Defect 4, both parts:
- Get-NTFSAudit kept the entries of the previous item and wrote them in a
finally block, so a path whose security descriptor failed to read
returned the previous item's entries again. Each item now starts empty,
and entries are written only after a successful read.
- Without the Security privilege, the cmdlet read the descriptor without
its SACL and returned nothing, like an item without audit entries. It
now reads the SACL alone, so a missing privilege is a ReadSecurityError
("A required privilege is not held by the client"). A descriptor from
Get-NTFSSecurityDescriptor that was read without the SACL gets the same
error; FileSystemSecurity2 now records which sections it read
(internal, visible to NTFSSecurity).
Tests/Audit.Tests.ps1 (new): 3 tests. The repeat test needs the Security
privilege to add an audit entry and runs in CI.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Defect 3. Get-FileHash2 left ProcessRecord at the first folder in -Path,
so the files that followed the folder in the same array were not hashed.
It now skips the folder, like Get-FileHash, and continues.
Tests/FileHash.Tests.ps1 (new): 1 test. It skips in PowerShell 7, where
every Get-FileHash2 call fails until the RIPEMD160 reference goes
(decision D5, later in this run).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Defect 2. Get-ChildItem2 cast every -Path item to DirectoryInfo, so a file
path stopped the cmdlet with an InvalidCastException, a terminating error
that also skipped the remaining paths. Like Get-ChildItem, a file path now
returns the file itself, filtered like the other items; with -Directory it
returns nothing.
Tests/ItemCmdlets.Tests.ps1 (new): 3 tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Defect 1. Set-NTFSInheritance compared the current state with an unset
Nullable<bool> and then read its value, so omitting
-AccessInheritanceEnabled always failed with "Nullable object must have a
value", and omitting -AuditInheritanceEnabled failed wherever the audit
section is readable. In the SecurityDescriptor set the error was
terminating.
An omitted parameter now leaves its section unchanged. The item, retry,
and security descriptor paths share one implementation instead of three
copies.
Tests/Inheritance.Tests.ps1 (new): 4 tests; the audit case needs the
Security privilege and runs in CI.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Tests/TestHelpers.psm1 lets a test that changes files, links, ACLs,
owners, audit entries, or inheritance work in its own sandbox below
$env:TEMP\NTFSSecurity.Tests:
- New-TestSandbox creates the folder; Assert-TestSandboxPath throws
unless every target, relative ones resolved against the location, is
inside it.
- Remove-TestSandbox removes the links first without following them
(Windows PowerShell 5.1 follows directory links when it removes a
folder), resets ACL changes, and deletes the folder.
- Test-IsElevated and Test-PrivilegeHeld decide which tests can run; CI
runners are elevated, the workstation isn't.
Tests/TestHelpers.Tests.ps1 (14 tests) covers the helpers. CI runs every
*.Tests.ps1 file in Tests, so new test files need no workflow change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Resolves the review of this branch (one Major, three Minor findings):
- Major: a Dependabot pull request runs the action versions it proposes
before anyone reviews them, and the wiki job of that run held
contents: write. The wiki job is now read-only and only previews the
changed pages; the new publish-wiki job, the only one besides release
with write access, publishes for master alone, after a merge.
dependabot.yml waits 7 days (cooldown) before it proposes a release.
- Minor: Repository.Tests.ps1 asserts that it found the 3 packages.config
files, checks version 2 and the directory, accepts either quote style,
and checks that the "*" pattern sits under groups (11 tests; the
cooldown test failed before the change).
Memory Bank: Decision 11 and techContext.md describe the two wiki jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- activeContext.md: the eight stacked branches of the overnight run, the
maintainer decisions D1 to D5 and D7, and the baseline test counts.
- progress.md: Dependabot for the pinned actions comes with this branch.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/dependabot.yml: weekly updates for the github-actions ecosystem
only, grouped into one pull request with the commit prefix "ci". The CI
workflow pins each action by commit SHA with a version comment, which
Dependabot updates together.
- NTFSSecurity/packages.config listed AlphaFS 2.2.6, but every HintPath and
the other packages.config files use 2.2.1, the version that ships.
- Tests/Repository.Tests.ps1 (new, 8 tests, no build needed) checks both;
before the change, 5 of them failed.
No CHANGELOG entry: build and CI metadata only (Decision 7).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- GitHub-hosted Windows runners run as administrators with UAC disabled,
so tests that need elevation run in CI; the workstation isn't elevated.
- E1 and E2 now state exactly what the cmdlets do; E4 notes that
MACTripleDES may use a random key (to verify).
- Contents of the remote branches fix/#34 and test/transfer.
- Finished work packages condensed to stay under the line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The PreCompact hook writes checkpoints to .memory-bank/session/. Like
promptHistory.md they are local session state and must not be committed.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- The Gallery command search lists 5.0.0-rc1 since 20:22 UTC.
- Repository settings reviewed: no branch protection or ruleset, a
release environment without protection rules, no Dependabot, and two
stale branches; proposed to the maintainer as item 4e.
- Issue triage starting points for work package 5.
- progress.md and systemPatterns.md trimmed below their line budgets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #98 merged; the tag 5.0.0-rc1 published to the PowerShell Gallery and
created the GitHub prerelease through CI.
- Verification: byte-identical packages, Release builds, Gallery flags
and command tags, and the full test suite against the installed module.
- Next: the maintainer tests the prerelease; then the final release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 12: releases are built and published by CI on a version
tag, prerelease first; Decision 10 gains the prerelease rule.
- techContext and systemPatterns: the release job, the packages, the
command tags, and the new tests.
- progress and activeContext: #97 merged, the release PR, and the steps
for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Pushing a tag such as 5.0.0 or 5.0.0-rc1 on master now publishes the
package that the build job built and tested to the PowerShell Gallery
and creates the GitHub release with NTFSSecurity.zip.
- New-ModulePackage.ps1 copies only the FileList files of the Release
build, so no debug symbols, XML documentation, or copy of
System.Management.Automation.dll ship. It builds the nupkg with
Compress-PSResource and adds the command tags (PSIncludes_Cmdlet,
PSCmdlet_*, PSCommand_*) that PSResourceGet leaves out and that the
Gallery uses to list cmdlets and that Find-Command searches. Every CI
run builds and uploads the packages.
- Get-ReleaseInfo.ps1 returns the version and release notes: a dated
CHANGELOG section for a release, the [Unreleased] section for a
prerelease.
- The release job checks that the tag matches the manifest version and
points to a commit on master, reads the API key from the environment
powershell-gallery, and skips steps already done, so a rerun is safe.
- The manifest gets the prerelease label rc1 and a release notes link;
the 5.0.0 changelog entries move back to [Unreleased] until the final
release.
- Tests/Release.Tests.ps1 covers both scripts and the packages; the
changelog check moves there from Manifest.Tests.ps1.
- Docs/Contributing/05-Releasing.md describes the one-time setup and the
release steps; Docs/README.md explains -AllowPrerelease.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #94, #95, and #96 merged; the first master run passed and published
the wiki; AppVeyor no longer reports.
- Decision 9 records that the version history stays separate from the
changelog, and why.
- techContext: Gallery versions and dates, the package comparison recipe,
and MD024 siblings_only for CHANGELOG.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Compare the six NTFSSecurity packages in the PowerShell Gallery (4.0.0
and 4.2.2 to 4.2.6) and the commit history to complete the version
history:
- Add the Gallery publish dates to 4.0 and 4.2.2 to 4.2.6.
- Add notes for 4.2.2, which had none: Test-Path2, Remove-Item2
-PassThur, the new audit parameters, and the hidden Show-SimpleAccess.
- Replace "Bug fixes" for 4.2.4 with its changes (#12, #31, #33, #35),
and move the MIT license there: the 4.2.4 package already links it.
- Split 4.2.5 (#18, #36, #48, Show-SimpleAccess removed) from 4.2.6,
which only fixed the Applies to column that 4.2.5 broke (#57).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 11: CI and the wiki run on GitHub Actions; the wiki is
generated from Docs. Decision 9 no longer retires the wiki; Decisions
6 and 8 name the CI workflow instead of appveyor.yml.
- techContext, systemPatterns, and projectbrief describe the workflow,
the test reporting, the wiki pattern, and how to read CI runs.
- progress and activeContext: PRs #94 and #95 open, the GitHub Actions
package PR-ready, and the steps after the merge.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
.github/workflows/ci.yml replaces appveyor.yml and runs on pull requests
and pushes to master:
- build (windows-2025): the same restore, Release build, and documentation
checks as before, then the Pester tests in Windows PowerShell 5.1 and in
PowerShell 7. .github/scripts/Invoke-Tests.ps1 writes the counts and
the failed tests to the job summary and the NUnit file to the
test-results artifact, and also fails on test files that fail.
- wiki (ubuntu-latest): generates the wiki from Docs; on pull requests it
lists the pages that would change, from master it publishes them with
the built-in token. Only this job has contents: write.
Actions are pinned by commit SHA. Every native command checks its exit
code, because GitHub checks only the last one. The contributor guide
describes the workflow and the wiki.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/scripts/Export-WikiContent.ps1 converts Docs, except the
contributor guide, into flat wiki pages: Docs/README.md becomes Home,
cmdlet pages lose their platyPS metadata, links point to wiki pages or
to the files on GitHub, and links in code stay unchanged. It writes a
sidebar from the cmdlet groups of Docs/README.md, a footer, and the
former page How-to-install, and keeps the page name Version-History
that the release notes link to.
- Tests/Wiki.Tests.ps1 checks the conversion rules with a sample of Docs
and every link and anchor of the wiki generated from the real Docs.
- README, CHANGELOG, and the version history mention the wiki again.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 10: one version for the manifest, the first-party
assemblies, and the changelog.
- Work packages 3 and 4 PR-ready; release checklist for 5.0.0.
- RootModule in the architecture; the new test files and what they
guard.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Require Windows PowerShell 5.1 or PowerShell 7 (PowerShellVersion
5.1, which CompatiblePSEditions needs) and .NET Framework 4.5.2, and
use RootModule instead of the deprecated ModuleToProcess. Before,
Test-ModuleManifest, and with it Publish-Module, failed.
- Export exactly the 36 cmdlets: remove Show-NTFSSimpleAccess, which no
longer exists, and the duplicate inheritance cmdlets.
- Keep -PassThur, the name in 4.2.6 and earlier, as an alias of
Remove-Item2 -PassThru, deprecated in the changelog.
- Set version 5.0.0 in the manifest, in NTFSSecurity, Security2, and
PrivilegeControl, and in a new 5.0.0 section of CHANGELOG.md.
- Tests/Manifest.Tests.ps1 and Tests/Remove-Item2.Tests.ps1 guard the
manifest, the versions, and the alias.
BREAKING CHANGE: the module requires Windows PowerShell 5.1 or
PowerShell 7; the manifest no longer claims PowerShell 2.0.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 9: keep the documentation on GitHub; no Read the Docs site,
and the wiki is retired. Decision 4 now rests on it.
- Work package 3 redefined and PR-ready; work package 4 decisions:
PowerShellVersion 5.1, DotNetFrameworkVersion 4.5.2, RootModule, and
5.0.0 with the PassThur alias.
- Correct the Windows PowerShell 5.1 recipe (don't clear PSModulePath),
and record the local build from the NuGet cache, the link-check
limits, and the deleted fork behind the Read the Docs project.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Remove the Read the Docs and MkDocs configuration (.readthedocs.yml,
mkdocs.yml, Docs/requirements.txt). The Read the Docs project belongs
to a third party and points to a fork that no longer exists.
- Rename Docs/index.md to Docs/README.md, so that GitHub shows the
overview when you open the Docs folder, and link the changelog and the
license relatively.
- Move the version history and the installation steps from the wiki into
Docs/Version-History.md and Docs/README.md. Add the notes for 4.2.5
and 4.2.6, which the wiki never had, from the commit history.
