The published prerelease passed every stage of the lab acceptance on
2026-10-10, with the counts of the final local candidate: the three cells
of the operating-system matrix (1,374 passed, 0 failed, 12 skipped), the
module's own suite in 24 runs on six machine classes without a failure,
and the first lab with case 9 (245 passed, 0 failed, 1 skipped per
edition). Every end state was verified clean. Each controller run used the
package that the identity check had verified byte for byte.
Add the record with four tables, link it from the lab README and describe
the order of the stages, which follows the one-hour life of the evaluation
client. Update Decision 24, the progress, the active context, and the
deployment notes for the state after the acceptance.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer merged the whole release-gate stack into master (fa0701b,
CI green): #116, #120 (it replaced #117, which GitHub closed unmerged when
the branch deletion after #116 removed its base), #118, and #119. rc7 is
not tagged yet.
Update the focus, evidence, next steps, progress, and deployment notes for
that state, and record the operating rule of a stack in Decision 15:
retarget before merging, delete head branches last.
The work of the night had pushed techContext (248 of 200 lines) and
systemPatterns (147 of 110) over their budgets, and activeContext and
progress close to theirs. Condense them and point to the records and to
Decision 24 for the detail; the full text is in git at 2b8643f. Port the
one durable pattern of the unmerged handoffs commit cb53fd7. The health
check passes: 0 errors, 2 near-limit warnings.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The final candidate passed the live controller in the first lab, where
case 9 runs (245 passed, 0 failed, 1 skipped per edition). The follow-up
review found no Blocker and no Major, and five Minors that are corrected.
One lifetime that fits both tests is 9.95 to 10.25 minutes. net.exe lists
a local user by its bare name and deleting a local user removes its group
entries, which the cleanup check now accounts for.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The failures of the effective-access tests in the Windows Server 2022
cell are not a defect of the module and not a Kerberos S4U staleness of
the fixture: a replay with the baseline and the final candidate
alternating failed both, and the remote authorization managers answer as
if the account had no groups while the local manager and a Kerberos
logon are right. The Windows mechanism is unknown.
The notes say that fdd7a8b reverts cleanly while 962887a conflicts with
it, that the three fixes are in two commits, and that Decision 24 is in
the index of the patterns.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 24 (proposed): the matrix lab, what its deployment and the runs showed,
and what the maintainer decides. The context, patterns, progress, and deployment
notes carry the lessons: the Authz regime of a domain member, the stale Kerberos
S4U state of a re-created account, the evaluation client, and the integration of
the stacked branches.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The independent review of the acceptance record found no Blocker or Major
issue. This commit corrects what it found: the commit that fixed the break
row, what the State test shows, the baseline failures that carry no message,
the count of results, the wording about the folders before the first run, the
truncated messages in the results file, the README row of case 10, and the
review section of the record.
The 42 messageless baseline failures are now explained by a diagnostic that
runs the bodies of those tests in a TEMP sandbox: on the base, the second item
is removed, copied, moved, re-owned, or rewritten after Select-Object -First 1
or a throw; on the candidate it stays. The diagnostic, the check of the result
files, and a read-only check of a published version are in Tests/Lab/Acceptance.
Decision 22 no longer says that Copy-Item2 is like Copy-Item for a folder: the
built-in Copy-Item creates the missing parent folders of a folder copy,
Copy-Item2 of rc6 and of the candidate doesn't. The choice stays, the reference
point is corrected, and the question is left to the maintainer. The migration
hint of item 8 is stated as it is.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 23 separates what the reporters of #34 said from what was tested
(Windows only), names the gaps, and lays out the maintainer's options: wait
for a report on the published candidate, or accept the untested risk with a
release-note caveat. It accepts nothing and keeps the gate open. It also holds
a draft comment for the issue, which the maintainer posts.
The checklist in Tests/Lab tells a storage administrator and a delegated user
how to run the commands of case 1 against a disposable folder on a NetApp, EMC,
or IBM file server, what to report, and what to keep out of the report.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer delegated open decisions to the agent on 2026-10-09 ("do it and
report about it later"). The agent checked the ten choices of Decision 22
against the source, the tests, the cmdlet pages, and the changelog, and
confirmed all of them. The record lists the impact for a caller and the
documentation of each choice, and says how to revert one. Its status stays
proposed until the maintainer confirms it.
