docs(auth): record final review fix round 1 evidence

This commit is contained in:
2026-08-18 15:26:23 +02:00
parent 10cd66fe6a
commit 0f762ad6b6
5 changed files with 311 additions and 106 deletions
+64 -52
View File
@@ -2,8 +2,8 @@
"schema": "thothii-task4-certification-v1", "schema": "thothii-task4-certification-v1",
"generated_on": "2026-08-18", "generated_on": "2026-08-18",
"started_at_utc": "2026-08-18T09:26:00Z", "started_at_utc": "2026-08-18T09:26:00Z",
"ended_at_utc": "2026-08-18T09:48:36Z", "ended_at_utc": "2026-08-18T13:18:56Z",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"source_immutability": { "source_immutability": {
"status": "PASS", "status": "PASS",
"tracked_changes_after_freeze": false, "tracked_changes_after_freeze": false,
@@ -15,6 +15,7 @@
"task2": "5f9a3ae066a060b43a11a959b60a1efadd1c2425", "task2": "5f9a3ae066a060b43a11a959b60a1efadd1c2425",
"task3": "0d8e707533fada938c99eb06f8457150e7ef2b40", "task3": "0d8e707533fada938c99eb06f8457150e7ef2b40",
"task3_follow_up": "b31b27e5845ffd3adf311429367319beaba263c7", "task3_follow_up": "b31b27e5845ffd3adf311429367319beaba263c7",
"fix_round_1_source": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"historical_task15_final": "74b062f1a737103524cbe706346cfd65f87cdfd1" "historical_task15_final": "74b062f1a737103524cbe706346cfd65f87cdfd1"
}, },
"versions": { "versions": {
@@ -26,39 +27,36 @@
"retained_report": ".superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md", "retained_report": ".superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md",
"task4_report": ".superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md", "task4_report": ".superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md",
"workflow": { "workflow": {
"run_id": "32122302381", "run_id": "32141428407",
"url": "https://github.com/mptyl/ThothII/actions/runs/32122302381", "url": "https://github.com/mptyl/ThothII/actions/runs/32141428407",
"event": "workflow_dispatch", "event": "workflow_dispatch",
"head_sha": "b31b27e5845ffd3adf311429367319beaba263c7", "head_sha": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"status": "completed", "status": "completed",
"conclusion": "failure", "conclusion": "failure",
"windows_job": { "windows_job": {
"name": "Windows clone and Compose contract", "name": "Windows clone and Compose contract",
"job_id": "95665197885", "job_id": "95724751282",
"url": "https://github.com/mptyl/ThothII/actions/runs/32122302381/job/95665197885", "url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751282",
"conclusion": "failure", "conclusion": "failure",
"native_step": "Run native Windows retained-capability tests", "native_step": "Run native Windows retained-capability tests",
"native_step_conclusion": "failure", "native_step_conclusion": "success",
"command": "go test ./internal/safeio ./internal/backup -count=1", "command": "go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1",
"requested_packages": ["internal/safeio", "internal/backup"], "requested_packages": ["internal/safeio", "internal/backup", "internal/authstorage"],
"executed_packages": ["internal/safeio", "internal/backup"], "executed_packages": ["internal/safeio", "internal/backup", "internal/authstorage"],
"not_executed_packages": ["internal/authstorage"], "not_executed_packages": [],
"focused_tests_observed": [ "package_results": {
"TestRemoveCanonicalPrivateClaimRetainsParentDuringDeletion", "internal/safeio": "PASS (8.230s)",
"TestRemoveCanonicalPrivateClaimPreservesOrphan", "internal/backup": "PASS (5.195s)",
"TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup" "internal/authstorage": "PASS (8.383s)"
], },
"failure_categories": [ "failed_step": "Verify Windows clone contract",
"safeio retained-capability tests failed with unsafe file", "failure_category": "baseline_powershell_parser",
