# Task 15 retained release-gate report — fix round 3 (sanitized) - Final tested source commit: `e20bf33e2a00102192e5be66b178037aeca3a7b1`. - Fix-round-2 commits retained unchanged: `fe190e7046acc173f510dddcb32f46ed142858c1` and follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`. - Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`; Pi `0.80.3`. - Automated gate artifact: `.artifacts/task-15/automated-gates.json`; SHA-256 `af835ab5eb37951881cc526a9576eb5789af510e0e4f2806d4d8ed080fb70fba`. - Docker image manifest: `.artifacts/task-15/unified-docker-images.json`; SHA-256 `835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7`. ## Fix-round-3 evidence - PASS: backup staging RED/GREEN focused set `4/4`; full backup package; full Go race and build across `18` packages. Staging now uses the repository `safeio` owner-only directory mechanisms, rejects a symlinked installation ancestor on Unix, and includes a Windows-only owner-DACL test. - PASS: Windows amd64 static test/build cross-compile across `18` packages. Native execution of the Windows-only ACL test was not available and is therefore PENDING, not PASS. - PASS on Node `v24.16.0`: deterministic provider security fixture `6/6`; authentication smoke `8/8` across `frontend/e2e/auth.spec.ts` and authenticated `frontend/e2e/f1.spec.ts`. The runtime sentinel was the exact fixture OIDC client secret and group bearer, and the retained output leak scan passed. - PASS: shell syntax, unified-smoke safety self-tests, default/unified Compose contracts, and Compose secret policy. - PASS: final unified Docker deployment smoke run `20260818054002-16619-2452`, bound to source commit `e20bf33e2a00102192e5be66b178037aeca3a7b1`. It exercised the maintenance authentication isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup. - PASS: Docker image traceability for all `5` images exercised by the final unified run. The authentication browser smoke exercised no Docker images and is explicitly retained as an empty image set. ## Sanitized Docker image identities - `sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6`; roles `compose-runtime`, `fixture-runtime`. - `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`; role `compose-runtime`. - `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`; role `compose-runtime`. - `sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d`; role `compose-runtime`. - `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`; role `rollback-candidate`. For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted. ## Complete observed matrix - PASS: Task13 lifecycle carry-ins; platform-private restore staging; provider fixture `6/6`; backend Node24 round-1 suite `75 files / 1081 tests`; frontend Node24 round-1 suite `61 files / 444 tests`; current authentication/F1 browser smoke `8/8`; Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness round-1 suite `921 passed / 4 L2 deselected`; authentication docs round-1 gate; shell/Compose contracts; unified Docker smoke; five-image traceability; Docker cleanup. - FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material. - PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied. The authentication feature is **not release-complete** while required FAIL or PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.