diff --git a/.memory-bank/activeContext.md b/.memory-bank/activeContext.md index 4218a31..e5fea34 100644 --- a/.memory-bank/activeContext.md +++ b/.memory-bank/activeContext.md @@ -9,8 +9,9 @@ source: current task evidence ## Current focus -Handoff 1 of the quality gate is finished locally on `ai/quality-gate-paths`, -from the reviewed head `f11ff41` of #117: 28 commits, nothing pushed. Both +Handoff 1 of the quality gate is finished on `ai/quality-gate-paths`, from the +reviewed head `f11ff41` of #117: 28 commits, which the maintainer pushed as +draft #118 (CI green on `83149ee`). Both stacked PRs stay open and green; rc6 remains the latest published candidate and 4.2.6 the stable Gallery version. Every C# method that no test visits is classified (223 explained, 8 open for the maintainer), and the @@ -19,9 +20,12 @@ with a regression guard that is red before the fix and green after it (owner restore, `InheritedFrom`, a later command that ends the pipeline or throws, also at the error, verbose, and debug streams, `-Filter` brackets, null, and `*.*`, public object APIs, a privilege left enabled); the leak of a native -buffer has no observable guard. Gate 3 must repeat the affected lab acceptance -before the next candidate is published. Decisions 21/22 and stable 5.0.0 -remain gated; Decision 22 is proposed, not accepted. +buffer has no observable guard. The lab acceptance of those fixes was repeated +on 2026-10-09 (below); the published package still needs its own acceptance +in gate 3. Decisions 21/22 and stable 5.0.0 +remain gated; Decision 22 is proposed: the agent confirmed all ten choices +on 2026-10-09 under the maintainer's delegation, and his own confirmation is +open. ## Evidence @@ -86,6 +90,16 @@ remain gated; Decision 22 is proposed, not accepted. - Six checkpoints exist but report Standard, even after a successful temporary ProductionOnly probe; policy restored, no restore performed. Do not claim verified Production rollback evidence. +- Lab acceptance of the paths fixes, 20:41 to 21:42 UTC on 2026-10-09: the + candidate `83149ee` and its base `f11ff41` ran the same 244 tests per + edition (78 new, case 10) from their extracted packages. Candidate 486 + passed, 0 failed, 2 expected skips; baseline 338 passed, 148 failed, each + green on the candidate; both editions gave the same counts. Fixture removal + verified by a separate read-only check in four domains and on both file + machines; six checkpoints (Standard type, no restore). Record, results CSV, + and limits: `Tests/Lab/Acceptance-2026-10-09-quality-gate-paths.md`. This + covers the gate-3 handoff table of the path report, except the published + package and the other operating systems. - Wider matrix not deployed: 13 Server 2025 VMs; Windows 11/2019/2022 media present, OS detection cache empty. #34 has no reply since Oct 6. - Full evidence: session artifact `quality-gate-3442194-20261009`; @@ -99,10 +113,9 @@ remain gated; Decision 22 is proposed, not accepted. lazy path overloads, abandoned `PrivilegeEnabler`, dot patterns of `Get-ChildItem2 -Filter`, the 17 owner-restore handlers without the later-command check, unused classes (Decisions 21/22). -2. Gate 3: repeat the affected packaged acceptance (the report's handoff - table: owner restore, `InheritedFrom`, later-command exceptions, filter, - privileges, public objects) before the next candidate is published. No - local upload. +2. Gate 3: the affected live acceptance of the paths fixes is repeated (record + above). Accept the published package again before the next candidate counts + as accepted; no local upload. 3. Retain stacked-PR order (15), obtain Decision 22 review, finish the OS matrix and obtain or explicitly accept #34 feedback through other gates. 4. Do not release stable 5.0.0 or equate a percentage with gate closure. diff --git a/.memory-bank/decisions/0022-phase-2-behavior-changes.md b/.memory-bank/decisions/0022-phase-2-behavior-changes.md index f59d750..f7d528c 100644 --- a/.memory-bank/decisions/0022-phase-2-behavior-changes.md +++ b/.memory-bank/decisions/0022-phase-2-behavior-changes.md @@ -1,9 +1,9 @@ --- status: proposed date: 2026-10-08 -last-verified: 2026-10-08 +last-verified: 2026-10-09 owner: shared -source: agent choices in autopilot on 2026-10-08, for the maintainer's review +source: agent choices in autopilot on 2026-10-08, for the maintainer's review; confirmed by the agent under his delegation on 2026-10-09 --- # Decision 22: The behavior changes of Phase 2 @@ -51,3 +51,43 @@ source: agent choices in autopilot on 2026-10-08, for the maintainer's review (3); the conventions of .NET and PowerShell (4, 9, 10). - Open: the maintainer accepts or reverts each choice; then this record becomes `accepted`. + +## Confirmed under delegation, 2026-10-09 + +- Context: on the evening of 2026-10-09 the maintainer went to bed and told + the agent to continue with the next work and, for any decision that comes + up, to "do it and report about it later". The handoff for this record asks + for one question per item, which nobody could answer overnight. The agent + checked each choice against the source, the tests, the cmdlet pages, and + the changelog, and confirmed all ten. This is the agent's decision under + that delegation, not the maintainer's own, so the status stays `proposed` + until he confirms it or reverts an item. Nothing in the code, the tests, + or the help changed. +- Impact for a caller, and where the choice is