docs(auth): record unresolved Task 15 review

This commit is contained in:
2026-08-18 09:27:11 +02:00
parent d7cd8fdf94
commit 39b5453287
2 changed files with 38 additions and 10 deletions
@@ -88,5 +88,24 @@ names and credentials are deliberately omitted.
identity/access is available; isolated provider readiness because an unrelated host port is identity/access is available; isolated provider readiness because an unrelated host port is
occupied. occupied.
The authentication feature is **not release-complete** while required FAIL or PENDING gates remain. ## Final Task 15 review after fix round 5
No secret values, real identities, internal endpoints, or registry names are retained.
The fresh Terra review verdict is **CHANGES REQUIRED**. The five-round breaker is exhausted; no
sixth implementation round was started. Two Important findings remain:
- `StageArchive` does not retain the opaque parent/directory capability through the complete
stream and `Close` lifecycle. Staging-directory creation and final cleanup still use pathname
operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect
cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and
native Windows.
- Windows claim removal closes its validated retained parent handles before calling pathname-based
`DeleteFile`. Removal must instead remain handle-relative (or delete through the opened handle),
with a native-Windows ancestor-swap test.
The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability,
and cleanup results above remain valid evidence for source `74b062f1a737103524cbe706346cfd65f87cdfd1`.
They do not override the final code-review verdict. Native Windows execution remains PENDING.
The authentication feature is **not implementation-complete or release-complete** while these code
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
endpoints, or registry names are retained.
+17 -8
View File
@@ -7,11 +7,12 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base > ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 15 fix-round-5 evidence recorded; the authentication feature is > Last updated: 2026-08-18 (Task 15 fix-round-5 evidence and final review recorded; the final
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain). > review is CHANGES REQUIRED and the authentication feature is not implementation- or
> release-complete).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work. > Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 15 authentication release — final automated smoke PASS, release incomplete (2026-08-18) ### Task 15 authentication — automated smoke PASS, final review CHANGES REQUIRED (2026-08-18)
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before - Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight; stages the immutable candidate and recovery archives under that lock; target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
@@ -19,8 +20,11 @@
transaction capability. Fix-round-5 makes private archive creation retain its validated parent transaction capability. Fix-round-5 makes private archive creation retain its validated parent
through the full create/metadata/failure-cleanup sequence: Unix uses `openat` plus descriptor through the full create/metadata/failure-cleanup sequence: Unix uses `openat` plus descriptor
`fchmod`/`fstat` and `unlinkat`; Windows uses NT `RootDirectory`-relative traversal and final `fchmod`/`fstat` and `unlinkat`; Windows uses NT `RootDirectory`-relative traversal and final
create with the owner-only DACL applied in that same operation. StageArchive capacity, lifecycle, create with the owner-only DACL applied in that same operation. Capacity, lifecycle, rollback,
rollback, streaming, and cleanup behavior remain covered by its existing tests. and streaming tests pass, but the final review found that StageArchive drops the retained
capability before pathname-based staging cleanup; an ancestor swap can therefore strand the
secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup tests are
still required on Unix and native Windows.
- Final tested source is `74b062f1a737103524cbe706346cfd65f87cdfd1`; fix-round-4 - Final tested source is `74b062f1a737103524cbe706346cfd65f87cdfd1`; fix-round-4
`54698e73400a54ce7c3e6c10099e14eb471ce8b9`, prior final Docker source `54698e73400a54ce7c3e6c10099e14eb471ce8b9`, prior final Docker source
`e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2 `e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2
@@ -45,7 +49,7 @@
`.artifacts/task-15/unified-docker-images.json` `.artifacts/task-15/unified-docker-images.json`
(`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and (`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md` `.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
(`058d4841ec3aa7296ff9ace8aff2efd12303a8e1b1a58d46d4d41941914343a9`). Authentication smoke (`67b3ad854457be66ee2525aaf08b8ca2b56b5ee9e6b28e297a7f9b6ede8e526a`). Authentication smoke
exercised no Docker images; the final unified run retained all five exercised image identities. exercised no Docker images; the final unified run retained all five exercised image identities.
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69 - FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
@@ -55,8 +59,13 @@
PSD/manual acceptance because no real identity/access is available; L2 because its configured PSD/manual acceptance because no real identity/access is available; L2 because its configured
secret layout is unavailable; isolated provider readiness because an unrelated host port is secret layout is unavailable; isolated provider readiness because an unrelated host port is
occupied. These are not PASS claims. occupied. These are not PASS claims.
- **Release state: NOT COMPLETE.** Do not mark authentication release-complete until every required - Final Task 15 review after fix round 5 is **CHANGES REQUIRED**. In addition to the StageArchive
FAIL/PENDING gate is rerun in an eligible environment and is PASS. cleanup race above, Windows claim removal closes validated retained parent handles before using
pathname-based `DeleteFile`, leaving an ancestor-swap race. The five-round breaker is exhausted;
no sixth implementation round was started.
- **Implementation/release state: NOT COMPLETE.** Resolve both Important code-review findings and
rerun the affected tests/review, then make every required FAIL/PENDING gate PASS in an eligible
environment before marking authentication complete or release-accepted.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13) ### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)