Browse Source

docs(memory-bank): record the published rc7 and fix the published-versions step

The maintainer tagged fa0701b as 5.0.0-rc7 at about 12:20Z; the CI run of
the tag passed and the Release job published rc7 (Gallery 12:30:57Z,
GitHub 12:31:09Z). The identity check of the published package passed: the
Gallery SHA-512 matches, the nupkg and the zip are identical, and the
manifest says 5.0.0-rc7.

Correct the release notes: rc7 is added to $publishedVersions only in the
change that sets the next version, because the reuse test fails when the
list holds the version of the manifest. Record the published state and the
hashes, and move the next steps to the lab acceptance of the published rc7.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/121/head
Raimund Andree 1 day ago
parent
commit
fef97681fb
  1. 35
      .memory-bank/activeContext.md
  2. 62
      .memory-bank/deployment-notes.md
  3. 20
      .memory-bank/progress.md
  4. 6
      .memory-bank/techContext.md

35
.memory-bank/activeContext.md

@ -9,16 +9,17 @@ source: current task evidence
## Current focus
State at 2026-10-10 11:47 UTC: the maintainer integrated the release-gate stack
State at 2026-10-10 12:40 UTC: the maintainer integrated the release-gate stack
into `master` (`fa0701b`, CI green at 11:40Z): #116 (rc7, `8a6be9f`), #120
(`bdb9981`; it replaced #117, which GitHub closed unmerged when the branch
deletion after #116 removed its base, see Decision 15), #118 (`03bef2c`,
handoff 1, the paths), and #119 (`fa0701b`, handoff 2, the operating-system
matrix). The remote head branches are deleted. rc7 is not tagged or published:
rc6 is the latest published prerelease, 4.2.6 the stable Gallery version. rc7
contains the Phase 2 behavior changes, the path tests and fixes, and the three
module fixes of the matrix (`962887a`, `fdd7a8b`). Stable 5.0.0 stays gated
(Decision 21).
matrix). He tagged `fa0701b` as `5.0.0-rc7` at about 12:20Z, and rc7 is
published (Gallery 12:30:57Z, GitHub 12:31:09Z); 4.2.6 stays the stable
Gallery version. rc7 contains the Phase 2 behavior changes, the path tests and
fixes, and the three module fixes of the matrix (`962887a`, `fdd7a8b`). The
Memory Bank update is pull request #121 (CI green at 12:33Z, open when this was
written). Stable 5.0.0 stays gated (Decision 21).
The maintainer asked on 2026-10-09 at 21:21 UTC to continue with the
release-gate handoffs and to decide and report later. The agent's decisions are
@ -37,6 +38,11 @@ acceptance is the maintainer's.
11:12, #119 11:28, head branches deleted 11:34, CI on `master` at `fa0701b`
green 11:40. A `git merge-tree` simulation of the chain was conflict-free and
ended in the tree of the matrix branch.
- rc7 on 2026-10-10: tag at `fa0701b` about 12:20Z, CI run `38051611526`
green, Gallery 12:30:57Z, GitHub 12:31:09Z. `Test-PublishedRelease.ps1`
(12:33Z): tag commit on `master`, Gallery SHA-512 matches the nupkg, 11
module files identical in nupkg and zip, manifest `5.0.0-rc7`; hashes in the
deployment notes, evidence in the session folder `published-rc7`.
- Handoff 1 (paths), measured at `5a5d58b` (frozen Release, four configurations,
CI wrappers, then AltCover): 1,310 cases per configuration, zero failures
(baseline `3442194`: 914 cases); coverage 3,192/3,634 sequence points
@ -91,17 +97,16 @@ acceptance is the maintainer's.
## Next step
1. The maintainer tags `fa0701b` as `5.0.0-rc7` and pushes the tag; the
`release` job then publishes to the Gallery and GitHub after the approval of
the `powershell-gallery` environment (deployment notes). Every release step
is his.
2. Gate 3, after rc7 is on the Gallery (the agent runs it on request):
`Test-PublishedRelease.ps1 -Version 5.0.0-rc7`, the live controller with
`-Version` in the first lab, and `Run-MatrixSequence.ps1 -Version 5.0.0-rc7`
for every cell (deployment notes, "Accept a published package"). Open: keep
or replace the matrix VMs (about 60 GB) and the evaluation client (it shuts
1. Gate 3 on the published rc7 (the agent runs it on request): the identity
check is done (12:33Z); the live controller with `-Version 5.0.0-rc7` in
the first lab and `Run-MatrixSequence.ps1 -Version 5.0.0-rc7` for every
cell remain (deployment notes, "Accept a published package"). Open: keep or
replace the matrix VMs (about 60 GB) and the evaluation client (it shuts
down every hour), and a domain cell for Windows 11 26H1, whose client loses
the secure channel to the Server 2025 domain controller.
2. The change that sets the next version (rc8 or 5.0.0) adds `5.0.0-rc7` to
`$publishedVersions`; adding it earlier fails the reuse test (deployment
notes). Every release step is the maintainer's.
3. He decides the open items of the paths report: `FileSecurity` conversions,
`RemoveAll` account filters, lazy path overloads, abandoned
`PrivilegeEnabler`, dot patterns of `Get-ChildItem2 -Filter`, the 17

