Files
ThothII/.superpowers/sdd/2026-08-03-diagnostic-contract-extension/task-3-report.md
T

4.2 KiB

Task 3 — Diagnostic contract remediation report

Date: 2026-08-04

Scope

This remediation is limited to the four approved review findings for the workspace diagnostic extension. It does not add registry routes, change workspace publication, alter session startup, or expand transport support.

Changes

  1. RuntimeBindings now has an explicit vectorWriter binding. The new resolveRuntimeBindings() resolves DWH, vector reader, vector writer, and embedding bindings together. The diagnoser takes the writer credential only from bindings.vectorWriter, never from vector-reader values.
  2. Direct PostgreSQL and SSH-tunnelled direct probes accept an absent CA binding while retaining certificate verification through the runtime system trust store. A supplied CA still uses verified private-CA trust. REST private-CA refusal is unchanged.
  3. A reversible vector probe now requires an authenticated POST declaration with a response map containing operation. The adapter requires the successful JSON response to echo create or remove respectively, so an arbitrary 2xx or an upsert-only response cannot activate the write probe.
  4. For DWH and vector REST diagnostics declared with auth: none, the resolver no longer requires an API-key file and the adapter sends no credential. Credential-backed diagnostics continue to require their local secret file.

TDD evidence

The first focused RED run failed for the intended missing behavior:

  • resolveRuntimeBindings is not a function for unauthenticated resolver bindings;
  • schema accepted a reversible probe without a response contract; and
  • existing diagnostic fixtures rejected the new response declaration until schema support was implemented.

The focused GREEN run passed 43/43 tests across:

  • test/workspaces-bindings.test.ts
  • test/workspaces-schema.test.ts
  • test/workspaces-diagnostics.test.ts

The regression coverage includes resolver-to-diagnoser writer propagation without manually inserting the writer key into vector-reader bindings, no-CA direct/SSH system-trust requests, operation-echo validation for create/remove, and auth: none bindings without secret files.

Documentation and design

  • docs/workspace-diagnostic-protocol.md now documents the verified system-trust fallback, no-secret auth: none behavior, and required reversible response contract.
  • docs/superpowers/specs/2026-08-03-git-workspace-registry-design.md now records the same response, CA, SSH, and authentication rules.

Final verification

The initial sandboxed full suite could not bind its local SSE listener (listen EPERM: operation not permitted 127.0.0.1). It was rerun unchanged with local-listener permission.

backend: npx vitest run
31 test files passed; 329 tests passed

backend: npx tsc --noEmit -p .
exit 0

repository: git diff --check
exit 0

Expected test harness stderr from existing Pi/process failure-path tests remained present; no test failed and no diagnostic secret was emitted.

Blockers

None.

Round 2 remediation

The final review found two remaining contract gaps. The binding resolver already treated auth: none as credential-free, but the runtime renderer and diagnostic connector still required the API-key file. Rendering and connector construction now make that requirement conditional on the declared REST authentication mode, so a DWH/vector auth: none workspace passes resolver, runtime rendering, and diagnostics with no API-key file.

SSH forwarding previously changed the PostgreSQL connection host to 127.0.0.1 without retaining the original target for TLS hostname validation. Forwarded probes now carry SSH_TARGET_HOST as tlsServername into the PostgreSQL TLS options; private CA and verified system trust behavior are unchanged.

TDD RED: the new end-to-end no-key test failed at the unconditional runtime API_KEY_FILE requirement, while the SSH test showed no tlsServername on the loopback probe or database-client request. TDD GREEN: the focused backend workspace tests passed 40/40.

Round 2 final verification:

backend: npx vitest run
31 test files passed; 332 tests passed

backend: npx tsc --noEmit -p .
exit 0

repository: git diff --check
exit 0