"backup retained-staging tests failed with unsafe file", "failure_detail": "scripts/test-windows-clone-contract.ps1:208 parses $remoteYaml: as an invalid variable reference"
"backup TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup timed out after 10m0s",
"some backup fixture tests could not read their external-secret declarations"
]
}, },
"lf_compose_docs_typescript_job": { "lf_compose_docs_typescript_job": {
"name": "LF, Compose, docs, and TypeScript", "name": "LF, Compose, docs, and TypeScript",
"job_id": "95665197839", "job_id": "95724751205",
"url": "https://github.com/mptyl/ThothII/actions/runs/32122302381/job/95665197839", "url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751205",
"conclusion": "failure", "conclusion": "failure",
"failed_step": "Verify Compose and installation contracts", "failed_step": "Verify Compose and installation contracts",
"category": "baseline_ci_contract", "category": "baseline_ci_contract",
@@ -67,14 +65,23 @@
}, },
"linux_docker_job": { "linux_docker_job": {
"name": "Linux Docker deployment and rollback", "name": "Linux Docker deployment and rollback",
"job_id": "95665197846", "job_id": "95724751356",
"url": "https://github.com/mptyl/ThothII/actions/runs/32122302381/job/95665197846", "url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751356",
"conclusion": "failure", "conclusion": "failure",
"failed_step": "Run unified deployment smoke", "failed_step": "Run unified deployment smoke",
"category": "infrastructure_prerequisite", "category": "infrastructure_prerequisite",
"detail": "Task 13 smoke failed before deployment because rg is required", "detail": "Task 13 smoke failed before deployment because rg is required",
"cleanup": "PASS", "cleanup": "PASS",
"image_manifest": "not_generated" "image_manifest": "not_generated"
},
"windows_docker_startup_job": {
"name": "Native Windows Docker Desktop/WSL2 startup",
"job_id": "95724752028",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724752028",
"status": "NOT_RUN",
"classification": "BLOCKED",
"workflow_conclusion": "skipped",
"reason": "workflow conditions skipped the job; no Windows Docker Desktop/WSL2 command executed"
} }
}, },
"docker_image_evidence": { "docker_image_evidence": {
@@ -85,9 +92,9 @@
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "FAIL", "status": "FAIL",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"run_id": "32122302381", "run_id": "32141428407",
"workflow_job_id": "95665197846", "workflow_job_id": "95724751356",
"manifest": ".artifacts/task-15/unified-docker-images.json", "manifest": ".artifacts/task-15/unified-docker-images.json",
"reason": "workflow attempt stopped before deployment because rg is required", "reason": "workflow attempt stopped before deployment because rg is required",
"cleanup": "PASS", "cleanup": "PASS",
@@ -113,10 +120,15 @@
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "b31b27e5845ffd3adf311429367319beaba263c7",
"evidence": "focused safeio/backup tests, Go race suite, and Unix ancestor-swap coverage" "evidence": "focused safeio/backup tests, Go race suite, and Unix ancestor-swap coverage"
}, },
"windows_stagearchive_retained_capability": {
"status": "PASS",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"evidence": "native Windows backup package passed, including the two-file shared retained-root staging test"
},
"windows_claim_retained_capability": { "windows_claim_retained_capability": {
"status": "FAIL", "status": "PASS",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"evidence": "native Windows workflow step failed" "evidence": "native Windows safeio and authstorage packages passed concurrent claim/consume coverage"
}, },
"workflow_lf_compose_docs_typescript": { "workflow_lf_compose_docs_typescript": {
"status": "FAIL", "status": "FAIL",
@@ -130,7 +142,7 @@
}, },
"go_security_build": { "go_security_build": {
