docs(auth): record final branch review
This commit is contained in:
@@ -109,3 +109,17 @@ They do not override the final code-review verdict. Native Windows execution rem
|
||||
The authentication feature is **not implementation-complete or release-complete** while these code
|
||||
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
|
||||
endpoints, or registry names are retained.
|
||||
|
||||
## Final whole-branch review
|
||||
|
||||
The final read-only Terra review of `351361f..39b5453` also returned **CHANGES REQUIRED** and found
|
||||
one additional Important issue: the POSIX local-user registry validates file type, link count, and
|
||||
mode for `users.yaml` and its parent directory, but does not require ownership by the effective UID.
|
||||
A foreign-owned `0600` registry inside a runtime-owned `0700` directory can remain writable by the
|
||||
foreign owner and be used to alter credentials or grant the administrator role. The registry must
|
||||
enforce effective-UID ownership on every POSIX `lstat`/`fstat` path and add foreign-owner rejection
|
||||
coverage.
|
||||
|
||||
No new Critical issue or load-bearing Minor issue was found. The branch is **not ready to merge**:
|
||||
this ownership defect and the two retained-capability cleanup defects above require fixes and renewed
|
||||
review, independently of the remaining FAIL/PENDING release gates.
|
||||
|
||||
+11
-6
@@ -7,9 +7,8 @@
|
||||
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
|
||||
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-18 (Task 15 fix-round-5 evidence and final review recorded; the final
|
||||
> review is CHANGES REQUIRED and the authentication feature is not implementation- or
|
||||
> release-complete).
|
||||
> Last updated: 2026-08-18 (Task 15 and final whole-branch reviews recorded; both are CHANGES
|
||||
> REQUIRED and the authentication feature is not implementation- or release-complete).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### Task 15 authentication — automated smoke PASS, final review CHANGES REQUIRED (2026-08-18)
|
||||
@@ -49,7 +48,7 @@
|
||||
`.artifacts/task-15/unified-docker-images.json`
|
||||
(`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and
|
||||
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
|
||||
(`67b3ad854457be66ee2525aaf08b8ca2b56b5ee9e6b28e297a7f9b6ede8e526a`). Authentication smoke
|
||||
(`9e4737e84bb9fb866eb0ee9ba2660f0fcfdef0c081dde11f19f6078c59b1bf56`). Authentication smoke
|
||||
exercised no Docker images; the final unified run retained all five exercised image identities.
|
||||
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
|
||||
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
|
||||
@@ -63,9 +62,15 @@
|
||||
cleanup race above, Windows claim removal closes validated retained parent handles before using
|
||||
pathname-based `DeleteFile`, leaving an ancestor-swap race. The five-round breaker is exhausted;
|
||||
no sixth implementation round was started.
|
||||
- Final whole-branch review found one additional Important defect: on POSIX, the local-user registry
|
||||
checks type, link count, and mode but not effective-UID ownership for `users.yaml` and its parent.
|
||||
A foreign-owned `0600` registry can therefore remain writable by that owner and alter local
|
||||
credentials or roles, including administrator access. Add fail-closed ownership checks on every
|
||||
POSIX registry path and foreign-owner rejection coverage.
|
||||
- **Implementation/release state: NOT COMPLETE.** Resolve both Important code-review findings and
|
||||
rerun the affected tests/review, then make every required FAIL/PENDING gate PASS in an eligible
|
||||
environment before marking authentication complete or release-accepted.
|
||||
the registry-ownership finding, rerun the affected tests/reviews, then make every required
|
||||
FAIL/PENDING gate PASS in an eligible environment before marking authentication complete or
|
||||
release-accepted. The branch is not ready to merge.
|
||||
|
||||
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user