docs(auth): record fix round 2 certification

This commit is contained in:
2026-08-18 16:29:09 +02:00
parent 2a93590712
commit 361d55a9c2
5 changed files with 220 additions and 66 deletions
+36 -30
View File
@@ -1,9 +1,9 @@
{ {
"schema": "thothii-task4-certification-v1", "schema": "thothii-task4-certification-v1",
"generated_on": "2026-08-18", "generated_on": "2026-08-18",
"started_at_utc": "2026-08-18T09:26:00Z", "started_at_utc": "2026-08-18T14:16:40Z",
"ended_at_utc": "2026-08-18T13:18:56Z", "ended_at_utc": "2026-08-18T14:20:10Z",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"source_immutability": { "source_immutability": {
"status": "PASS", "status": "PASS",
"tracked_changes_after_freeze": false, "tracked_changes_after_freeze": false,
@@ -16,6 +16,7 @@
"task3": "0d8e707533fada938c99eb06f8457150e7ef2b40", "task3": "0d8e707533fada938c99eb06f8457150e7ef2b40",
"task3_follow_up": "b31b27e5845ffd3adf311429367319beaba263c7", "task3_follow_up": "b31b27e5845ffd3adf311429367319beaba263c7",
"fix_round_1_source": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "fix_round_1_source": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4",
"fix_round_2_source": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"historical_task15_final": "74b062f1a737103524cbe706346cfd65f87cdfd1" "historical_task15_final": "74b062f1a737103524cbe706346cfd65f87cdfd1"
}, },
"versions": { "versions": {
@@ -26,17 +27,18 @@
}, },
"retained_report": ".superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md", "retained_report": ".superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md",
"task4_report": ".superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md", "task4_report": ".superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md",
"fix_round_2_report": ".superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md",
"workflow": { "workflow": {
"run_id": "32141428407", "run_id": "32147345625",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407", "url": "https://github.com/mptyl/ThothII/actions/runs/32147345625",
"event": "workflow_dispatch", "event": "workflow_dispatch",
"head_sha": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "head_sha": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"status": "completed", "status": "completed",
"conclusion": "failure", "conclusion": "failure",
"windows_job": { "windows_job": {
"name": "Windows clone and Compose contract", "name": "Windows clone and Compose contract",
"job_id": "95724751282", "job_id": "95744249248",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751282", "url": "https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249248",
"conclusion": "failure", "conclusion": "failure",
"native_step": "Run native Windows retained-capability tests", "native_step": "Run native Windows retained-capability tests",
"native_step_conclusion": "success", "native_step_conclusion": "success",
@@ -45,9 +47,9 @@
"executed_packages": ["internal/safeio", "internal/backup", "internal/authstorage"], "executed_packages": ["internal/safeio", "internal/backup", "internal/authstorage"],
"not_executed_packages": [], "not_executed_packages": [],
"package_results": { "package_results": {
"internal/safeio": "PASS (8.230s)", "internal/safeio": "PASS (22.058s)",
"internal/backup": "PASS (5.195s)", "internal/backup": "PASS (7.161s)",
"internal/authstorage": "PASS (8.383s)" "internal/authstorage": "PASS (16.088s)"
}, },
"failed_step": "Verify Windows clone contract", "failed_step": "Verify Windows clone contract",
"failure_category": "baseline_powershell_parser", "failure_category": "baseline_powershell_parser",
@@ -55,8 +57,8 @@
}, },
"lf_compose_docs_typescript_job": { "lf_compose_docs_typescript_job": {
"name": "LF, Compose, docs, and TypeScript", "name": "LF, Compose, docs, and TypeScript",
"job_id": "95724751205", "job_id": "95744249458",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751205", "url": "https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249458",
"conclusion": "failure", "conclusion": "failure",
"failed_step": "Verify Compose and installation contracts", "failed_step": "Verify Compose and installation contracts",
"category": "baseline_ci_contract", "category": "baseline_ci_contract",
@@ -65,8 +67,8 @@
}, },
"linux_docker_job": { "linux_docker_job": {
