docs(state): retain Task 15 final gate evidence
This commit is contained in:
+35
-33
@@ -7,46 +7,48 @@
|
||||
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
|
||||
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-18 (Task 15 fix-round-1 evidence recorded; the authentication feature is
|
||||
> Last updated: 2026-08-18 (Task 15 fix-round-3 evidence recorded; the authentication feature is
|
||||
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### Task 15 authentication release — automated evidence, release incomplete (2026-08-18)
|
||||
### Task 15 authentication release — final automated smoke PASS, release incomplete (2026-08-18)
|
||||
|
||||
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
|
||||
target-dependent preflight, stages/revalidates archive bytes and hashes under that lock, and uses
|
||||
an opaque installation-bound transaction capability. Focused mutation/concurrency/lock-leak
|
||||
tests and the full Go race/build gate pass.
|
||||
- PASS on the pinned Node `v24.16.0`: backend 75 files / 1081 tests plus typecheck/build; frontend
|
||||
61 files / 444 tests plus typecheck/build and current Playwright 8/8 (7 authentication + 1 shared
|
||||
F1); hermetic authentication smoke; round-1 provider security fixture 6/6; harness 921 passed /
|
||||
4 L2 deselected; authentication-documentation smoke; installer shell test; relevant
|
||||
Compose/security contracts. The default host Node is `v25.6.1`; it is not the release contract
|
||||
and no tracked `v24.19.0` pin exists.
|
||||
- Task15 fix-round-1 source commits are `2b618c5a0f6f07045700cfe7146ca517fb5f78ab`
|
||||
(provider/E2E) and `b2772f10a5729bf08bbd1f3dc6abc0cee1eb5043` (failed-run image
|
||||
retention). The current unified Docker smoke is **FAIL**, reproduced twice at
|
||||
`workspace_maintenance_auth_isolation`; both runs completed scoped cleanup. Docker image
|
||||
traceability is PASS for the retained failed run: all 4 images exercised before that checkpoint
|
||||
were inspected and revalidated before cleanup. Authentication smoke exercised no Docker image.
|
||||
- Sanitized evidence digests: `.artifacts/task-15/automated-gates.json`
|
||||
`aa50c17880d6fff5af74f985aed888fce0d0d1a4608e9da241e1c1c1deb2d19c`;
|
||||
target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
|
||||
accounts their combined capacity before mutation; and uses an opaque installation-bound
|
||||
transaction capability. Restore staging uses the repository `safeio` owner-only mechanisms on
|
||||
Unix and Windows rather than POSIX-mode assumptions.
|
||||
- Final tested source is `e20bf33e2a00102192e5be66b178037aeca3a7b1`; fix-round-2 commits
|
||||
`fe190e7046acc173f510dddcb32f46ed142858c1` and follow-up
|
||||
`4d230b840f99f33005a7c66566c16c48177e990b` remain intact in history. The final unified Docker
|
||||
smoke is PASS for run `20260818054002-16619-2452`, including maintenance auth isolation,
|
||||
restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup.
|
||||
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
|
||||
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
|
||||
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
|
||||
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
|
||||
it is not the release contract and no tracked `v24.19.0` pin exists.
|
||||
- PASS: focused and full backup tests; full Go race/build across 18 packages; Windows amd64 static
|
||||
test/build cross-compile across 18 packages; shell syntax and unified safety self-tests;
|
||||
default/unified Compose and secret-policy contracts; final unified Docker smoke and cleanup.
|
||||
Native execution of the Windows-only owner-DACL test was unavailable and remains PENDING.
|
||||
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
|
||||
(`73c5c4f2b497aeda114e725f718f1e542a4c05691bd9257b6e607e55b1d02236`),
|
||||
`.artifacts/task-15/unified-docker-images.json`
|
||||
`525d269b72995e41358b29bcd33704f6b04ff35b99b9f2cfa40c03be8664f9f6`; ignored Task15 report
|
||||
`8b67b9a3bd7b55a7ad74fcc560f0cd8dac5667588568ed3428ad5125f1e0071a`.
|
||||
- Task15 fixture regressions in preprocess, server Pi-state, and Pi-auth Compose contracts were
|
||||
repaired and their focused checks pass. Static Windows amd64 cross-build and test compilation
|
||||
pass for 18 Go packages.
|
||||
- FAIL baseline evidence: Ruff reports 192 errors; MkDocs `--strict` exits 1 with 69 warnings;
|
||||
the canonical-install and workspace-install-doc checks report existing manual wording mismatches;
|
||||
the Pi user-auth Compose check reaches an existing model allow-list mismatch; and the broad
|
||||
deployment-coupling scanner sees preserved ignored private deployment material.
|
||||
- PENDING evidence: native Windows execution (no KVM, `sshpass`, Windows container, or PowerShell);
|
||||
real PSD/manual acceptance (no real test identity/access); L2 (no configured local secret layout);
|
||||
and isolated provider-readiness Docker smoke (a host port is already occupied by an unrelated
|
||||
resource). These are not PASS claims.
|
||||
(`835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`), and
|
||||
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
|
||||
(`4d086bbecf4f20edd6df76a92909fc15b04996a1b2409e7d6ffef07c98684086`). Authentication smoke
|
||||
exercised no Docker images; the final unified run retained all five exercised image identities.
|
||||
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
|
||||
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
|
||||
Compose has the existing model-policy mismatch; deployment coupling sees preserved ignored private
|
||||
material.
|
||||
- PENDING: native Windows execution because required host prerequisites are unavailable; real
|
||||
PSD/manual acceptance because no real identity/access is available; L2 because its configured
|
||||
secret layout is unavailable; isolated provider readiness because an unrelated host port is
|
||||
occupied. These are not PASS claims.
|
||||
- **Release state: NOT COMPLETE.** Do not mark authentication release-complete until every required
|
||||
gate is rerun in an eligible environment and is PASS.
|
||||
FAIL/PENDING gate is rerun in an eligible environment and is PASS.
|
||||
|
||||
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user