activeContext, progress, and techContext carry the final measurement (61e936e,
built at 8a625c8), the acceptance of the final build, the open items for the
maintainer, and the rule that the branch summary of the coverage tool is not
read. systemPatterns names the culture-invariant matching of Get-ChildItem2
-Filter and the Get-Acl -Audit oracle. The new debugging-insights.md keeps the
recurring defect classes of the work: culture-sensitive comparisons (including
the ones inside AlphaFS), a test oracle that is wrong on a domain member, and a
piped AppliesTo property that a path drops.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The report gets the section on the acceptance of the fixed build in the first
lab (both editions 245 passed, 0 failed, 1 skipped), the matching row of the
completion matrix, and the bullet of the summary. The Memory Bank carries the
Handoff 5 evidence, the coverage baselines and the live-coverage method.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The unit tests reach all 36 cmdlets and all 147 documented parameters,
and the live tests reach 34 of the cmdlets. The coverage that was
measured at 5a5d58b is 87.84% of the sequence points; the unvisited
code is classified, and 158 of its 442 points are reachable but
defensive or environment-specific. The coverage of the live tests and of
the suite on a domain member is not measured.
Record what is measured, what is not, and the two optional measurements
that would close the gaps.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The published prerelease passed every stage of the lab acceptance on
2026-10-10, with the counts of the final local candidate: the three cells
of the operating-system matrix (1,374 passed, 0 failed, 12 skipped), the
module's own suite in 24 runs on six machine classes without a failure,
and the first lab with case 9 (245 passed, 0 failed, 1 skipped per
edition). Every end state was verified clean. Each controller run used the
package that the identity check had verified byte for byte.
Add the record with four tables, link it from the lab README and describe
the order of the stages, which follows the one-hour life of the evaluation
client. Update Decision 24, the progress, the active context, and the
deployment notes for the state after the acceptance.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer tagged fa0701b as 5.0.0-rc7 at about 12:20Z; the CI run of
the tag passed and the Release job published rc7 (Gallery 12:30:57Z,
GitHub 12:31:09Z). The identity check of the published package passed: the
Gallery SHA-512 matches, the nupkg and the zip are identical, and the
manifest says 5.0.0-rc7.
Correct the release notes: rc7 is added to $publishedVersions only in the
change that sets the next version, because the reuse test fails when the
list holds the version of the manifest. Record the published state and the
hashes, and move the next steps to the lab acceptance of the published rc7.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer merged the whole release-gate stack into master (fa0701b,
CI green): #116, #120 (it replaced #117, which GitHub closed unmerged when
the branch deletion after #116 removed its base), #118, and #119. rc7 is
not tagged yet.
Update the focus, evidence, next steps, progress, and deployment notes for
that state, and record the operating rule of a stack in Decision 15:
retarget before merging, delete head branches last.
The work of the night had pushed techContext (248 of 200 lines) and
systemPatterns (147 of 110) over their budgets, and activeContext and
progress close to theirs. Condense them and point to the records and to
Decision 24 for the detail; the full text is in git at 2b8643f. Port the
one durable pattern of the unmerged handoffs commit cb53fd7. The health
check passes: 0 errors, 2 near-limit warnings.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The branch deletion that followed the merge of #116 removed
ai/release-5.0.0-rc7, the base branch of #117, and GitHub closed#117
unmerged instead of retargeting it (events base_ref_deleted and closed,
three seconds after the merge). Nothing is lost: ai/quality-gate-coverage
is intact at f11ff41, and a simulated merge of the rest of the stack is
conflict-free.
Correct the deployment notes, which relied on a retarget, and record the
order: retarget, merge, and delete head branches last. Update the focus,
the next steps, and the progress for the merged #116 and the draft #119.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The built-in security-review agent (the custom security-reviewer still can't
start: its model isn't offered, and it wasn't overridden) read the branch and
found no exploitable vulnerability in the module changes. It reported two LOW
items that are not changed and are left for the maintainer: the swallowed
initialization exceptions of GetEffectiveAccess (older than the fixes and not
reproducible on any machine of the matrix) and the ACL of the stage folders
under C:\ in the lab kit. The record, the Memory Bank, and the next steps say
so, and the record says how the decision of "this computer" was tested.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The second follow-up review (the first-lab run and the cleanup changes)
found no Blocker and no Major, and four Minors that are corrected. Both
labs are clean and the six VMs of the matrix run.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The final candidate passed the live controller in the first lab, where
case 9 runs (245 passed, 0 failed, 1 skipped per edition). The follow-up
review found no Blocker and no Major, and five Minors that are corrected.
