A Gallery upload can succeed while PSResourceGet reports a timeout or a
409 from its retry. Recover that uncertain outcome only after the
published SHA512 matches the exact build artifact. Verify the same hash
before skipping an existing version, and preserve the original upload
error when the version is absent, different, or unverifiable.
Keep API keys in the existing environment secret. Unexpected discovery
errors fail instead of silently proceeding. Offline tests reproduce
legacy false failures and blind skips; all 14 tests pass in each edition
and privilege configuration. No real package was published by tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Join-Path appended an absolute ResultPath to the repository path,
producing an invalid path and preventing the restricted-token test run.
Use Path.Combine to keep rooted paths intact while retaining repository-
relative paths. Clarify the script parameter help.
The offline process-boundary tests fail with the original expression in
both editions and pass in all four configurations with the fix. They do
not launch a process or modify privileges.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Exercise all 13 scopes using named scopes and explicit Windows flags,
through disk paths and in-memory descriptors, for access and audit
entries. Verify removal keeps another account, and check actual
inheritance through children and grandchildren, including OneLevel.
Cover keep/remove switches and successful PassThru for both files and
folders, including Set-NTFSInheritance enabling protection states.
Controlled mutations lose OneLevel and keep folders protected: 12 tests
fail as expected. Restored implementations pass the 170-test focused
suite in all four configurations where privileges permit. No cmdlet
contract changes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Cover recursive, read-only, locked, long-path, and junction deletion in
sandbox folders. Exercise denied ownership retries and both successful
and failed restoration after an operation fails, without inconclusive
results or a success-shaped hash.
The tests fail when folder deletion and owner restoration are omitted:
16 expected failures in the controlled mutation run. Restored code passes
all 66 focused tests where applicable in both editions and privilege
configurations. No production behavior changes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
5.0.0-rc6 is on the PowerShell Gallery, and its GitHub release waits for a
rerun of the failed Release job. The publish step's false failure is open
work for the maintainer's decision; #116 waits for his review of
Decision 22.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The tag 5.0.0-rc6 published the package to the PowerShell Gallery; the
Release job failed after the upload, because Publish-PSResource gave up
waiting while the Gallery accepted the package and its retry got 409. The
live tests downloaded the package, checked the hash of the Gallery, and
passed in both editions, except the one test whose expected warning text
5.0.0-rc7 changed. The rc6 record gets a section on the release; the run
is the baseline of the rc7 record.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 22 lists the ten choices for the behavior changes of Phase 2,
proposed for the maintainer's review, and the outcome of the review.
progress.md and activeContext.md record the branch, the suite, the lab
acceptance, and the next steps; systemPatterns.md adds patterns for
writing cmdlets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The live tests of dc6e9f5, the last commit of the branch that changes the
module, passed in both editions after the checkpoint of step 3: 326 tests,
none failed, 2 skipped as in rc6. The record names the package hashes,
the suite, the readiness of the lab, the earlier runs, and the removal of
the fixture.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
From the security-reviewer pass over be04cb7..4ee01e5 (Nit 8): the
probe for the administrative share and the conversion of a sandbox path
to \\localhost\C$\... were copied into ItemCmdlets.Tests.ps1 and
Links.Tests.ps1, and only the local path passed Assert-TestSandboxPath.
TestHelpers.psm1 now has Test-AdminShareAvailable and
ConvertTo-TestAdminSharePath, which checks the local path against the
sandbox before it returns the share path, with tests of their own.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Where a computer doesn't offer the remote interface of the authorization
manager, the cmdlet calculates the result with the local one and warns
that the result might be inaccurate. Only localhost in lowercase counted
as this computer, so the cmdlet warned that the computer couldn't be
reached for ., LOCALHOST, or the computer name, although the local result
is the result of that computer. A name of this computer is now localhost
in any case, ., the NetBIOS name, the DNS host name, or the fully
qualified domain name.
