docs(state): retain Task 15 final gate evidence

This commit is contained in:
2026-08-18 07:49:40 +02:00
parent e20bf33e2a
commit cb1bd101f0
4 changed files with 296 additions and 33 deletions
+140
View File
@@ -0,0 +1,140 @@
{
"schema": "thothii-task15-gates-v2",
"generated_on": "2026-08-18",
"source_commits": {
"authentication_round1": "2b618c5a0f6f07045700cfe7146ca517fb5f78ab",
"fix_round2": "fe190e7046acc173f510dddcb32f46ed142858c1",
"maintenance_profile_follow_up": "4d230b840f99f33005a7c66566c16c48177e990b",
"fix_round3_and_final_docker": "e20bf33e2a00102192e5be66b178037aeca3a7b1"
},
"versions": {
"node_contract": "v24.16.0",
"node_host_default": "v25.6.1",
"go": "go1.26.5",
"pi": "0.80.3"
},
"retained_report": ".superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md",
"docker_image_evidence": {
"authentication_smoke": {
"status": "PASS",
"docker_images": [],
"reason": "no_docker_images_exercised"
},
"unified_docker_smoke": {
"status": "PASS",
"source_commit": "e20bf33e2a00102192e5be66b178037aeca3a7b1",
"run_id": "20260818054002-16619-2452",
"manifest": ".artifacts/task-15/unified-docker-images.json",
"manifest_sha256": "835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7",
"images": 5,
"cleanup": "PASS"
}
},
"gates": {
"task13_lifecycle_carry_ins": {
"status": "PASS",
"evidence": "focused_backup_red_green_full_go_race_build"
},
"platform_private_restore_staging": {
"status": "PASS",
"evidence": "unix_behavior_test_and_windows_static_cross_compile"
},
"provider_fixture": {
"status": "PASS",
"tests": 6,
"node": "v24.16.0"
},
"backend_node24_round1": {
"status": "PASS",
"tests": 1081,
"files": 75
},
"frontend_node24_round1": {
"status": "PASS",
"tests": 444,
"files": 61
},
"authentication_and_f1_smoke": {
"status": "PASS",
"playwright": 8,
"files": 2,
"node": "v24.16.0",
"sentinel_leak_scan": "PASS"
},
"go_race_build": {
"status": "PASS",
"packages": 18
},
"windows_cross_compile": {
"status": "PASS",
"packages": 18
},
"shell_and_compose_contracts": {
"status": "PASS",
"checks": [
"shell_syntax",
"unified_smoke_self_test",
"default_compose",
"unified_compose",
"compose_secret_policy"
]
},
"unified_docker_smoke": {
"status": "PASS",
"run_id": "20260818054002-16619-2452",
"images": 5,
"cleanup": "PASS"
},
"harness_pytest_round1": {
"status": "PASS",
"passed": 921,
"l2_deselected": 4
},
"authentication_docs_round1": {
"status": "PASS"
},
"windows_native": {
"status": "PENDING",
"reason": "required_host_prerequisites_unavailable"
},
"l2": {
"status": "PENDING",
"reason": "configured_secret_layout_unavailable"
},
"manual_psd": {
"status": "PENDING",
"reason": "real_identity_or_access_unavailable"
},
"provider_readiness": {
"status": "PENDING",
"reason": "unrelated_host_port_occupied"
},
"ruff": {
"status": "FAIL",
"errors": 192,
"classification": "known_baseline"
},
"mkdocs_strict": {
"status": "FAIL",
"warnings": 69,
"classification": "known_baseline"
},
"canonical_install_docs": {
"status": "FAIL",
"classification": "existing_manual_wording_mismatch"
},
"workspace_install_docs": {
"status": "FAIL",
"classification": "existing_manual_wording_mismatch"
},
"pi_user_auth_compose": {
"status": "FAIL",
"classification": "existing_model_policy_mismatch"
},
"deployment_coupling": {
"status": "FAIL",
"classification": "protected_ignored_local_material"
}
},
"release_complete": false
}
@@ -0,0 +1,54 @@
{
"gate": "unified-deployment-smoke",
"status": "pass",
"source_commit": "e20bf33e2a00102192e5be66b178037aeca3a7b1",
"run_id": "20260818054002-16619-2452",
"images": [
{
"id": "sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6",
"roles": [
"compose-runtime",
"fixture-runtime"
],
"repo_digests": [
"sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6"
]
},
{
"id": "sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a",
"roles": [
"compose-runtime"
],
"repo_digests": [
"sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a"
]
},
{
"id": "sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c",
"roles": [
"compose-runtime"
],
"repo_digests": [
"sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c"
]
},
{
"id": "sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d",
"roles": [
"compose-runtime"
],
"repo_digests": [
"sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d"
]
},
{
"id": "sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178",
"roles": [
"rollback-candidate"
],
"repo_digests": [
"sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178"
]
}
]
}
@@ -0,0 +1,67 @@
# Task 15 retained release-gate report — fix round 3 (sanitized)
- Final tested source commit: `e20bf33e2a00102192e5be66b178037aeca3a7b1`.
