134 lines
8.1 KiB
Markdown
134 lines
8.1 KiB
Markdown
# Final-review fix round 2 report (sanitized)
|
|
|
|
## Verdict
|
|
|
|
- Base evidence head: `0f762ad6b67675356389cc546421a1c46ad5a736`.
|
|
- Frozen source: `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.
|
|
- Authentication remediation: **PASS**.
|
|
- Three original remediation Important findings: **RESOLVED**.
|
|
- Fix-round-2 bounded lifecycle Important: **ADDRESSED**.
|
|
- Fix-round-2 temporary Windows diagnostics Minor: **ADDRESSED**.
|
|
- Release readiness: **FAIL** for executed unrelated baseline gates, with unavailable
|
|
external/manual gates separately **PENDING**.
|
|
- Source and evidence are separate commits. The evidence-only phase changed no source or tests and
|
|
dispatched no workflow.
|
|
|
|
## Finding disposition
|
|
|
|
| Finding | Disposition | Evidence |
|
|
|---|---|---|
|
|
| Original Important — POSIX local-registry ownership | RESOLVED | Effective-UID ownership enforcement and its Node 24 coverage remain green at their recorded source. Fix round 2 did not alter this boundary. |
|
|
| Original Important — retained-capability StageArchive lifecycle | RESOLVED | Native Windows `internal/backup` passed on the exact source, preserving the retained-root staging and cleanup coverage. |
|
|
| Original Important — handle-relative Windows claim removal | RESOLVED | Native Windows `internal/safeio` and `internal/authstorage` passed on the exact source, including retained claim/consume coverage. |
|
|
| Fix-round-2 Important — fully bounded restore lifecycle test | ADDRESSED | Gate publication and release are context-aware; stage, outcome, admission, checkpoint, and verification waits are bounded; aborts cancel, safely release, bounded-join, then assert lock-free. The deterministic withheld-gate test proves prompt timeout/cancellation, worker join, and eventual lock release. |
|
|
| Fix-round-2 Minor — temporary Windows diagnostic matrix | ADDRESSED | `windowsRelativeOpenMatrix` and its diagnostic-only call/import were removed. Owner-only DACL shape, NT access normalization, full-control, cleanup, and retained no-delete tests remain. |
|
|
|
|
The round-1 restore lifecycle finding was broadened by the scoped round-2 review: bounded release
|
|
alone was insufficient while stage publication, gate waits, and nearby outcome/admission waits
|
|
could still outlive a controller abort. The round-2 implementation closes that broader test
|
|
orchestration gap without changing production authentication semantics.
|
|
|
|
## RED → GREEN record
|
|
|
|
### RED
|
|
|
|
The deterministic withheld-gate regression was introduced first and run without relying on a
|
|
global ten-minute package timeout:
|
|
|
|
```text
|
|
go test ./internal/backup -run '^TestRestoreLifecycleCancellationJoinsWithWithheldGate$' -count=1
|
|
```
|
|
|
|
It failed in approximately `0.64s` with:
|
|
|
|
```text
|
|
cancelled restore worker did not join within the bounded deadline
|
|
```
|
|
|
|
This proved that cancellation did not yet unblock and join a worker retained at the lifecycle
|
|
gate.
|
|
|
|
### GREEN and refactor
|
|
|
|
- The gate uses a cancellation source shared by controller and worker. Both publication and
|
|
release are `select`-based and cancellation-aware.
|
|
- Shared bounded helpers cover stage, outcome, error, signal, release, and admission waits.
|
|
- Abort cleanup is ordered: cancel, cancel the controller gate when distinct, safely release a
|
|
pending gate, bounded-join the worker, then prove the lifecycle lock is free.
|
|
- Premature worker outcomes retain and surface their original error.
|
|
- The existing success, recovery, maintenance-barrier, stale-checkpoint, and verification
|
|
assertions remain active.
|
|
|
|
Final local gates on the frozen source:
|
|
|
|
```text
|
|
go test ./internal/backup -run '^(TestRestoreLifecycleCancellationJoinsWithWithheldGate|TestReleaseLifecycleStage|TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup|TestRestoreCannotApplyAStaleCheckpointOverAnInterleavedRestore|TestRestoreKeepsAdmissionBarrierActiveUntilVerificationCommits)$' -count=1
|
|
go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1
|
|
go test ./... -count=1
|
|
go test -race ./...
|
|
go vet ./...
|
|
go build -o /tmp/thothii-tht-host-fix-round-2 ./cmd/tht
|
|
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/safeio -o /tmp/tht-safeio-fix-round-2-windows.test.exe
|
|
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/backup -o /tmp/tht-backup-fix-round-2-windows.test.exe
|
|
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/authstorage -o /tmp/tht-authstorage-fix-round-2-windows.test.exe
|
|
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -o /tmp/thothii-tht-fix-round-2-windows.exe ./cmd/tht
|
|
```
|
|
|
|
All commands passed. The final focused lifecycle run completed in `0.672s`; the full security
|
|
package run passed safeio, backup, and authstorage; race, vet, host build, Windows test-package
|
|
cross-compiles, and Windows CLI cross-compile also passed. Cross-compilation is recorded only as
|
|
compile evidence and is not used as native authority.
|
|
|
|
## Exact-source native certification
|
|
|
|
- Controller-authorized run: `32147345625` —
|
|
https://github.com/mptyl/ThothII/actions/runs/32147345625.
|
|
- Event/status/conclusion: `workflow_dispatch` / `completed` / `failure`.
|
|
- Head SHA: `2a9359071257f9b8a71d36ec2bbb25b161003f81`, exactly matching the frozen source.
|
|
- Windows job: `Windows clone and Compose contract`, job `95744249248` —
|
|
https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249248.
|
|
- Native step: `Run native Windows retained-capability tests` — **PASS**.
|
|
- Exact unfiltered command:
|
|
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`.
|
|
- Native package results:
|
|
- `internal/safeio` PASS (`22.058s`);
|
|
- `internal/backup` PASS (`7.161s`);
|
|
- `internal/authstorage` PASS (`16.088s`).
|
|
|
|
The Windows job failed only in the following baseline clone-contract step. PowerShell reported a
|
|
parser error at `scripts/test-windows-clone-contract.ps1:208` because `$remoteYaml:` is not a
|
|
delimited variable reference. This later failure does not alter the successful native Go step.
|
|
|
|
## Separate release-readiness verdict
|
|
|
|
| Gate | Classification | Exact outcome |
|
|
|---|---|---|
|
|
| Authentication remediation | PASS | Source and exact-source native three-package authority are green. |
|
|
| Windows clone contract | FAIL / baseline | Job `95744249248`; parser error at `scripts/test-windows-clone-contract.ps1:208`, after native PASS. |
|
|
| LF, Compose, docs, and TypeScript | FAIL / baseline CI contract | Job `95744249458`; unified Compose passed, then the existing unset-`TMPDIR` failure stopped the contract step. Downstream commands were skipped. |
|
|
| Linux Docker deployment and rollback | FAIL / infrastructure prerequisite | Job `95744249354`; the existing missing-`rg` prerequisite stopped the smoke before deployment. Cleanup passed and no new image manifest was generated. |
|
|
| Native Windows Docker Desktop/WSL2 startup | NOT_RUN / BLOCKED | Job `95744250450` was skipped by workflow conditions; no native Docker/WSL2 command ran. |
|
|
| L2, real PSD/manual acceptance, provider readiness | PENDING | Required secrets, identity/access, or provider prerequisites remain unavailable. |
|
|
|
|
Executed failures remain `FAIL`; skipped commands are `NOT_RUN` / `BLOCKED`; unavailable external
|
|
gates remain `PENDING`. Therefore remediation PASS does not imply release readiness PASS.
|
|
|
|
## Evidence and protection status
|
|
|
|
- Machine-readable evidence: `.artifacts/task-15/automated-gates.json`; SHA-256
|
|
`6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`.
|
|
- Current Task 4 report:
|
|
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
|
|
- Retained Task 15 report:
|
|
`.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md`.
|
|
- Project snapshot: `PROJECT_STATE.md`.
|
|
- Historical Docker evidence remains bound to its recorded older source and is not reused as proof
|
|
for `2a9359071257f9b8a71d36ec2bbb25b161003f81`.
|
|
- `.playwright-cli/` and `.thothctl/` remain protected and untracked. No source/test file,
|
|
instruction file, workflow, or `docs/agents/` content changed in this evidence phase.
|
|
- The separate evidence commit SHA is reported after commit creation because a commit cannot
|
|
contain its own final hash.
|
|
|
|
No credentials, tokens, internal endpoints, identities, registry names, raw environments, or
|
|
browser traces are retained in this report.
|