security.
The labels follow Decision 17; #16, #21, #45, and #89 wait for their
reporters (Needs Info). Not planned for 5.0.0: the enhancements #22,
#49, #68, #77, #87.
3. Review findings, not filed: of rc3, an extra DACL read and four SDDL
snapshots on read paths, and a duplicate SACL check; of rc4, R3 to R5,
R7, and five older defects, listed in the description of #113, among
them the accounts filter that `RemoveFileSystemAccessRuleAll` and
`RemoveFileSystemAuditRuleAll` ignore, which no cmdlet passes.
4. `pwsh` 7.6.1 crashed three times during test runs on the ARM64
workstation (x64 emulation), without module frames; none of the CI runs
on native x64 on 2026-10-05 crashed.
5. Optional for the maintainer: delete the AppVeyor project and revoke its
GitHub authorization, restrict wiki editing to collaborators, ask
`Sup3rlativ3` to delete the Read the Docs project, and delete the branch
`test/transfer`. The branch `fix/#34` is superseded by #112.
`test/transfer`.

24
.memory-bank/techContext.md

@ -15,7 +15,9 @@ source: repository evidence
interop), `PrivilegeControl` and `ProcessPrivileges` (token privileges),
`Log`, `TestClient`, `NTFSSecurityTest` (MSTest, minimal coverage).
- NuGet (`packages.config`): AlphaFS 2.2.x for long paths;
`System.Management.Automation.dll` 10.0.10586.0.
`System.Management.Automation.dll` 10.0.10586.0. For a drive or volume
root, AlphaFS `DirectoryInfo` reaches the device object, while
`Directory.Get/SetAccessControl('C:\')` reaches the root folder (#41).
- Module: `NTFSSecurity.psd1` loads `NTFSSecurity.psm1` (aliases `dir2`,
`gi2`, `rm2`, `del2`), `NTFSSecurity.Init.ps1` (Add-Type of the helper
assemblies, prepends `NTFSSecurity.format.ps1xml`), and `NTFSSecurity.dll`.
@ -24,10 +26,8 @@ source: repository evidence
Cmdlet pages are platyPS 0.14 markdown (schema 2.0.0) in `Docs/Cmdlets`.
- Help: `NTFSSecurity\en-US\NTFSSecurity.dll-Help.xml`, generated from
`Docs/Cmdlets` and committed (Decision 8).
- Tests: Pester 5 tests in `Tests`: `Help.Tests.ps1` (help of every
cmdlet), `Manifest.Tests.ps1` (manifest and versions, Decision 10), and
`Remove-Item2.Tests.ps1` (`-PassThur` alias) against the Release build;
`Wiki.Tests.ps1` (wiki conversion) without a build.
- Tests: Pester 5 in `Tests`, one file per area, against the Release
build; `Wiki.Tests.ps1` (wiki conversion) runs without a build.
- CI: GitHub Actions, `.github/workflows/ci.yml` with the scripts in
`.github/scripts` (Decision 11).
@ -72,7 +72,7 @@ source: repository evidence
## Constraints
- `ModuleVersion` on `master` is `5.0.0` with the prerelease label `rc3`.
- `ModuleVersion` on `master` is `5.0.0` with the prerelease label `rc4`.
The latest stable tag and Gallery release is `4.2.6`. The manifest
requires PowerShell 5.1 and .NET Framework 4.5.2, uses `RootModule`, and
lists exactly 36 cmdlets; `Test-ModuleManifest` passes in Windows
@ -83,18 +83,16 @@ source: repository evidence
- PowerShell Gallery versions (publish dates): 4.0.0 (2015-08-19), 4.2.2
(2016-05-18), 4.2.3 (2016-05-19), 4.2.4 (2018-08-13), 4.2.5 (2019-07-11),
4.2.6 (2019-07-12), none with release notes; 5.0.0-rc1 (2026-10-04),
5.0.0-rc2 (2026-10-05), and 5.0.0-rc3 (2026-10-06), published by CI.
Older versions were released on CodePlex only, and their dates are lost.
The git history starts on 2016-10-10, when the project moved from
5.0.0-rc2 (2026-10-05), 5.0.0-rc3 and 5.0.0-rc4 (2026-10-06), published
by CI. Older versions were released on CodePlex only, and their dates are
lost. The git history starts on 2016-10-10, when the project moved from
CodePlex.
- Releases up to 4.2.6 were Debug builds published by hand, with the whole
output folder; their tags carry the previous version. From 5.0.0 on, CI
publishes on a version tag (Decision 12). GitHub releases attach
`NTFSSecurity.zip`.
- CI: GitHub Actions on pull requests and pushes to `master` (Decision 11).
AppVeyor no longer reports on `master`. The Read the Docs project
`ntfssecurity` and a second AppVeyor project belong to the deleted fork
`Sup3rlativ3/NTFSSecurity` and aren't used (Decision 9).
- CI: GitHub Actions on pull requests, pushes to `master`, and version tags
(Decision 11); AppVeyor and Read the Docs aren't used (Decision 9).
- `CHANGELOG.md` lists user-visible changes only; CI and build-only changes
get no entry
([Decision 7](decisions/0007-changelog-user-visible-only.md)).

Loading…
Cancel
Save