- Describe previews and section anchors on GitHub in the contributor
guide, and drop the changelog entry about the documentation site.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Work packages 1 and 2 are merged and master is green on AppVeyor
(218 of 218 Pester tests). Mark them done, condense the older
milestones, and spell out work packages 3 and 4 so a new chat can
continue from the Memory Bank alone, including cleaning the installed
module folder before the next release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The remote-mutation hook blocked creating the pull requests even after
the maintainer's explicit request: its override is read from the
environment that VS Code starts the hook with, so the agent can't set
it for a single command. The hook also matches text inside commit
messages.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* fix(help): ship the generated help file so Get-Help works
Get-Help showed only the syntax of the cmdlets: the module shipped a
pre-4.x MAML file for the old command names under the wrong name
(NTFSSecurity-Help.xml), while PowerShell looks for
en-US\NTFSSecurity.dll-Help.xml.
- Generate en-US\NTFSSecurity.dll-Help.xml from Docs/Cmdlets with
New-ExternalHelp and commit it. The csproj copies it to the output,
so every build ships it, including the local Debug builds that
releases are published from.
- List all runtime files, including the help file, in FileList.
- Remove the stale NTFSSecurity-Help.xml and the unused help editor
project NTFSSecurity\Help\NTFSSecurity.Help.pshproj.
- Add Tests\Help.Tests.ps1 (Pester 5): Get-Help shows the synopsis,
parameters, examples, and online link of every page, and
Get-Help -Online resolves to the GitHub page.
- Reword six sentences in five cmdlet pages so that each link ends its
sentence: platyPS drops the space after a link in the help text.
- CI regenerates the help file and fails when it differs from the
committed file, then runs the Pester tests.
- Document the regeneration step and the link rule in the contributor
guide.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: report each Pester test once on AppVeyor
AppVeyor build 54834154 passed all 218 Pester tests but listed 870 on
its Tests tab: the NUnit import files a Pester 5 test under every block
that contains it (Pester, test file, Describe, and Context).
Report the results through the build worker API instead
(POST api/tests/batch): one entry per test with its outcome, duration,
and error message. Outside AppVeyor, and when no test ran, the step
sends nothing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
PR #83 replaces two dead TechNet tutorial links in Docs/index.md.
PR #91 already ships the same learn.microsoft.com links in
Docs/index.md and README.md, so #83 has nothing left to merge. The
maintainer decided to close it.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Ignore .memory-bank/promptHistory.md, a local log that is not
version-controlled.
- Record the merge of PR #91 and the agreed order of the follow-up
work packages in progress.md.
- Record the changelog policy as Decision 7: CHANGELOG.md lists
user-visible changes only; CI and build-only changes get no entry.
- Move the inline Decisions to .memory-bank/decisions/ records, so
systemPatterns.md keeps an index below its 110-line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* chore: initialize the memory bank
Add the canonical .memory-bank base with evidence-based project context:
purpose and scope, workflows, stack and validation commands, architecture
map, decisions, and the open work found while documenting the cmdlets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* docs: align documentation with the cmdlet source
- Fill all 36 platyPS cmdlet pages from the C# source: synopsis,
description, parameters, defaults, examples, inputs, outputs, and
notes, including documented limitations of the current code
- Check every example against live parameter metadata and run them in a
sandbox; fix examples that did not work (CSV restore, account filter,
recursive inheritance, -AccessRights typos)
- Rewrite the home, concepts, examples, README, and contributor pages;
add a grouped cmdlet overview, module settings, privileges, long paths,
and the platyPS workflow
- Document Remove-Item2 -PassThru as renamed after 4.2.6 (#64)
- Fix mkdocs.yml navigation, edit_uri, and copyright markup; add
build.os and a pinned MkDocs version for Read the Docs
- Point online help links to the pages on GitHub; add CHANGELOG.md
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: build the module and check the docs against the build
The documentation check ran Update-MarkdownHelp against the NTFSSecurity
release from the PowerShell Gallery (4.2.6), so it failed for every
unreleased parameter change. PR #91 failed because 4.2.6 still has
Remove-Item2 -PassThur while the source and the docs have -PassThru.
- Build NTFSSecurity.csproj in Release on the Visual Studio 2022 image,
using the .NET Framework 4.5.2 reference assemblies package instead of
an installed targeting pack
- Check Docs/Cmdlets against the module built from source
- Pin platyPS 0.14.2 and MarkdownLinkCheck 0.2.0, and enable TLS 1.2 so
the NuGet provider bootstrap works
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* chore: record the green PR 91 build in the memory bank
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>