mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
1.4 KiB
1.4 KiB
| status | date | last-verified | owner | source |
|---|---|---|---|---|
| accepted | 2026-10-06 | 2026-10-06 | shared | maintainer decisions of 2026-10-06 for 5.0.0-rc3 (#112) |
Decision 19: Cmdlets write only the sections that they change
- Choice: A cmdlet that changes a file or folder reads and writes only the
section of the security descriptor that it changes, and names that
section in the write: the access and access inheritance cmdlets the
DACL, the audit cmdlets the SACL.
Set-NTFSSecurityDescriptorwrites only the sections that changed since the descriptor was read or last written; a descriptor without changes writes nothing, and-Verbosenames the sections. When the descriptor ofGet-NTFSSecurityDescriptorincludes the SACL, it reads the DACL in a separate call.Clear-NTFSAuditreports an error without the Security privilege, like the other audit cmdlets. - Rationale: For a DACL without the auto-inherit flag, Windows returns the owner and the group even when only the DACL is read, and writing every section of the descriptor writes the owner back. Where the account may not assign that owner, that fails with error 1307 (#34). Read together with the SACL, such a DACL loses the inherited flag of its entries when the parent folder has no SACL, and writing it back stored them as explicit copies.
- Rejected: writing every section in turn and ignoring the errors, the
approach of the branch
fix/#34(2023). - Applied: 5.0.0-rc3, #112.