docs(auth): record Task 4 certification evidence

This commit is contained in:
2026-08-18 11:58:38 +02:00
parent b31b27e584
commit fa499a9bdd
4 changed files with 364 additions and 151 deletions
@@ -0,0 +1,97 @@
# Task 4 authentication remediation recertification (sanitized)
## Result
- Frozen source under test: `b31b27e5845ffd3adf311429367319beaba263c7` on `feat/thoth-auth`.
- Freeze check: PASS. No tracked source changed during certification. The only untracked paths
retained are `.playwright-cli/` and `.thothctl/`.
- Certification window: `2026-08-18T09:26Z` to `2026-08-18T09:48:36Z` (UTC; the start marker is
minute-precision because no earlier second-level operator timestamp was captured).
- Overall result: `FAIL` / `CHANGES_REQUIRED`. The three Important findings are not closed and
authentication is not implementation-complete or release-complete.
## Local gate matrix
| Gate | Result | Sanitized evidence |
|---|---|---|
| Go focused security tests | PASS | `safeio`, `backup`, and `authstorage`; 3 packages |
| Go race/vet/host build | PASS | 18 race-tested packages; vet and host CLI build exit 0 |
| Windows amd64 cross-compile | PASS | focused safeio/backup test binaries and CLI build; compile-only |
| POSIX registry ownership | PASS | Node 24 backend suite includes local-registry ownership coverage |
| Unix StageArchive retained capability | PASS | focused safeio/backup and race coverage passed on host |
| Backend Node 24 | PASS | 76 files / 1092 tests; typecheck and build passed |
| Frontend Node 24 | PASS | 61 files / 444 tests; typecheck and build passed |
| Authentication/F1 browser smoke | PASS | Node `v24.16.0`; filtered E2E 1 passed; sentinel scan passed |
| Harness pytest | FAIL | 951 passed, 1 failed, 4 skipped, 232 subtests; `test_f4_emits_column_types` could not find `workflow.yaml` from its test cwd |
| Ruff | FAIL | 192 errors; known baseline |
| Authentication docs smoke | PASS | required-term and forbidden-word checks passed |
| Shell syntax | PASS | `bash -n scripts/*.sh` |
| Default Compose contract | FAIL | required `THT_WORKSPACE_GIT_REMOTE` was unavailable |
| Unified Compose contract | FAIL | `compose.unified.yaml` is absent from the frozen source |
| Unified Docker smoke | FAIL | workflow attempted it on the frozen SHA but stopped before deployment because `rg` was unavailable; cleanup proof passed and no new image manifest was generated |
| L2 / PSD manual / provider readiness | PENDING | required external secrets, identities/access, or provider prerequisites unavailable/not reached |
The first full backend Vitest attempt had one workspace-registry timeout. The focused test and a
fresh complete rerun passed, so the current backend result above is the fresh complete rerun.
## Native Windows authority
The authorized dispatch was bound to the frozen SHA:
- Run: `32122302381`
- URL: https://github.com/mptyl/ThothII/actions/runs/32122302381
- Head SHA: `b31b27e5845ffd3adf311429367319beaba263c7`
- Workflow conclusion: `failure`
- Job: `Windows clone and Compose contract`, job `95665197885`
- Job URL: https://github.com/mptyl/ThothII/actions/runs/32122302381/job/95665197885
- Native step: `Run native Windows retained-capability tests` — `failure`
- Executed command: `go test ./internal/safeio ./internal/backup -count=1`
- Observed focused failures include `TestRemoveCanonicalPrivateClaimRetainsParentDuringDeletion`
and `TestRemoveCanonicalPrivateClaimPreservesOrphan`.
- The backup package timed out in
`TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup` after `10m0s`.
- Additional backup failures included retained-staging `unsafe file` results, Windows temporary-file
cleanup reporting that a file was still in use, and fixture cases that could not read external
secret declarations. The first two categories are remediation/security-boundary failures; the
fixture declaration failures are recorded as an accompanying CI-fixture issue.
- `internal/authstorage` was not requested by the frozen workflow step and therefore has no native
Windows execution evidence. Cross-compilation does not substitute for this gate.
This native failure is the blocking gate. No source fix was attempted, and no later Docker smoke
was run locally after the failure.
## Other workflow failures
- `LF, Compose, docs, and TypeScript` (job `95665197839`) failed in
`Verify Compose and installation contracts` after the unified Compose contract itself passed.
`test-no-deployment-coupling-scope.sh` aborted on `TMPDIR: unbound variable`; this is classified
as a baseline/CI contract prerequisite, and later docs/TypeScript steps were skipped.
- `Linux Docker deployment and rollback` (job `95665197846`) failed before deployment because the
runner did not provide `rg` (`Task 13 smoke failed: rg is required`). The sanitized cleanup proof
passed and no Docker image manifest was generated. This is classified as an infrastructure
prerequisite failure, not as evidence of a remediation regression.
## Evidence and provenance
- Current machine-readable matrix: `.artifacts/task-15/automated-gates.json`; SHA-256
`e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`.
- Current requested report: this file (SHA-256 recorded after the evidence commit if needed for
external indexing).
- Historical Docker image manifest: `.artifacts/task-15/unified-docker-images.json`, unchanged
because no new immutable-source Docker smoke ran. Its retained historical SHA-256 is
`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`, bound to historical source
`74b062f1a737103524cbe706346cfd65f87cdfd1`, not to this Task 4 candidate.
- The historical Task 15 report remains provenance for earlier source SHAs; its current addendum
records this recertification separately.
No credentials, tokens, internal endpoints, provider identities, registry names, raw environments,
or browser traces are retained here.
## Separate verdicts
- Three Important findings: `CHANGES_REQUIRED`. Native Windows retained-capability authority
failed, and the frozen workflow omits the required `authstorage` package from its native command.
- Overall release readiness: `FAIL` with additional `PENDING` gates. The native Windows remediation
gate failed; the remote Docker attempt failed on a missing runner prerequisite; existing
Ruff/harness/Compose failures and external/manual prerequisites remain unresolved; and no
successful new unified Docker image evidence exists.