"name": "Linux Docker deployment and rollback", "name": "Linux Docker deployment and rollback",
"job_id": "95724751356", "job_id": "95744249354",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724751356", "url": "https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249354",
"conclusion": "failure", "conclusion": "failure",
"failed_step": "Run unified deployment smoke", "failed_step": "Run unified deployment smoke",
"category": "infrastructure_prerequisite", "category": "infrastructure_prerequisite",
@@ -76,8 +78,8 @@
}, },
"windows_docker_startup_job": { "windows_docker_startup_job": {
"name": "Native Windows Docker Desktop/WSL2 startup", "name": "Native Windows Docker Desktop/WSL2 startup",
"job_id": "95724752028", "job_id": "95744250450",
"url": "https://github.com/mptyl/ThothII/actions/runs/32141428407/job/95724752028", "url": "https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744250450",
"status": "NOT_RUN", "status": "NOT_RUN",
"classification": "BLOCKED", "classification": "BLOCKED",
"workflow_conclusion": "skipped", "workflow_conclusion": "skipped",
@@ -92,9 +94,9 @@
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "FAIL", "status": "FAIL",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"run_id": "32141428407", "run_id": "32147345625",
"workflow_job_id": "95724751356", "workflow_job_id": "95744249354",
"manifest": ".artifacts/task-15/unified-docker-images.json", "manifest": ".artifacts/task-15/unified-docker-images.json",
"reason": "workflow attempt stopped before deployment because rg is required", "reason": "workflow attempt stopped before deployment because rg is required",
"cleanup": "PASS", "cleanup": "PASS",
@@ -122,12 +124,12 @@
}, },
"windows_stagearchive_retained_capability": { "windows_stagearchive_retained_capability": {
"status": "PASS", "status": "PASS",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"evidence": "native Windows backup package passed, including the two-file shared retained-root staging test" "evidence": "native Windows backup package passed, including the two-file shared retained-root staging test"
}, },
"windows_claim_retained_capability": { "windows_claim_retained_capability": {
"status": "PASS", "status": "PASS",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"evidence": "native Windows safeio and authstorage packages passed concurrent claim/consume coverage" "evidence": "native Windows safeio and authstorage packages passed concurrent claim/consume coverage"
}, },
"workflow_lf_compose_docs_typescript": { "workflow_lf_compose_docs_typescript": {
@@ -142,7 +144,7 @@
}, },
"go_security_build": { "go_security_build": {
"status": "PASS", "status": "PASS",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"focused_packages": 3, "focused_packages": 3,
"race_packages": 18, "race_packages": 18,
"focused_test": "PASS", "focused_test": "PASS",
@@ -152,7 +154,7 @@
}, },
"windows_cross_compile": { "windows_cross_compile": {
"status": "PASS", "status": "PASS",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"focused_test_packages": 3, "focused_test_packages": 3,
"cli_build": "PASS", "cli_build": "PASS",
"execution": "cross_compile_only_not_native_execution" "execution": "cross_compile_only_not_native_execution"
@@ -215,8 +217,8 @@
}, },
"unified_docker_smoke": { "unified_docker_smoke": {
"status": "FAIL", "status": "FAIL",
"source_commit": "10cd66fe6a5b484a4dc569326a228c1c5484a5d4", "source_commit": "2a9359071257f9b8a71d36ec2bbb25b161003f81",
"workflow_run_id": "32141428407", "workflow_run_id": "32147345625",
"reason": "remote workflow attempted the smoke but stopped before deployment because rg is required", "reason": "remote workflow attempted the smoke but stopped before deployment because rg is required",
"cleanup": "PASS", "cleanup": "PASS",
"image_manifest": "not_generated" "image_manifest": "not_generated"
@@ -266,11 +268,15 @@
} }
}, },
"review": { "review": {
"four_important_findings_closed": true, "original_important_findings_resolved": 3,
"verdict": "ADDRESSED", "fix_round_2_important_lifecycle": "ADDRESSED",
"reason": "the exact-source native Windows step passed safeio, backup, and authstorage; cleanup and deadlock tests are green and the workflow command includes all three packages" "fix_round_2_minor_windows_diagnostics": "ADDRESSED",
