docs(auth): retain Task 15 round four evidence

This commit is contained in:
2026-08-18 08:24:08 +02:00
parent 54698e7340
commit 0b77d1e850
4 changed files with 102 additions and 73 deletions
+18 -10
View File
@@ -5,7 +5,8 @@
"authentication_round1": "2b618c5a0f6f07045700cfe7146ca517fb5f78ab", "authentication_round1": "2b618c5a0f6f07045700cfe7146ca517fb5f78ab",
"fix_round2": "fe190e7046acc173f510dddcb32f46ed142858c1", "fix_round2": "fe190e7046acc173f510dddcb32f46ed142858c1",
"maintenance_profile_follow_up": "4d230b87afdcd24f02264f8f937c8628b92db05a", "maintenance_profile_follow_up": "4d230b87afdcd24f02264f8f937c8628b92db05a",
"fix_round3_and_final_docker": "e20bf33e2a00102192e5be66b178037aeca3a7b1" "fix_round3_and_final_docker": "e20bf33e2a00102192e5be66b178037aeca3a7b1",
"fix_round4_streamed_archive_privacy": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
}, },
"versions": { "versions": {
"node_contract": "v24.16.0", "node_contract": "v24.16.0",
@@ -22,10 +23,10 @@
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "PASS", "status": "PASS",
"source_commit": "e20bf33e2a00102192e5be66b178037aeca3a7b1", "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818054002-16619-2452", "run_id": "20260818061612-31842-22636",
"manifest": ".artifacts/task-15/unified-docker-images.json", "manifest": ".artifacts/task-15/unified-docker-images.json",
"manifest_sha256": "835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7", "manifest_sha256": "d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e",
"images": 5, "images": 5,
"cleanup": "PASS" "cleanup": "PASS"
} }
@@ -37,7 +38,8 @@
}, },
"platform_private_restore_staging": { "platform_private_restore_staging": {
"status": "PASS", "status": "PASS",
"evidence": "unix_behavior_test_and_windows_static_cross_compile" "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"evidence": "safeio_streamed_archive_unix_test_and_windows_static_cross_compile"
}, },
"provider_fixture": { "provider_fixture": {
"status": "PASS", "status": "PASS",
@@ -59,15 +61,19 @@
"playwright": 8, "playwright": 8,
"files": 2, "files": 2,
"node": "v24.16.0", "node": "v24.16.0",
"sentinel_leak_scan": "PASS" "sentinel_leak_scan": "PASS",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
}, },
"go_race_build": { "go_race_build": {
"status": "PASS", "status": "PASS",
"packages": 18 "packages": 18,
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
}, },
"windows_cross_compile": { "windows_cross_compile": {
"status": "PASS", "status": "PASS",
"packages": 18 "packages": 18,
"execution": "cross_compile_only_not_native_execution",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
}, },
"shell_and_compose_contracts": { "shell_and_compose_contracts": {
"status": "PASS", "status": "PASS",
@@ -77,11 +83,13 @@
"default_compose", "default_compose",
"unified_compose", "unified_compose",
"compose_secret_policy" "compose_secret_policy"
] ],
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "PASS", "status": "PASS",
"run_id": "20260818054002-16619-2452", "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818061612-31842-22636",
"images": 5, "images": 5,
"cleanup": "PASS" "cleanup": "PASS"
}, },
+14 -14
View File
@@ -1,19 +1,9 @@
{ {
"gate": "unified-deployment-smoke", "gate": "unified-deployment-smoke",
"status": "pass", "status": "pass",
"source_commit": "e20bf33e2a00102192e5be66b178037aeca3a7b1", "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818054002-16619-2452", "run_id": "20260818061612-31842-22636",
"images": [ "images": [
{
"id": "sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6",
"roles": [
"compose-runtime",
"fixture-runtime"
],
"repo_digests": [
"sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6"
]
},
{ {
"id": "sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a", "id": "sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a",
"roles": [ "roles": [
@@ -33,12 +23,22 @@
] ]
}, },
{ {
"id": "sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d", "id": "sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532",
"roles": [ "roles": [
"compose-runtime" "compose-runtime"
], ],
"repo_digests": [ "repo_digests": [
"sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d" "sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532"
]
},
{
"id": "sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5",
"roles": [
"compose-runtime",
"fixture-runtime"
],
"repo_digests": [
"sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5"
] ]
}, },
{ {
@@ -1,46 +1,63 @@
# Task 15 retained release-gate report — fix round 3 (sanitized) # Task 15 retained release-gate report — fix round 4 (sanitized)
- Final tested source commit: `e20bf33e2a00102192e5be66b178037aeca3a7b1`. - Final tested source commit: `54698e73400a54ce7c3e6c10099e14eb471ce8b9`.
