mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
5.2 KiB
5.2 KiB
| status | last-verified | owner | source |
|---|---|---|---|
| current | 2026-10-04 | active-agent | repository evidence |
System patterns
Architecture
NTFSSecurity.psd1 ─┬─ ScriptsToProcess: NTFSSecurity.Init.ps1
│ Add-Type: Security2.dll, PrivilegeControl.dll,
│ ProcessPrivileges.dll, inline NTFS.DriveInfoExt;
│ Update-FormatData -PrependPath format.ps1xml
├─ TypesToProcess: NTFSSecurity.types.ps1xml
│ (Owner, IsInheritanceBlocked, LengthOnDisk on
│ FileInfo/DirectoryInfo; AccountType on ACEs)
├─ RootModule: NTFSSecurity.psm1 (aliases)
├─ NestedModules: NTFSSecurity.dll (36 cmdlets)
└─ en-US\NTFSSecurity.dll-Help.xml (Get-Help; generated
from Docs/Cmdlets, Decision 8)
NTFSSecurity.dll ── cmdlets ──> Security2.dll (FileSystemAccessRule2,
FileSystemAuditRule2, IdentityReference2,
FileSystemInheritanceInfo, EffectiveAccess)
── long paths ──> AlphaFS
── privileges ──> PrivilegeControl / ProcessPrivileges
BaseCmdletresolves relative paths against$PWD.BaseCmdletWithPrivControl(access, audit, inheritance, owner, security descriptor, and privilege cmdlets) enables Backup, Restore, TakeOwnership, and Security inBeginProcessingwhenPrivateData.EnablePrivilegesis$true, and disables the ones it enabled inEndProcessing.PrivateDataswitches:EnablePrivileges(base cmdlet),GetInheritedFrom(Get-NTFSAccess,Get-NTFSAudit),GetFileSystemModePropertyandIdentifyHardLinks(Get-ChildItem2),ShowAccountSid(format file).- Cmdlets accept either
-Path(aliasFullName) or-SecurityDescriptor(fromGet-NTFSSecurityDescriptor); SD sets change the in-memory object untilSet-NTFSSecurityDescriptorwrites it back.
Decisions
Each Decision record is a file in decisions/; read only the relevant ones.
Patterns
Verifying documentation
- Run platyPS in Windows PowerShell 5.1 against a module build; a copy of
Docs/Cmdletsmust round-trip throughUpdate-MarkdownHelpunchanged. platyPS rewrites non-ASCII punctuation, so keep cmdlet pages ASCII-only. - GitHub renders the docs (Decision 9); CI publishes them to the wiki
(Decision 11). MarkdownLinkCheck: relative
Docslinks, no anchors;Tests\Wiki.Tests.ps1: every wiki link and anchor (GitHub slug rules). Neither covers the links inREADME.mdandCHANGELOG.md. - The wiki is generated from
Docs; never edit the wiki. Pages are named after their files,Docs/README.mdbecomes Home, and its cmdlet groups form the sidebar; a cmdlet missing there failsWiki.Tests.ps1. - In cmdlet pages, end a sentence with a link: platyPS renders a link as
text (url)in the help file and drops the space after it. - Verify examples in a
$env:TEMPsandbox, never on real data; parse every example and check its parameters againstGet-Commandmetadata.
Testing the module
- Pester 5 tests in
Tests/*.Tests.ps1importNTFSSecurity\bin\Release\NTFSSecurity.psd1; CI runs them in Windows PowerShell 5.1 and in PowerShell 7 (Decision 11). Get-Help -Onlinetests use the internal hookBypassOnlineHelpRetrieval(URI instead of a browser); it skips the help file in PowerShell 7, so those 36 tests run only in Windows PowerShell..github/scripts/Invoke-Tests.ps1runs Pester in CI: counts and failures to the job summary, NUnit totest-results; failed test files fail too.Tests\Manifest.Tests.ps1:Test-ModuleManifestwithout errors or warnings, exactly 36 cmdlets, one version in manifest and assemblies (Decision 10). A new cmdlet updatesCmdletsToExportand that count.Tests\Release.Tests.ps1checks thatCHANGELOG.mdhas release notes for the manifest version (dated section, or[Unreleased]for a prerelease) and the packages: onlyFileListfiles, version with label, command tags, andNTFSSecurity.zipwith the module folder.