Files
ThothII/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md
T

5.1 KiB

Task 15 retained release-gate report — fix round 4 (sanitized)

  • Final tested source commit: 54698e73400a54ce7c3e6c10099e14eb471ce8b9.
  • Historical retained source commits: fix-round-2 fe190e7046acc173f510dddcb32f46ed142858c1, maintenance follow-up 4d230b87afdcd24f02264f8f937c8628b92db05a, and prior final Docker source e20bf33e2a00102192e5be66b178037aeca3a7b1.
  • Versions: Node contract v24.16.0; host default Node v25.6.1; Go go1.26.5; Pi 0.80.3.
  • Automated gate artifact: .artifacts/task-15/automated-gates.json; SHA-256 cce61f6a51ea0a3312e26b7b38a2601512b3e45cd4177d37e60ed7d7ee5cf110.
  • Docker image manifest: .artifacts/task-15/unified-docker-images.json; SHA-256 d6845cb3436872ee6a722916f3aa2ad058c5fd66c61333ccad18c0302933361e.

Fix-round-4 evidence

  • PASS: test-first safe-I/O stream creator. The focused test first failed because CreateCanonicalNewPrivateFile was absent; after implementation, four native selected tests passed: the safe-I/O read/write stream, Unix staged-file privacy, post-write cleanup, and immutable staged bytes. The staged archive now enters through safeio with an exclusive private parent, 0600 Unix regular-file protection, and an owner-only DACL set in the Windows creation call before archive bytes are streamed.
  • PASS: full backup and safe-I/O package tests and their race runs. The final source also passed go test -race ./... across 18 packages and a native host tht CLI build.
  • PASS: Windows amd64 static test/build cross-compile across 18 packages, including the staged archive Windows test that calls safeio.ValidatePrivateRegular. This was cross-compile only; no Windows executable was run. Native execution remains PENDING.
  • PASS on Node v24.16.0: the hermetic OIDC/F1 authentication browser smoke passed for the current 8 checks in frontend/e2e/auth.spec.ts and frontend/e2e/f1.spec.ts; its exact runtime sentinel leak scan passed.
  • PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract.
  • PASS: final unified Docker deployment smoke run 20260818061612-31842-22636, bound to source 54698e73400a54ce7c3e6c10099e14eb471ce8b9. It exercised the maintenance-auth isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.

Sanitized final unified Docker output

== Build and start isolated local Compose distribution ==
== Recreate offline and retain the validated registry snapshot ==
== Pull a valid catalog+descriptor metadata update ==
== Pull a content-only Git Evidence update ==
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
== Reject orphan descriptor directories not listed in the catalog ==
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818061612-31842-22636.

Sanitized Docker image identities

  • sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a; role compose-runtime.
  • sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c; role compose-runtime.
  • sha256:9e59fd16740628538879652e9fb94472ef4f192418bfd5203fdf6a929df80532; role compose-runtime.
  • sha256:b3441d8c9ce6c95fc28eb6df8db1eb83d522e72e2a9d2a0709edb99f53ef5ad5; roles compose-runtime, fixture-runtime.
  • sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178; role rollback-candidate.

For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted.

Complete observed matrix

  • PASS: Task 13 lifecycle carry-ins; streamed owner-private restore staging; provider fixture round-one 6/6; backend Node 24 round-one suite 75 files / 1081 tests; frontend Node 24 round-one suite 61 files / 444 tests; current Node 24 authentication/F1 browser smoke 8/8; final-source Go race/build 18 packages; Windows static cross-compile 18 packages; harness round-one suite 921 passed / 4 L2 deselected; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
  • FAIL: Ruff 192 known-baseline errors; MkDocs strict 69 known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material.
  • PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied.

The authentication feature is not release-complete while required FAIL or PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.