- Fix-round-2 commits retained unchanged: `fe190e7046acc173f510dddcb32f46ed142858c1` - Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`,
and follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`. maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, and prior final Docker
source `e20bf33e2a00102192e5be66b178037aeca3a7b1`.
- Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`; - Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`;
Pi `0.80.3`. Pi `0.80.3`.
- Automated gate artifact: `.artifacts/task-15/automated-gates.json`; - Automated gate artifact: `.artifacts/task-15/automated-gates.json`;
SHA-256 `af835ab5eb37951881cc526a9576eb5789af510e0e4f2806d4d8ed080fb70fba`. SHA-256 `cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`.
- Docker image manifest: `.artifacts/task-15/unified-docker-images.json`; - Docker image manifest: `.artifacts/task-15/unified-docker-images.json`;
SHA-256 `835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`. SHA-256 `d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`.
## Fix-round-3 evidence ## Fix-round-4 evidence
- PASS: backup staging RED/GREEN focused set `4/4`; full backup package; full Go race and build - PASS: test-first safe-I/O stream creator. The focused test first failed because
across `18` packages. Staging now uses the repository `safeio` owner-only directory mechanisms, `CreateCanonicalNewPrivateFile` was absent; after implementation, four native selected tests
rejects a symlinked installation ancestor on Unix, and includes a Windows-only owner-DACL test. passed: the safe-I/O read/write stream, Unix staged-file privacy, post-write cleanup, and
- PASS: Windows amd64 static test/build cross-compile across `18` packages. Native execution of immutable staged bytes. The staged archive now enters through safeio with an exclusive private
the Windows-only ACL test was not available and is therefore PENDING, not PASS. parent, `0600` Unix regular-file protection, and an owner-only DACL set in the Windows creation
- PASS on Node `v24.16.0`: deterministic provider security fixture `6/6`; authentication smoke call before archive bytes are streamed.
`8/8` across `frontend/e2e/auth.spec.ts` and authenticated `frontend/e2e/f1.spec.ts`. The - PASS: full backup and safe-I/O package tests and their race runs. The final source also passed
runtime sentinel was the exact fixture OIDC client secret and group bearer, and the retained `go test -race ./...` across `18` packages and a native host `tht` CLI build.
output leak scan passed. - PASS: Windows amd64 static test/build cross-compile across `18` packages, including the staged
- PASS: shell syntax, unified-smoke safety self-tests, default/unified Compose contracts, and archive Windows test that calls `safeio.ValidatePrivateRegular`. This was **cross-compile only**;
Compose secret policy. no Windows executable was run. Native execution remains PENDING.
- PASS: final unified Docker deployment smoke run `20260818054002-16619-2452`, bound to source - PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed for the
commit `e20bf33e2a00102192e5be66b178037aeca3a7b1`. It exercised the maintenance authentication current `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; its exact
isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and runtime sentinel leak scan passed.
task-scoped cleanup. - PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose
- PASS: Docker image traceability for all `5` images exercised by the final unified run. The contract, and Compose secret-policy contract.
authentication browser smoke exercised no Docker images and is explicitly retained as an empty - PASS: final unified Docker deployment smoke run `20260818061612-31842-22636`, bound to source
image set. `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. It exercised the maintenance-auth isolation check,
restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
## Sanitized final unified Docker output
```text
== Build and start isolated local Compose distribution ==
== Recreate offline and retain the validated registry snapshot ==
== Pull a valid catalog+descriptor metadata update ==
== Pull a content-only Git Evidence update ==
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
== Reject orphan descriptor directories not listed in the catalog ==
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818061612-31842-22636.
```
## Sanitized Docker image identities ## Sanitized Docker image identities
- `sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6`;
roles `compose-runtime`, `fixture-runtime`.
- `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`; - `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`;
role `compose-runtime`. role `compose-runtime`.
- `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`; - `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`;
role `compose-runtime`. role `compose-runtime`.
- `sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d`; - `sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532`;
role `compose-runtime`. role `compose-runtime`.
- `sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5`;
roles `compose-runtime`, `fixture-runtime`.
- `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`; - `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`;
role `rollback-candidate`. role `rollback-candidate`.
@@ -49,17 +66,17 @@ names and credentials are deliberately omitted.
## Complete observed matrix ## Complete observed matrix
- PASS: Task13 lifecycle carry-ins; platform-private restore staging; provider fixture `6/6`; - PASS: Task 13 lifecycle carry-ins; streamed owner-private restore staging; provider fixture
backend Node24 round-1 suite `75 files / 1081 tests`; frontend Node24 round-1 suite round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24
`61 files / 444 tests`; current authentication/F1 browser smoke `8/8`; Go race/build round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`;
`18 packages`; Windows static cross-compile `18 packages`; harness round-1 suite final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness
`921 passed / 4 L2 deselected`; authentication docs round-1 gate; shell/Compose contracts; round-one suite `921 passed / 4 L2 deselected`; authentication docs round-one gate; shell/Compose
unified Docker smoke; five-image traceability; Docker cleanup. contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
- FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing - FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing
canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling
scan against preserved ignored private material. scan against preserved ignored private material.
- PENDING: native Windows execution because required host prerequisites are unavailable; L2 - PENDING: native Windows execution because required host prerequisites are unavailable; L2 because
because the configured secret layout is unavailable; real PSD/manual acceptance because no real the configured secret layout is unavailable; real PSD/manual acceptance because no real
identity/access is available; isolated provider readiness because an unrelated host port is identity/access is available; isolated provider readiness because an unrelated host port is
occupied. occupied.
+17 -13
View File
@@ -7,7 +7,7 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base > ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 15 fix-round-3 evidence recorded; the authentication feature is > Last updated: 2026-08-18 (Task 15 fix-round-4 evidence recorded; the authentication feature is
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain). > not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work. > Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
@@ -16,28 +16,32 @@
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before - Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight; stages the immutable candidate and recovery archives under that lock; target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
accounts their combined capacity before mutation; and uses an opaque installation-bound accounts their combined capacity before mutation; and uses an opaque installation-bound
transaction capability. Restore staging uses the repository `safeio` owner-only mechanisms on transaction capability. Fix-round-4 makes `StageArchive` create its streamed, secret-bearing
Unix and Windows rather than POSIX-mode assumptions. `archive.zip` through a narrow safeio read/write primitive: Unix keeps exact private regular-file
- Final tested source is `e20bf33e2a00102192e5be66b178037aeca3a7b1`; fix-round-2 commits behavior and Windows installs an owner-only DACL atomically before any archive bytes are written.
`fe190e7046acc173f510dddcb32f46ed142858c1` and follow-up - Final tested source is `54698e73400a54ce7c3e6c10099e14eb471ce8b9`; prior final Docker source
`e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2
`fe190e7046acc173f510dddcb32f46ed142858c1`, and follow-up
`4d230b87afdcd24f02264f8f937c8628b92db05a` remain intact in history. The final unified Docker `4d230b87afdcd24f02264f8f937c8628b92db05a` remain intact in history. The final unified Docker
smoke is PASS for run `20260818054002-16619-2452`, including maintenance auth isolation, smoke is PASS for run `20260818061612-31842-22636`, including maintenance auth isolation,
restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup. restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup.
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1 - PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`; 61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
it is not the release contract and no tracked `v24.19.0` pin exists. it is not the release contract and no tracked `v24.19.0` pin exists.
- PASS: focused and full backup tests; full Go race/build across 18 packages; Windows amd64 static - PASS: focused native TDD (`safeio` stream, Unix archive privacy, post-write cleanup, immutable
test/build cross-compile across 18 packages; shell syntax and unified safety self-tests; staged bytes); full backup/safeio tests; final-source Go race/build across 18 packages; Windows
default/unified Compose and secret-policy contracts; final unified Docker smoke and cleanup. amd64 static test/build cross-compile across 18 packages; Node 24 authentication smoke; shell
Native execution of the Windows-only owner-DACL test was unavailable and remains PENDING. syntax and unified safety self-tests; default/unified Compose and secret-policy contracts; final
unified Docker smoke and cleanup. Windows results are cross-compile only; native execution of the
Windows-only `ValidatePrivateRegular` staged-archive test was unavailable and remains PENDING.
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json` - Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
(`af835ab5eb37951881cc526a9576eb5789af510e0e4f2806d4d8ed080fb70fba`), (`cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`),
`.artifacts/task-15/unified-docker-images.json` `.artifacts/task-15/unified-docker-images.json`
(`835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`), and (`d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`), and
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md` `.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
(`ba4da7f5bfb445ffb0fcca4d0620786e001c4b892efae22b26cbb33b194c6a86`). Authentication smoke (`628bdc6759c12c688d414825eef7b56881d96af1d91577dd9487959e90a9d0bf`). Authentication smoke
exercised no Docker images; the final unified run retained all five exercised image identities. exercised no Docker images; the final unified run retained all five exercised image identities.
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69 - FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth