Browse Source

docs: record the lab acceptance of 5.0.0-rc6

The candidate acfe3af passed the live tests in both editions with all
roles: 326 tests, none failed. The record lists the hashes of the
packages, the readiness of the lab, the checkpoint, the results, the
baseline, and the checked removal of the fixture. The published 5.0.0-rc5
fails only the two hard-link tests of case 8 on the share, the defect that
rc6 fixes.

The README of the live tests describes the acceptance of a release
candidate, and the release guide runs it before a release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/release-5.0.0-rc6
Raimund Andree 3 days ago
parent
commit
cff40c392d
  1. 5
      Docs/Contributing/05-Releasing.md
  2. 131
      Tests/Lab/Acceptance-2026-10-08-5.0.0-rc6.md
  3. 25
      Tests/Lab/README.md

5
Docs/Contributing/05-Releasing.md

@ -77,6 +77,11 @@ Gallery compares labels as text, so `rc10` sorts before `rc2`.
## Publish a release
Before you publish a release, run the live tests in a lab against the last
prerelease from the PowerShell Gallery, as the
[acceptance of a release candidate](../../Tests/Lab/README.md#acceptance-of-a-release-candidate)
describes, with `-Version` instead of `-ModulePath`.
1. Remove the `Prerelease` value from the module manifest.
2. In `CHANGELOG.md`, rename `## [Unreleased]` to the version with the
release date, such as `## [5.0.0] - 2026-10-31`, add an empty

