Merge current main into development guidance

Reconcile the read-only guidance output with the machine-readable skill index,
adopt linked sample references required by bounded retrieval, and update the
guidance regression fixture for the retrieval helper dependency. Permit only
the known endpoint-DLP metadata stream during read-only evidence capture.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 638b66d2-9f06-4f60-8781-808709e1485c
This commit is contained in:
Jesper Schulz-Wedde 2026-09-18 12:04:06 +02:00
commit 8f025ac679
127 changed files with 5251 additions and 136 deletions

View file

@ -80,24 +80,15 @@ function Assert-GuidanceItem {
if (($Item.Attributes -band [IO.FileAttributes]::ReparsePoint) -or $Item.LinkType -or $Item.LinkTarget) {
throw 'Links, junctions, hard links and reparse points are not supported.'
}
}
function Get-GuidanceStreams {
param([string] $Path)
if (-not $IsWindows) { return @() }
return @(
Get-Item -LiteralPath $Path -Stream '*' -Force -ErrorAction Stop |
Where-Object Stream -ne ':$DATA' |
Sort-Object Stream -CaseSensitive |
ForEach-Object {
$streamPath = "$($_.FileName):$($_.Stream)"
[ordered]@{
name = $_.Stream
length = $_.Length
sha256 = Get-GuidanceHash $streamPath
}
}
)
if (-not $Item.PSIsContainer -and $IsWindows) {
$unsupportedStreams = @(
Get-Item -LiteralPath $Item.FullName -Stream '*' -Force -ErrorAction Stop |
Where-Object Stream -notin @(':$DATA', 'sec.endpointdlp')
)
if ($unsupportedStreams.Count) {
throw 'Alternate data streams are not supported.'
}
}
}
function Get-GuidanceSafePath {
@ -210,7 +201,6 @@ function Get-GuidanceSnapshot {
$entry.length = $item.Length
$entry.lastWriteUtcTicks = $item.LastWriteTimeUtc.Ticks
$entry.sha256 = Get-GuidanceHash $item.FullName
$entry.streams = @(Get-GuidanceStreams $item.FullName)
}
$files.Add($entry)
}