8.1 KiB
Final-review fix round 2 report (sanitized)
Verdict
- Base evidence head:
0f762ad6b67675356389cc546421a1c46ad5a736. - Frozen source:
2a9359071257f9b8a71d36ec2bbb25b161003f81onfeat/thoth-auth. - Authentication remediation: PASS.
- Three original remediation Important findings: RESOLVED.
- Fix-round-2 bounded lifecycle Important: ADDRESSED.
- Fix-round-2 temporary Windows diagnostics Minor: ADDRESSED.
- Release readiness: FAIL for executed unrelated baseline gates, with unavailable external/manual gates separately PENDING.
- Source and evidence are separate commits. The evidence-only phase changed no source or tests and dispatched no workflow.
Finding disposition
| Finding | Disposition | Evidence |
|---|---|---|
| Original Important — POSIX local-registry ownership | RESOLVED | Effective-UID ownership enforcement and its Node 24 coverage remain green at their recorded source. Fix round 2 did not alter this boundary. |
| Original Important — retained-capability StageArchive lifecycle | RESOLVED | Native Windows internal/backup passed on the exact source, preserving the retained-root staging and cleanup coverage. |
| Original Important — handle-relative Windows claim removal | RESOLVED | Native Windows internal/safeio and internal/authstorage passed on the exact source, including retained claim/consume coverage. |
| Fix-round-2 Important — fully bounded restore lifecycle test | ADDRESSED | Gate publication and release are context-aware; stage, outcome, admission, checkpoint, and verification waits are bounded; aborts cancel, safely release, bounded-join, then assert lock-free. The deterministic withheld-gate test proves prompt timeout/cancellation, worker join, and eventual lock release. |
| Fix-round-2 Minor — temporary Windows diagnostic matrix | ADDRESSED | windowsRelativeOpenMatrix and its diagnostic-only call/import were removed. Owner-only DACL shape, NT access normalization, full-control, cleanup, and retained no-delete tests remain. |
The round-1 restore lifecycle finding was broadened by the scoped round-2 review: bounded release alone was insufficient while stage publication, gate waits, and nearby outcome/admission waits could still outlive a controller abort. The round-2 implementation closes that broader test orchestration gap without changing production authentication semantics.
RED → GREEN record
RED
The deterministic withheld-gate regression was introduced first and run without relying on a global ten-minute package timeout:
go test ./internal/backup -run '^TestRestoreLifecycleCancellationJoinsWithWithheldGate$' -count=1
It failed in approximately 0.64s with:
cancelled restore worker did not join within the bounded deadline
This proved that cancellation did not yet unblock and join a worker retained at the lifecycle gate.
GREEN and refactor
- The gate uses a cancellation source shared by controller and worker. Both publication and
release are
select-based and cancellation-aware. - Shared bounded helpers cover stage, outcome, error, signal, release, and admission waits.
- Abort cleanup is ordered: cancel, cancel the controller gate when distinct, safely release a pending gate, bounded-join the worker, then prove the lifecycle lock is free.
- Premature worker outcomes retain and surface their original error.
- The existing success, recovery, maintenance-barrier, stale-checkpoint, and verification assertions remain active.
Final local gates on the frozen source:
go test ./internal/backup -run '^(TestRestoreLifecycleCancellationJoinsWithWithheldGate|TestReleaseLifecycleStage|TestRestoreLifecycleLockExcludesCompetingTransactionsUntilTerminalCleanup|TestRestoreCannotApplyAStaleCheckpointOverAnInterleavedRestore|TestRestoreKeepsAdmissionBarrierActiveUntilVerificationCommits)$' -count=1
go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1
go test ./... -count=1
go test -race ./...
go vet ./...
go build -o /tmp/thothii-tht-host-fix-round-2 ./cmd/tht
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/safeio -o /tmp/tht-safeio-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/backup -o /tmp/tht-backup-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -c ./internal/authstorage -o /tmp/tht-authstorage-fix-round-2-windows.test.exe
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -o /tmp/thothii-tht-fix-round-2-windows.exe ./cmd/tht
All commands passed. The final focused lifecycle run completed in 0.672s; the full security
package run passed safeio, backup, and authstorage; race, vet, host build, Windows test-package
cross-compiles, and Windows CLI cross-compile also passed. Cross-compilation is recorded only as
compile evidence and is not used as native authority.
Exact-source native certification
- Controller-authorized run:
32147345625— https://github.com/mptyl/ThothII/actions/runs/32147345625. - Event/status/conclusion:
workflow_dispatch/completed/failure. - Head SHA:
2a9359071257f9b8a71d36ec2bbb25b161003f81, exactly matching the frozen source. - Windows job:
Windows clone and Compose contract, job95744249248— https://github.com/mptyl/ThothII/actions/runs/32147345625/job/95744249248. - Native step:
Run native Windows retained-capability tests— PASS. - Exact unfiltered command:
go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1. - Native package results:
internal/safeioPASS (22.058s);internal/backupPASS (7.161s);internal/authstoragePASS (16.088s).
The Windows job failed only in the following baseline clone-contract step. PowerShell reported a
parser error at scripts/test-windows-clone-contract.ps1:208 because $remoteYaml: is not a
delimited variable reference. This later failure does not alter the successful native Go step.
Separate release-readiness verdict
| Gate | Classification | Exact outcome |
|---|---|---|
| Authentication remediation | PASS | Source and exact-source native three-package authority are green. |
| Windows clone contract | FAIL / baseline | Job 95744249248; parser error at scripts/test-windows-clone-contract.ps1:208, after native PASS. |
| LF, Compose, docs, and TypeScript | FAIL / baseline CI contract | Job 95744249458; unified Compose passed, then the existing unset-TMPDIR failure stopped the contract step. Downstream commands were skipped. |
| Linux Docker deployment and rollback | FAIL / infrastructure prerequisite | Job 95744249354; the existing missing-rg prerequisite stopped the smoke before deployment. Cleanup passed and no new image manifest was generated. |
| Native Windows Docker Desktop/WSL2 startup | NOT_RUN / BLOCKED | Job 95744250450 was skipped by workflow conditions; no native Docker/WSL2 command ran. |
| L2, real PSD/manual acceptance, provider readiness | PENDING | Required secrets, identity/access, or provider prerequisites remain unavailable. |
Executed failures remain FAIL; skipped commands are NOT_RUN / BLOCKED; unavailable external
gates remain PENDING. Therefore remediation PASS does not imply release readiness PASS.
Evidence and protection status
- Machine-readable evidence:
.artifacts/task-15/automated-gates.json; SHA-2566c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599. - Current Task 4 report:
.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md. - Retained Task 15 report:
.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md. - Project snapshot:
PROJECT_STATE.md. - Historical Docker evidence remains bound to its recorded older source and is not reused as proof
for
2a9359071257f9b8a71d36ec2bbb25b161003f81. .playwright-cli/and.thothctl/remain protected and untracked. No source/test file, instruction file, workflow, ordocs/agents/content changed in this evidence phase.- The separate evidence commit SHA is reported after commit creation because a commit cannot contain its own final hash.
No credentials, tokens, internal endpoints, identities, registry names, raw environments, or browser traces are retained in this report.