131
Tests/Lab/Acceptance-2026-10-08-5.0.0-rc6.md

@ -0,0 +1,131 @@
# Lab acceptance of 5.0.0-rc6
Acceptance of the release candidate 5.0.0-rc6 in the lab, on 2026-10-08,
before the pull request. It follows the procedure in the
[README](README.md#acceptance-of-a-release-candidate).
## Candidate
- Branch `ai/release-5.0.0-rc6`, commit
`acfe3af4cf184e6b12b0bf9b20a8a4d65149b01c`, 26 commits on `fcb370e`
(5.0.0-rc5).
- Release build of that commit, packaged with
`.github\scripts\New-ModulePackage.ps1`. The live tests imported the
module from the extracted `NTFSSecurity.zip`. CI builds the packages that
the tag publishes again, so their hashes differ; the live tests run once
more against the published package.
| SHA-256 | File |
| --- | --- |
| `30F9694556CB3ADB57D0455AC8E917FA7DC405770DAD3F8C37F42337AECE6374` | `NTFSSecurity.5.0.0-rc6.nupkg` |
| `2A1E5482A67167658A33C7977D7251681F25D4EA437C06B441B5EAAC1016EF55` | `NTFSSecurity.zip` |
| `D308BD24061DEBB633F7A11C924D6347457C530924ACDD4893BEA48BEC58B63E` | `NTFSSecurity\NTFSSecurity.dll` |
| `32C8EA2A55F8721F7953A4E1DE382E1DA6D1CD4BBA844347DD1CA4DA38661D04` | `NTFSSecurity\Security2.dll` |
| `902157ABBD2E0B76DA744A918BDD174D5226C3494908ABA75F9E5DE28AE6A008` | `NTFSSecurity\ProcessPrivileges.dll` |
| `E2077AFEB38703345AE7857C1266F8B26E167ED887BFFAC8C8169A8F267BE6E9` | `NTFSSecurity\PrivilegeControl.dll` |
| `A8DA47194AB0F71232C69D01955AD93BA73C7ECEB58D0DE800CA085D4A2E18D8` | `NTFSSecurity\AlphaFS.dll` |
| `75DA9F7A54DF7011968BACB3FDF5E30B33F4C078861D1DF87BC06F5E64A962D8` | `NTFSSecurity\NTFSSecurity.psd1` |
| `3F777E9D141EE0046119DA9D5ECF88A3BC7E023726098FE2FB150528E2FB59B8` | `NTFSSecurity\NTFSSecurity.psm1` |
| `59583423241951EBE0FC2D8237D0C28C3ECC8C7CD2C115D2660F8579888632FC` | `NTFSSecurity\NTFSSecurity.Init.ps1` |
| `FB0920CC37ED858F55AFD54998DC854E27FBBE6A0177CB059CB03CFE91361197` | `NTFSSecurity\NTFSSecurity.format.ps1xml` |
| `CB6882FF91E6716605D5599E7B464C3346E461216ACED07E847621738F04FB9B` | `NTFSSecurity\NTFSSecurity.types.ps1xml` |
| `DF9657E224E1DDA6D933099A3A09F7E794391B307FD4DDD1C8358049961BF146` | `NTFSSecurity\en-US\NTFSSecurity.dll-Help.xml` |
## Tests without a lab
The Pester suite of the commit, 657 tests, against the same build. No test
failed, and every test ran in at least one configuration.
| Configuration | Passed | Failed | Skipped |
| --- | ---: | ---: | ---: |
| Windows PowerShell 5.1, elevated | 635 | 0 | 22 |
| PowerShell 7, elevated | 605 | 0 | 52 |
| Windows PowerShell 5.1, basic user | 566 | 0 | 91 |
| PowerShell 7, basic user | 536 | 0 | 121 |
## Lab
`WindowsAccessControlLab` (AutomatedLab on Hyper-V). Every machine runs
Windows Server 2025 Datacenter (10.0.26100).
| Machine | Domain | Role in the tests |
| --- | --- | --- |
| `F1ADC1` | `a.forest1.net` | Domain controller of the accounts |
| `F1AFile1` | `a.forest1.net` | Client that runs the tests |
| `F1AFile2` | `a.forest1.net` | File server with the share |
| `F1BDC1` | `b.forest1.net` | Account of another domain of the forest |
| `F2DC1` | `forest2.net` | Account of another forest |
| `F3DC1` | `forest3.net` | Account of another forest |
Readiness, 11:06 to 11:07 UTC: WinRM answered on all six machines. The
four domain controllers answered LDAP (RootDSE, synchronized) and issued a
Kerberos ticket for `krbtgt`. The client and the file server found a
domain controller, had a working secure channel, and got a service ticket
for each other. The clocks were 4.3 to 5.0 seconds ahead of the host.
Checkpoint `ntfs-rc6-acfe3af-before-acceptance` (Production) of the six
machines, taken 11:07 to 11:08 UTC before the run.
## Results
`Invoke-NTFSSecurityLabTest.ps1 -ModulePath <extracted package>` in both
editions, 11:08 to 11:25 UTC. The module reported version 5.0.0-rc6 in
every role that loads it.
| Edition | Role | Passed | Failed | Skipped |
| --- | --- | ---: | ---: | ---: |
| Windows PowerShell 5.1 | Delegate | 38 | 0 | 0 |
| Windows PowerShell 5.1 | ServerAdmin | 13 | 0 | 0 |
| Windows PowerShell 5.1 | Admin | 40 | 0 | 0 |
| Windows PowerShell 5.1 | Server | 72 | 0 | 1 |
| PowerShell 7 | Delegate | 38 | 0 | 0 |
| PowerShell 7 | ServerAdmin | 13 | 0 | 0 |
| PowerShell 7 | Admin | 40 | 0 | 0 |
| PowerShell 7 | Server | 72 | 0 | 1 |
The role Server skips the check of the module version, because it doesn't
load the module. The accounts of the other domain and forests were
`B\NtfsLiveForeign`, `forest2\NtfsLiveForeign`, and
`forest3\NtfsLiveForeign`; their 13 tests passed in both editions.
## Baseline
The published 5.0.0-rc5 from the PowerShell Gallery, whose hash the script
checks against the one the Gallery publishes, in Windows PowerShell 5.1,
11:26 to 11:34 UTC: Delegate 38 passed, ServerAdmin 13, Admin 38 passed and
2 failed, Server 72 passed and 1 skipped. The two failures are the defect
that 5.0.0-rc6 fixes: on the share, `Get-NTFSHardLink` and
`New-NTFSHardLink -PassThru` stopped with the terminating error "(50) The
request is not supported" instead of writing a `GetHardLinkError`. The new
cases find no other difference between the two versions; the local tests
cover the other fixes of 5.0.0-rc6.
## Cleanup
`Invoke-NTFSSecurityLabTest.ps1 -RemoveFixture`, 11:38 UTC, after the
baseline. The check compared the lab with the 10 SIDs of the fixture's
accounts and groups, read before the removal; the same check had found the
fixture before the removal:
- No domain has the organizational unit `NTFSSecurityLive` or an account
whose name starts with `NtfsLive`.
- The file server has no share `NTFSSecurityLive`, no folder
`C:\NTFSSecurityLive` or `C:\NTFSSecurityLab`, and no local group
`NtfsLiveLocal`.
- The client has no folder `C:\NTFSSecurityLab`.
- On both machines, Administrators, Access Control Assistance Operators,
and Remote Management Users have no member of the fixture, and no
profile of the fixture's accounts is left.
The checkpoint `ntfs-rc6-acfe3af-before-acceptance` stays on the six
machines until the maintainer deletes it.
## Not covered
- Other operating systems than Windows Server 2025, such as a Windows 11
client and Server 2019 or 2022 file servers: Phase 3 of the quality
gate.
- File servers that aren't Windows, such as the IBM ESS system of #34:
only the feedback of the reporter covers them.
- The package that CI publishes for the tag: the live tests run against it
after the release, with `-Version 5.0.0-rc6`.

25
Tests/Lab/README.md

@ -118,9 +118,30 @@ Each call writes to a new folder in `$env:TEMP\NTFSSecurityLab\Results`:
folder after the run
A version before 5.0.0-rc3 fails case 1 with error 1307, a version before
5.0.0-rc4 fails the tests of #108, and a version before 5.0.0-rc5 fails the
5.0.0-rc4 fails the tests of #108, a version before 5.0.0-rc5 fails the
test of case 3 with a computer that can't be reached: it returned no access
instead of the result of the client.
instead of the result of the client. A version before 5.0.0-rc6 fails two
tests of case 8: `Get-NTFSHardLink` and `New-NTFSHardLink -PassThru` stopped
on the share with the terminating error (50).
## Acceptance of a release candidate
Before a release, run the live tests once more under controlled conditions
and record the evidence in this folder:
1. Build the candidate once, package it with
`.github\scripts\New-ModulePackage.ps1`, and record the SHA-256 of the
packages and of the module files.
2. Check that WinRM, LDAP, Kerberos, the secure channel, and the clocks of
the lab machines work.
3. Take a checkpoint of the machines, named after the candidate and its
commit.
4. Run the tests with `-ModulePath` of the extracted `NTFSSecurity.zip` in
both editions.
5. Remove the fixture with `-RemoveFixture` and check that its accounts,
share, folders, group memberships, and profiles are gone.
Records: [5.0.0-rc6](Acceptance-2026-10-08-5.0.0-rc6.md).
## Files

Loading…
Cancel
Save