diff --git a/.memory-bank/activeContext.md b/.memory-bank/activeContext.md index 6d9356e..b308665 100644 --- a/.memory-bank/activeContext.md +++ b/.memory-bank/activeContext.md @@ -9,16 +9,17 @@ source: current task evidence ## Current focus -State at 2026-10-10 11:47 UTC: the maintainer integrated the release-gate stack +State at 2026-10-10 12:40 UTC: the maintainer integrated the release-gate stack into `master` (`fa0701b`, CI green at 11:40Z): #116 (rc7, `8a6be9f`), #120 (`bdb9981`; it replaced #117, which GitHub closed unmerged when the branch deletion after #116 removed its base, see Decision 15), #118 (`03bef2c`, handoff 1, the paths), and #119 (`fa0701b`, handoff 2, the operating-system -matrix). The remote head branches are deleted. rc7 is not tagged or published: -rc6 is the latest published prerelease, 4.2.6 the stable Gallery version. rc7 -contains the Phase 2 behavior changes, the path tests and fixes, and the three -module fixes of the matrix (`962887a`, `fdd7a8b`). Stable 5.0.0 stays gated -(Decision 21). +matrix). He tagged `fa0701b` as `5.0.0-rc7` at about 12:20Z, and rc7 is +published (Gallery 12:30:57Z, GitHub 12:31:09Z); 4.2.6 stays the stable +Gallery version. rc7 contains the Phase 2 behavior changes, the path tests and +fixes, and the three module fixes of the matrix (`962887a`, `fdd7a8b`). The +Memory Bank update is pull request #121 (CI green at 12:33Z, open when this was +written). Stable 5.0.0 stays gated (Decision 21). The maintainer asked on 2026-10-09 at 21:21 UTC to continue with the release-gate handoffs and to decide and report later. The agent's decisions are @@ -37,6 +38,11 @@ acceptance is the maintainer's. 11:12, #119 11:28, head branches deleted 11:34, CI on `master` at `fa0701b` green 11:40. A `git merge-tree` simulation of the chain was conflict-free and ended in the tree of the matrix branch. +- rc7 on 2026-10-10: tag at `fa0701b` about 12:20Z, CI run `38051611526` + green, Gallery 12:30:57Z, GitHub 12:31:09Z. `Test-PublishedRelease.ps1` + (12:33Z): tag commit on `master`, Gallery SHA-512 matches the nupkg, 11 + module files identical in nupkg and zip, manifest `5.0.0-rc7`; hashes in the + deployment notes, evidence in the session folder `published-rc7`. - Handoff 1 (paths), measured at `5a5d58b` (frozen Release, four configurations, CI wrappers, then AltCover): 1,310 cases per configuration, zero failures (baseline `3442194`: 914 cases); coverage 3,192/3,634 sequence points @@ -91,17 +97,16 @@ acceptance is the maintainer's. ## Next step -1. The maintainer tags `fa0701b` as `5.0.0-rc7` and pushes the tag; the - `release` job then publishes to the Gallery and GitHub after the approval of - the `powershell-gallery` environment (deployment notes). Every release step - is his. -2. Gate 3, after rc7 is on the Gallery (the agent runs it on request): - `Test-PublishedRelease.ps1 -Version 5.0.0-rc7`, the live controller with - `-Version` in the first lab, and `Run-MatrixSequence.ps1 -Version 5.0.0-rc7` - for every cell (deployment notes, "Accept a published package"). Open: keep - or replace the matrix VMs (about 60 GB) and the evaluation client (it shuts +1. Gate 3 on the published rc7 (the agent runs it on request): the identity + check is done (12:33Z); the live controller with `-Version 5.0.0-rc7` in + the first lab and `Run-MatrixSequence.ps1 -Version 5.0.0-rc7` for every + cell remain (deployment notes, "Accept a published package"). Open: keep or + replace the matrix VMs (about 60 GB) and the evaluation client (it shuts down every hour), and a domain cell for Windows 11 26H1, whose client loses the secure channel to the Server 2025 domain controller. +2. The change that sets the next version (rc8 or 5.0.0) adds `5.0.0-rc7` to + `$publishedVersions`; adding it earlier fails the reuse test (deployment + notes). Every release step is the maintainer's. 3. He decides the open items of the paths report: `FileSecurity` conversions, `RemoveAll` account filters, lazy path overloads, abandoned `PrivilegeEnabler`, dot patterns of `Get-ChildItem2 -Filter`, the 17 diff --git a/.memory-bank/deployment-notes.md b/.memory-bank/deployment-notes.md index 6c2d106..2b20f04 100644 --- a/.memory-bank/deployment-notes.md +++ b/.memory-bank/deployment-notes.md @@ -7,21 +7,36 @@ source: release gates of 5.0.0 (lab acceptance, OS matrix, publication plan), re # Deployment notes -## Publish the next prerelease (rc7) +## Publish the next prerelease (rc7 is published) -State on 2026-10-10 at 11:47 UTC: the whole stack is merged into `master`, -which stands at `fa0701b` and has the tree of `2b8643f`: #116 (rc7, `8a6be9f`, -09:10Z), #120 (`bdb9981`, 10:50Z), #118 (`03bef2c`, 11:12Z), and #119 -(`fa0701b`, 11:28Z). #117 had been closed without a merge at 09:10:16Z, when -the branch deletion after the merge of #116 removed its base branch (Decision -15, operating rule); #120, a new pull request from its head `f11ff41`, -replaced it. The remote head branches were deleted at 11:34Z. The CI run on -`master` at `fa0701b` passed at 11:40Z (Build and test, Wiki, Publish the -wiki; Release skipped, as for any push without a tag). The manifest says -`5.0.0` with `Prerelease = 'rc7'`, and `$publishedVersions` in -`Tests/Repository.Tests.ps1` lists the versions up to rc6, as it must before -rc7 is published. The release notes of a prerelease are the `[Unreleased]` -section of `CHANGELOG.md`. +State on 2026-10-10 at 12:40 UTC: rc7 is published. The whole stack is merged +into `master` (`fa0701b`, the tree of `2b8643f`): #116 (rc7, `8a6be9f`, 09:10Z), +#120 (`bdb9981`, 10:50Z), #118 (`03bef2c`, 11:12Z), and #119 (`fa0701b`, +11:28Z). #117 had been closed without a merge at 09:10:16Z, when the branch +deletion after the merge of #116 removed its base branch (Decision 15, +operating rule); #120, a new pull request from its head `f11ff41`, replaced +it. The CI run on `master` at `fa0701b` passed at 11:40Z. The maintainer pushed +the lightweight tag `5.0.0-rc7` at `fa0701b` at about 12:20Z. The CI run +`38051611526` of the tag passed: Build and test, then Release at 12:31:34Z +without an approval step, because the `powershell-gallery` environment has no +required reviewer. The Gallery has rc7 since 12:30:57Z, GitHub since 12:31:09Z. + +`Test-PublishedRelease.ps1 -Version 5.0.0-rc7` verified the published identity +at 12:33Z: the tag commit is `fa0701b` on `master`, the Gallery's SHA-512 +matches the downloaded nupkg, the 11 module files are byte-identical in the +nupkg and the GitHub zip, and the manifest says `5.0.0-rc7`. The evidence is +outside git, in `published-rc7` of the session folder +`4b12e2f4-d4c7-4a5d-883a-ddb7421c4848\files`. The published bytes: + +- `NTFSSecurity.dll` SHA-256 + `D3B7CBE362C37D1016559669CB2EFF5034A6945CA1B03DDB49F1361363D203A7` +- `NTFSSecurity.zip` SHA-256 + `9705C8CCFA0FB8FC355E401444044D94BF176729BA84104D2C423C429AC1430B` +- nupkg SHA-256 + `40922397B7CB307C64DD99960659539AF5C8AD9D2F55C6BF26E8AB434DEC8DCC` + +The release notes of a prerelease are the `[Unreleased]` section of +`CHANGELOG.md`. rc7 contains everything that is merged: the behavior changes of Phase 2 (#116), the quality-gate paths (#120, #118), and the three module fixes of @@ -30,15 +45,13 @@ don't revert separately, because they conflict in `Security2/Win32/Lib.cs` and `CHANGELOG.md`), with the kit, the controller changes, and the record of the operating-system matrix (Decision 24). -1. Tag the commit `fa0701b` on `master` with `5.0.0-rc7` and push the tag - (lightweight tags, as for rc1 to rc6). The `release` job checks the tag - against the manifest and builds nothing new: it publishes the package that - the `build` job tested. Approve the deployment of the `powershell-gallery` - environment if it asks. -2. Accept the published package (next section): `Test-PublishedRelease.ps1`, - the first lab, and every cell of the matrix. -3. After the publication, add `5.0.0-rc7` to `$publishedVersions` with the - next change that goes to `master`. +1. Accept the published package (next section). The identity check is done; + the first lab and every cell of the matrix remain (gate 3). +2. Add `5.0.0-rc7` to `$publishedVersions` in `Tests/Repository.Tests.ps1` + only in the change that sets the next version (rc8 or 5.0.0), as + `Docs/Contributing/05-Releasing.md` says. The test "Should not reuse a + version that the PowerShell Gallery already has" fails when the list holds + the version of the manifest, which still says rc7. ## Accept a published package @@ -48,7 +61,8 @@ Local `-ModulePath` runs are validation; the gate needs the published bytes. -OutputPath ` (read-only): tag and commit on `master`, the CI run of the tag, the Gallery's SHA-512 against the downloaded nupkg (ordinal, case-sensitive base64), the nupkg against the GitHub zip file by file, and - the identity of the manifest. Dry run on rc6: all checks passed. + the identity of the manifest. Run on rc6 (dry run) and on rc7 (2026-10-10, + 12:33Z): all checks passed. 