"status": "PASS", "status": "PASS",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"focused_packages": 3, "focused_packages": 3,
"race_packages": 18, "race_packages": 18,
"focused_test": "PASS", "focused_test": "PASS",
@@ -140,8 +152,8 @@
}, },
"windows_cross_compile": { "windows_cross_compile": {
"status": "PASS", "status": "PASS",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"focused_test_packages": 2, "focused_test_packages": 3,
"cli_build": "PASS", "cli_build": "PASS",
"execution": "cross_compile_only_not_native_execution" "execution": "cross_compile_only_not_native_execution"
}, },
@@ -203,8 +215,8 @@
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "FAIL", "status": "FAIL",
"source_commit": "b31b27e5845ffd3adf311429367319beaba263c7", "source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"workflow_run_id": "32122302381", "workflow_run_id": "32141428407",
"reason": "remote workflow attempted the smoke but stopped before deployment because rg is required", "reason": "remote workflow attempted the smoke but stopped before deployment because rg is required",
"cleanup": "PASS", "cleanup": "PASS",
"image_manifest": "not_generated" "image_manifest": "not_generated"
@@ -215,29 +227,29 @@
"classification": "known_baseline" "classification": "known_baseline"
}, },
"mkdocs_strict": { "mkdocs_strict": {
"status": "FAIL", "status": "NOT_RUN",
"classification": "not_reached_after_stop", "classification": "BLOCKED",
"historical_status": "FAIL", "historical_status": "FAIL",
"historical_warnings": 69 "historical_warnings": 69
}, },
"canonical_install_docs": { "canonical_install_docs": {
"status": "FAIL", "status": "NOT_RUN",
"classification": "not_reached_after_stop", "classification": "BLOCKED",
"historical_status": "FAIL" "historical_status": "FAIL"
}, },
"workspace_install_docs": { "workspace_install_docs": {
"status": "FAIL", "status": "NOT_RUN",
"classification": "not_reached_after_stop", "classification": "BLOCKED",
"historical_status": "FAIL" "historical_status": "FAIL"
}, },
"pi_user_auth_compose": { "pi_user_auth_compose": {
"status": "FAIL", "status": "NOT_RUN",
"classification": "not_reached_after_stop", "classification": "BLOCKED",
"historical_status": "FAIL" "historical_status": "FAIL"
}, },
"deployment_coupling": { "deployment_coupling": {
"status": "FAIL", "status": "NOT_RUN",
"classification": "not_reached_after_stop", "classification": "BLOCKED",
"historical_status": "FAIL" "historical_status": "FAIL"
}, },
"l2": { "l2": {
@@ -254,11 +266,11 @@
} }
}, },
"review": { "review": {
"three_important_findings_closed": false, "four_important_findings_closed": true,
"verdict": "CHANGES_REQUIRED", "verdict": "ADDRESSED",
"reason": "native Windows retained-capability tests failed; the frozen workflow omits internal/authstorage from its native command" "reason": "the exact-source native Windows step passed safeio, backup, and authstorage; cleanup and deadlock tests are green and the workflow command includes all three packages"
}, },
"release_complete": false, "release_complete": false,
"authentication_implementation_complete": false, "authentication_implementation_complete": true,
"release_readiness": "FAIL" "release_readiness": "FAIL"
} }
@@ -1,30 +1,33 @@
# Task 15 retained release-gate report — fix round 5 (sanitized) # Task 15 retained release-gate report — fix round 5 (sanitized)
## Task 4 recertification addendum — frozen source `b31b27e5845ffd3adf311429367319beaba263c7` ## Final-review fix-round-1 addendum — frozen source `10cd66fe6a5b484a4dc569326a228c1c5484a5d4`
This addendum supersedes the earlier source-bound matrix for current certification while preserving This addendum supersedes the earlier Task 4 pre-fix certification for current authentication
the fix-round-5 material below as historical provenance. remediation status while preserving the fix-round-5 material below as historical provenance.