62
.memory-bank/deployment-notes.md

@ -7,21 +7,36 @@ source: release gates of 5.0.0 (lab acceptance, OS matrix, publication plan), re
# Deployment notes
## Publish the next prerelease (rc7)
## Publish the next prerelease (rc7 is published)
State on 2026-10-10 at 11:47 UTC: the whole stack is merged into `master`,
which stands at `fa0701b` and has the tree of `2b8643f`: #116 (rc7, `8a6be9f`,
09:10Z), #120 (`bdb9981`, 10:50Z), #118 (`03bef2c`, 11:12Z), and #119
(`fa0701b`, 11:28Z). #117 had been closed without a merge at 09:10:16Z, when
the branch deletion after the merge of #116 removed its base branch (Decision
15, operating rule); #120, a new pull request from its head `f11ff41`,
replaced it. The remote head branches were deleted at 11:34Z. The CI run on
`master` at `fa0701b` passed at 11:40Z (Build and test, Wiki, Publish the
wiki; Release skipped, as for any push without a tag). The manifest says
`5.0.0` with `Prerelease = 'rc7'`, and `$publishedVersions` in
`Tests/Repository.Tests.ps1` lists the versions up to rc6, as it must before
rc7 is published. The release notes of a prerelease are the `[Unreleased]`
section of `CHANGELOG.md`.
State on 2026-10-10 at 12:40 UTC: rc7 is published. The whole stack is merged
into `master` (`fa0701b`, the tree of `2b8643f`): #116 (rc7, `8a6be9f`, 09:10Z),
#120 (`bdb9981`, 10:50Z), #118 (`03bef2c`, 11:12Z), and #119 (`fa0701b`,
11:28Z). #117 had been closed without a merge at 09:10:16Z, when the branch
deletion after the merge of #116 removed its base branch (Decision 15,
operating rule); #120, a new pull request from its head `f11ff41`, replaced
it. The CI run on `master` at `fa0701b` passed at 11:40Z. The maintainer pushed
the lightweight tag `5.0.0-rc7` at `fa0701b` at about 12:20Z. The CI run
`38051611526` of the tag passed: Build and test, then Release at 12:31:34Z
without an approval step, because the `powershell-gallery` environment has no
required reviewer. The Gallery has rc7 since 12:30:57Z, GitHub since 12:31:09Z.
`Test-PublishedRelease.ps1 -Version 5.0.0-rc7` verified the published identity
at 12:33Z: the tag commit is `fa0701b` on `master`, the Gallery's SHA-512
matches the downloaded nupkg, the 11 module files are byte-identical in the
nupkg and the GitHub zip, and the manifest says `5.0.0-rc7`. The evidence is
outside git, in `published-rc7` of the session folder
`4b12e2f4-d4c7-4a5d-883a-ddb7421c4848\files`. The published bytes:
- `NTFSSecurity.dll` SHA-256
`D3B7CBE362C37D1016559669CB2EFF5034A6945CA1B03DDB49F1361363D203A7`
- `NTFSSecurity.zip` SHA-256
`9705C8CCFA0FB8FC355E401444044D94BF176729BA84104D2C423C429AC1430B`
- nupkg SHA-256
`40922397B7CB307C64DD99960659539AF5C8AD9D2F55C6BF26E8AB434DEC8DCC`
The release notes of a prerelease are the `[Unreleased]` section of
`CHANGELOG.md`.
rc7 contains everything that is merged: the behavior changes of Phase 2
(#116), the quality-gate paths (#120, #118), and the three module fixes of
@ -30,15 +45,13 @@ don't revert separately, because they conflict in `Security2/Win32/Lib.cs` and
`CHANGELOG.md`), with the kit, the controller changes, and the record of the
operating-system matrix (Decision 24).
1. Tag the commit `fa0701b` on `master` with `5.0.0-rc7` and push the tag
(lightweight tags, as for rc1 to rc6). The `release` job checks the tag
against the manifest and builds nothing new: it publishes the package that
the `build` job tested. Approve the deployment of the `powershell-gallery`
environment if it asks.
2. Accept the published package (next section): `Test-PublishedRelease.ps1`,
the first lab, and every cell of the matrix.
3. After the publication, add `5.0.0-rc7` to `$publishedVersions` with the
next change that goes to `master`.
1. Accept the published package (next section). The identity check is done;
the first lab and every cell of the matrix remain (gate 3).
2. Add `5.0.0-rc7` to `$publishedVersions` in `Tests/Repository.Tests.ps1`
only in the change that sets the next version (rc8 or 5.0.0), as
`Docs/Contributing/05-Releasing.md` says. The test "Should not reuse a
version that the PowerShell Gallery already has" fails when the list holds
the version of the manifest, which still says rc7.
## Accept a published package
@ -48,7 +61,8 @@ Local `-ModulePath` runs are validation; the gate needs the published bytes.
-OutputPath <folder>` (read-only): tag and commit on `master`, the CI run
of the tag, the Gallery's SHA-512 against the downloaded nupkg (ordinal,
case-sensitive base64), the nupkg against the GitHub zip file by file, and
the identity of the manifest. Dry run on rc6: all checks passed.
the identity of the manifest. Run on rc6 (dry run) and on rc7 (2026-10-10,
12:33Z): all checks passed.
2. `Tests/Lab/Invoke-NTFSSecurityLabTest.ps1 -Version <version>` in the
existing lab, both editions, and `Tests/Lab/Acceptance/Run-MatrixSequence.ps1
-Version <version>` for each cell of the matrix (Decision 24; pass the file