The Memory Bank notes the repeated lab acceptance of the paths fixes and the
lesson about proving a fix with a baseline run.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 22 lists the ten choices for the behavior changes of Phase 2,
proposed for the maintainer's review, and the outcome of the review.
progress.md and activeContext.md record the branch, the suite, the lab
acceptance, and the next steps; systemPatterns.md adds patterns for
writing cmdlets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Phase 2 is complete on the branch: the fixes, the basic-user CI, the
live tests of all cmdlet groups, three passing lab acceptances, two
reviews, and the coverage across the four configurations, measured again
without --save, which kept only one run. The behavior changes for the
maintainer and the reachable code that no test runs are open work. The
Set-Acl pitfall of the test fixtures is a pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the release of 5.0.0-rc5, Phase 1 of the quality gate that the
maintainer set before 5.0.0 (Decision 21): the published package passes
the live tests, every test runs in at least one configuration, and the
suite runs 55.9% of the C# lines and 37.4% of the branches. Record the
coverage measurement with AltCover, the GitHub CLI on the third
workstation, and the plan of Phase 2, which ends with 5.0.0-rc6.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the results of the live tests against 5.0.0-rc2, 5.0.0-rc4, and
the rc5 build, Decision 20 for the location of the live tests, the third
workstation, the deferred review findings, and the next steps to 5.0.0.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- progress and activeContext: 5.0.0-rc3 published from 914e8da; #34
reopened for a tester, #67 closed as not planned; 5.0.0 is next.
- Decision 19: the cmdlets write only the sections that they change.
Decision 18: the Gallery description announces the archive, and the
module writes no warning on import.
- techContext: the label rc3 and the Gallery versions; commands for the
maintainer as code blocks at the end of the reply; no closing keywords
in pull requests unless the merge should close the issue; test runs as a
basic user; stale lines removed.
- systemPatterns: Decision 19 in the index, and Set-TestOwner.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer decided on 2026-10-06 to publish 5.0.0-rc3 before 5.0.0
and to archive NTFSSecurity in favor of WindowsAccessControl.
- Decision 18: the project will be archived; the notes in the README,
the docs home, and the changelog stay until then.
- activeContext: rc3 is the focus. #34 reproduces locally with rc2, on a
file owned by TrustedInstaller without the Restore privilege, so CI can
test the fix without a file server.
- progress: rc3, then 5.0.0, with the version steps of each.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer approved a label scheme on 2026-10-06, and it was applied
to the 42 issues triaged on 2026-10-05, with the new label Needs Info for
issues that wait for their reporters.
- Decision 17: the meaning of each label and the close reasons.
- activeContext and progress: the labels are applied; five issues wait
for their reporters.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
5.0.0-rc2 is on the PowerShell Gallery and in the GitHub releases. The
PRs #99 to #106 were merged in order with merge commits, CI on master
passed, and the tag 5.0.0-rc2 on 7ddda8d published it on the third
attempt of the release run, after GitHub's Actions outage of 2026-10-05.
The open issues got their replies, 16 were closed, and the follow-up
issues #107 to #111 track the open Minor review findings.
- Decision 14: repository hardening is optional; the outdated "pending"
text is gone.
- Decision 15: merge stacked pull requests in order with merge commits.
- Decision 16: fix only reproducible bugs (the maintainer's decision D6).
- activeContext and progress: the CI fix 629f4e7, the copied inherited
entries behind #34, the issue state, and the next step (test rc2, then
5.0.0 or rc3).
- techContext: the current versions, the second workstation, and
one-line commands for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
-AccessInheritanceEnabled $false now copies the inherited access entries
into the DACL, and -AuditInheritanceEnabled $true keeps the explicit audit
entries, as Disable-NTFSAccessInheritance and Enable-NTFSAuditInheritance
do without their switches (Decision 13).
BREAKING CHANGE: to remove the entries, use
Disable-NTFSAccessInheritance -RemoveInheritedAccessRules or
Enable-NTFSAuditInheritance -RemoveExplicitAuditRules.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Resolves the review of this branch (one Major, three Minor findings):
- Major: a Dependabot pull request runs the action versions it proposes
before anyone reviews them, and the wiki job of that run held
contents: write. The wiki job is now read-only and only previews the
changed pages; the new publish-wiki job, the only one besides release
with write access, publishes for master alone, after a merge.
dependabot.yml waits 7 days (cooldown) before it proposes a release.