- Fix-round-2 commits retained unchanged: `fe190e7046acc173f510dddcb32f46ed142858c1`
and follow-up `4d230b840f99f33005a7c66566c16c48177e990b`.
- Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`;
Pi `0.80.3`.
- Automated gate artifact: `.artifacts/task-15/automated-gates.json`;
SHA-256 `73c5c4f2b497aeda114e725f718f1e542a4c05691bd9257b6e607e55b1d02236`.
- Docker image manifest: `.artifacts/task-15/unified-docker-images.json`;
SHA-256 `835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`.
## Fix-round-3 evidence
- PASS: backup staging RED/GREEN focused set `4/4`; full backup package; full Go race and build
across `18` packages. Staging now uses the repository `safeio` owner-only directory mechanisms,
rejects a symlinked installation ancestor on Unix, and includes a Windows-only owner-DACL test.
- PASS: Windows amd64 static test/build cross-compile across `18` packages. Native execution of
the Windows-only ACL test was not available and is therefore PENDING, not PASS.
- PASS on Node `v24.16.0`: deterministic provider security fixture `6/6`; authentication smoke
`8/8` across `frontend/e2e/auth.spec.ts` and authenticated `frontend/e2e/f1.spec.ts`. The
runtime sentinel was the exact fixture OIDC client secret and group bearer, and the retained
output leak scan passed.
- PASS: shell syntax, unified-smoke safety self-tests, default/unified Compose contracts, and
Compose secret policy.
- PASS: final unified Docker deployment smoke run `20260818054002-16619-2452`, bound to source
commit `e20bf33e2a00102192e5be66b178037aeca3a7b1`. It exercised the maintenance authentication
isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and
task-scoped cleanup.
- PASS: Docker image traceability for all `5` images exercised by the final unified run. The
authentication browser smoke exercised no Docker images and is explicitly retained as an empty
image set.
## Sanitized Docker image identities
- `sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6`;
roles `compose-runtime`, `fixture-runtime`.
- `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`;
role `compose-runtime`.
- `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`;
role `compose-runtime`.
- `sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d`;
role `compose-runtime`.
- `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`;
role `rollback-candidate`.
For each image, the retained repository-digest component equals the listed image digest. Registry
names and credentials are deliberately omitted.
## Complete observed matrix
- PASS: Task13 lifecycle carry-ins; platform-private restore staging; provider fixture `6/6`;
backend Node24 round-1 suite `75 files / 1081 tests`; frontend Node24 round-1 suite
`61 files / 444 tests`; current authentication/F1 browser smoke `8/8`; Go race/build
`18 packages`; Windows static cross-compile `18 packages`; harness round-1 suite
`921 passed / 4 L2 deselected`; authentication docs round-1 gate; shell/Compose contracts;
unified Docker smoke; five-image traceability; Docker cleanup.
- FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing
canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling
scan against preserved ignored private material.
- PENDING: native Windows execution because required host prerequisites are unavailable; L2
because the configured secret layout is unavailable; real PSD/manual acceptance because no real
identity/access is available; isolated provider readiness because an unrelated host port is
occupied.
The authentication feature is **not release-complete** while required FAIL or PENDING gates remain.
No secret values, real identities, internal endpoints, or registry names are retained.
+35 -33
View File
@@ -7,46 +7,48 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 15 fix-round-1 evidence recorded; the authentication feature is
> Last updated: 2026-08-18 (Task 15 fix-round-3 evidence recorded; the authentication feature is
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 15 authentication release — automated evidence, release incomplete (2026-08-18)
### Task 15 authentication release — final automated smoke PASS, release incomplete (2026-08-18)
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight, stages/revalidates archive bytes and hashes under that lock, and uses
an opaque installation-bound transaction capability. Focused mutation/concurrency/lock-leak
tests and the full Go race/build gate pass.