20
.memory-bank/progress.md

@ -9,13 +9,13 @@ source: repository and validation evidence
## Current status
5.0.0-rc6 is published on the Gallery and GitHub (its failed Release job
recovered in attempt 2 on 2026-10-09). On 2026-10-10 the maintainer merged the
5.0.0-rc7 is published on the Gallery and GitHub (2026-10-10, tag at
`fa0701b`); rc6 is the one before it. On 2026-10-10 the maintainer merged the
whole stack into `master` (`fa0701b`, CI green): #116 (rc7), #120 (it replaced
#117, which GitHub closed unmerged when the branch deletion after #116 removed
its base), #118 (the quality-gate paths), and #119 (the operating-system
matrix with three module fixes, Decision 24 proposed). rc7 is not tagged or
published. Stable Gallery version: 4.2.6.
matrix with three module fixes, Decision 24 proposed). The published rc7 still
needs its lab acceptance (gate 3). Stable Gallery version: 4.2.6.
After 5.0.0, archive in favor of WindowsAccessControl (Decision 18).
## Recent milestones
@ -87,6 +87,11 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18).
retarget was wrong. Nothing was lost: #120 (`bdb9981`, 10:50Z) replaced #117,
then #118 (`03bef2c`, 11:12Z) and #119 (`fa0701b`, 11:28Z) merged after their
retargeting; CI on `master` passed at 11:40Z. Decision 15 has the rule.
- 2026-10-10: rc7 published. The maintainer tagged `fa0701b` at about 12:20Z;
the CI run of the tag passed and the Release job published without an
approval step (Gallery 12:30:57Z, GitHub 12:31:09Z). The identity check
(`Test-PublishedRelease.ps1`, 12:33Z) passed: Gallery SHA-512, nupkg and zip
identical, manifest `5.0.0-rc7`. Hashes: deployment notes.
## Stable capabilities
@ -99,11 +104,12 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18).
## Open work
1. Decision 21 gate: tag and publish rc7, then test the published package
(first lab, every matrix cell) and review Decision 22. Do not release 5.0.0
1. Decision 21 gate: test the published rc7 (identity verified; the first lab
and every matrix cell remain) and review Decision 22. Do not release 5.0.0
until the remaining-path and OS-matrix gates close. Release steps:
`Docs/Contributing/05-Releasing.md`; remove the prerelease label, date
`[5.0.0]`, update `$publishedVersions`, tag through CI.
`[5.0.0]`, add the last prerelease to `$publishedVersions` (never the
version of the manifest), tag through CI.
2. Issues: #110's seven items were addressed by rc6, but #115 deliberately
used no closing keyword. #34 stays open for non-Windows owner feedback
or maintainer acceptance. #16, #21, #45, #89 await reporters. #68 tracks

6
.memory-bank/techContext.md

@ -42,9 +42,9 @@ source: repository and executable evidence
## Constraints
- Manifest: ModuleVersion 5.0.0, prerelease rc7 (on `master` since
2026-10-10, untagged). Latest stable 4.2.6; latest published prerelease
rc6 (2026-10-08). rc7 publication is pending.
- Manifest: ModuleVersion 5.0.0, prerelease rc7, published 2026-10-10 (tag at
`fa0701b`). Latest stable 4.2.6. The reuse test fails if `$publishedVersions`
holds the manifest's version: add rc7 in the change that sets the next one.
- Changed-section writes preserve unchanged owner/group/DACL/SACL (19).
Roots use root-folder APIs, not AlphaFS device security (#41).
- CHANGELOG contains user-visible changes only (7); tests and CI-only fixes

Loading…
Cancel
Save