One lifetime that fits both tests is 9.95 to 10.25 minutes. net.exe lists
a local user by its bare name and deleting a local user removes its group
entries, which the cleanup check now accounts for.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The failures of the effective-access tests in the Windows Server 2022
cell are not a defect of the module and not a Kerberos S4U staleness of
the fixture: a replay with the baseline and the final candidate
alternating failed both, and the remote authorization managers answer as
if the account had no groups while the local manager and a Kerberos
logon are right. The Windows mechanism is unknown.
The notes say that fdd7a8b reverts cleanly while 962887a conflicts with
it, that the three fixes are in two commits, and that Decision 24 is in
the index of the patterns.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 24 (proposed): the matrix lab, what its deployment and the runs showed,
and what the maintainer decides. The context, patterns, progress, and deployment
notes carry the lessons: the Authz regime of a domain member, the stale Kerberos
S4U state of a re-created account, the evaluation client, and the integration of
the stacked branches.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 23 separates what the reporters of #34 said from what was tested
(Windows only), names the gaps, and lays out the maintainer's options: wait
for a report on the published candidate, or accept the untested risk with a
release-note caveat. It accepts nothing and keeps the gate open. It also holds
a draft comment for the issue, which the maintainer posts.
The checklist in Tests/Lab tells a storage administrator and a delegated user
how to run the commands of case 1 against a disposable folder on a NetApp, EMC,
or IBM file server, what to report, and what to keep out of the report.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer delegated open decisions to the agent on 2026-10-09 ("do it and
report about it later"). The agent checked the ten choices of Decision 22
against the source, the tests, the cmdlet pages, and the changelog, and
confirmed all of them. The record lists the impact for a caller and the
documentation of each choice, and says how to revert one. Its status stays
proposed until the maintainer confirms it.
The Memory Bank notes the repeated lab acceptance of the paths fixes and the
lesson about proving a fix with a baseline run.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Handoff 1 of the pre-5.0.0 quality gate. The report classifies every
C# method that no test visited at 5a5d58b (231 methods, 442 sequence
points: 223 explained, 8 open for the maintainer) and records the
measurement (3,192/3,634 sequence points, 87.84%), 26 bounded
mutations, a red/green matrix of the fix commits over ten states of
the branch, the open items, the handoff to gate 3, and nine static
review passes. The CSV files hold the method, cmdlet, and parameter
set tables, the guard rows of the matrix with their test files, and
the SHA-256 of each of its 40 logs.
The Memory Bank notes (active context, progress, tech context, system
patterns) and the lab README point to it. No code, test, or help
changes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Reproduce and fix public rule paths, simplified audit comparisons and ReadData conversion, and boxed privilege equality. Add behavior guards for descriptor inheritance, unresolved identities, audit capability and recursive denial. Freeze this source for Release matrix measurement; final gate evidence and independent review follow.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
5.0.0-rc6 is on the PowerShell Gallery, and its GitHub release waits for a
rerun of the failed Release job. The publish step's false failure is open
work for the maintainer's decision; #116 waits for his review of
Decision 22.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 22 lists the ten choices for the behavior changes of Phase 2,
proposed for the maintainer's review, and the outcome of the review.
progress.md and activeContext.md record the branch, the suite, the lab
acceptance, and the next steps; systemPatterns.md adds patterns for
writing cmdlets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Phase 2 is complete on the branch: the fixes, the basic-user CI, the
live tests of all cmdlet groups, three passing lab acceptances, two
reviews, and the coverage across the four configurations, measured again
without --save, which kept only one run. The behavior changes for the
maintainer and the reachable code that no test runs are open work. The
Set-Acl pitfall of the test fixtures is a pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record in activeContext the link cmdlet tests, the two corrections of the
New-NTFSSymbolicLink page with the lab check of Developer Mode, the
security review of fcb370e..00c3646 and its fix round, the next step, and
the open question about unprivileged symbolic links. Add the milestone to
progress, the cleanup rule for privileges to systemPatterns, and the way
to check the lab client as an account without administrator rights to
techContext.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the new tests, the two defects that they found, and the privilege
handling in Dispose since 5.0.0-rc6.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the release of 5.0.0-rc5, Phase 1 of the quality gate that the
maintainer set before 5.0.0 (Decision 21): the published package passes
the live tests, every test runs in at least one configuration, and the
suite runs 55.9% of the C# lines and 37.4% of the branches. Record the
coverage measurement with AltCover, the GitHub CLI on the third
workstation, and the plan of Phase 2, which ends with 5.0.0-rc6.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the results of the live tests against 5.0.0-rc2, 5.0.0-rc4, and
the rc5 build, Decision 20 for the location of the live tests, the third
workstation, the deferred review findings, and the next steps to 5.0.0.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext: the maintainer decided to run live tests of 5.0.0-rc4 in
a lab before 5.0.0, on another workstation with his lab script; the four
cases that no local test covers (#34 and the audit cmdlets over SMB,
effective access with domain accounts and -ServerName, orphaned entries
of a deleted domain account), against rc2 as the baseline and rc4; the
tester feedback on IBM ESS expected in #34.