From the security-reviewer pass over be04cb7..4ee01e5 (Nit 7),
reproduced in Windows PowerShell 5.1 and PowerShell 7 on a workstation
without the remote interface.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
From the security-reviewer pass over be04cb7..4ee01e5 (Minor 3 and 4):
ea2f6df compares the paths of folders without regard to case, which no
test covered; a parent folder in another case counted as not reported
before, so the folder was left out. The test of a drive root now expects
all of its entries instead of any. The page and the changelog say that
paths that differ only in case name the same folder.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
From the security-reviewer pass over be04cb7..4ee01e5 (Minor 1, 2, and
5, Nit 9):
- A path with a character that Windows doesn't allow, such as |, stopped
the pipeline in Windows PowerShell, where resolving the path throws an
ArgumentException; both cmdlets now write a non-terminating error with
the category InvalidArgument, also in PowerShell 7, where AlphaFS
rejects the path when it creates the link.
- The errors of New-NTFSSymbolicLink for an existing -Path and a missing
-Target, and of New-NTFSHardLink for a folder as -Target, named no path.
- New-NTFSSymbolicLink checked -Target before -Path, so that the two
cmdlets reported different errors for an existing -Path with a missing
-Target; both check -Path first now.
- The pages list objects with Path and Target as input of their own.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Set the prerelease label to rc7 and add 5.0.0-rc6, which the maintainer
publishes from #115 before this branch, to the versions that the
PowerShell Gallery has (Docs/Contributing/05-Releasing.md).
A separate commit, so that it can be dropped if the changes of this
branch go into 5.0.0-rc6 instead.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Entries and descriptors are equal only when they hold the same .NET
object, as in .NET, so two reads of the same entry differ. The FAQ shows
how to compare the entries of two items with Compare-Object -Property.
Decision 22, item 9: keep the equality of .NET, an assumption in
autopilot, flagged for the maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
New-NTFSHardLink and New-NTFSSymbolicLink now require -Path and -Target.
Without -Path, they failed with an index error; without -Target, they
used the current location, so New-NTFSSymbolicLink -Path Link created a
link to the current folder.
For a link that they can't create, they write a non-terminating
CreateHardLinkError or CreateSymbolicLinkError with the category
ResourceExists, ObjectNotFound, InvalidArgument, PermissionDenied, or
WriteError, and continue with the next object from the pipeline; they
stopped with a terminating error.
Fixed on the way: every object piped to the cmdlets failed with
GetDefaultValueFailed, because PowerShell reads a parameter that takes
pipeline input before it binds the input, and the getter of -Path threw
on the empty list. The pages show piping rows of a CSV file.
BREAKING CHANGE: a script that omits -Path or -Target gets a prompt, or
an error in a non-interactive session, and a script that relies on a
terminating error of the link cmdlets needs -ErrorAction Stop.
Decision 22, items 7 and 8: assumptions in autopilot, flagged for the
maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Windows can't move a folder to another volume. Move-Item2 moved folders
with CopyAllowed, so AlphaFS copied and deleted them instead: an empty
folder was deleted without being created at the destination, and a
folder with files failed with an error that named one of its files.
Folders now move without CopyAllowed, and the cmdlet writes a MoveError
with the category InvalidOperation that names the folder and the
destination, and leaves the folder in place. A file still moves to
another volume; with -Force, it keeps the error of Windows, (17).
The tests move to \\localhost\C$, which Windows treats as another volume,
and run only elevated.
Decision 22, item 6: an assumption in autopilot, flagged for the
maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
When the computer of -ServerName can't be reached, the cmdlet calculates
the result with the group memberships known on this computer and warns.
The warning now names that computer, which a command with many items
couldn't tell otherwise. The live test expects the new text as well.
Decision 22, item 5: an assumption in autopilot, flagged for the
maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Get-NTFSSimpleAccess compares each folder with its parent folder. A
folder whose parent folder it hadn't reported was left out, and with it
all of its subfolders; a drive root, which has no parent folder, was left
out or compared with the parent folder of the folder before it; and a
folder that came after its parent folder a second time failed with a
ReadError, "An item with the same key has already been added". Such
folders are now reported with all of their entries, and the paths are
compared without regard to case.