- Certification status: `FAIL` / `CHANGES_REQUIRED`; no tracked source changed after the freeze. - Authentication remediation status: implementation `PASS`; all four final-review Important
- Native Windows workflow run `32122302381` was dispatched on the exact frozen SHA and concluded findings are addressed. Overall branch/release readiness remains `FAIL` with external gates
`failure`. Job `Windows clone and Compose contract` (`95665197885`) executed the native `PENDING`.
`safeio`/`backup` test command, which failed; `internal/authstorage` was not part of that frozen - Completed exact-source workflow run `32141428407` concluded `failure` on baseline release jobs.
workflow command. Its `Windows clone and Compose contract` job (`95724751282`) executed the unfiltered command
- Local current results: Go focused/race/vet/build and Windows cross-compile PASS; Node 24 backend `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step
`76 files / 1092 tests`, frontend `61 files / 444 tests`, typechecks/builds and authentication passed all three packages: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`.
smoke PASS; harness `951 passed / 1 failed / 4 skipped`, Ruff `192` errors, and Compose contracts - The Windows job failed only afterward in the baseline clone-contract script at
FAIL; authentication docs and shell syntax PASS. `scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited
- The same run's `LF, Compose, docs, and TypeScript` job (`95665197839`) failed on an unset `TMPDIR` `$remoteYaml:` variable reference.
in the deployment-coupling scope script after its unified Compose contract passed; this is a - `LF, Compose, docs, and TypeScript` job `95724751205` reproduced the baseline unset-`TMPDIR`
baseline/CI contract issue. Its Linux Docker job (`95665197846`) stopped before deployment because failure after unified Compose passed. Linux Docker job `95724751356` reproduced the missing-`rg`
`rg` was unavailable; cleanup proof passed and no image manifest was generated, so this is an prerequisite failure; cleanup passed and no image manifest was generated.
infrastructure prerequisite issue rather than a source-bound Docker result. - The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL.
- The remote unified Docker smoke attempt therefore failed before deployment; the existing image Downstream commands skipped after executed baseline failures use the same classification. The
manifest below remains historical and is not evidence for the new source. matrix contains an explicit native `windows_stagearchive_retained_capability` PASS row.
- Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to
its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness
remain `PENDING`.
- Current machine-readable evidence and the requested Task 4 report are recorded in - Current machine-readable evidence and the requested Task 4 report are recorded in
`.artifacts/task-15/automated-gates.json` and `.artifacts/task-15/automated-gates.json` and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`. `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
- Current automated-gates SHA-256: `e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`. - Current automated-gates SHA-256: `5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`.
- Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. - Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the
@@ -0,0 +1,162 @@
# Final-review fix round 1 report (sanitized)
## Verdict
- Base: `fa499a9bdd37011833691b0f447470d8b7e8a3a6`.
- Final frozen source: `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on
`feat/thoth-auth`.
- Authentication remediation: **PASS / ADDRESSED**. All four final-review Important findings are
resolved relative to the remediation brief.
- Terra Minor evidence corrections: **ADDRESSED**.
- Branch/release readiness: **FAIL**. The completed exact-source workflow still contains executed
baseline clone-contract, LF/Compose, and Linux Docker failures. Unavailable external/manual
gates remain **PENDING**.
- Source and evidence remain separate commits. No workflow was dispatched from the evidence-only
phase.