"verdict": "PASS",
"reason": "the lifecycle controller is bounded and cancellation-aware with cancel, bounded join, and lock-release proof; the temporary Windows diagnostic matrix is removed; exact-source native safeio, backup, and authstorage all pass"
}, },
"remediation_status": "PASS",
"release_complete": false, "release_complete": false,
"authentication_implementation_complete": true, "authentication_implementation_complete": true,
"release_readiness": "FAIL" "release_readiness": "FAIL",
"release_readiness_pending_external_gates": true
} }
@@ -1,22 +1,24 @@
# Task 15 retained release-gate report — fix round 5 (sanitized) # Task 15 retained release-gate report — fix round 5 (sanitized)
## Final-review fix-round-1 addendum — frozen source `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` ## Final-review fix-round-2 addendum — frozen source `2a9359071257f9b8a71d36ec2bbb25b161003f81`
This addendum supersedes the earlier Task 4 pre-fix certification for current authentication This addendum supersedes the fix-round-1 addendum for current authentication remediation status
remediation status while preserving the fix-round-5 material below as historical provenance. while preserving the fix-round-5 material below as historical provenance.
- Authentication remediation status: implementation `PASS`; all four final-review Important - Authentication remediation status: `PASS`. The three original remediation Important findings
findings are addressed. Overall branch/release readiness remains `FAIL` with external gates remain `RESOLVED`; the fix-round-2 fully bounded lifecycle Important is `ADDRESSED`; and the
temporary Windows diagnostic-matrix Minor is `ADDRESSED`.
- Overall branch/release readiness is separately `FAIL`, with unavailable external/manual gates
`PENDING`. `PENDING`.
- Completed exact-source workflow run `32141428407` concluded `failure` on baseline release jobs. - Completed exact-source workflow run `32147345625` concluded `failure` on baseline release jobs.
Its `Windows clone and Compose contract` job (`95724751282`) executed the unfiltered command Its `Windows clone and Compose contract` job (`95744249248`) executed the unfiltered command
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step
passed all three packages: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`. passed all three packages: safeio `22.058s`, backup `7.161s`, authstorage `16.088s`.
- The Windows job failed only afterward in the baseline clone-contract script at - The Windows job failed only afterward in the baseline clone-contract script at
`scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited `scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited
`$remoteYaml:` variable reference. `$remoteYaml:` variable reference.
- `LF, Compose, docs, and TypeScript` job `95724751205` reproduced the baseline unset-`TMPDIR` - `LF, Compose, docs, and TypeScript` job `95744249458` reproduced the baseline unset-`TMPDIR`
failure after unified Compose passed. Linux Docker job `95724751356` reproduced the missing-`rg` failure after unified Compose passed. Linux Docker job `95744249354` reproduced the missing-`rg`
prerequisite failure; cleanup passed and no image manifest was generated. prerequisite failure; cleanup passed and no image manifest was generated.
- The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL. - The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL.
Downstream commands skipped after executed baseline failures use the same classification. The Downstream commands skipped after executed baseline failures use the same classification. The
@@ -27,7 +29,10 @@ remediation status while preserving the fix-round-5 material below as historical
- Current machine-readable evidence and the requested Task 4 report are recorded in - Current machine-readable evidence and the requested Task 4 report are recorded in
`.artifacts/task-15/automated-gates.json` and `.artifacts/task-15/automated-gates.json` and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`. `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
- Current automated-gates SHA-256: `5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`. - The full fix-round-2 RED/GREEN and finding disposition is recorded in
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`.