Decision 22, item 2: an assumption in autopilot, flagged for the
maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Without the Security privilege, Get-NTFSOrphanedAudit read the item
without its SACL and returned nothing, which looked like an item without
orphaned entries, and it wrote a warning for an item that it couldn't
read. It now reads only the SACL, like Get-NTFSAudit, and writes a
ReadSecurityError with the category PermissionDenied or OpenError. The
error for a path that doesn't exist stays ReadError.
Decision 22, item 1: an assumption in autopilot, flagged for the
maintainer's review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Phase 2 is complete on the branch: the fixes, the basic-user CI, the
live tests of all cmdlet groups, three passing lab acceptances, two
reviews, and the coverage across the four configurations, measured again
without --save, which kept only one run. The behavior changes for the
maintainer and the reachable code that no test runs are open work. The
Set-Acl pitfall of the test fixtures is a pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The acceptance ran three times, for acfe3af, 1b9edbb, and 7b0781f, the
last commit that changes the module; each run passed 326 tests in both
editions with no failure. The record now describes the run of 7b0781f,
with its hashes, readiness, checkpoint, and the checked removal of the
fixture after each run, and names the earlier runs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- The conversions of a FileSystemSecurity2 to FileSecurity and
DirectorySecurity returned fields that were never set, so they gave
null; they return the descriptor, and the dead fields are gone
(finding 1).
- Equals of the entries and descriptors accepted the .NET type as well,
which doesn't know the wrapper, so equality depended on the direction;
only an object of the module can now be equal (finding 2).
- Invoke-TestsAsBasicUser.ps1 refuses a title with a line break, also a
final one, which $ let through (finding 6).
- The InheritedFrom test of the access entries checks a known parent
folder with two explicit entries in front; it fails on acfe3af
(finding 7).
Checked and kept: a callback ACE before the inherited entries doesn't
shift InheritedFrom, because .NET returns it as a rule (finding 3).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Equals of FileSystemAccessRule2, FileSystemAuditRule2, and
FileSystemSecurity2 cast its argument to the .NET type, which throws for
the wrapper types themselves: -eq and -contains, and in PowerShell 7 also
Select-Object -Unique and Compare-Object, stopped with an
InvalidCastException. GetHashCode of FileSystemSecurity2 read a field
that is never set and threw a NullReferenceException. Two objects are now
equal when they hold the same entry or descriptor, like the .NET types.
InheritedFrom: Win32.GetInheritedFrom returned the sources of the SACL
whenever the descriptor had one, also for the access entries, and the
callers gave the filtered entries of -ExcludeExplicit the sources of the
first entries of the ACL. Get-NTFSAccess -SecurityDescriptor stopped with
an ArgumentOutOfRangeException for a descriptor with audit entries, as
Get-NTFSSecurityDescriptor reads them in an elevated session. The method
now takes the ACL of the entries, and the callers map the sources before
they filter.
The coverage report of rc6 pointed at both; each test fails without its
fix.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
GetRelativePath treated every path that started with a dot as .\path and
dropped its first two characters, so a command on .gitignore read,
changed, or removed itignore in the same folder when that item existed;
Remove-Item2 -Path .RemoveMe removed emoveMe, and Copy-Item2 -Force with
the destination .CopyTarget overwrote opyTarget. Only .\ and ./ are now
stripped, and only .. and ..\ go up a folder; any other name is combined
with the current location. All path parameters resolve through this
method: -Path, -Destination, and -Target.
The coverage report of rc6 found the untested branch. The tests use a
decoy item with the shortened name and fail without the fix.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The coverage report of rc6 showed parameters that no test used: -PassThru
after a successful change in both parameter sets, -InheritanceFlags and
-PropagationFlags on a folder and on a file, where the page says they are
ignored, and Clear-NTFSAccess -DisableInheritance on a security
descriptor. The tests pin the documented behavior; all pass in the four
configurations.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The candidate acfe3af passed the live tests in both editions with all
roles: 326 tests, none failed. The record lists the hashes of the
packages, the readiness of the lab, the checkpoint, the results, the
baseline, and the checked removal of the fixture. The published 5.0.0-rc5
fails only the two hard-link tests of case 8 on the share, the defect that
rc6 fixes.
The README of the live tests describes the acceptance of a release
candidate, and the release guide runs it before a release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Copy-Item2 and Move-Item2 name a missing destination folder in a verbose
message with -WhatIf, like an existing destination (#108); the operation
itself fails with an error that names the folder (finding 1).
- Invoke-TestsAsBasicUser.ps1 refuses a title with a double quote or a
percent sign, which cmd.exe interprets inside the quoted argument, and
fails when waiting for the test process fails (findings 4 and 5).
- The page of Get-NTFSSimpleAccess says that ReadData is the right to list
a folder (ListDirectory), which the cmdlet reports as Read (finding 10).
Checked and kept: a UNC destination on a share that doesn't exist names
the share, which a new test pins (finding 3); the lab script refuses
machines outside the lab before it changes anything (finding 6).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Set the prerelease label rc6, and add 5.0.0-rc5 to the versions that the
PowerShell Gallery already has.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The authorization manager of a computer answers only its administrators
and the members of its group Access Control Assistance Operators
(S-1-5-32-579); any other account gets "Access is denied" and no result.
A probe in the lab confirmed it on 2026-10-08: the delegated account got
error 5 without the membership and its rights with it.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Add the cases 4b (orphaned audit entry), 5 (owner), 6 (audit inheritance,
Clear-NTFSAudit, Get-NTFSInheritance), 7 (item cmdlets on the share),
8 (link cmdlets on the share), and 9 (Get-NTFSSimpleAccess), and the
accounts of three other domains and forests (-ForeignDomainController).
The fixture writes the folders with SetAccessControl instead of Set-Acl,
which also wrote an empty SACL and dropped the inherited audit entries.
The delegated account expects the denial of Get-NTFSEffectiveAccess
-ServerName, which the file server answers only for its administrators
and the members of Access Control Assistance Operators.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Invoke-TestsAsBasicUser.ps1 derives a token of the SAFER level Normal User
from the token of the runner, as runas /trustlevel:0x20000 does, and runs
Invoke-Tests.ps1 with it in the same edition. The tests that skip in the
elevated session of the runner, because they need a session without the
privileges of an administrator, now run in CI as well. The contributor
page explains how to run the script locally.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Set-Acl compares AreAuditRulesProtected of the new descriptor with
AreAccessRulesProtected of the item (FileSystemSecurity.cs in PowerShell),
so it also writes the audit section of an item whose DACL is protected.
Without the Security privilege that fails with PrivilegeNotHeldException:
after Disable-NTFSAccessInheritance, Add-TestDenyRule added nothing, and
the take-ownership test of PathErrors.Tests.ps1 failed as a basic user.
With the privilege, Set-Acl wrote all sections and dropped the audit
entries of the item.
Add-TestDenyRule now writes only the DACL with SetAccessControl. Two
regression tests cover both effects; each failed before the change in its
configuration.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Since a324484, Get-NTFSHardLink writes a non-terminating GetHardLinkError
for a folder. The current-location test still used -ErrorAction
SilentlyContinue and so no longer saw the error; -ErrorAction Stop turns it
into the exception that the test expects. The first full-suite run as a
basic user found it.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Remove-NTFSAccess and Remove-NTFSAudit with -RemoveSpecific are tested
also with -Path, not only with -SecurityDescriptor.
- Copy-Item2 and Move-Item2 name the destination of a folder in their
verbose message, not only of a file.
- The Enable-Privileges count compares with the privileges of the token,
so that it passes as a basic user, whose token holds one; the tests of
-PassThru restore the privilege states that they found.
- The type name comparison of Get-FileHash2 is exact, the inherited-entry
counts must be greater than zero, and the braces test (#3) checks the
verbose message that raised the FormatException.
- Remove-TestSandbox removes paths longer than 260 characters in Windows
PowerShell, through the \\?\ prefix and rd, so the long-path test of
Test-Path2 no longer cleans up itself; after a failed setup, it returns
instead of stopping AfterAll with a binding error.