## Finding disposition
| Finding | Disposition | Evidence |
|---|---|---|
| Important 1 — exhaustive Windows cleanup | RESOLVED | Cleanup now attempts close/delete/validation operations in deterministic order and returns sanitized `ErrUnsafeFile` after aggregating failures. `TestWindowsPrivateRegularCleanupClosesAfterDeleteDispositionFailure` and `TestWindowsClaimCleanupAttemptsLaterOperationsAfterEarlierFailure` cover the non-short-circuit contract. Global no-delete sharing remains unchanged. |
| Important 2 — usable native Windows authority | RESOLVED | Owner-only descriptors use the current user SID, protected/non-defaulted DACL semantics, valid NT attributes/access masks, self-relative creation descriptors, and semantic full-control validation. Equal-or-stronger Windows fixture adaptations retain no-delete handles instead of weakening ACL/identity checks. The final native three-package gate passes. |
| Important 3 — restore-test deadlock | RESOLVED | Lifecycle-stage release observes the buffered worker outcome, uses a bounded/cancellable release, reports premature completion directly, and never waits indefinitely on `done`. `TestReleaseLifecycleStageReturnsPrematureWorkerOutcome` and the lifecycle-lock terminal-cleanup test are green. |
| Important 4 — complete native package gate | RESOLVED | Workflow and remediation plan both use the exact unfiltered command `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. Final logs prove all three packages executed natively. |
| Minor — non-executed gate classification | RESOLVED | Non-executed/skipped commands are `NOT_RUN` / `BLOCKED`; `FAIL` is reserved for commands that ran and failed. Historical results remain separately labelled. |
| Minor — explicit Windows StageArchive row | RESOLVED | `.artifacts/task-15/automated-gates.json` contains `windows_stagearchive_retained_capability` = PASS, bound to the final source and native backup result. |
Additional failures exposed by the required unfiltered gate were fixed without narrowing the
workflow: Windows secret-bearing archive reservation is protected before use; StageArchive shares
one retained root capability across both staged files; claim/consume transitions serialize the
complete public validation and retained-handle operation while preserving ACL, hard-link identity,
reparse rejection, and no-delete invariants.
## RED → GREEN record
### Initial RED
- Run `32122302381`:
https://github.com/mptyl/ThothII/actions/runs/32122302381
- Source: `b31b27e5845ffd3adf311429367319beaba263c7`.
- Windows job: `95665197885`.
- Result: native `safeio`/`backup` failure, including the 10-minute restore lifecycle timeout;
`authstorage` was absent from the command. This established the RED for Important 2–4 and the
required native authority.
- Cleanup failure-injection tests added for Important 1 first exposed the short-circuit behavior
before the implementation was changed.
### Final concurrency RED
- Run `32140481263`:
https://github.com/mptyl/ThothII/actions/runs/32140481263
- Source: `b48e9e9189dd0e8083db9bd0378704524e670edb`.
- Windows job: `95721724645`.
- Native results: backup PASS (`20.757s`), authstorage PASS (`104.180s`), safeio FAIL
(`63.502s`). The only failures were:
- `TestCanonicalPrivateClaimWaitsForRetainedRemoveOperation`: the concurrent claim returned
`false, unsafe file` before retained removal completed;
- `TestCanonicalPrivateClaimConsumeHasOneConcurrentWinner`: iteration 8 returned `unsafe file`.
- Diagnosis: the process mutex started below `validateClaimPaths`; a concurrent caller could fail
while reopening the retained no-delete directory before reaching the lock.
### GREEN implementation and local gates
The lock boundary was moved to the three public claim/read/remove APIs, covering validation,
relative operation, and handle close. The Unix implementation uses a no-op boundary and retains its
existing descriptor-relative semantics.
Final-source local commands passed:
```text
go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1
go test -race ./...
go vet ./...
go build -o /tmp/thothii-tht-host ./cmd/tht
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -o /tmp/thothii-tht-windows.exe ./cmd/tht
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ... ./internal/{safeio,backup,authstorage}
```
- Focused host package times: safeio `8.750s`, backup `8.378s`, authstorage `8.854s`.
- Race suite and vet: PASS.
- Host CLI: Mach-O arm64; Windows CLI and all three Windows test binaries: PE32+ x86-64.
- Cross-compilation remains compile-only and is not used as native proof.
## Exact-source native certification
- Run: `32141428407`
- URL: https://github.com/mptyl/ThothII/actions/runs/32141428407
- Event/status/conclusion: `workflow_dispatch` / `completed` / `failure`.
- Head SHA: `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` — exact final source match.