- progress: 5.0.0 waits for the live tests and the #34 feedback.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- progress and activeContext: 5.0.0-rc4 published from 01d9264; #41,
#108, #109, and #111 closed as completed, #90 and #107 as not planned;
the deferred review findings are listed in #113; 5.0.0 is next.
- techContext: the label rc4 and the Gallery versions; AlphaFS reaches the
device object for a drive or volume root through DirectoryInfo and the
root folder through the path methods; stale lines shortened.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- progress and activeContext: 5.0.0-rc3 published from 914e8da; #34
reopened for a tester, #67 closed as not planned; 5.0.0 is next.
- Decision 19: the cmdlets write only the sections that they change.
Decision 18: the Gallery description announces the archive, and the
module writes no warning on import.
- techContext: the label rc3 and the Gallery versions; commands for the
maintainer as code blocks at the end of the reply; no closing keywords
in pull requests unless the merge should close the issue; test runs as a
basic user; stale lines removed.
- systemPatterns: Decision 19 in the index, and Set-TestOwner.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer decided on 2026-10-06 to publish 5.0.0-rc3 before 5.0.0
and to archive NTFSSecurity in favor of WindowsAccessControl.
- Decision 18: the project will be archived; the notes in the README,
the docs home, and the changelog stay until then.
- activeContext: rc3 is the focus. #34 reproduces locally with rc2, on a
file owned by TrustedInstaller without the Restore privilege, so CI can
test the fix without a file server.
- progress: rc3, then 5.0.0, with the version steps of each.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer approved a label scheme on 2026-10-06, and it was applied
to the 42 issues triaged on 2026-10-05, with the new label Needs Info for
issues that wait for their reporters.
- Decision 17: the meaning of each label and the close reasons.
- activeContext and progress: the labels are applied; five issues wait
for their reporters.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
5.0.0-rc2 is on the PowerShell Gallery and in the GitHub releases. The
PRs #99 to #106 were merged in order with merge commits, CI on master
passed, and the tag 5.0.0-rc2 on 7ddda8d published it on the third
attempt of the release run, after GitHub's Actions outage of 2026-10-05.
The open issues got their replies, 16 were closed, and the follow-up
issues #107 to #111 track the open Minor review findings.
- Decision 14: repository hardening is optional; the outdated "pending"
text is gone.
- Decision 15: merge stacked pull requests in order with merge commits.
- Decision 16: fix only reproducible bugs (the maintainer's decision D6).
- activeContext and progress: the CI fix 629f4e7, the copied inherited
entries behind #34, the issue state, and the next step (test rc2, then
5.0.0 or rc3).
- techContext: the current versions, the second workstation, and
one-line commands for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Keep the details of the pending repository settings out of the Memory
Bank, which is public. Replace the test for the one published version with a
list of the versions that the PowerShell Gallery has, which the release guide
now asks to maintain, and name the description test after its assertion.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Remove the fixed defects from progress.md, rewrite activeContext.md for the
maintainer, and curate systemPatterns.md below its line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext.md: the results of ai/defects-c and the next step.
- progress.md: group C is fixed on ai/defects-c (not merged yet).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext.md: the results of ai/defects-b and the next step.
- progress.md: group B is fixed on ai/defects-b (not merged yet).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext.md: the results of ai/defects-a and the next step.
- progress.md: group A is fixed on ai/defects-a (not merged yet).
- systemPatterns.md: the sandbox test helpers and how platyPS takes a
parameter position from the shipped help file; older bullets condensed
to stay within the line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext.md: the eight stacked branches of the overnight run, the
maintainer decisions D1 to D5 and D7, and the baseline test counts.
- progress.md: Dependabot for the pinned actions comes with this branch.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- The Gallery command search lists 5.0.0-rc1 since 20:22 UTC.
- Repository settings reviewed: no branch protection or ruleset, a
release environment without protection rules, no Dependabot, and two
stale branches; proposed to the maintainer as item 4e.