- Current automated-gates SHA-256:
`6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`.
- Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. - Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the
@@ -0,0 +1,133 @@
# Final-review fix round 2 report (sanitized)
## Verdict
- Base evidence head: `0f762ad6b67675356389cc546421a1c46ad5a736`.
- Frozen source: `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.
- Authentication remediation: **PASS**.
- Three original remediation Important findings: **RESOLVED**.
- Fix-round-2 bounded lifecycle Important: **ADDRESSED**.
- Fix-round-2 temporary Windows diagnostics Minor: **ADDRESSED**.
- Release readiness: **FAIL** for executed unrelated baseline gates, with unavailable
external/manual gates separately **PENDING**.
- Source and evidence are separate commits. The evidence-only phase changed no source or tests and
dispatched no workflow.
## Finding disposition
| Finding | Disposition | Evidence |
|---|---|---|
| Original Important — POSIX local-registry ownership | RESOLVED | Effective-UID ownership enforcement and its Node 24 coverage remain green at their recorded source. Fix round 2 did not alter this boundary. |
| Original Important — retained-capability StageArchive lifecycle | RESOLVED | Native Windows `internal/backup` passed on the exact source, preserving the retained-root staging and cleanup coverage. |
| Original Important — handle-relative Windows claim removal | RESOLVED | Native Windows `internal/safeio` and `internal/authstorage` passed on the exact source, including retained claim/consume coverage. |
| Fix-round-2 Important — fully bounded restore lifecycle test | ADDRESSED | Gate publication and release are context-aware; stage, outcome, admission, checkpoint, and verification waits are bounded; aborts cancel, safely release, bounded-join, then assert lock-free. The deterministic withheld-gate test proves prompt timeout/cancellation, worker join, and eventual lock release. |
| Fix-round-2 Minor — temporary Windows diagnostic matrix | ADDRESSED | `windowsRelativeOpenMatrix` and its diagnostic-only call/import were removed. Owner-only DACL shape, NT access normalization, full-control, cleanup, and retained no-delete tests remain. |
The round-1 restore lifecycle finding was broadened by the scoped round-2 review: bounded release
alone was insufficient while stage publication, gate waits, and nearby outcome/admission waits
could still outlive a controller abort. The round-2 implementation closes that broader test
orchestration gap without changing production authentication semantics.
## RED → GREEN record
### RED
The deterministic withheld-gate regression was introduced first and run without relying on a
global ten-minute package timeout:
```text
go test ./internal/backup -run '^TestRestoreLifecycleCancellationJoinsWithWithheldGate$' -count=1
```
It failed in approximately `0.64s` with:
```text
cancelled restore worker did not join within the bounded deadline
```
This proved that cancellation did not yet unblock and join a worker retained at the lifecycle
gate.
### GREEN and refactor
- The gate uses a cancellation source shared by controller and worker. Both publication and
release are `select`-based and cancellation-aware.
- Shared bounded helpers cover stage, outcome, error, signal, release, and admission waits.
- Abort cleanup is ordered: cancel, cancel the controller gate when distinct, safely release a
pending gate, bounded-join the worker, then prove the lifecycle lock is free.
- Premature worker outcomes retain and surface their original error.
- The existing success, recovery, maintenance-barrier, stale-checkpoint, and verification
assertions remain active.
