docs(task15): record retained-handle fix evidence

This commit is contained in:
2026-08-18 09:15:14 +02:00
parent 74b062f1a7
commit d7cd8fdf94
4 changed files with 92 additions and 79 deletions
+13 -12
View File
@@ -6,7 +6,8 @@
"fix_round2": "fe190e7046acc173f510dddcb32f46ed142858c1",
"maintenance_profile_follow_up": "4d230b87afdcd24f02264f8f937c8628b92db05a",
"fix_round3_and_final_docker": "e20bf33e2a00102192e5be66b178037aeca3a7b1",
"fix_round4_streamed_archive_privacy": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
"fix_round4_streamed_archive_privacy": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"fix_round5_retained_handle_private_creation": "74b062f1a737103524cbe706346cfd65f87cdfd1"
},
"versions": {
"node_contract": "v24.16.0",
@@ -23,10 +24,10 @@
},
"unified_docker_smoke": {
"status": "PASS",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818061612-31842-22636",
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1",
"run_id": "20260818070637-66409-30058",
"manifest": ".artifacts/task-15/unified-docker-images.json",
"manifest_sha256": "d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e",
"manifest_sha256": "9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6",
"images": 5,
"cleanup": "PASS"
}
@@ -38,8 +39,8 @@
},
"platform_private_restore_staging": {
"status": "PASS",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"evidence": "safeio_streamed_archive_unix_test_and_windows_static_cross_compile"
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1",
"evidence": "safeio_unix_ancestor_swap_red_green_and_windows_rootdirectory_static_cross_compile"
},
"provider_fixture": {
"status": "PASS",
@@ -62,18 +63,18 @@
"files": 2,
"node": "v24.16.0",
"sentinel_leak_scan": "PASS",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1"
},
"go_race_build": {
"status": "PASS",
"packages": 18,
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1"
},
"windows_cross_compile": {
"status": "PASS",
"packages": 18,
"execution": "cross_compile_only_not_native_execution",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1"
},
"shell_and_compose_contracts": {
"status": "PASS",
@@ -84,12 +85,12 @@
"unified_compose",
"compose_secret_policy"
],
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9"
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1"
},
"unified_docker_smoke": {
"status": "PASS",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818061612-31842-22636",
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1",
"run_id": "20260818070637-66409-30058",
"images": 5,
"cleanup": "PASS"
},
+21 -21
View File
@@ -1,9 +1,28 @@
{
"gate": "unified-deployment-smoke",
"status": "pass",
"source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9",
"run_id": "20260818061612-31842-22636",
"source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1",
"run_id": "20260818070637-66409-30058",
"images": [
{
"id": "sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d",
"roles": [
"compose-runtime",
"fixture-runtime"
],
"repo_digests": [
"sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d"
]
},
{
"id": "sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687",
"roles": [
"compose-runtime"
],
"repo_digests": [
"sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687"
]
},
{
"id": "sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a",
"roles": [
@@ -22,25 +41,6 @@
"sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c"
]
},
{
"id": "sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532",
"roles": [
"compose-runtime"
],
"repo_digests": [
"sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532"
]
},
{
"id": "sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5",
"roles": [
"compose-runtime",
"fixture-runtime"
],
"repo_digests": [
"sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5"
]
},
{
"id": "sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178",
"roles": [
@@ -1,36 +1,44 @@
# Task 15 retained release-gate report — fix round 4 (sanitized)
# Task 15 retained release-gate report — fix round 5 (sanitized)
- Final tested source commit: `54698e73400a54ce7c3e6c10099e14eb471ce8b9`.
- Final tested source commit: `74b062f1a737103524cbe706346cfd65f87cdfd1`.
- Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`,
maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, and prior final Docker
source `e20bf33e2a00102192e5be66b178037aeca3a7b1`.
maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, prior final Docker
source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, and fix-round-4 streamed
archive privacy `54698e73400a54ce7c3e6c10099e14eb471ce8b9`.
- Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`;
Pi `0.80.3`.
- Automated gate artifact: `.artifacts/task-15/automated-gates.json`;
SHA-256 `cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`.
SHA-256 `7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`.
- Docker image manifest: `.artifacts/task-15/unified-docker-images.json`;
SHA-256 `d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`.
SHA-256 `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
## Fix-round-4 evidence
## Fix-round-5 evidence
- PASS: test-first safe-I/O stream creator. The focused test first failed because
`CreateCanonicalNewPrivateFile` was absent; after implementation, four native selected tests
passed: the safe-I/O read/write stream, Unix staged-file privacy, post-write cleanup, and
immutable staged bytes. The staged archive now enters through safeio with an exclusive private
parent, `0600` Unix regular-file protection, and an owner-only DACL set in the Windows creation
call before archive bytes are streamed.
- PASS: full backup and safe-I/O package tests and their race runs. The final source also passed
`go test -race ./...` across `18` packages and a native host `tht` CLI build.
- PASS: Windows amd64 static test/build cross-compile across `18` packages, including the staged
archive Windows test that calls `safeio.ValidatePrivateRegular`. This was **cross-compile only**;
no Windows executable was run. Native execution remains PENDING.
- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed for the
current `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; its exact
runtime sentinel leak scan passed.
- PASS, RED then GREEN: `TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap`
first failed because the creator had not retained its parent before creation. It now opens every
Unix ancestor once, creates the leaf with `openat(O_NOFOLLOW|O_CREAT|O_EXCL)`, applies and checks
`0600` by descriptor (`fchmod`/`fstat`), and uses `unlinkat` for creator failure cleanup. The
deterministic test moves the opened parent, replaces its lexical name with an outside symlink,
validates the archive under the moved original parent, and proves no outside archive was written.
