Files
ThothII/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md
T

10 KiB

Task 15 retained release-gate report — fix round 5 (sanitized)

Final-review fix-round-1 addendum — frozen source 10cd66fe6a5b484a4dc569326a228c1c5484a5d4

This addendum supersedes the earlier Task 4 pre-fix certification for current authentication remediation status while preserving the fix-round-5 material below as historical provenance.

  • Authentication remediation status: implementation PASS; all four final-review Important findings are addressed. Overall branch/release readiness remains FAIL with external gates PENDING.
  • Completed exact-source workflow run 32141428407 concluded failure on baseline release jobs. Its Windows clone and Compose contract job (95724751282) executed the unfiltered command go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1; the native step passed all three packages: safeio 8.230s, backup 5.195s, authstorage 8.383s.
  • The Windows job failed only afterward in the baseline clone-contract script at scripts/test-windows-clone-contract.ps1:208, where PowerShell rejects the undelimited $remoteYaml: variable reference.
  • LF, Compose, docs, and TypeScript job 95724751205 reproduced the baseline unset-TMPDIR failure after unified Compose passed. Linux Docker job 95724751356 reproduced the missing-rg prerequisite failure; cleanup passed and no image manifest was generated.
  • The skipped Windows Docker Desktop/WSL2 job is recorded as NOT_RUN / BLOCKED, not FAIL. Downstream commands skipped after executed baseline failures use the same classification. The matrix contains an explicit native windows_stagearchive_retained_capability PASS row.
  • Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness remain PENDING.
  • Current machine-readable evidence and the requested Task 4 report are recorded in .artifacts/task-15/automated-gates.json and .superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md.
  • Current automated-gates SHA-256: 5c110b7b2607693de078def441b10290c5a29024c83b7e5a0ced894b72b7507f.
  • Historical unified Docker manifest SHA-256: 9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.

The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the requested Task 4 report.

  • Final tested source commit: 74b062f1a737103524cbe706346cfd65f87cdfd1.
  • Historical retained source commits: fix-round-2 fe190e7046acc173f510dddcb32f46ed142858c1, maintenance follow-up 4d230b87afdcd24f02264f8f937c8628b92db05a, prior final Docker source e20bf33e2a00102192e5be66b178037aeca3a7b1, and fix-round-4 streamed archive privacy 54698e73400a54ce7c3e6c10099e14eb471ce8b9.
  • Versions: Node contract v24.16.0; host default Node v25.6.1; Go go1.26.5; Pi 0.80.3.
  • Historical automated gate artifact: .artifacts/task-15/automated-gates.json; SHA-256 7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f.
  • Docker image manifest: .artifacts/task-15/unified-docker-images.json; SHA-256 9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.

Fix-round-5 evidence

  • PASS, RED then GREEN: TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap first failed because the creator had not retained its parent before creation. It now opens every Unix ancestor once, creates the leaf with openat(O_NOFOLLOW|O_CREAT|O_EXCL), applies and checks 0600 by descriptor (fchmod/fstat), and uses unlinkat for creator failure cleanup. The deterministic test moves the opened parent, replaces its lexical name with an outside symlink, validates the archive under the moved original parent, and proves no outside archive was written.
  • PASS: the Windows implementation uses NT RootDirectory-relative traversal for every component after the volume root and for final file creation. The retained final parent receives only the required child-create right (FILE_WRITE_DATA for a file, FILE_APPEND_DATA for a directory), reparse points are rejected, and the owner-only protected DACL is installed in the same NtCreateFile operation. The native-Windows test attempts the pre-create parent swap and calls safeio.ValidatePrivateRegular; it is compiled but not executed on this host.
  • PASS: go test ./internal/safeio ./internal/backup -count=1, go test -race ./... across 18 packages, go vet ./..., and a native host tht CLI build. Existing StageArchive capacity, lifecycle, rollback, streaming, and cleanup tests remain passing.
  • PASS, compile-only: Windows amd64 static test/build compilation across 18 packages, including the retained-handle Windows tests. No Windows executable was run; native execution remains PENDING and is not inferred from compilation.
  • PASS on Node v24.16.0: the hermetic OIDC/F1 authentication browser smoke passed all current 8 checks in frontend/e2e/auth.spec.ts and frontend/e2e/f1.spec.ts; the runtime sentinel leak scan passed.
  • PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract.
  • PASS: final unified Docker deployment smoke run 20260818070637-66409-30058, bound exactly to source 74b062f1a737103524cbe706346cfd65f87cdfd1. It exercised maintenance-auth isolation, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.

Sanitized final unified Docker output

== Build and start isolated local Compose distribution ==
== Recreate offline and retain the validated registry snapshot ==
== Pull a valid catalog+descriptor metadata update ==
== Pull a content-only Git Evidence update ==
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
== Reject orphan descriptor directories not listed in the catalog ==
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.

Sanitized Docker image identities

  • sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d; roles compose-runtime, fixture-runtime.
  • sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687; role compose-runtime.
  • sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a; role compose-runtime.
  • sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c; role compose-runtime.
  • sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178; role rollback-candidate.

For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted.

Complete observed matrix

  • PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture round-one 6/6; backend Node 24 round-one suite 75 files / 1081 tests; frontend Node 24 round-one suite 61 files / 444 tests; current Node 24 authentication/F1 browser smoke 8/8; final-source Go race/build 18 packages; Windows static cross-compile 18 packages; harness round-one suite 921 passed / 4 L2 deselected; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
  • FAIL: Ruff 192 known-baseline errors; MkDocs strict 69 known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material.
  • PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied.

Final Task 15 review after fix round 5

The fresh Terra review verdict is CHANGES REQUIRED. The five-round breaker is exhausted; no sixth implementation round was started. Two Important findings remain:

  • StageArchive does not retain the opaque parent/directory capability through the complete stream and Close lifecycle. Staging-directory creation and final cleanup still use pathname operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and native Windows.
  • Windows claim removal closes its validated retained parent handles before calling pathname-based DeleteFile. Removal must instead remain handle-relative (or delete through the opened handle), with a native-Windows ancestor-swap test.

The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability, and cleanup results above remain valid evidence for source 74b062f1a737103524cbe706346cfd65f87cdfd1. They do not override the final code-review verdict. Native Windows execution remains PENDING.

The authentication feature is not implementation-complete or release-complete while these code findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.

Final whole-branch review

The final read-only Terra review of 351361f..39b5453 also returned CHANGES REQUIRED and found one additional Important issue: the POSIX local-user registry validates file type, link count, and mode for users.yaml and its parent directory, but does not require ownership by the effective UID. A foreign-owned 0600 registry inside a runtime-owned 0700 directory can remain writable by the foreign owner and be used to alter credentials or grant the administrator role. The registry must enforce effective-UID ownership on every POSIX lstat/fstat path and add foreign-owner rejection coverage.

No new Critical issue or load-bearing Minor issue was found. The branch is not ready to merge: this ownership defect and the two retained-capability cleanup defects above require fixes and renewed review, independently of the remaining FAIL/PENDING release gates.