Reproduce and fix public rule paths, simplified audit comparisons and ReadData conversion, and boxed privilege equality. Add behavior guards for descriptor inheritance, unresolved identities, audit capability and recursive denial. Freeze this source for Release matrix measurement; final gate evidence and independent review follow.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Entries and descriptors are equal only when they hold the same .NET
object, as in .NET, so two reads of the same entry differ. The FAQ shows
how to compare the entries of two items with Compare-Object -Property.
Decision 22, item 9: keep the equality of .NET, an assumption in
autopilot, flagged for the maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
GetRelativePath treated every path that started with a dot as .\path and
dropped its first two characters, so a command on .gitignore read,
changed, or removed itignore in the same folder when that item existed;
Remove-Item2 -Path .RemoveMe removed emoveMe, and Copy-Item2 -Force with
the destination .CopyTarget overwrote opyTarget. Only .\ and ./ are now
stripped, and only .. and ..\ go up a folder; any other name is combined
with the current location. All path parameters resolve through this
method: -Path, -Destination, and -Target.
The coverage report of rc6 found the untested branch. The tests use a
decoy item with the shortened name and fail without the fix.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Written through its UNC path, the DACL of a share root can't re-inherit
from the parent folder on the server: Windows drops the inherited entries
of a DACL in the auto-inherit format and stores the others as explicit
copies. icacls and Set-Acl behave the same; a subfolder through the share
and the local path keep them (#67).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The new FAQ page answers the questions that the issues ask again and again
and links the pages with the details. The Get-NTFSEffectiveAccess page said
that a security descriptor produces no result, and the Copy-Item2 page now
says that -PassThru returns the copy; tests pin both -PassThru objects.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>