docs(auth): retain Task 15 round four evidence
This commit is contained in:
+17
-13
@@ -7,7 +7,7 @@
|
||||
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
|
||||
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-18 (Task 15 fix-round-3 evidence recorded; the authentication feature is
|
||||
> Last updated: 2026-08-18 (Task 15 fix-round-4 evidence recorded; the authentication feature is
|
||||
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
@@ -16,28 +16,32 @@
|
||||
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
|
||||
target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
|
||||
accounts their combined capacity before mutation; and uses an opaque installation-bound
|
||||
transaction capability. Restore staging uses the repository `safeio` owner-only mechanisms on
|
||||
Unix and Windows rather than POSIX-mode assumptions.
|
||||
- Final tested source is `e20bf33e2a00102192e5be66b178037aeca3a7b1`; fix-round-2 commits
|
||||
`fe190e7046acc173f510dddcb32f46ed142858c1` and follow-up
|
||||
transaction capability. Fix-round-4 makes `StageArchive` create its streamed, secret-bearing
|
||||
`archive.zip` through a narrow safeio read/write primitive: Unix keeps exact private regular-file
|
||||
behavior and Windows installs an owner-only DACL atomically before any archive bytes are written.
|
||||
- Final tested source is `54698e73400a54ce7c3e6c10099e14eb471ce8b9`; prior final Docker source
|
||||
`e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2
|
||||
`fe190e7046acc173f510dddcb32f46ed142858c1`, and follow-up
|
||||
`4d230b87afdcd24f02264f8f937c8628b92db05a` remain intact in history. The final unified Docker
|
||||
smoke is PASS for run `20260818054002-16619-2452`, including maintenance auth isolation,
|
||||
smoke is PASS for run `20260818061612-31842-22636`, including maintenance auth isolation,
|
||||
restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup.
|
||||
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
|
||||
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
|
||||
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
|
||||
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
|
||||
it is not the release contract and no tracked `v24.19.0` pin exists.
|
||||
- PASS: focused and full backup tests; full Go race/build across 18 packages; Windows amd64 static
|
||||
test/build cross-compile across 18 packages; shell syntax and unified safety self-tests;
|
||||
default/unified Compose and secret-policy contracts; final unified Docker smoke and cleanup.
|
||||
Native execution of the Windows-only owner-DACL test was unavailable and remains PENDING.
|
||||
- PASS: focused native TDD (`safeio` stream, Unix archive privacy, post-write cleanup, immutable
|
||||
staged bytes); full backup/safeio tests; final-source Go race/build across 18 packages; Windows
|
||||
amd64 static test/build cross-compile across 18 packages; Node 24 authentication smoke; shell
|
||||
syntax and unified safety self-tests; default/unified Compose and secret-policy contracts; final
|
||||
unified Docker smoke and cleanup. Windows results are cross-compile only; native execution of the
|
||||
Windows-only `ValidatePrivateRegular` staged-archive test was unavailable and remains PENDING.
|
||||
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
|
||||
(`af835ab5eb37951881cc526a9576eb5789af510e0e4f2806d4d8ed080fb70fba`),
|
||||
(`cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`),
|
||||
`.artifacts/task-15/unified-docker-images.json`
|
||||
(`835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`), and
|
||||
(`d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`), and
|
||||
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
|
||||
(`ba4da7f5bfb445ffb0fcca4d0620786e001c4b892efae22b26cbb33b194c6a86`). Authentication smoke
|
||||
(`628bdc6759c12c688d414825eef7b56881d96af1d91577dd9487959e90a9d0bf`). Authentication smoke
|
||||
exercised no Docker images; the final unified run retained all five exercised image identities.
|
||||
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
|
||||
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
|
||||
|
||||
Reference in New Issue
Block a user