- Issue triage starting points for work package 5.
- progress.md and systemPatterns.md trimmed below their line budgets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #98 merged; the tag 5.0.0-rc1 published to the PowerShell Gallery and
created the GitHub prerelease through CI.
- Verification: byte-identical packages, Release builds, Gallery flags
and command tags, and the full test suite against the installed module.
- Next: the maintainer tests the prerelease; then the final release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 12: releases are built and published by CI on a version
tag, prerelease first; Decision 10 gains the prerelease rule.
- techContext and systemPatterns: the release job, the packages, the
command tags, and the new tests.
- progress and activeContext: #97 merged, the release PR, and the steps
for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #94, #95, and #96 merged; the first master run passed and published
the wiki; AppVeyor no longer reports.
- Decision 9 records that the version history stays separate from the
changelog, and why.
- techContext: Gallery versions and dates, the package comparison recipe,
and MD024 siblings_only for CHANGELOG.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 11: CI and the wiki run on GitHub Actions; the wiki is
generated from Docs. Decision 9 no longer retires the wiki; Decisions
6 and 8 name the CI workflow instead of appveyor.yml.
- techContext, systemPatterns, and projectbrief describe the workflow,
the test reporting, the wiki pattern, and how to read CI runs.
- progress and activeContext: PRs #94 and #95 open, the GitHub Actions
package PR-ready, and the steps after the merge.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 10: one version for the manifest, the first-party
assemblies, and the changelog.
- Work packages 3 and 4 PR-ready; release checklist for 5.0.0.
- RootModule in the architecture; the new test files and what they
guard.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 9: keep the documentation on GitHub; no Read the Docs site,
and the wiki is retired. Decision 4 now rests on it.
- Work package 3 redefined and PR-ready; work package 4 decisions:
PowerShellVersion 5.1, DotNetFrameworkVersion 4.5.2, RootModule, and
5.0.0 with the PassThur alias.
- Correct the Windows PowerShell 5.1 recipe (don't clear PSModulePath),
and record the local build from the NuGet cache, the link-check
limits, and the deleted fork behind the Read the Docs project.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Work packages 1 and 2 are merged and master is green on AppVeyor
(218 of 218 Pester tests). Mark them done, condense the older
milestones, and spell out work packages 3 and 4 so a new chat can
continue from the Memory Bank alone, including cleaning the installed
module folder before the next release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The remote-mutation hook blocked creating the pull requests even after
the maintainer's explicit request: its override is read from the
environment that VS Code starts the hook with, so the agent can't set
it for a single command. The hook also matches text inside commit
messages.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* fix(help): ship the generated help file so Get-Help works
Get-Help showed only the syntax of the cmdlets: the module shipped a
pre-4.x MAML file for the old command names under the wrong name
(NTFSSecurity-Help.xml), while PowerShell looks for
en-US\NTFSSecurity.dll-Help.xml.
- Generate en-US\NTFSSecurity.dll-Help.xml from Docs/Cmdlets with
New-ExternalHelp and commit it. The csproj copies it to the output,
so every build ships it, including the local Debug builds that
releases are published from.
- List all runtime files, including the help file, in FileList.
- Remove the stale NTFSSecurity-Help.xml and the unused help editor
project NTFSSecurity\Help\NTFSSecurity.Help.pshproj.
- Add Tests\Help.Tests.ps1 (Pester 5): Get-Help shows the synopsis,
parameters, examples, and online link of every page, and
Get-Help -Online resolves to the GitHub page.
- Reword six sentences in five cmdlet pages so that each link ends its
sentence: platyPS drops the space after a link in the help text.
- CI regenerates the help file and fails when it differs from the
committed file, then runs the Pester tests.
- Document the regeneration step and the link rule in the contributor
guide.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: report each Pester test once on AppVeyor
AppVeyor build 54834154 passed all 218 Pester tests but listed 870 on
its Tests tab: the NUnit import files a Pester 5 test under every block
that contains it (Pester, test file, Describe, and Context).
Report the results through the build worker API instead
(POST api/tests/batch): one entry per test with its outcome, duration,
and error message. Outside AppVeyor, and when no test ran, the step
sends nothing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Ignore .memory-bank/promptHistory.md, a local log that is not
version-controlled.
- Record the merge of PR #91 and the agreed order of the follow-up
work packages in progress.md.
- Record the changelog policy as Decision 7: CHANGELOG.md lists
user-visible changes only; CI and build-only changes get no entry.
- Move the inline Decisions to .memory-bank/decisions/ records, so
systemPatterns.md keeps an index below its 110-line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>