docs(auth): record unresolved Task 15 review

This commit is contained in:
2026-08-18 09:27:11 +02:00
parent d7cd8fdf94
commit 39b5453287
2 changed files with 38 additions and 10 deletions
@@ -88,5 +88,24 @@ names and credentials are deliberately omitted.
identity/access is available; isolated provider readiness because an unrelated host port is
occupied.
The authentication feature is **not release-complete** while required FAIL or PENDING gates remain.
No secret values, real identities, internal endpoints, or registry names are retained.
## Final Task 15 review after fix round 5
The fresh Terra review verdict is **CHANGES REQUIRED**. The five-round breaker is exhausted; no
sixth implementation round was started. Two Important findings remain:
- `StageArchive` does not retain the opaque parent/directory capability through the complete
stream and `Close` lifecycle. Staging-directory creation and final cleanup still use pathname
operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect
cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and
native Windows.
- Windows claim removal closes its validated retained parent handles before calling pathname-based
`DeleteFile`. Removal must instead remain handle-relative (or delete through the opened handle),
with a native-Windows ancestor-swap test.
The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability,
and cleanup results above remain valid evidence for source `74b062f1a737103524cbe706346cfd65f87cdfd1`.
They do not override the final code-review verdict. Native Windows execution remains PENDING.
The authentication feature is **not implementation-complete or release-complete** while these code
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
endpoints, or registry names are retained.