diff --git a/.memory-bank/activeContext.md b/.memory-bank/activeContext.md index 9385651..891adcc 100644 --- a/.memory-bank/activeContext.md +++ b/.memory-bank/activeContext.md @@ -19,10 +19,11 @@ that the matrix found (`962887a`, `fdd7a8b`), the kit, the controller changes, a record `Tests/Lab/Acceptance-2026-10-10-os-matrix.md` (Decision 24, proposed). The final local candidate `fdd7a8b` passes the module's suite on five operating systems and the host (24 runs, no failure) and the live controller in three -cells (1,374 passed, 0 failed, 12 skipped). Handoff 3: Decision 22 was confirmed +cells of the matrix (1,374 passed, 0 failed, 12 skipped) and in the first lab, +where case 9 runs (245 passed, 0 failed, 1 skipped per edition). Handoff 3: Decision 22 was confirmed under the delegation and stays proposed; nothing is published. Handoff 4: Decision 23 (the #34 dossier); the risk acceptance is the maintainer's. The -agent's decisions of the night are D1 to D37 in +agent's decisions of the night are D1 to D42 in `decisions-night-2026-10-09.md` of the session files. Stable 5.0.0 stays gated. The earlier state of handoff 1, from the reviewed head `f11ff41` of #117: 28 @@ -122,7 +123,9 @@ open. OSFile22, OSFile25, OSWin11E, OSWin11, and the host, four configurations each, zero failures, skipped tests identical to the host's; the baseline `83149ee` (run on OSFile22 and OSFile25) fails 4 elevated and 20 basic-user tests. Live: run - `rc7l`, three cells, 1,374 passed, 0 failed, 12 skipped. The Admin-role + `rc7l`, three cells, 1,374 passed, 0 failed, 12 skipped. First lab (run `fl1`, + case 9 included, both editions): 245 passed, 0 failed, 1 skipped per edition, + fixture removed and verified clean. The Admin-role effective-access failures of the earlier cells were not the module: in a replay (`ab0` to `ab6`) the baseline failed two of three cells and the final candidate one of three (not counting the warm-up `ab0`), and one model (the remote @@ -133,7 +136,8 @@ open. passed, two of them where the model predicts a failure for a reused name. Reviewed by the built-in code-review agent (custom `security-reviewer` unavailable): approve with Minor, fixed; a second review found one Major - (record accuracy), addressed by the replay. + (record accuracy), addressed by the replay; a follow-up review found no + Blocker or Major and five Minors, corrected. ## Next step diff --git a/.memory-bank/decisions/0024-os-matrix-lab.md b/.memory-bank/decisions/0024-os-matrix-lab.md index 9f1d653..c36e8ab 100644 --- a/.memory-bank/decisions/0024-os-matrix-lab.md +++ b/.memory-bank/decisions/0024-os-matrix-lab.md @@ -41,7 +41,9 @@ source: agent decisions under the maintainer's delegation of 2026-10-09 (Handoff `Complete-OsMatrixLab.ps1`. 3. Case 9 (accounts of other domains and forests) needs trusts to the forests of the existing lab, so the matrix cells run with - `-ForeignDomainController @()`; the existing lab keeps that case. + `-ForeignDomainController @()`; the existing lab keeps that case. The final + candidate ran it there (run `fl1`: 245 passed, 0 failed, 1 skipped per + edition, 16 case-9 tests per edition). 4. The controller of the repository runs in every cell with `-LabName`, `-DomainController`, `-FileServer`, and `-Client`. The matrix showed three defects of its setup and removal, fixed in `7d47316`: a recursive delete diff --git a/.memory-bank/progress.md b/.memory-bank/progress.md index 6ab8c56..27e2210 100644 --- a/.memory-bank/progress.md +++ b/.memory-bank/progress.md @@ -83,14 +83,15 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). 148 green on the candidate; fixture removed and verified clean on six machines. Record: `Tests/Lab/Acceptance-2026-10-09-quality-gate-paths.md`. - 2026-10-09 to 10: handoffs 2 to 4 under the maintainer's delegation (decisions - D1 to D37 in the night log of the session files). The matrix lab + D1 to D42 in the night log of the session files). The matrix lab `NtfsSecurityOsMatrixLab` (Server 2019, 2022, and 2025 file servers, Windows 11 Enterprise 22H2 client, Windows 11 26H1 suite only) found three defects of the module, fixed in `962887a` and `fdd7a8b`: audit inheritance by descriptor, `Get-NTFSEffectiveAccess -ServerName ''`, and the same cmdlet for a user who isn't an administrator on a domain member. The final candidate passes the module's suite on every machine (24 runs, no failure) and the live controller - in three cells (1,374 passed, 0 failed, 12 skipped). The failures of the + in three cells (1,374 passed, 0 failed, 12 skipped) and in the first lab with + case 9 (245 passed, 0 failed, 1 skipped per edition). The failures of the effective-access tests in the Server 2022 cell were not a defect of the module: in a replay of the same cells the baseline failed two of three and the final candidate one of three (not counting the warm-up cell), and one model (the @@ -101,7 +102,8 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). built-in review of the kit and the fixes approved with Minor findings, fixed in `db04ef2`. A second review of the later commits found one Major (the record called the cause settled without a baseline replay), addressed by the replay, - `9344ff7`, and `ab0d8e1`. Record: + `9344ff7`, and `ab0d8e1`; a follow-up review of those fixes found no Blocker or + Major and five Minors, corrected in `e2384e5` and `70f494a`. Record: `Tests/Lab/Acceptance-2026-10-10-os-matrix.md`; nothing was pushed. ## Stable capabilities diff --git a/.memory-bank/techContext.md b/.memory-bank/techContext.md index 8f896ea..29c5837 100644 --- a/.memory-bank/techContext.md +++ b/.memory-bank/techContext.md @@ -229,10 +229,16 @@ source: repository and executable evidence name resolution, and the local manager were right in the same second. A replay with the baseline and the final candidate alternating failed the baseline in two of three cells and the final candidate in one of three (not counting the warm-up - cell). The mechanism in Windows is unknown; a model with one lifetime (9.35 to - 10.20 minutes) fits all 43 Admin-role runs of 27 cells. When the accounts are - created again within seconds, the S4U + cell). The mechanism in Windows is unknown; a model with one lifetime (9.95 to + 10.25 minutes for both tests, to within 0.05 minute) fits all 43 Admin-role runs + of 27 cells. When the accounts are created again within seconds, the S4U logon itself returns the old account for 7 to 15 minutes. A `klist purge`, `nltest /sc_reset`, a DNS flush, and a restart of the Kerberos service didn't help. `Probe-AccountRecreation.ps1`, `Export-CellTimeline.ps1`, and `Test-StaleAuthzModel.ps1` show it. +- `net.exe localgroup` lists a local user by its bare name and the entry of a + deleted domain account as its SID (or as its cached name for a while); + deleting a local user removes its entries from the local groups, so only the + entries of domain accounts stay orphaned. `Test-MatrixCleanup.ps1` finds the + entries of the account probe in Performance Log Users by either form and its + profiles by their folder `C:\Users\NtfsProbe*`.