# Task 15 retained release-gate report — fix round 4 (sanitized) - Final tested source commit: `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. - Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`, maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, and prior final Docker source `e20bf33e2a00102192e5be66b178037aeca3a7b1`. - Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`; Pi `0.80.3`. - Automated gate artifact: `.artifacts/task-15/automated-gates.json`; SHA-256 `cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110`. - Docker image manifest: `.artifacts/task-15/unified-docker-images.json`; SHA-256 `d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e`. ## Fix-round-4 evidence - PASS: test-first safe-I/O stream creator. The focused test first failed because `CreateCanonicalNewPrivateFile` was absent; after implementation, four native selected tests passed: the safe-I/O read/write stream, Unix staged-file privacy, post-write cleanup, and immutable staged bytes. The staged archive now enters through safeio with an exclusive private parent, `0600` Unix regular-file protection, and an owner-only DACL set in the Windows creation call before archive bytes are streamed. - PASS: full backup and safe-I/O package tests and their race runs. The final source also passed `go test -race ./...` across `18` packages and a native host `tht` CLI build. - PASS: Windows amd64 static test/build cross-compile across `18` packages, including the staged archive Windows test that calls `safeio.ValidatePrivateRegular`. This was **cross-compile only**; no Windows executable was run. Native execution remains PENDING. - PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed for the current `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; its exact runtime sentinel leak scan passed. - PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract. - PASS: final unified Docker deployment smoke run `20260818061612-31842-22636`, bound to source `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. It exercised the maintenance-auth isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup. ## Sanitized final unified Docker output ```text == Build and start isolated local Compose distribution == == Recreate offline and retain the validated registry snapshot == == Pull a valid catalog+descriptor metadata update == == Pull a content-only Git Evidence update == == Reject catalog/descriptor metadata mismatch and retain the valid snapshot == == Reject orphan descriptor directories not listed in the catalog == == Reject the retired flat workspace layout and retain the valid snapshot == == Inject a bad pinned Pi candidate and prove automatic rollback == Task 13 full deployment smoke passed. Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818061612-31842-22636. ``` ## Sanitized Docker image identities - `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`; role `compose-runtime`. - `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`; role `compose-runtime`. - `sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532`; role `compose-runtime`. - `sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5`; roles `compose-runtime`, `fixture-runtime`. - `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`; role `rollback-candidate`. For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted. ## Complete observed matrix - PASS: Task 13 lifecycle carry-ins; streamed owner-private restore staging; provider fixture round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24 round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`; final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness round-one suite `921 passed / 4 L2 deselected`; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup. - FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material. - PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied. The authentication feature is **not release-complete** while required FAIL or PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.