- Windows job: `Windows clone and Compose contract`, job `95724751282`:
https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751282
- Native step: `Run native Windows retained-capability tests` — **PASS**.
- Exact command: `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`.
- Native package results:
- safeio PASS (`8.230s`);
- backup PASS (`5.195s`);
- authstorage PASS (`8.383s`).
- Job conclusion: `failure` only because the following `Verify Windows clone contract` baseline
step failed with a PowerShell `ParserError` at
`scripts/test-windows-clone-contract.ps1:208`; `$remoteYaml:` is not delimited before `:`.
## Remaining branch/release blockers
| Gate | Classification | Exact outcome |
|---|---|---|
| Windows native authentication packages | PASS | All three required packages executed on final source. |
| Windows clone contract | FAIL / baseline | Executed after native PASS; PowerShell parser error at line 208. |
| LF, Compose, docs, and TypeScript | FAIL / baseline CI contract | Job `95724751205`; unified Compose passed, then `test-no-deployment-coupling-scope.sh` failed because `TMPDIR` was unset. Downstream skipped commands are `NOT_RUN` / `BLOCKED`. |
| Linux Docker deployment and rollback | FAIL / infrastructure prerequisite | Job `95724751356`; executed smoke stopped because `rg` was unavailable. Cleanup proof passed; no new image manifest was generated. |
| Native Windows Docker Desktop/WSL2 startup | NOT_RUN / BLOCKED | Job `95724752028` was skipped by workflow conditions; no Docker/WSL2 command executed. |
| Harness/Ruff/other historical baseline gates | FAIL | Retained with their recorded source and results; not rewritten as final-source proof. |
| L2, real PSD/manual acceptance, provider readiness | PENDING | Required secrets, identity/access, or provider prerequisites remain unavailable. |
The historical Docker image manifest remains bound to source
`74b062f1a737103524cbe706346cfd65f87cdfd1`; it was not reused as proof for the final source.
## Principal source commits
- `cd5f505` — exhaustive cleanup, Windows authority foundation, restore deadlock tests/fix, and
complete workflow/plan package command.
- `a0e05ad` through `b6396e6` — effective full-control DACL semantics, valid NT attributes/access,
self-relative descriptors, retained no-delete fixture ordering, and Windows installation fixture
protection.
- `824245d` — preserve existing lifecycle ACL trees instead of mutating inherited authority.
- `455fffb`, `2d1670e`, `c01482c`, `9fc1a15` — concurrent claim/consume and settled-loss handling.
- `6474118` — one retained StageArchive root capability shared across staged files.
- `feee4ee` — unified Windows path wrappers on the retained primitive.
- `b261dd4` — bounded private-root sharing contention handling.
- `b48e9e9` — deterministic retained-remove concurrency regression and claim-operation lock.
- `10cd66f` — final lock boundary includes public path validation; frozen source.
## Files changed
Source changes relative to the fix-round base:
- `.github/workflows/deployment.yml`;
- `docs/superpowers/plans/2026-08-18-thothii-authentication-remediation.md`;
- `tools/tht/internal/authstorage/storage_test.go`;
- `tools/tht/internal/backup/{create.go,create_test.go,fixture_security_unix_test.go,fixture_security_windows_test.go,preflight.go,preflight_test.go,preflight_windows_test.go,restore.go,restore_test.go}`;
- `tools/tht/internal/safeio/{claim_unix.go,claim_windows.go,claim_windows_test.go,files.go,files_test.go,private_root_windows.go,private_windows.go,private_windows_test.go}`.
Evidence/status changes are restricted to:
- `.artifacts/task-15/automated-gates.json`;
- `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`;
- `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-1-report.md`;
- `.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`;
- `PROJECT_STATE.md`.
Machine-readable evidence SHA-256:
`5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`.
## Git and protection status
- The evidence commit contains only the five evidence/status files listed above; no source is
changed after frozen source `10cd66fe6a5b484a4dc569326a228c1c5484a5d4`.