Final local gates on the frozen source:
```text
go test ./internal/backup -run '^(TestRestoreLifecycleCancellationJoinsWithWithheldGate|TestReleaseLifecycleStage|TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup|TestRestoreCannotApplyAStaleCheckpointOverAnInterleavedRestore|TestRestoreKeepsAdmissionBarrierActiveUntilVerificationCommits)$' -count=1
go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1
go test ./... -count=1
go test -race ./...
go vet ./...
go build -o /tmp/thothii-tht-host-fix-round-2 ./cmd/tht
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/safeio -o /tmp/tht-safeio-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/backup -o /tmp/tht-backup-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/authstorage -o /tmp/tht-authstorage-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -o /tmp/thothii-tht-fix-round-2-windows.exe ./cmd/tht
```
All commands passed. The final focused lifecycle run completed in `0.672s`; the full security
package run passed safeio, backup, and authstorage; race, vet, host build, Windows test-package
cross-compiles, and Windows CLI cross-compile also passed. Cross-compilation is recorded only as
compile evidence and is not used as native authority.
## Exact-source native certification
- Controller-authorized run: `32147345625` —
https://github.com/mptyl/ThothII/actions/runs/32147345625.
- Event/status/conclusion: `workflow_dispatch` / `completed` / `failure`.
- Head SHA: `2a9359071257f9b8a71d36ec2bbb25b161003f81`, exactly matching the frozen source.
- Windows job: `Windows clone and Compose contract`, job `95744249248` —
https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249248.
- Native step: `Run native Windows retained-capability tests` — **PASS**.
- Exact unfiltered command:
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`.
- Native package results:
- `internal/safeio` PASS (`22.058s`);
- `internal/backup` PASS (`7.161s`);
- `internal/authstorage` PASS (`16.088s`).
The Windows job failed only in the following baseline clone-contract step. PowerShell reported a
parser error at `scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a
delimited variable reference. This later failure does not alter the successful native Go step.
## Separate release-readiness verdict
| Gate | Classification | Exact outcome |
|---|---|---|
| Authentication remediation | PASS | Source and exact-source native three-package authority are green. |
| Windows clone contract | FAIL / baseline | Job `95744249248`; parser error at `scripts/test-windows-clone-contract.ps1:208`, after native PASS. |
| LF, Compose, docs, and TypeScript | FAIL / baseline CI contract | Job `95744249458`; unified Compose passed, then the existing unset-`TMPDIR` failure stopped the contract step. Downstream commands were skipped. |
| Linux Docker deployment and rollback | FAIL / infrastructure prerequisite | Job `95744249354`; the existing missing-`rg` prerequisite stopped the smoke before deployment. Cleanup passed and no new image manifest was generated. |
| Native Windows Docker Desktop/WSL2 startup | NOT_RUN / BLOCKED | Job `95744250450` was skipped by workflow conditions; no native Docker/WSL2 command ran. |
| L2, real PSD/manual acceptance, provider readiness | PENDING | Required secrets, identity/access, or provider prerequisites remain unavailable. |
Executed failures remain `FAIL`; skipped commands are `NOT_RUN` / `BLOCKED`; unavailable external
gates remain `PENDING`. Therefore remediation PASS does not imply release readiness PASS.
## Evidence and protection status
- Machine-readable evidence: `.artifacts/task-15/automated-gates.json`; SHA-256
`6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`.
- Current Task 4 report:
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
- Retained Task 15 report:
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`.
- Project snapshot: `PROJECT_STATE.md`.
- Historical Docker evidence remains bound to its recorded older source and is not reused as proof
for `2a9359071257f9b8a71d36ec2bbb25b161003f81`.
- `.playwright-cli/` and `.thothctl/` remain protected and untracked. No source/test file,
instruction file, workflow, or `docs/agents/` content changed in this evidence phase.
- The separate evidence commit SHA is reported after commit creation because a commit cannot
contain its own final hash.
No credentials, tokens, internal endpoints, identities, registry names, raw environments, or
browser traces are retained in this report.
@@ -1,16 +1,16 @@
# Task 4 authentication remediation recertification (sanitized) # Task 4 authentication remediation recertification (sanitized)
## Fix-round-1 recertification — Windows remediation PASS ## Fix-round-2 recertification — remediation PASS
- Exact source: `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on `feat/thoth-auth`. - Exact source: `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.
- Authorized workflow: completed run `32141428407`, - Authorized workflow: completed run `32147345625`,
https://github.com/mptyl/ThothII/actions/runs/32141428407, exact matching head SHA. https://github.com/mptyl/ThothII/actions/runs/32147345625, exact matching head SHA.
- Native job: `Windows clone and Compose contract`, job `95724751282`. - Native job: `Windows clone and Compose contract`, job `95744249248`.
- Required native step: `Run native Windows retained-capability tests` — **PASS**. - Required native step: `Run native Windows retained-capability tests` — **PASS**.
- Exact unfiltered command: - Exact unfiltered command:
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`.
- Package evidence: `internal/safeio` PASS (`8.230s`), `internal/backup` PASS (`5.195s`), - Package evidence: `internal/safeio` PASS (`22.058s`), `internal/backup` PASS (`7.161s`),
`internal/authstorage` PASS (`8.383s`). This includes explicit native Windows `internal/authstorage` PASS (`16.088s`). This includes explicit native Windows
StageArchive retained-capability and concurrent claim-consume coverage. StageArchive retained-capability and concurrent claim-consume coverage.
- The later `Verify Windows clone contract` step failed independently at - The later `Verify Windows clone contract` step failed independently at
`scripts/test-windows-clone-contract.ps1:208`: PowerShell parsed `$remoteYaml:` as an invalid `scripts/test-windows-clone-contract.ps1:208`: PowerShell parsed `$remoteYaml:` as an invalid
@@ -20,13 +20,15 @@
conditions. It is `NOT_RUN` / `BLOCKED`, because no Docker Desktop/WSL2 command executed. conditions. It is `NOT_RUN` / `BLOCKED`, because no Docker Desktop/WSL2 command executed.
- The workflow reached `completed` with conclusion `failure`: the native authentication step is - The workflow reached `completed` with conclusion `failure`: the native authentication step is
PASS, while the later clone-contract, LF/Compose, and Linux Docker baseline steps are FAIL. PASS, while the later clone-contract, LF/Compose, and Linux Docker baseline steps are FAIL.
- Existing LF/Compose and Linux Docker failures repeated before downstream work. Skipped commands - Existing LF/Compose job `95744249458` and Linux Docker job `95744249354` failures repeated
are `NOT_RUN` / `BLOCKED`, not executed failures. External L2/PSD/provider gates remain before downstream work. Skipped commands are `NOT_RUN` / `BLOCKED`, not executed failures.
`PENDING`. External L2/PSD/provider gates remain `PENDING`.
All four final-review Important findings are addressed. Authentication implementation is complete Finding disposition is explicit: the three original remediation Important findings remain
for this fix round; overall release readiness remains `FAIL` because the unrelated deployment, **RESOLVED**; the fix-round-2 lifecycle Important is **ADDRESSED**; and the temporary Windows
Compose, harness/Ruff, Docker-runner, and external/manual gates above are not green. diagnostic-matrix Minor is **ADDRESSED**. Authentication remediation is **PASS**. This does not
change overall release readiness: executed baseline gates remain **FAIL**, while unavailable
external/manual gates remain **PENDING**.
The section below is retained as historical evidence for the pre-fix frozen source. The section below is retained as historical evidence for the pre-fix frozen source.
@@ -104,9 +106,11 @@ was run locally after the failure.
## Evidence and provenance ## Evidence and provenance
- Current machine-readable matrix: `.artifacts/task-15/automated-gates.json`; SHA-256 - Current machine-readable matrix: `.artifacts/task-15/automated-gates.json`; SHA-256
`5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`. `6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`.
- Current requested report: this file (SHA-256 recorded after the evidence commit if needed for - Current requested report: this file (SHA-256 recorded after the evidence commit if needed for
external indexing). external indexing).
- Current fix-round report:
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`.
