docs(auth): record Task 4 certification evidence

This commit is contained in:
2026-08-18 11:58:38 +02:00
parent b31b27e584
commit fa499a9bdd
4 changed files with 364 additions and 151 deletions
+32 -61
View File
@@ -7,70 +7,41 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 15 and final whole-branch reviews recorded; both are CHANGES
> REQUIRED and the authentication feature is not implementation- or release-complete).
> Last updated: 2026-08-18 (Task 4 recertification recorded; native Windows authority failed and
> the authentication feature is not implementation- or release-complete).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 15 authentication — automated smoke PASS, final review CHANGES REQUIRED (2026-08-18)
### Task 4 authentication recertification — FAIL, native Windows CHANGES REQUIRED (2026-08-18)
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight; stages the immutable candidate and recovery archives under that lock;
accounts their combined capacity before mutation; and uses an opaque installation-bound
transaction capability. Fix-round-5 makes private archive creation retain its validated parent
through the full create/metadata/failure-cleanup sequence: Unix uses `openat` plus descriptor
`fchmod`/`fstat` and `unlinkat`; Windows uses NT `RootDirectory`-relative traversal and final
create with the owner-only DACL applied in that same operation. Capacity, lifecycle, rollback,
and streaming tests pass, but the final review found that StageArchive drops the retained
capability before pathname-based staging cleanup; an ancestor swap can therefore strand the
secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup tests are
still required on Unix and native Windows.
- Final tested source is `74b062f1a737103524cbe706346cfd65f87cdfd1`; fix-round-4
`54698e73400a54ce7c3e6c10099e14eb471ce8b9`, prior final Docker source
`e20bf33e2a00102192e5be66b178037aeca3a7b1`, fix-round-2
`fe190e7046acc173f510dddcb32f46ed142858c1`, and follow-up
`4d230b87afdcd24f02264f8f937c8628b92db05a` remain historical provenance. The final unified
Docker smoke is PASS for run `20260818070637-66409-30058`, exactly bound to `74b062f...`,
including maintenance auth isolation, restore, registry lifecycle, rollback, five-image
revalidation, and task-scoped cleanup.
- PASS on pinned Node `v24.16.0`: provider security fixture 6/6 and current authentication/F1
Playwright smoke 8/8 with the runtime sentinel used as the exact fixture credential and absent
from retained output. Round-1 full suites remain PASS: backend 75 files / 1081 tests, frontend
61 files / 444 tests, harness 921 passed / 4 L2 deselected. The host default Node is `v25.6.1`;
it is not the release contract and no tracked `v24.19.0` pin exists.
- PASS: focused RED then GREEN Unix ancestor-swap creation test; full backup/safeio tests;
final-source Go race/vet/native-host build across 18 packages; Windows amd64 static test/build
cross-compile across 18 packages; Node 24 authentication smoke; shell syntax and unified safety
self-tests; default/unified Compose and secret-policy contracts; final unified Docker smoke and
cleanup. Windows results are compile-only; the native retained-handle
`ValidatePrivateRegular` test was not executable on this host and remains PENDING.
- Durable sanitized evidence is tracked at `.artifacts/task-15/automated-gates.json`
(`7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`),
`.artifacts/task-15/unified-docker-images.json`
(`9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`), and
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`
(`9e4737e84bb9fb866eb0ee9ba2660f0fcfdef0c081dde11f19f6078c59b1bf56`). Authentication smoke
exercised no Docker images; the final unified run retained all five exercised image identities.
- FAIL baseline evidence remains unchanged: Ruff reports 192 errors; MkDocs strict reports 69
warnings; canonical/workspace install checks have existing wording mismatches; Pi user-auth
Compose has the existing model-policy mismatch; deployment coupling sees preserved ignored private
material.
- PENDING: native Windows execution because required host prerequisites are unavailable; real
PSD/manual acceptance because no real identity/access is available; L2 because its configured
secret layout is unavailable; isolated provider readiness because an unrelated host port is
occupied. These are not PASS claims.
- Final Task 15 review after fix round 5 is **CHANGES REQUIRED**. In addition to the StageArchive
cleanup race above, Windows claim removal closes validated retained parent handles before using
pathname-based `DeleteFile`, leaving an ancestor-swap race. The five-round breaker is exhausted;
no sixth implementation round was started.
- Final whole-branch review found one additional Important defect: on POSIX, the local-user registry
checks type, link count, and mode but not effective-UID ownership for `users.yaml` and its parent.
A foreign-owned `0600` registry can therefore remain writable by that owner and alter local
credentials or roles, including administrator access. Add fail-closed ownership checks on every
POSIX registry path and foreign-owner rejection coverage.
- **Implementation/release state: NOT COMPLETE.** Resolve both Important code-review findings and
the registry-ownership finding, rerun the affected tests/reviews, then make every required
FAIL/PENDING gate PASS in an eligible environment before marking authentication complete or
release-accepted. The branch is not ready to merge.
- Frozen source under test is `b31b27e5845ffd3adf311429367319beaba263c7` on `feat/thoth-auth`.
No tracked source changed during certification; only `.playwright-cli/` and `.thothctl/` remain
untracked.
- Local PASS: Go focused security tests for `safeio`, `backup`, and `authstorage`; Go race across
18 packages; `go vet`; host build; Windows amd64 cross-compile; Node `v24.16.0` backend
`76/1092` and frontend `61/444` with typecheck/build; authentication/F1 smoke and sentinel
scan; authentication docs smoke; shell syntax.
- Local FAIL: harness `951 passed / 1 failed / 4 skipped` (the F4 column-decision test cannot find
`workflow.yaml` from its test cwd); Ruff `192` errors; default Compose missing its required
workspace-remote variable; unified Compose references absent `compose.unified.yaml`.
- Authorized workflow run `32122302381` (URL in the Task 4 report) has the exact frozen SHA and
conclusion `failure`. Its `Windows clone and Compose contract` job `95665197885` really ran the
native `safeio`/`backup` command and failed, including a 10-minute backup lifecycle-lock
timeout. The frozen workflow does not request `internal/authstorage`, so that native evidence is
absent rather than inferred from cross-compilation.
- The same run's LF/Compose/docs/TS job failed on an unset `TMPDIR` after its unified Compose
contract passed (baseline/CI contract). Its Linux Docker job failed before deployment because
`rg` was unavailable; cleanup proof passed and no new image manifest was generated (runner
prerequisite). The historical five-image manifest remains bound to source
`74b062f1a737103524cbe706346cfd65f87cdfd1` and was not rewritten for this candidate. L2, real
PSD/manual acceptance, and provider readiness remain `PENDING` where prerequisites are unavailable.
- Durable current evidence is tracked in `.artifacts/task-15/automated-gates.json` and
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`; the historical
Task 15 report contains a separate Task 4 addendum. Current automated-gates SHA-256 is
`e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`; the unchanged historical
Docker manifest SHA-256 is `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
- **Implementation/release state: NOT COMPLETE.** The three Important findings remain
`CHANGES_REQUIRED`; overall release readiness is `FAIL` with additional `PENDING` gates. No
source fix was attempted in Task 4.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)