docs(auth): record final branch review

This commit is contained in:
2026-08-18 09:41:09 +02:00
parent 39b5453287
commit 178113a7e8
2 changed files with 25 additions and 6 deletions
@@ -109,3 +109,17 @@ They do not override the final code-review verdict. Native Windows execution rem
The authentication feature is **not implementation-complete or release-complete** while these code
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
endpoints, or registry names are retained.
## Final whole-branch review
The final read-only Terra review of `351361f..39b5453` also returned **CHANGES REQUIRED** and found
one additional Important issue: the POSIX local-user registry validates file type, link count, and
mode for `users.yaml` and its parent directory, but does not require ownership by the effective UID.
A foreign-owned `0600` registry inside a runtime-owned `0700` directory can remain writable by the
foreign owner and be used to alter credentials or grant the administrator role. The registry must
enforce effective-UID ownership on every POSIX `lstat`/`fstat` path and add foreign-owner rejection
coverage.
No new Critical issue or load-bearing Minor issue was found. The branch is **not ready to merge**:
this ownership defect and the two retained-capability cleanup defects above require fixes and renewed
review, independently of the remaining FAIL/PENDING release gates.