- PASS: the Windows implementation uses NT `RootDirectory`-relative traversal for every component
after the volume root and for final file creation. The retained final parent receives only the
required child-create right (`FILE_WRITE_DATA` for a file, `FILE_APPEND_DATA` for a directory),
reparse points are rejected, and the owner-only protected DACL is installed in the same
`NtCreateFile` operation. The native-Windows test attempts the pre-create parent swap and calls
`safeio.ValidatePrivateRegular`; it is compiled but not executed on this host.
- PASS: `go test ./internal/safeio ./internal/backup -count=1`, `go test -race ./...` across
`18` packages, `go vet ./...`, and a native host `tht` CLI build. Existing StageArchive
capacity, lifecycle, rollback, streaming, and cleanup tests remain passing.
- PASS, compile-only: Windows amd64 static test/build compilation across `18` packages, including
the retained-handle Windows tests. No Windows executable was run; native execution remains
PENDING and is not inferred from compilation.
- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed all current
`8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; the runtime sentinel
leak scan passed.
- PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose
contract, and Compose secret-policy contract.
- PASS: final unified Docker deployment smoke run `20260818061612-31842-22636`, bound to source
`54698e73400a54ce7c3e6c10099e14eb471ce8b9`. It exercised the maintenance-auth isolation check,
- PASS: final unified Docker deployment smoke run `20260818070637-66409-30058`, bound exactly to
source `74b062f1a737103524cbe706346cfd65f87cdfd1`. It exercised maintenance-auth isolation,
restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
## Sanitized final unified Docker output
@@ -45,19 +53,19 @@
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818061612-31842-22636.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.
```
## Sanitized Docker image identities
- `sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d`;
roles `compose-runtime`, `fixture-runtime`.
- `sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687`;
role `compose-runtime`.
- `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`;
role `compose-runtime`.
- `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`;
role `compose-runtime`.
- `sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532`;
role `compose-runtime`.
- `sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5`;
roles `compose-runtime`, `fixture-runtime`.
- `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`;
role `rollback-candidate`.
@@ -66,7 +74,7 @@ names and credentials are deliberately omitted.
## Complete observed matrix
- PASS: Task 13 lifecycle carry-ins; streamed owner-private restore staging; provider fixture
- PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture
round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24
round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`;
final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness
+21 -17
View File
@@ -7,7 +7,7 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 15 fix-round-4 evidence recorded; the authentication feature is
> Last updated: 2026-08-18 (Task 15 fix-round-5 evidence recorded; the authentication feature is
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
@@ -16,32 +16,36 @@
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
accounts their combined capacity before mutation; and uses an opaque installation-bound
transaction capability. Fix-round-4 makes `StageArchive` create its streamed, secret-bearing
`archive.zip` through a narrow safeio read/write primitive: Unix keeps exact private regular-file
behavior and Windows installs an owner-only DACL atomically before any archive bytes are written.
- Final tested source is `54698e73400a54ce7c3e6c10099e14eb471ce8b9`; prior final Docker source
transaction capability. Fix-round-5 makes private archive creation retain its validated parent
through the full create/metadata/failure-cleanup sequence: Unix uses `openat` plus descriptor
`fchmod`/`fstat` and `unlinkat`; Windows uses NT `RootDirectory`-relative traversal and final
create with the owner-only DACL applied in that same operation. StageArchive capacity, lifecycle,
rollback, streaming, and cleanup behavior remain covered by its existing tests.
- Final tested source is `74b062f1a737103524cbe706346cfd65f87cdfd1`; fix-round-4
`54698e73400a54ce7c3e6c10099e14eb471ce8b9`, prior final Docker source
`e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2
`fe190e7046acc173f510dddcb32f46ed142858c1`, and follow-up
`4d230b87afdcd24f02264f8f937c8628b92db05a` remain intact in history. The final unified Docker
smoke is PASS for run `20260818061612-31842-22636`, including maintenance auth isolation,
restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup.
`4d230b87afdcd24f02264f8f937c8628b92db05a` remain historical provenance. The final unified
Docker smoke is PASS for run `20260818070637-66409-30058`, exactly bound to `74b062f...`,
including maintenance auth isolation, restore, registry lifecycle, rollback, five-image
revalidation, and task-scoped cleanup.
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
it is not the release contract and no tracked `v24.19.0` pin exists.
- PASS: focused native TDD (`safeio` stream, Unix archive privacy, post-write cleanup, immutable
staged bytes); full backup/safeio tests; final-source Go race/build across 18 packages; Windows
amd64 static test/build cross-compile across 18 packages; Node 24 authentication smoke; shell
syntax and unified safety self-tests; default/unified Compose and secret-policy contracts; final
unified Docker smoke and cleanup. Windows results are cross-compile only; native execution of the
Windows-only `ValidatePrivateRegular` staged-archive test was unavailable and remains PENDING.
- PASS: focused RED then GREEN Unix ancestor-swap creation test; full backup/safeio tests;
final-source Go race/vet/native-host build across 18 packages; Windows amd64 static test/build
cross-compile across 18 packages; Node 24 authentication smoke; shell syntax and unified safety
self-tests; default/unified Compose and secret-policy contracts; final unified Docker smoke and
cleanup. Windows results are compile-only; the native retained-handle
`ValidatePrivateRegular` test was not executable on this host and remains PENDING.
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
(`cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`),
(`7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`),
`.artifacts/task-15/unified-docker-images.json`
(`d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`), and
(`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
(`628bdc6759c12c688d414825eef7b56881d96af1d91577dd9487959e90a9d0bf`). Authentication smoke
(`058d4841ec3aa7296ff9ace8aff2efd12303a8e1b1a58d46d4d41941914343a9`). Authentication smoke
exercised no Docker images; the final unified run retained all five exercised image identities.
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth