docs(auth): record fix round 2 certification

This commit is contained in:
2026-08-18 16:29:09 +02:00
parent 2a93590712
commit 361d55a9c2
5 changed files with 220 additions and 66 deletions
+17 -11
View File
@@ -7,21 +7,26 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (final-review fix round 1 recorded; native Windows authentication gate
> passed, implementation is complete, and unrelated release gates remain open).
> Last updated: 2026-08-18 (final-review fix round 2 recorded; native Windows authentication gate
> passed, remediation is complete, and unrelated release gates remain open).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Authentication final-review fix round 1 — implementation PASS, release gates remain (2026-08-18)
### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18)
- Frozen source is `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on `feat/thoth-auth`.
- Frozen source is `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.
Source and evidence are separate commits; `.playwright-cli/` and `.thothctl/` remain the only
untracked paths.
- Local PASS on the frozen source: exact `safeio`/`backup`/`authstorage` tests, full Go race suite,
`go vet`, macOS host build, Windows amd64 package cross-compiles, and Windows CLI build.
- Authorized exact-source workflow run `32141428407` completed on the exact frozen SHA and
- The lifecycle tests now use context-aware gate publication/release, bounded waits for stages,
outcomes and admission, and cancel plus bounded worker join before lock-release assertions. A
deterministic withheld-gate case proves timeout, cancellation, join, and eventual lock release.
The temporary Windows relative-open diagnostic matrix was removed without reducing DACL, NT
normalization, or retained no-delete assertions.
- Authorized exact-source workflow run `32147345625` completed on the exact frozen SHA and
executed the unfiltered native command
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. The required step
passed: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`. Native Windows StageArchive and
passed: safeio `22.058s`, backup `7.161s`, authstorage `16.088s`. Native Windows StageArchive and
concurrent claim-consume evidence are therefore PASS, not inferred from cross-compilation.
- The same Windows job later failed the unrelated clone-contract script at
`scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a valid PowerShell
@@ -33,13 +38,14 @@
`PENDING`; no new Docker image manifest was generated.
- Durable evidence: `.artifacts/task-15/automated-gates.json`,
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`, and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-1-report.md`.
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`.
- Current automated-gates SHA-256 is
`5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`; the historical Docker
`6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`; the historical Docker
manifest remains bound to its recorded older source and was not reused for this candidate.
- **State:** all four final-review Important findings are addressed and authentication
implementation is complete. Overall release readiness remains `FAIL` until the unrelated
deployment, Docker-runner, baseline, and external/manual gates are resolved.
- **State:** the three original remediation Important findings remain `RESOLVED`; the fix-round-2
lifecycle Important is `ADDRESSED`; the Windows diagnostics Minor is `ADDRESSED`; authentication
remediation is `PASS`. Separately, release readiness remains `FAIL`, with L2, PSD/manual, and
provider gates `PENDING`, until unrelated deployment, runner, baseline, and external gates close.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)