docs(auth): record final review fix round 1 evidence

This commit is contained in:
2026-08-18 15:26:23 +02:00
parent 10cd66fe6a
commit 0f762ad6b6
5 changed files with 311 additions and 106 deletions
@@ -1,30 +1,33 @@
# Task 15 retained release-gate report — fix round 5 (sanitized)
## Task 4 recertification addendum — frozen source `b31b27e5845ffd3adf311429367319beaba263c7`
## Final-review fix-round-1 addendum — frozen source `10cd66fe6a5b484a4dc569326a228c1c5484a5d4`
This addendum supersedes the earlier source-bound matrix for current certification while preserving
the fix-round-5 material below as historical provenance.
This addendum supersedes the earlier Task 4 pre-fix certification for current authentication
remediation status while preserving the fix-round-5 material below as historical provenance.
- Certification status: `FAIL` / `CHANGES_REQUIRED`; no tracked source changed after the freeze.
- Native Windows workflow run `32122302381` was dispatched on the exact frozen SHA and concluded
`failure`. Job `Windows clone and Compose contract` (`95665197885`) executed the native
`safeio`/`backup` test command, which failed; `internal/authstorage` was not part of that frozen
workflow command.
- Local current results: Go focused/race/vet/build and Windows cross-compile PASS; Node 24 backend
`76 files / 1092 tests`, frontend `61 files / 444 tests`, typechecks/builds and authentication
smoke PASS; harness `951 passed / 1 failed / 4 skipped`, Ruff `192` errors, and Compose contracts
FAIL; authentication docs and shell syntax PASS.
- The same run's `LF, Compose, docs, and TypeScript` job (`95665197839`) failed on an unset `TMPDIR`
in the deployment-coupling scope script after its unified Compose contract passed; this is a
baseline/CI contract issue. Its Linux Docker job (`95665197846`) stopped before deployment because
`rg` was unavailable; cleanup proof passed and no image manifest was generated, so this is an
infrastructure prerequisite issue rather than a source-bound Docker result.
- The remote unified Docker smoke attempt therefore failed before deployment; the existing image
manifest below remains historical and is not evidence for the new source.
- Authentication remediation status: implementation `PASS`; all four final-review Important
findings are addressed. Overall branch/release readiness remains `FAIL` with external gates
`PENDING`.
- Completed exact-source workflow run `32141428407` concluded `failure` on baseline release jobs.
Its `Windows clone and Compose contract` job (`95724751282`) executed the unfiltered command
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step
passed all three packages: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`.
- The Windows job failed only afterward in the baseline clone-contract script at
`scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited
`$remoteYaml:` variable reference.
- `LF, Compose, docs, and TypeScript` job `95724751205` reproduced the baseline unset-`TMPDIR`
failure after unified Compose passed. Linux Docker job `95724751356` reproduced the missing-`rg`
prerequisite failure; cleanup passed and no image manifest was generated.
- The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL.
Downstream commands skipped after executed baseline failures use the same classification. The
matrix contains an explicit native `windows_stagearchive_retained_capability` PASS row.
- Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to
its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness
remain `PENDING`.
- Current machine-readable evidence and the requested Task 4 report are recorded in
`.artifacts/task-15/automated-gates.json` and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
- Current automated-gates SHA-256: `e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`.
- Current automated-gates SHA-256: `5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`.
- Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the