- Historical Docker image manifest: `.artifacts/task-15/unified-docker-images.json`, unchanged - Historical Docker image manifest: `.artifacts/task-15/unified-docker-images.json`, unchanged
because no new immutable-source Docker smoke ran. Its retained historical SHA-256 is because no new immutable-source Docker smoke ran. Its retained historical SHA-256 is
`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`, bound to historical source `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`, bound to historical source
+17 -11
View File
@@ -7,21 +7,26 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base > ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (final-review fix round 1 recorded; native Windows authentication gate > Last updated: 2026-08-18 (final-review fix round 2 recorded; native Windows authentication gate
> passed, implementation is complete, and unrelated release gates remain open). > passed, remediation is complete, and unrelated release gates remain open).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work. > Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Authentication final-review fix round 1 — implementation PASS, release gates remain (2026-08-18) ### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18)
- Frozen source is `10cd66fe6a5b484a4dc569326a228c1c5484a5d4` on `feat/thoth-auth`. - Frozen source is `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.
Source and evidence are separate commits; `.playwright-cli/` and `.thothctl/` remain the only Source and evidence are separate commits; `.playwright-cli/` and `.thothctl/` remain the only
untracked paths. untracked paths.
- Local PASS on the frozen source: exact `safeio`/`backup`/`authstorage` tests, full Go race suite, - Local PASS on the frozen source: exact `safeio`/`backup`/`authstorage` tests, full Go race suite,
`go vet`, macOS host build, Windows amd64 package cross-compiles, and Windows CLI build. `go vet`, macOS host build, Windows amd64 package cross-compiles, and Windows CLI build.
- Authorized exact-source workflow run `32141428407` completed on the exact frozen SHA and - The lifecycle tests now use context-aware gate publication/release, bounded waits for stages,
outcomes and admission, and cancel plus bounded worker join before lock-release assertions. A
deterministic withheld-gate case proves timeout, cancellation, join, and eventual lock release.
The temporary Windows relative-open diagnostic matrix was removed without reducing DACL, NT
normalization, or retained no-delete assertions.
- Authorized exact-source workflow run `32147345625` completed on the exact frozen SHA and
executed the unfiltered native command executed the unfiltered native command
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. The required step `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`. The required step
passed: safeio `8.230s`, backup `5.195s`, authstorage `8.383s`. Native Windows StageArchive and passed: safeio `22.058s`, backup `7.161s`, authstorage `16.088s`. Native Windows StageArchive and
concurrent claim-consume evidence are therefore PASS, not inferred from cross-compilation. concurrent claim-consume evidence are therefore PASS, not inferred from cross-compilation.
- The same Windows job later failed the unrelated clone-contract script at - The same Windows job later failed the unrelated clone-contract script at
`scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a valid PowerShell `scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a valid PowerShell
@@ -33,13 +38,14 @@
`PENDING`; no new Docker image manifest was generated. `PENDING`; no new Docker image manifest was generated.
- Durable evidence: `.artifacts/task-15/automated-gates.json`, - Durable evidence: `.artifacts/task-15/automated-gates.json`,
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`, and `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`, and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-1-report.md`. `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`.
- Current automated-gates SHA-256 is - Current automated-gates SHA-256 is
`5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f`; the historical Docker `6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`; the historical Docker
manifest remains bound to its recorded older source and was not reused for this candidate. manifest remains bound to its recorded older source and was not reused for this candidate.
- **State:** all four final-review Important findings are addressed and authentication - **State:** the three original remediation Important findings remain `RESOLVED`; the fix-round-2
implementation is complete. Overall release readiness remains `FAIL` until the unrelated lifecycle Important is `ADDRESSED`; the Windows diagnostics Minor is `ADDRESSED`; authentication
deployment, Docker-runner, baseline, and external/manual gates are resolved. remediation is `PASS`. Separately, release readiness remains `FAIL`, with L2, PSD/manual, and
provider gates `PENDING`, until unrelated deployment, runner, baseline, and external gates close.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13) ### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)