The cached-name form of a log-group entry and the profile of an unloaded
user did; a bare SID and a loaded profile did not. Every unresolved
S-1-5-21-* member of Performance Log Users counts as the probe's.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The final candidate passed the live controller in the first lab, where
case 9 runs (245 passed, 0 failed, 1 skipped per edition). The follow-up
review found no Blocker and no Major, and five Minors that are corrected.
One lifetime that fits both tests is 9.95 to 10.25 minutes. net.exe lists
a local user by its bare name and deleting a local user removes its group
entries, which the cleanup check now accounts for.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The failures of the effective-access tests in the Windows Server 2022
cell are not a defect of the module and not a Kerberos S4U staleness of
the fixture: a replay with the baseline and the final candidate
alternating failed both, and the remote authorization managers answer as
if the account had no groups while the local manager and a Kerberos
logon are right. The Windows mechanism is unknown.
The notes say that fdd7a8b reverts cleanly while 962887a conflicts with
it, that the three fixes are in two commits, and that Decision 24 is in
the index of the patterns.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Decision 24 (proposed): the matrix lab, what its deployment and the runs showed,
and what the maintainer decides. The context, patterns, progress, and deployment
notes carry the lessons: the Authz regime of a domain member, the stale Kerberos
S4U state of a re-created account, the evaluation client, and the integration of
the stacked branches.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The maintainer delegated open decisions to the agent on 2026-10-09 ("do it and
report about it later"). The agent checked the ten choices of Decision 22
against the source, the tests, the cmdlet pages, and the changelog, and
confirmed all of them. The record lists the impact for a caller and the
documentation of each choice, and says how to revert one. Its status stays
proposed until the maintainer confirms it.
The Memory Bank notes the repeated lab acceptance of the paths fixes and the
lesson about proving a fix with a baseline run.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Handoff 1 of the pre-5.0.0 quality gate. The report classifies every
C# method that no test visited at 5a5d58b (231 methods, 442 sequence
points: 223 explained, 8 open for the maintainer) and records the
measurement (3,192/3,634 sequence points, 87.84%), 26 bounded
mutations, a red/green matrix of the fix commits over ten states of
the branch, the open items, the handoff to gate 3, and nine static
review passes. The CSV files hold the method, cmdlet, and parameter
set tables, the guard rows of the matrix with their test files, and
the SHA-256 of each of its 40 logs.
The Memory Bank notes (active context, progress, tech context, system
patterns) and the lab README point to it. No code, test, or help
changes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Phase 2 is complete on the branch: the fixes, the basic-user CI, the
live tests of all cmdlet groups, three passing lab acceptances, two
reviews, and the coverage across the four configurations, measured again
without --save, which kept only one run. The behavior changes for the
maintainer and the reachable code that no test runs are open work. The
Set-Acl pitfall of the test fixtures is a pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record in activeContext the link cmdlet tests, the two corrections of the
New-NTFSSymbolicLink page with the lab check of Developer Mode, the
security review of fcb370e..00c3646 and its fix round, the next step, and
the open question about unprivileged symbolic links. Add the milestone to
progress, the cleanup rule for privileges to systemPatterns, and the way
to check the lab client as an account without administrator rights to
techContext.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the release of 5.0.0-rc5, Phase 1 of the quality gate that the
maintainer set before 5.0.0 (Decision 21): the published package passes
the live tests, every test runs in at least one configuration, and the
suite runs 55.9% of the C# lines and 37.4% of the branches. Record the
coverage measurement with AltCover, the GitHub CLI on the third
workstation, and the plan of Phase 2, which ends with 5.0.0-rc6.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Record the results of the live tests against 5.0.0-rc2, 5.0.0-rc4, and
the rc5 build, Decision 20 for the location of the live tests, the third
workstation, the deferred review findings, and the next steps to 5.0.0.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- progress and activeContext: 5.0.0-rc4 published from 01d9264; #41,
#108, #109, and #111 closed as completed, #90 and #107 as not planned;
the deferred review findings are listed in #113; 5.0.0 is next.
- techContext: the label rc4 and the Gallery versions; AlphaFS reaches the
device object for a drive or volume root through DirectoryInfo and the
root folder through the path methods; stale lines shortened.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- progress and activeContext: 5.0.0-rc3 published from 914e8da; #34
reopened for a tester, #67 closed as not planned; 5.0.0 is next.