- Minor: Repository.Tests.ps1 asserts that it found the 3 packages.config
files, checks version 2 and the directory, accepts either quote style,
and checks that the "*" pattern sits under groups (11 tests; the
cooldown test failed before the change).
Memory Bank: Decision 11 and techContext.md describe the two wiki jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 12: releases are built and published by CI on a version
tag, prerelease first; Decision 10 gains the prerelease rule.
- techContext and systemPatterns: the release job, the packages, the
command tags, and the new tests.
- progress and activeContext: #97 merged, the release PR, and the steps
for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #94, #95, and #96 merged; the first master run passed and published
the wiki; AppVeyor no longer reports.
- Decision 9 records that the version history stays separate from the
changelog, and why.
- techContext: Gallery versions and dates, the package comparison recipe,
and MD024 siblings_only for CHANGELOG.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 11: CI and the wiki run on GitHub Actions; the wiki is
generated from Docs. Decision 9 no longer retires the wiki; Decisions
6 and 8 name the CI workflow instead of appveyor.yml.
- techContext, systemPatterns, and projectbrief describe the workflow,
the test reporting, the wiki pattern, and how to read CI runs.
- progress and activeContext: PRs #94 and #95 open, the GitHub Actions
package PR-ready, and the steps after the merge.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 10: one version for the manifest, the first-party
assemblies, and the changelog.
- Work packages 3 and 4 PR-ready; release checklist for 5.0.0.
- RootModule in the architecture; the new test files and what they
guard.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 9: keep the documentation on GitHub; no Read the Docs site,
and the wiki is retired. Decision 4 now rests on it.
- Work package 3 redefined and PR-ready; work package 4 decisions:
PowerShellVersion 5.1, DotNetFrameworkVersion 4.5.2, RootModule, and
5.0.0 with the PassThur alias.
- Correct the Windows PowerShell 5.1 recipe (don't clear PSModulePath),
and record the local build from the NuGet cache, the link-check
limits, and the deleted fork behind the Read the Docs project.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* fix(help): ship the generated help file so Get-Help works
Get-Help showed only the syntax of the cmdlets: the module shipped a
pre-4.x MAML file for the old command names under the wrong name
(NTFSSecurity-Help.xml), while PowerShell looks for
en-US\NTFSSecurity.dll-Help.xml.
- Generate en-US\NTFSSecurity.dll-Help.xml from Docs/Cmdlets with
New-ExternalHelp and commit it. The csproj copies it to the output,
so every build ships it, including the local Debug builds that
releases are published from.
- List all runtime files, including the help file, in FileList.
- Remove the stale NTFSSecurity-Help.xml and the unused help editor
project NTFSSecurity\Help\NTFSSecurity.Help.pshproj.
- Add Tests\Help.Tests.ps1 (Pester 5): Get-Help shows the synopsis,
parameters, examples, and online link of every page, and
Get-Help -Online resolves to the GitHub page.
- Reword six sentences in five cmdlet pages so that each link ends its
sentence: platyPS drops the space after a link in the help text.
- CI regenerates the help file and fails when it differs from the
committed file, then runs the Pester tests.
- Document the regeneration step and the link rule in the contributor
guide.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: report each Pester test once on AppVeyor
AppVeyor build 54834154 passed all 218 Pester tests but listed 870 on
its Tests tab: the NUnit import files a Pester 5 test under every block
that contains it (Pester, test file, Describe, and Context).
Report the results through the build worker API instead
(POST api/tests/batch): one entry per test with its outcome, duration,
and error message. Outside AppVeyor, and when no test ran, the step
sends nothing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Ignore .memory-bank/promptHistory.md, a local log that is not
version-controlled.
- Record the merge of PR #91 and the agreed order of the follow-up
work packages in progress.md.
- Record the changelog policy as Decision 7: CHANGELOG.md lists
user-visible changes only; CI and build-only changes get no entry.
- Move the inline Decisions to .memory-bank/decisions/ records, so
systemPatterns.md keeps an index below its 110-line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>