- PASS on the pinned Node `v24.16.0`: backend 75 files / 1081 tests plus typecheck/build; frontend
61 files / 444 tests plus typecheck/build and current Playwright 8/8 (7 authentication + 1 shared
F1); hermetic authentication smoke; round-1 provider security fixture 6/6; harness 921 passed /
4 L2 deselected; authentication-documentation smoke; installer shell test; relevant
Compose/security contracts. The default host Node is `v25.6.1`; it is not the release contract
and no tracked `v24.19.0` pin exists.
- Task15 fix-round-1 source commits are `2b618c5a0f6f07045700cfe7146ca517fb5f78ab`
(provider/E2E) and `b2772f10a5729bf08bbd1f3dc6abc0cee1eb5043` (failed-run image
retention). The current unified Docker smoke is **FAIL**, reproduced twice at
`workspace_maintenance_auth_isolation`; both runs completed scoped cleanup. Docker image
traceability is PASS for the retained failed run: all 4 images exercised before that checkpoint
were inspected and revalidated before cleanup. Authentication smoke exercised no Docker image.
- Sanitized evidence digests: `.artifacts/task-15/automated-gates.json`
`aa50c17880d6fff5af74f985aed888fce0d0d1a4608e9da241e1c1c1deb2d19c`;
target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
accounts their combined capacity before mutation; and uses an opaque installation-bound
transaction capability. Restore staging uses the repository `safeio` owner-only mechanisms on
Unix and Windows rather than POSIX-mode assumptions.
- Final tested source is `e20bf33e2a00102192e5be66b178037aeca3a7b1`; fix-round-2 commits
`fe190e7046acc173f510dddcb32f46ed142858c1` and follow-up
`4d230b840f99f33005a7c66566c16c48177e990b` remain intact in history. The final unified Docker
smoke is PASS for run `20260818054002-16619-2452`, including maintenance auth isolation,
restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup.
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
it is not the release contract and no tracked `v24.19.0` pin exists.
- PASS: focused and full backup tests; full Go race/build across 18 packages; Windows amd64 static
test/build cross-compile across 18 packages; shell syntax and unified safety self-tests;
default/unified Compose and secret-policy contracts; final unified Docker smoke and cleanup.
Native execution of the Windows-only owner-DACL test was unavailable and remains PENDING.
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
(`73c5c4f2b497aeda114e725f718f1e542a4c05691bd9257b6e607e55b1d02236`),
`.artifacts/task-15/unified-docker-images.json`
`525d269b72995e41358b29bcd33704f6b04ff35b99b9f2cfa40c03be8664f9f6`; ignored Task15 report
`8b67b9a3bd7b55a7ad74fcc560f0cd8dac5667588568ed3428ad5125f1e0071a`.
- Task15 fixture regressions in preprocess, server Pi-state, and Pi-auth Compose contracts were
repaired and their focused checks pass. Static Windows amd64 cross-build and test compilation
pass for 18 Go packages.
- FAIL baseline evidence: Ruff reports 192 errors; MkDocs `--strict` exits 1 with 69 warnings;
the canonical-install and workspace-install-doc checks report existing manual wording mismatches;
the Pi user-auth Compose check reaches an existing model allow-list mismatch; and the broad
deployment-coupling scanner sees preserved ignored private deployment material.
- PENDING evidence: native Windows execution (no KVM, `sshpass`, Windows container, or PowerShell);
real PSD/manual acceptance (no real test identity/access); L2 (no configured local secret layout);
and isolated provider-readiness Docker smoke (a host port is already occupied by an unrelated
resource). These are not PASS claims.
(`835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`), and
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
(`4d086bbecf4f20edd6df76a92909fc15b04996a1b2409e7d6ffef07c98684086`). Authentication smoke
exercised no Docker images; the final unified run retained all five exercised image identities.
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
Compose has the existing model-policy mismatch; deployment coupling sees preserved ignored private
material.
- PENDING: native Windows execution because required host prerequisites are unavailable; real
PSD/manual acceptance because no real identity/access is available; L2 because its configured
secret layout is unavailable; isolated provider readiness because an unrelated host port is
occupied. These are not PASS claims.
- **Release state: NOT COMPLETE.** Do not mark authentication release-complete until every required
gate is rerun in an eligible environment and is PASS.
FAIL/PENDING gate is rerun in an eligible environment and is PASS.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)