Your deny rules now block a path even when it's written a different way.
What's wrong with this entry?
A deny rule now matches even when the path is written in a form other than the one that got resolved.
- the deny lookup iterates over the path's variants and returns the first matching rule, instead of testing only the single resolved path
- the drive-relative rejection message now names the original argument when one is available
- drive-relative paths still require manual approval because they resolve against the per-drive current directory
is drive-relative (resolves against the per-drive current directory, which cannot be statically validated) and requires manual approval
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.