Not reachable by a test: a second path whose SACL read fails while the
Security privilege is enabled; a declined -Confirm takes the code path of
-WhatIf. The tests that need a session without privileges get the CI run
as a basic user.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Clear-NTFSAccess, Disable-NTFSAccessInheritance,
Enable-NTFSAccessInheritance, Clear-NTFSAudit, and
Enable-NTFSAuditInheritance change a descriptor of
Get-NTFSSecurityDescriptor in memory only, and the item changes when
Set-NTFSSecurityDescriptor writes it. Get-NTFSAccess, Get-NTFSOwner, and
Get-NTFSAudit return for a descriptor what they return for its path.
All pass elevated and as a basic user in both editions; the audit tests
skip without the Security privilege.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Add tests for the error handling that the cmdlets with -Path share: a
path that doesn't exist (16 cmdlets, and 6 audit cmdlets with the
Security privilege), an item whose owner may not read its permissions
(6 cmdlets), and an item whose owner may not change them, which the 6
cmdlets that write the DACL handle by taking ownership. Each error
belongs to its path only, and the cmdlet goes on with the next one.
The tests found one defect: Get-NTFSOrphanedAccess reported an item that
it couldn't read as an AddAceError with the category WriteError. It now
writes a ReadSecurityError, like Get-NTFSAccess.
They also show that the take-ownership retry works without privileges
when the account holds the Take Ownership right and may assign the
previous owner, and that it can't help a denied read, because reading
the owner needs the same right. Concepts and five cmdlet pages said that
the retry needs the privileges; they now describe both, and that Windows
removes the OWNER RIGHTS entries when the owner changes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
PowerShell 7 has no static File.GetAccessControl, because .NET Core made
it an extension method, so the assertion of the -PassThru test passed
there for the wrong reason: the method was missing. The test now reads
with FileInfo.GetAccessControl or FileSystemAclExtensions and expects an
UnauthorizedAccessException in both editions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The cmdlet read the item again for -PassThru inside the try block that
retries a denied write as the owner (R5 of the review of #113). A read
that was denied after a successful write therefore started another
attempt of the write and ended in a WriteSdError, and a write that
needed the ownership retry wrote no object at all.
The read now follows the write and its retry, and a failed read is a
ReadSecurityError. The page also says what happens when setting the
previous owner back fails.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Windows can't list the names of a file on a network share and answers
with (50) The request is not supported. The new live tests found that
Get-NTFSHardLink then stopped with a terminating error, so that it
skipped the remaining paths, and that New-NTFSHardLink -PassThru did so
after it had created the link. A folder stopped Get-NTFSHardLink the
same way.
Both cmdlets now write a non-terminating GetHardLinkError and go on.
The tests reach the sandbox over the administrative share of its drive,
which behaves like the share of a file server, and skip where that share
isn't available, such as for a basic user. The pages describe the limit
on shares.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The check for an existing destination looked for a file only. For a
folder whose name existed at the destination, the cmdlets failed in the
middle with a CopyError or a MoveError, and Copy-Item2 could copy a part
of the folder first. They now write DestinationFileAlreadyExists, as
for a file.
When the folder that is to contain the new item didn't exist, AlphaFS
reported a DirectoryNotFoundException that named the source item, which
reproduces the symptom of #21. The cmdlets now write an error that names
the missing folder, with the destination as the target. Copy-Item2 no
longer creates the missing folders for a folder: the workaround that
creates the destination folder for AlphaFS created its parents as well,
which only the prereleases of 5.0.0 did.
The pages also say that -Force merges a folder into an existing folder
of the same name, and that a folder can't move to another volume.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Two deviations from the cmdlet page, found by new tests from its
contract:
- An entry that grants only ReadData became None: the reduction tested
the combined Read mask, and nothing mapped ReadData alone. .NET adds
Synchronize to every allow entry, which hid it; other tools write such
entries.
- With -IncludeRootFolder, on by default, a relative path with a single
folder name had no parent folder in the result, because the parent was
taken from the path before it was resolved.
The tests also cover the rights reduction, the comparison of folders
with their parent, the pipeline, the current location, -ExcludeExplicit,
files, and missing paths, elevated and as a basic user in both editions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Add tests from the contract of its cmdlet page: the security descriptor
parameter set, an inherited entry with and without -ExcludeInherited, an
entry of an account that resolves, the verbose count, the error for a
missing path and for a descriptor without the audit entries, and the
result without the Security privilege, which the page describes as empty.
The setup of the entries moves into BeforeAll, so that the -Account test
no longer depends on the test before it (#110).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record in activeContext the link cmdlet tests, the two corrections of the
New-NTFSSymbolicLink page with the lab check of Developer Mode, the
security review of fcb370e..00c3646 and its fix round, the next step, and
the open question about unprivileged symbolic links. Add the milestone to
progress, the cleanup rule for privileges to systemPatterns, and the way
to check the lab client as an account without administrator rights to
techContext.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Since this branch, Test-Path2 writes $false for a path that Windows
PowerShell rejects, such as one with a |, but it didn't say why. It now
writes the reason as a debug message. Only the lookup of the item is in
the try block, so that an error elsewhere in the cmdlet can't turn into
$false.
Found by the security review of fcb370e..00c3646 (finding 4).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
A cmdlet that enables the Backup, Restore, Take Ownership, and Security
privileges decided which ones to disable on the states that it had read
when it enabled them, and stopped at the first one that failed. When
another command in the pipeline, such as Disable-Privileges, had disabled
one of them, the cmdlet stopped with "Priviledge already disabled" and
left the privileges after that one enabled. After an early stop, which
Dispose handles since this branch, it left them enabled without any
message, because PowerShell ignores exceptions thrown in Dispose; and
Disable-Privileges threw that exception in Dispose on every call while
the privileges were disabled. 4.2.6 already decided on the old states.
DisablePrivilege now reads the current state, and the cleanup tries every
privilege: in EndProcessing, a privilege that it can't disable gives a
warning; in Dispose, it is ignored.
The early-stop tests now pin EnablePrivileges and check that the cmdlet
had enabled the privileges, so that they can't pass without testing
anything.
Found by the security review of fcb370e..00c3646 (findings 1 to 3).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Since 5.0.0, -PassThru returns a folder object for a link to a folder, as
the OUTPUTS section and the changelog say; the description and the
parameter still said a file object.
The notes said that in Windows Developer Mode, accounts without the right
to create symbolic links can create them. Windows allows that only to
programs that request it, and the cmdlet doesn't: in the lab, with
Developer Mode on, mklink created a link as an account without the right,
and New-NTFSSymbolicLink of 5.0.0-rc5 failed with error 1314.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Add 18 tests for New-NTFSHardLink, Get-NTFSHardLink, and
New-NTFSSymbolicLink from the contracts of their cmdlet pages: output with
and without -PassThru, relative paths, the refusal of an existing -Path and
of a folder as the target of a hard link, the non-terminating errors for
missing paths, and the error 1314 without the right to create symbolic
links, compared by its HRESULT because the message is localized.
The tests that need SeCreateSymbolicLinkPrivilege skip without it, and the
test without it skips with it. Elevated and as a basic user, in Windows
PowerShell 5.1 and PowerShell 7, all 20 link tests pass, and each one runs
in at least one of the four configurations.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the new tests, the two defects that they found, and the privilege
handling in Dispose since 5.0.0-rc6.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Set-NTFSOwner ran in no test of its own. Cover the owner change with and
without -PassThru, pipeline input, an owner that only the Restore
privilege allows, a missing path, an owner that Windows refuses (1307),
and the -SecurityDescriptor parameter set.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
In Windows PowerShell, .NET rejects a path with a character that Windows
doesn't allow in names, such as | or <, and Test-Path2 stopped with the
terminating error "Illegal characters in path". Such an item can't
exist, so the cmdlet now writes false, as in PowerShell 7 and like
Test-Path. Add tests for every -PathType, long paths, relative paths,
and the pipeline, and for Get-DiskSpace, which had no tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>