- After the evidence commit and push, the intended status is synchronized
`feat/thoth-auth...origin/feat/thoth-auth` with only protected untracked `.playwright-cli/` and
`.thothctl/`.
- `AGENTS.md`, `CLAUDE.md`, and `docs/agents/` are untouched. No generated `tools/tht/tht` exists.
- Evidence commit SHA is reported externally after commit creation because a commit cannot contain
its own final hash.
@@ -1,6 +1,36 @@
# Task 4 authentication remediation recertification (sanitized) # Task 4 authentication remediation recertification (sanitized)
## Result ## Fix-round-1 recertification — Windows remediation PASS
- Exact source: `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on `feat/thoth-auth`.
- Authorized workflow: completed run `32141428407`,
https://github.com/mptyl/ThothII/actions/runs/32141428407, exact matching head SHA.
- Native job: `Windows clone and Compose contract`, job `95724751282`.
- Required native step: `Run native Windows retained-capability tests` — **PASS**.
- Exact unfiltered command:
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`.
- Package evidence: `internal/safeio` PASS (`8.230s`), `internal/backup` PASS (`5.195s`),
`internal/authstorage` PASS (`8.383s`). This includes explicit native Windows
StageArchive retained-capability and concurrent claim-consume coverage.
- The later `Verify Windows clone contract` step failed independently at
`scripts/test-windows-clone-contract.ps1:208`: PowerShell parsed `$remoteYaml:` as an invalid
variable reference. This baseline deployment-contract failure does not change the native Go
package result.
- The optional `Native Windows Docker Desktop/WSL2 startup` job was skipped by workflow
conditions. It is `NOT_RUN` / `BLOCKED`, because no Docker Desktop/WSL2 command executed.
- The workflow reached `completed` with conclusion `failure`: the native authentication step is
PASS, while the later clone-contract, LF/Compose, and Linux Docker baseline steps are FAIL.
- Existing LF/Compose and Linux Docker failures repeated before downstream work. Skipped commands
are `NOT_RUN` / `BLOCKED`, not executed failures. External L2/PSD/provider gates remain
`PENDING`.
All four final-review Important findings are addressed. Authentication implementation is complete
for this fix round; overall release readiness remains `FAIL` because the unrelated deployment,
Compose, harness/Ruff, Docker-runner, and external/manual gates above are not green.
The section below is retained as historical evidence for the pre-fix frozen source.
## Historical pre-fix result
- Frozen source under test: `b31b27e5845ffd3adf311429367319beaba263c7` on `feat/thoth-auth`. - Frozen source under test: `b31b27e5845ffd3adf311429367319beaba263c7` on `feat/thoth-auth`.
- Freeze check: PASS. No tracked source changed during certification. The only untracked paths - Freeze check: PASS. No tracked source changed during certification. The only untracked paths
@@ -74,7 +104,7 @@ was run locally after the failure.
## Evidence and provenance ## Evidence and provenance
- Current machine-readable matrix: `.artifacts/task-15/automated-gates.json`; SHA-256 - Current machine-readable matrix: `.artifacts/task-15/automated-gates.json`; SHA-256
`e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`. `5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`.
- Current requested report: this file (SHA-256 recorded after the evidence commit if needed for - Current requested report: this file (SHA-256 recorded after the evidence commit if needed for
external indexing). external indexing).
- Historical Docker image manifest: `.artifacts/task-15/unified-docker-images.json`, unchanged - Historical Docker image manifest: `.artifacts/task-15/unified-docker-images.json`, unchanged
+30 -32
View File
@@ -7,41 +7,39 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base > ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 4 recertification recorded; native Windows authority failed and > Last updated: 2026-08-18 (final-review fix round 1 recorded; native Windows authentication gate
> the authentication feature is not implementation- or release-complete). > passed, implementation is complete, and unrelated release gates remain open).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work. > Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 4 authentication recertification — FAIL, native Windows CHANGES REQUIRED (2026-08-18) ### Authentication final-review fix round 1 — implementation PASS, release gates remain (2026-08-18)
- Frozen source under test is `b31b27e5845ffd3adf311429367319beaba263c7` on `feat/thoth-auth`. - Frozen source is `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on `feat/thoth-auth`.
No tracked source changed during certification; only `.playwright-cli/` and `.thothctl/` remain Source and evidence are separate commits; `.playwright-cli/` and `.thothctl/` remain the only
untracked. untracked paths.
- Local PASS: Go focused security tests for `safeio`, `backup`, and `authstorage`; Go race across - Local PASS on the frozen source: exact `safeio`/`backup`/`authstorage` tests, full Go race suite,
18 packages; `go vet`; host build; Windows amd64 cross-compile; Node `v24.16.0` backend `go vet`, macOS host build, Windows amd64 package cross-compiles, and Windows CLI build.
`76/1092` and frontend `61/444` with typecheck/build; authentication/F1 smoke and sentinel - Authorized exact-source workflow run `32141428407` completed on the exact frozen SHA and
scan; authentication docs smoke; shell syntax. executed the unfiltered native command
- Local FAIL: harness `951 passed / 1 failed / 4 skipped` (the F4 column-decision test cannot find `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. The required step
`workflow.yaml` from its test cwd); Ruff `192` errors; default Compose missing its required passed: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`. Native Windows StageArchive and
workspace-remote variable; unified Compose references absent `compose.unified.yaml`. concurrent claim-consume evidence are therefore PASS, not inferred from cross-compilation.
- Authorized workflow run `32122302381` (URL in the Task 4 report) has the exact frozen SHA and - The same Windows job later failed the unrelated clone-contract script at
conclusion `failure`. Its `Windows clone and Compose contract` job `95665197885` really ran the `scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a valid PowerShell
native `safeio`/`backup` command and failed, including a 10-minute backup lifecycle-lock variable reference. LF/Compose and Linux Docker baseline failures also repeated. The optional
timeout. The frozen workflow does not request `internal/authstorage`, so that native evidence is Windows Docker startup job was skipped without executing and is `NOT_RUN` / `BLOCKED`; the
absent rather than inferred from cross-compilation. overall completed run conclusion is `failure` because the baseline jobs remain red.
- The same run's LF/Compose/docs/TS job failed on an unset `TMPDIR` after its unified Compose - Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to
contract passed (baseline/CI contract). Its Linux Docker job failed before deployment because its recorded source where not rerun. L2, PSD/manual, and provider prerequisites remain
`rg` was unavailable; cleanup proof passed and no new image manifest was generated (runner `PENDING`; no new Docker image manifest was generated.
prerequisite). The historical five-image manifest remains bound to source - Durable evidence: `.artifacts/task-15/automated-gates.json`,
`74b062f1a737103524cbe706346cfd65f87cdfd1` and was not rewritten for this candidate. L2, real `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`, and
PSD/manual acceptance, and provider readiness remain `PENDING` where prerequisites are unavailable. `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-1-report.md`.
- Durable current evidence is tracked in `.artifacts/task-15/automated-gates.json` and - Current automated-gates SHA-256 is
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`; the historical `5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`; the historical Docker
Task 15 report contains a separate Task 4 addendum. Current automated-gates SHA-256 is manifest remains bound to its recorded older source and was not reused for this candidate.
`e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`; the unchanged historical - **State:** all four final-review Important findings are addressed and authentication
Docker manifest SHA-256 is `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. implementation is complete. Overall release readiness remains `FAIL` until the unrelated
- **Implementation/release state: NOT COMPLETE.** The three Important findings remain deployment, Docker-runner, baseline, and external/manual gates are resolved.
`CHANGES_REQUIRED`; overall release readiness is `FAIL` with additional `PENDING` gates. No
source fix was attempted in Task 4.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13) ### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)