mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
3.6 KiB
3.6 KiB
| status | last-verified | owner | source |
|---|---|---|---|
| current | 2026-10-08 | active-agent | current task evidence |
Active context
Current focus
Phase 2 of the quality gate before 5.0.0 (Decision 21), on the branch
ai/release-5.0.0-rc6, released as 5.0.0-rc6: tests until every code
path is tested or explained, live tests for the remaining cmdlets, and
test-first fixes of the known defects. The maintainer approved it on
2026-10-08. Then Phase 3 and 5.0.0; after 5.0.0 the repository is archived
in favor of WindowsAccessControl (Decision 18).
Evidence
- 2026-10-08, Phase 1, measured on 5.0.0-rc5 (
fcb370e):- The published package passes the live tests in both editions: 8 role runs, no failure.
- As a basic user, the 11 tests that CI skips pass in both editions. The
one failure,
Enable-Privileges should write one object per privilege, assumes more than one privilege. Every test runs in at least one of four configurations (elevated or basic user, two editions), but CI runs only elevated. - The suite runs 55.9% of the C# lines and 37.4% of the branches
(
techContext.md, Validation). No line ofTest-Path2andGet-DiskSpaceruns;Set-NTFSOwner(46%) runs only as a setup step of another test;Clear-NTFSAccessand the access inheritance cmdlets run about 43%,FileSystemSecurity242%. No cmdlet calls the registry classes,SimpleFileSystemAuditRule,PrivilegeEnabler, orFileSystemEffectivePermissionEntry(244 lines). - 19 of the 36 cmdlets never ran over SMB, among them
Get-NTFSOwner,Set-NTFSOwner, the audit inheritance cmdlets, andClear-NTFSAudit; no account of another domain or forest ran; both ends of the lab run Windows Server 2025.
- Known defects from the reviews of #113 and #114 (
progress.md, open work 3):Move-Item2 -PassThrureturns the source item; the conflict checks ofCopy-Item2andMove-Item2useFile.Existsalso for folders, maybe the cause of #21; an error while restoring the owner can hide the original one (R4);Set-NTFSSecurityDescriptor -PassThrureads the item again inside the retry (R5); the access check doesn't readAUTHZ_ACCESS_REPLY.Error, and its buffers aren't initialized. #110 lists seven test follow-ups. - #34: no reply from the tester by 06:44 UTC on 2026-10-08.
- Phase 2, step 1, first part (2026-10-08, commits
82969batoff74100): 34 new tests forSet-NTFSOwner,Test-Path2, andGet-DiskSpace, and two defects found and fixed test-first. Every cmdlet that enables privileges left the Backup, Restore, Take Ownership, and Security privileges enabled in the session when a later command or a terminating error stopped the pipeline;Test-Path2stopped with "Illegal characters in path" in Windows PowerShell for a path such asC:\a|b. The suite (533 tests) passes elevated in both editions.
Next step
Phase 2, one step at a time, each with evidence before the next:
- Tests for the cmdlets without tests of their own: done for
Set-NTFSOwner,Test-Path2, andGet-DiskSpace; open for the link cmdlets,Get-NTFSOrphanedAudit, andGet-NTFSSimpleAccess. - The other parameter sets and error paths, such as the
-SecurityDescriptorsets of the inheritance cmdlets and ofClear-NTFSAccess. - The paths of
Security2that no test runs, and #110. - Test-first fixes of the known defects; behavior changes go to the maintainer (Decision 16).
- A CI job as a basic user, live tests for the other cmdlets over SMB and for accounts of other forests, and a lab run.
- Measure the coverage again, explain what remains, review, and prepare 5.0.0-rc6.