- Decision 19: the cmdlets write only the sections that they change.
Decision 18: the Gallery description announces the archive, and the
module writes no warning on import.
- techContext: the label rc3 and the Gallery versions; commands for the
maintainer as code blocks at the end of the reply; no closing keywords
in pull requests unless the merge should close the issue; test runs as a
basic user; stale lines removed.
- systemPatterns: Decision 19 in the index, and Set-TestOwner.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
5.0.0-rc2 is on the PowerShell Gallery and in the GitHub releases. The
PRs #99 to #106 were merged in order with merge commits, CI on master
passed, and the tag 5.0.0-rc2 on 7ddda8d published it on the third
attempt of the release run, after GitHub's Actions outage of 2026-10-05.
The open issues got their replies, 16 were closed, and the follow-up
issues #107 to #111 track the open Minor review findings.
- Decision 14: repository hardening is optional; the outdated "pending"
text is gone.
- Decision 15: merge stacked pull requests in order with merge commits.
- Decision 16: fix only reproducible bugs (the maintainer's decision D6).
- activeContext and progress: the CI fix 629f4e7, the copied inherited
entries behind #34, the issue state, and the next step (test rc2, then
5.0.0 or rc3).
- techContext: the current versions, the second workstation, and
one-line commands for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Remove the fixed defects from progress.md, rewrite activeContext.md for the
maintainer, and curate systemPatterns.md below its line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Resolves the review of this branch (one Major, three Minor findings):
- Major: a Dependabot pull request runs the action versions it proposes
before anyone reviews them, and the wiki job of that run held
contents: write. The wiki job is now read-only and only previews the
changed pages; the new publish-wiki job, the only one besides release
with write access, publishes for master alone, after a merge.
dependabot.yml waits 7 days (cooldown) before it proposes a release.
- Minor: Repository.Tests.ps1 asserts that it found the 3 packages.config
files, checks version 2 and the directory, accepts either quote style,
and checks that the "*" pattern sits under groups (11 tests; the
cooldown test failed before the change).
Memory Bank: Decision 11 and techContext.md describe the two wiki jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #98 merged; the tag 5.0.0-rc1 published to the PowerShell Gallery and
created the GitHub prerelease through CI.
- Verification: byte-identical packages, Release builds, Gallery flags
and command tags, and the full test suite against the installed module.
- Next: the maintainer tests the prerelease; then the final release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 12: releases are built and published by CI on a version
tag, prerelease first; Decision 10 gains the prerelease rule.
- techContext and systemPatterns: the release job, the packages, the
command tags, and the new tests.
- progress and activeContext: #97 merged, the release PR, and the steps
for the maintainer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #94, #95, and #96 merged; the first master run passed and published
the wiki; AppVeyor no longer reports.
- Decision 9 records that the version history stays separate from the
changelog, and why.
- techContext: Gallery versions and dates, the package comparison recipe,
and MD024 siblings_only for CHANGELOG.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 11: CI and the wiki run on GitHub Actions; the wiki is
generated from Docs. Decision 9 no longer retires the wiki; Decisions
6 and 8 name the CI workflow instead of appveyor.yml.
- techContext, systemPatterns, and projectbrief describe the workflow,
the test reporting, the wiki pattern, and how to read CI runs.
- progress and activeContext: PRs #94 and #95 open, the GitHub Actions
package PR-ready, and the steps after the merge.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 10: one version for the manifest, the first-party
assemblies, and the changelog.
- Work packages 3 and 4 PR-ready; release checklist for 5.0.0.
- RootModule in the architecture; the new test files and what they
guard.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Decision 9: keep the documentation on GitHub; no Read the Docs site,
and the wiki is retired. Decision 4 now rests on it.
- Work package 3 redefined and PR-ready; work package 4 decisions:
PowerShellVersion 5.1, DotNetFrameworkVersion 4.5.2, RootModule, and
5.0.0 with the PassThur alias.
- Correct the Windows PowerShell 5.1 recipe (don't clear PSModulePath),
and record the local build from the NuGet cache, the link-check
limits, and the deleted fork behind the Read the Docs project.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Work packages 1 and 2 are merged and master is green on AppVeyor
(218 of 218 Pester tests). Mark them done, condense the older
milestones, and spell out work packages 3 and 4 so a new chat can
continue from the Memory Bank alone, including cleaning the installed
module folder before the next release.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The remote-mutation hook blocked creating the pull requests even after
the maintainer's explicit request: its override is read from the
environment that VS Code starts the hook with, so the agent can't set
it for a single command. The hook also matches text inside commit
messages.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* fix(help): ship the generated help file so Get-Help works
Get-Help showed only the syntax of the cmdlets: the module shipped a
pre-4.x MAML file for the old command names under the wrong name
(NTFSSecurity-Help.xml), while PowerShell looks for
en-US\NTFSSecurity.dll-Help.xml.
- Generate en-US\NTFSSecurity.dll-Help.xml from Docs/Cmdlets with
New-ExternalHelp and commit it. The csproj copies it to the output,
so every build ships it, including the local Debug builds that
releases are published from.
- List all runtime files, including the help file, in FileList.
- Remove the stale NTFSSecurity-Help.xml and the unused help editor
project NTFSSecurity\Help\NTFSSecurity.Help.pshproj.
- Add Tests\Help.Tests.ps1 (Pester 5): Get-Help shows the synopsis,
parameters, examples, and online link of every page, and
Get-Help -Online resolves to the GitHub page.
- Reword six sentences in five cmdlet pages so that each link ends its
sentence: platyPS drops the space after a link in the help text.
- CI regenerates the help file and fails when it differs from the
committed file, then runs the Pester tests.
- Document the regeneration step and the link rule in the contributor
guide.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: report each Pester test once on AppVeyor
AppVeyor build 54834154 passed all 218 Pester tests but listed 870 on
its Tests tab: the NUnit import files a Pester 5 test under every block
that contains it (Pester, test file, Describe, and Context).
Report the results through the build worker API instead
(POST api/tests/batch): one entry per test with its outcome, duration,
and error message. Outside AppVeyor, and when no test ran, the step
sends nothing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Ignore .memory-bank/promptHistory.md, a local log that is not
version-controlled.
- Record the merge of PR #91 and the agreed order of the follow-up
work packages in progress.md.
- Record the changelog policy as Decision 7: CHANGELOG.md lists
user-visible changes only; CI and build-only changes get no entry.
- Move the inline Decisions to .memory-bank/decisions/ records, so
systemPatterns.md keeps an index below its 110-line budget.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* chore: initialize the memory bank
Add the canonical .memory-bank base with evidence-based project context:
purpose and scope, workflows, stack and validation commands, architecture
map, decisions, and the open work found while documenting the cmdlets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* docs: align documentation with the cmdlet source
- Fill all 36 platyPS cmdlet pages from the C# source: synopsis,
description, parameters, defaults, examples, inputs, outputs, and
notes, including documented limitations of the current code
- Check every example against live parameter metadata and run them in a
sandbox; fix examples that did not work (CSV restore, account filter,
recursive inheritance, -AccessRights typos)
- Rewrite the home, concepts, examples, README, and contributor pages;
add a grouped cmdlet overview, module settings, privileges, long paths,
and the platyPS workflow
- Document Remove-Item2 -PassThru as renamed after 4.2.6 (#64)
- Fix mkdocs.yml navigation, edit_uri, and copyright markup; add
build.os and a pinned MkDocs version for Read the Docs
- Point online help links to the pages on GitHub; add CHANGELOG.md
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* ci: build the module and check the docs against the build
The documentation check ran Update-MarkdownHelp against the NTFSSecurity
release from the PowerShell Gallery (4.2.6), so it failed for every
unreleased parameter change. PR #91 failed because 4.2.6 still has
Remove-Item2 -PassThur while the source and the docs have -PassThru.
- Build NTFSSecurity.csproj in Release on the Visual Studio 2022 image,
using the .NET Framework 4.5.2 reference assemblies package instead of
an installed targeting pack
- Check Docs/Cmdlets against the module built from source
- Pin platyPS 0.14.2 and MarkdownLinkCheck 0.2.0, and enable TLS 1.2 so
the NuGet provider bootstrap works
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
* chore: record the green PR 91 build in the memory bank
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>