documented (the changelog + under [Unreleased], and the page of each cmdlet in `Docs\Cmdlets`): + +| # | Impact for a caller | Documented | +| --- | --- | --- | +| 1 | Without the Security privilege, `Get-NTFSOrphanedAudit` writes a non-terminating `ReadSecurityError` per item and goes on; an empty result no longer hides unread items. A script that took empty output for "nothing orphaned" now sees errors | `Get-NTFSOrphanedAudit` page, notes | +| 2 | A recursive `Get-NTFSSimpleAccess` reports the folders that earlier versions left out, with their subfolders; the output can have more rows | `Get-NTFSSimpleAccess` page, notes | +| 3 | None: `New-NTFSSymbolicLink` still needs the right to create symbolic links; Developer Mode doesn't help | `New-NTFSSymbolicLink` page, notes | +| 4 | With `-WhatIf`, a conflict at the destination is a verbose message, so `-WhatIf -ErrorAction Stop` no longer stops on it | `Move-Item2` page, description; the changelog | +| 5 | The warning of `Get-NTFSEffectiveAccess` names the computer; a script that matches the old text must change | the changelog | +| 6 | `Move-Item2` writes a `MoveError` for a folder on another volume and leaves the folder in place; before, AlphaFS copied and deleted it, which lost empty folders | `Move-Item2` page, notes; the changelog | +| 7 | **Breaking:** the link cmdlets write a non-terminating error per link and go on; a script that relies on the stop needs `-ErrorAction Stop` | both link pages, notes; the changelog, **Breaking** | +| 8 | **Breaking:** `-Path` and `-Target` are required; a script that omitted one must pass it | both link pages, notes; the changelog, **Breaking** | +| 9 | None: entries and descriptors are equal only as the same .NET object, as in .NET; `Compare-Object -Property` compares values | `Docs\FAQ.md` | +| 10 | Only against the earlier 5.0.0 prereleases: `Copy-Item2` no longer creates the missing folders of the destination of a folder copy, like `Copy-Item` and `Move-Item2` | `Copy-Item2` page; the changelog | + +- Why all ten stand: 5.0.0 is a major version, so documented breaking + changes are allowed (7 and 8 have a **Breaking:** entry and a migration + hint); 1, 2, and 6 replace a result that looked valid with an error or a + complete result; 3, 4, 9, and 10 follow the conventions of .NET and + PowerShell and add no feature before the archive; 5 is a clearer message. + Reverting item 8 would bring back the failure for every object piped to + the link cmdlets (found on the way, above). +- To revert an item: revert its commit (the range in Context), regenerate + the help from `Docs`, adjust the changelog and the cmdlet page, and run + the four test configurations again; a later commit on the same page or + test can conflict. +- Open: the maintainer confirms (`accepted`) or reverts each item. diff --git a/.memory-bank/progress.md b/.memory-bank/progress.md index 3621123..fd5745d 100644 --- a/.memory-bank/progress.md +++ b/.memory-bank/progress.md @@ -12,8 +12,8 @@ source: repository and validation evidence 5.0.0-rc6 is published on the Gallery and GitHub; its failed Release job recovered in attempt 2 on 2026-10-09. #116 (rc7, `d25647d`, base `master`) is open and green, not merged or published. Further quality-gate work is -local: `ai/quality-gate-coverage` (#117) and `ai/quality-gate-paths`, which -classifies every remaining unvisited path; the open items are the +`ai/quality-gate-coverage` (#117) and `ai/quality-gate-paths` (draft #118), +which classifies every remaining unvisited path; the open items are the maintainer's decisions. Stable Gallery version: 4.2.6. After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). @@ -74,6 +74,11 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). through the error stream) and a privilege left enabled. Nine static passes of the built-in code-review agent: no Blocker or Major. Report in `Tests/Coverage`. +- 2026-10-09: lab acceptance of those fixes, `83149ee` against its base + `f11ff41` with the same 244 tests per edition (78 new, case 10): candidate + 486 passed, 0 failed, 2 expected skips; baseline 338 passed, 148 failed, all + 148 green on the candidate; fixture removed and verified clean on six + machines. Record: `Tests/Lab/Acceptance-2026-10-09-quality-gate-paths.md`. ## Stable capabilities diff --git a/.memory-bank/techContext.md b/.memory-bank/techContext.md index 8d66d37..15990e4 100644 --- a/.memory-bank/techContext.md +++ b/.memory-bank/techContext.md @@ -175,5 +175,13 @@ source: repository and executable evidence - Remote Authz answers administrators and Access Control Assistance Operators (S-1-5-32-579); other accounts get access denied. Check firewall when remote resource-manager RPC fails. Expected rights use S4U tokens. +- A live test is evidence of a fix only when it fails on the build without + the fix: run the same tests, controller, and lab against the candidate and + the base of the branch, a new process per edition, and join both result + sets by edition, role, and full test name; the tests that pass on both are + controls (`Tests\Lab\Acceptance-2026-10-09-quality-gate-paths.md`). A + validator must not name a loop variable like a typed parameter: PowerShell + variables ignore case, so `$edition` overwrote `$Edition` and every edition + in the CSV became `System.String[]`. - RemoveFixture after the run; verify OUs/accounts, share, folders, local memberships, and test profiles removed. Credentials must never be printed.