2. `Tests/Lab/Invoke-NTFSSecurityLabTest.ps1 -Version ` in the existing lab, both editions, and `Tests/Lab/Acceptance/Run-MatrixSequence.ps1 -Version ` for each cell of the matrix (Decision 24; pass the file diff --git a/.memory-bank/progress.md b/.memory-bank/progress.md index 0f2f529..5747a56 100644 --- a/.memory-bank/progress.md +++ b/.memory-bank/progress.md @@ -9,13 +9,13 @@ source: repository and validation evidence ## Current status -5.0.0-rc6 is published on the Gallery and GitHub (its failed Release job -recovered in attempt 2 on 2026-10-09). On 2026-10-10 the maintainer merged the +5.0.0-rc7 is published on the Gallery and GitHub (2026-10-10, tag at +`fa0701b`); rc6 is the one before it. On 2026-10-10 the maintainer merged the whole stack into `master` (`fa0701b`, CI green): #116 (rc7), #120 (it replaced #117, which GitHub closed unmerged when the branch deletion after #116 removed its base), #118 (the quality-gate paths), and #119 (the operating-system -matrix with three module fixes, Decision 24 proposed). rc7 is not tagged or -published. Stable Gallery version: 4.2.6. +matrix with three module fixes, Decision 24 proposed). The published rc7 still +needs its lab acceptance (gate 3). Stable Gallery version: 4.2.6. After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). ## Recent milestones @@ -87,6 +87,11 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). retarget was wrong. Nothing was lost: #120 (`bdb9981`, 10:50Z) replaced #117, then #118 (`03bef2c`, 11:12Z) and #119 (`fa0701b`, 11:28Z) merged after their retargeting; CI on `master` passed at 11:40Z. Decision 15 has the rule. +- 2026-10-10: rc7 published. The maintainer tagged `fa0701b` at about 12:20Z; + the CI run of the tag passed and the Release job published without an + approval step (Gallery 12:30:57Z, GitHub 12:31:09Z). The identity check + (`Test-PublishedRelease.ps1`, 12:33Z) passed: Gallery SHA-512, nupkg and zip + identical, manifest `5.0.0-rc7`. Hashes: deployment notes. ## Stable capabilities @@ -99,11 +104,12 @@ After 5.0.0, archive in favor of WindowsAccessControl (Decision 18). ## Open work -1. Decision 21 gate: tag and publish rc7, then test the published package - (first lab, every matrix cell) and review Decision 22. Do not release 5.0.0 +1. Decision 21 gate: test the published rc7 (identity verified; the first lab + and every matrix cell remain) and review Decision 22. Do not release 5.0.0 until the remaining-path and OS-matrix gates close. Release steps: `Docs/Contributing/05-Releasing.md`; remove the prerelease label, date - `[5.0.0]`, update `$publishedVersions`, tag through CI. + `[5.0.0]`, add the last prerelease to `$publishedVersions` (never the + version of the manifest), tag through CI. 2. Issues: #110's seven items were addressed by rc6, but #115 deliberately used no closing keyword. #34 stays open for non-Windows owner feedback or maintainer acceptance. #16, #21, #45, #89 await reporters. #68 tracks diff --git a/.memory-bank/techContext.md b/.memory-bank/techContext.md index 4430756..59ca08d 100644 --- a/.memory-bank/techContext.md +++ b/.memory-bank/techContext.md @@ -42,9 +42,9 @@ source: repository and executable evidence ## Constraints -- Manifest: ModuleVersion 5.0.0, prerelease rc7 (on `master` since - 2026-10-10, untagged). Latest stable 4.2.6; latest published prerelease - rc6 (2026-10-08). rc7 publication is pending. +- Manifest: ModuleVersion 5.0.0, prerelease rc7, published 2026-10-10 (tag at + `fa0701b`). Latest stable 4.2.6. The reuse test fails if `$publishedVersions` + holds the manifest's version: add rc7 in the change that sets the next one. - Changed-section writes preserve unchanged owner/group/DACL/SACL (19). Roots use root-folder APIs, not AlphaFS device security (#41). - CHANGELOG contains user-visible changes only (7); tests and CI-only fixes