diff --git a/.artifacts/task-15/automated-gates.json b/.artifacts/task-15/automated-gates.json index aee618a4..7fbeabc7 100644 --- a/.artifacts/task-15/automated-gates.json +++ b/.artifacts/task-15/automated-gates.json @@ -6,7 +6,8 @@ "fix_round2": "fe190e7046acc173f510dddcb32f46ed142858c1", "maintenance_profile_follow_up": "4d230b87afdcd24f02264f8f937c8628b92db05a", "fix_round3_and_final_docker": "e20bf33e2a00102192e5be66b178037aeca3a7b1", - "fix_round4_streamed_archive_privacy": "54698e73400a54ce7c3e6c10099e14eb471ce8b9" + "fix_round4_streamed_archive_privacy": "54698e73400a54ce7c3e6c10099e14eb471ce8b9", + "fix_round5_retained_handle_private_creation": "74b062f1a737103524cbe706346cfd65f87cdfd1" }, "versions": { "node_contract": "v24.16.0", @@ -23,10 +24,10 @@ }, "unified_docker_smoke": { "status": "PASS", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9", - "run_id": "20260818061612-31842-22636", + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1", + "run_id": "20260818070637-66409-30058", "manifest": ".artifacts/task-15/unified-docker-images.json", - "manifest_sha256": "d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e", + "manifest_sha256": "9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6", "images": 5, "cleanup": "PASS" } @@ -38,8 +39,8 @@ }, "platform_private_restore_staging": { "status": "PASS", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9", - "evidence": "safeio_streamed_archive_unix_test_and_windows_static_cross_compile" + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1", + "evidence": "safeio_unix_ancestor_swap_red_green_and_windows_rootdirectory_static_cross_compile" }, "provider_fixture": { "status": "PASS", @@ -62,18 +63,18 @@ "files": 2, "node": "v24.16.0", "sentinel_leak_scan": "PASS", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9" + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1" }, "go_race_build": { "status": "PASS", "packages": 18, - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9" + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1" }, "windows_cross_compile": { "status": "PASS", "packages": 18, "execution": "cross_compile_only_not_native_execution", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9" + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1" }, "shell_and_compose_contracts": { "status": "PASS", @@ -84,12 +85,12 @@ "unified_compose", "compose_secret_policy" ], - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9" + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1" }, "unified_docker_smoke": { "status": "PASS", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9", - "run_id": "20260818061612-31842-22636", + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1", + "run_id": "20260818070637-66409-30058", "images": 5, "cleanup": "PASS" }, diff --git a/.artifacts/task-15/unified-docker-images.json b/.artifacts/task-15/unified-docker-images.json index 5743f5e4..4cbfd1fa 100644 --- a/.artifacts/task-15/unified-docker-images.json +++ b/.artifacts/task-15/unified-docker-images.json @@ -1,9 +1,28 @@ { "gate": "unified-deployment-smoke", "status": "pass", - "source_commit": "54698e73400a54ce7c3e6c10099e14eb471ce8b9", - "run_id": "20260818061612-31842-22636", + "source_commit": "74b062f1a737103524cbe706346cfd65f87cdfd1", + "run_id": "20260818070637-66409-30058", "images": [ + { + "id": "sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d", + "roles": [ + "compose-runtime", + "fixture-runtime" + ], + "repo_digests": [ + "sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d" + ] + }, + { + "id": "sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687", + "roles": [ + "compose-runtime" + ], + "repo_digests": [ + "sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687" + ] + }, { "id": "sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a", "roles": [ @@ -22,25 +41,6 @@ "sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c" ] }, - { - "id": "sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532", - "roles": [ - "compose-runtime" - ], - "repo_digests": [ - "sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532" - ] - }, - { - "id": "sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5", - "roles": [ - "compose-runtime", - "fixture-runtime" - ], - "repo_digests": [ - "sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5" - ] - }, { "id": "sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178", "roles": [ diff --git a/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md b/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md index 150c7b44..582199d7 100644 --- a/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md +++ b/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md @@ -1,36 +1,44 @@ -# Task 15 retained release-gate report — fix round 4 (sanitized) +# Task 15 retained release-gate report — fix round 5 (sanitized) -- Final tested source commit: `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. +- Final tested source commit: `74b062f1a737103524cbe706346cfd65f87cdfd1`. - Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`, - maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, and prior final Docker - source `e20bf33e2a00102192e5be66b178037aeca3a7b1`. + maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, prior final Docker + source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, and fix-round-4 streamed + archive privacy `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. - Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`; Pi `0.80.3`. - Automated gate artifact: `.artifacts/task-15/automated-gates.json`; - SHA-256 `cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`. + SHA-256 `7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`. - Docker image manifest: `.artifacts/task-15/unified-docker-images.json`; - SHA-256 `d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`. + SHA-256 `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. -## Fix-round-4 evidence +## Fix-round-5 evidence -- PASS: test-first safe-I/O stream creator. The focused test first failed because - `CreateCanonicalNewPrivateFile` was absent; after implementation, four native selected tests - passed: the safe-I/O read/write stream, Unix staged-file privacy, post-write cleanup, and - immutable staged bytes. The staged archive now enters through safeio with an exclusive private - parent, `0600` Unix regular-file protection, and an owner-only DACL set in the Windows creation - call before archive bytes are streamed. -- PASS: full backup and safe-I/O package tests and their race runs. The final source also passed - `go test -race ./...` across `18` packages and a native host `tht` CLI build. -- PASS: Windows amd64 static test/build cross-compile across `18` packages, including the staged - archive Windows test that calls `safeio.ValidatePrivateRegular`. This was **cross-compile only**; - no Windows executable was run. Native execution remains PENDING. -- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed for the - current `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; its exact - runtime sentinel leak scan passed. +- PASS, RED then GREEN: `TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap` + first failed because the creator had not retained its parent before creation. It now opens every + Unix ancestor once, creates the leaf with `openat(O_NOFOLLOW|O_CREAT|O_EXCL)`, applies and checks + `0600` by descriptor (`fchmod`/`fstat`), and uses `unlinkat` for creator failure cleanup. The + deterministic test moves the opened parent, replaces its lexical name with an outside symlink, + validates the archive under the moved original parent, and proves no outside archive was written. +- PASS: the Windows implementation uses NT `RootDirectory`-relative traversal for every component + after the volume root and for final file creation. The retained final parent receives only the + required child-create right (`FILE_WRITE_DATA` for a file, `FILE_APPEND_DATA` for a directory), + reparse points are rejected, and the owner-only protected DACL is installed in the same + `NtCreateFile` operation. The native-Windows test attempts the pre-create parent swap and calls + `safeio.ValidatePrivateRegular`; it is compiled but not executed on this host. +- PASS: `go test ./internal/safeio ./internal/backup -count=1`, `go test -race ./...` across + `18` packages, `go vet ./...`, and a native host `tht` CLI build. Existing StageArchive + capacity, lifecycle, rollback, streaming, and cleanup tests remain passing. +- PASS, compile-only: Windows amd64 static test/build compilation across `18` packages, including + the retained-handle Windows tests. No Windows executable was run; native execution remains + PENDING and is not inferred from compilation. +- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed all current + `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; the runtime sentinel + leak scan passed. - PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract. -- PASS: final unified Docker deployment smoke run `20260818061612-31842-22636`, bound to source - `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. It exercised the maintenance-auth isolation check, +- PASS: final unified Docker deployment smoke run `20260818070637-66409-30058`, bound exactly to + source `74b062f1a737103524cbe706346cfd65f87cdfd1`. It exercised maintenance-auth isolation, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup. ## Sanitized final unified Docker output @@ -45,19 +53,19 @@ == Reject the retired flat workspace layout and retain the valid snapshot == == Inject a bad pinned Pi candidate and prove automatic rollback == Task 13 full deployment smoke passed. -Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818061612-31842-22636. +Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058. ``` ## Sanitized Docker image identities +- `sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d`; + roles `compose-runtime`, `fixture-runtime`. +- `sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687`; + role `compose-runtime`. - `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`; role `compose-runtime`. - `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`; role `compose-runtime`. -- `sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532`; - role `compose-runtime`. -- `sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5`; - roles `compose-runtime`, `fixture-runtime`. - `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`; role `rollback-candidate`. @@ -66,7 +74,7 @@ names and credentials are deliberately omitted. ## Complete observed matrix -- PASS: Task 13 lifecycle carry-ins; streamed owner-private restore staging; provider fixture +- PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24 round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`; final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness diff --git a/PROJECT_STATE.md b/PROJECT_STATE.md index 241bb4e4..301407c7 100644 --- a/PROJECT_STATE.md +++ b/PROJECT_STATE.md @@ -7,7 +7,7 @@ > ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. -> Last updated: 2026-08-18 (Task 15 fix-round-4 evidence recorded; the authentication feature is +> Last updated: 2026-08-18 (Task 15 fix-round-5 evidence recorded; the authentication feature is > not complete or release-accepted while the required FAIL/PENDING gates listed below remain). > Point a fresh session here ("read PROJECT_STATE.md") before substantial work. @@ -16,32 +16,36 @@ - Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before target-dependent preflight; stages the immutable candidate and recovery archives under that lock; accounts their combined capacity before mutation; and uses an opaque installation-bound - transaction capability. Fix-round-4 makes `StageArchive` create its streamed, secret-bearing - `archive.zip` through a narrow safeio read/write primitive: Unix keeps exact private regular-file - behavior and Windows installs an owner-only DACL atomically before any archive bytes are written. -- Final tested source is `54698e73400a54ce7c3e6c10099e14eb471ce8b9`; prior final Docker source + transaction capability. Fix-round-5 makes private archive creation retain its validated parent + through the full create/metadata/failure-cleanup sequence: Unix uses `openat` plus descriptor + `fchmod`/`fstat` and `unlinkat`; Windows uses NT `RootDirectory`-relative traversal and final + create with the owner-only DACL applied in that same operation. StageArchive capacity, lifecycle, + rollback, streaming, and cleanup behavior remain covered by its existing tests. +- Final tested source is `74b062f1a737103524cbe706346cfd65f87cdfd1`; fix-round-4 + `54698e73400a54ce7c3e6c10099e14eb471ce8b9`, prior final Docker source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`, and follow-up - `4d230b87afdcd24f02264f8f937c8628b92db05a` remain intact in history. The final unified Docker - smoke is PASS for run `20260818061612-31842-22636`, including maintenance auth isolation, - restore, registry lifecycle, rollback, five-image revalidation, and task-scoped cleanup. + `4d230b87afdcd24f02264f8f937c8628b92db05a` remain historical provenance. The final unified + Docker smoke is PASS for run `20260818070637-66409-30058`, exactly bound to `74b062f...`, + including maintenance auth isolation, restore, registry lifecycle, rollback, five-image + revalidation, and task-scoped cleanup. - PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1 Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend 61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`; it is not the release contract and no tracked `v24.19.0` pin exists. -- PASS: focused native TDD (`safeio` stream, Unix archive privacy, post-write cleanup, immutable - staged bytes); full backup/safeio tests; final-source Go race/build across 18 packages; Windows - amd64 static test/build cross-compile across 18 packages; Node 24 authentication smoke; shell - syntax and unified safety self-tests; default/unified Compose and secret-policy contracts; final - unified Docker smoke and cleanup. Windows results are cross-compile only; native execution of the - Windows-only `ValidatePrivateRegular` staged-archive test was unavailable and remains PENDING. +- PASS: focused RED then GREEN Unix ancestor-swap creation test; full backup/safeio tests; + final-source Go race/vet/native-host build across 18 packages; Windows amd64 static test/build + cross-compile across 18 packages; Node 24 authentication smoke; shell syntax and unified safety + self-tests; default/unified Compose and secret-policy contracts; final unified Docker smoke and + cleanup. Windows results are compile-only; the native retained-handle + `ValidatePrivateRegular` test was not executable on this host and remains PENDING. - Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json` - (`cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`), + (`7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`), `.artifacts/task-15/unified-docker-images.json` - (`d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`), and + (`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and `.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md` - (`628bdc6759c12c688d414825eef7b56881d96af1d91577dd9487959e90a9d0bf`). Authentication smoke + (`058d4841ec3aa7296ff9ace8aff2efd12303a8e1b1a58d46d4d41941914343a9`). Authentication smoke exercised no Docker images; the final unified run retained all five exercised image identities. - FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69 warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth