# Task 15 retained release-gate report — fix round 5 (sanitized) ## Final-review fix-round-2 addendum — frozen source `2a9359071257f9b8a71d36ec2bbb25b161003f81` This addendum supersedes the fix-round-1 addendum for current authentication remediation status while preserving the fix-round-5 material below as historical provenance. - Authentication remediation status: `PASS`. The three original remediation Important findings remain `RESOLVED`; the fix-round-2 fully bounded lifecycle Important is `ADDRESSED`; and the temporary Windows diagnostic-matrix Minor is `ADDRESSED`. - Overall branch/release readiness is separately `FAIL`, with unavailable external/manual gates `PENDING`. - Completed exact-source workflow run `32147345625` concluded `failure` on baseline release jobs. Its `Windows clone and Compose contract` job (`95744249248`) executed the unfiltered command `go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step passed all three packages: safeio `22.058s`, backup `7.161s`, authstorage `16.088s`. - The Windows job failed only afterward in the baseline clone-contract script at `scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited `$remoteYaml:` variable reference. - `LF, Compose, docs, and TypeScript` job `95744249458` reproduced the baseline unset-`TMPDIR` failure after unified Compose passed. Linux Docker job `95744249354` reproduced the missing-`rg` prerequisite failure; cleanup passed and no image manifest was generated. - The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL. Downstream commands skipped after executed baseline failures use the same classification. The matrix contains an explicit native `windows_stagearchive_retained_capability` PASS row. - Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness remain `PENDING`. - Current machine-readable evidence and the requested Task 4 report are recorded in `.artifacts/task-15/automated-gates.json` and `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`. - The full fix-round-2 RED/GREEN and finding disposition is recorded in `.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`. - Current automated-gates SHA-256: `6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`. - Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the requested Task 4 report. - Final tested source commit: `74b062f1a737103524cbe706346cfd65f87cdfd1`. - Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`, maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, prior final Docker source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, and fix-round-4 streamed archive privacy `54698e73400a54ce7c3e6c10099e14eb471ce8b9`. - Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`; Pi `0.80.3`. - Historical automated gate artifact: `.artifacts/task-15/automated-gates.json`; SHA-256 `7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`. - Docker image manifest: `.artifacts/task-15/unified-docker-images.json`; SHA-256 `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`. ## Fix-round-5 evidence - PASS, RED then GREEN: `TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap` first failed because the creator had not retained its parent before creation. It now opens every Unix ancestor once, creates the leaf with `openat(O_NOFOLLOW|O_CREAT|O_EXCL)`, applies and checks `0600` by descriptor (`fchmod`/`fstat`), and uses `unlinkat` for creator failure cleanup. The deterministic test moves the opened parent, replaces its lexical name with an outside symlink, validates the archive under the moved original parent, and proves no outside archive was written. - PASS: the Windows implementation uses NT `RootDirectory`-relative traversal for every component after the volume root and for final file creation. The retained final parent receives only the required child-create right (`FILE_WRITE_DATA` for a file, `FILE_APPEND_DATA` for a directory), reparse points are rejected, and the owner-only protected DACL is installed in the same `NtCreateFile` operation. The native-Windows test attempts the pre-create parent swap and calls `safeio.ValidatePrivateRegular`; it is compiled but not executed on this host. - PASS: `go test ./internal/safeio ./internal/backup -count=1`, `go test -race ./...` across `18` packages, `go vet ./...`, and a native host `tht` CLI build. Existing StageArchive capacity, lifecycle, rollback, streaming, and cleanup tests remain passing. - PASS, compile-only: Windows amd64 static test/build compilation across `18` packages, including the retained-handle Windows tests. No Windows executable was run; native execution remains PENDING and is not inferred from compilation. - PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed all current `8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; the runtime sentinel leak scan passed. - PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract. - PASS: final unified Docker deployment smoke run `20260818070637-66409-30058`, bound exactly to source `74b062f1a737103524cbe706346cfd65f87cdfd1`. It exercised maintenance-auth isolation, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup. ## Sanitized final unified Docker output ```text == Build and start isolated local Compose distribution == == Recreate offline and retain the validated registry snapshot == == Pull a valid catalog+descriptor metadata update == == Pull a content-only Git Evidence update == == Reject catalog/descriptor metadata mismatch and retain the valid snapshot == == Reject orphan descriptor directories not listed in the catalog == == Reject the retired flat workspace layout and retain the valid snapshot == == Inject a bad pinned Pi candidate and prove automatic rollback == Task 13 full deployment smoke passed. Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058. ``` ## Sanitized Docker image identities - `sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d`; roles `compose-runtime`, `fixture-runtime`. - `sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687`; role `compose-runtime`. - `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`; role `compose-runtime`. - `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`; role `compose-runtime`. - `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`; role `rollback-candidate`. For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted. ## Complete observed matrix - PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24 round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`; final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness round-one suite `921 passed / 4 L2 deselected`; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup. - FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material. - PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied. ## Final Task 15 review after fix round 5 The fresh Terra review verdict is **CHANGES REQUIRED**. The five-round breaker is exhausted; no sixth implementation round was started. Two Important findings remain: - `StageArchive` does not retain the opaque parent/directory capability through the complete stream and `Close` lifecycle. Staging-directory creation and final cleanup still use pathname operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and native Windows. - Windows claim removal closes its validated retained parent handles before calling pathname-based `DeleteFile`. Removal must instead remain handle-relative (or delete through the opened handle), with a native-Windows ancestor-swap test. The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability, and cleanup results above remain valid evidence for source `74b062f1a737103524cbe706346cfd65f87cdfd1`. They do not override the final code-review verdict. Native Windows execution remains PENDING. The authentication feature is **not implementation-complete or release-complete** while these code findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained. ## Final whole-branch review The final read-only Terra review of `351361f..39b5453` also returned **CHANGES REQUIRED** and found one additional Important issue: the POSIX local-user registry validates file type, link count, and mode for `users.yaml` and its parent directory, but does not require ownership by the effective UID. A foreign-owned `0600` registry inside a runtime-owned `0700` directory can remain writable by the foreign owner and be used to alter credentials or grant the administrator role. The registry must enforce effective-UID ownership on every POSIX `lstat`/`fstat` path and add foreign-owner rejection coverage. No new Critical issue or load-bearing Minor issue was found. The branch is **not ready to merge**: this ownership defect and the two retained-capability cleanup defects above require fixes and renewed review, independently of the remaining FAIL/PENDING release gates.