156 lines
10 KiB
Markdown
156 lines
10 KiB
Markdown
# Task 15 retained release-gate report — fix round 5 (sanitized)
|
|
|
|
## Task 4 recertification addendum — frozen source `b31b27e5845ffd3adf311429367319beaba263c7`
|
|
|
|
This addendum supersedes the earlier source-bound matrix for current certification while preserving
|
|
the fix-round-5 material below as historical provenance.
|
|
|
|
- Certification status: `FAIL` / `CHANGES_REQUIRED`; no tracked source changed after the freeze.
|
|
- Native Windows workflow run `32122302381` was dispatched on the exact frozen SHA and concluded
|
|
`failure`. Job `Windows clone and Compose contract` (`95665197885`) executed the native
|
|
`safeio`/`backup` test command, which failed; `internal/authstorage` was not part of that frozen
|
|
workflow command.
|
|
- Local current results: Go focused/race/vet/build and Windows cross-compile PASS; Node 24 backend
|
|
`76 files / 1092 tests`, frontend `61 files / 444 tests`, typechecks/builds and authentication
|
|
smoke PASS; harness `951 passed / 1 failed / 4 skipped`, Ruff `192` errors, and Compose contracts
|
|
FAIL; authentication docs and shell syntax PASS.
|
|
- The same run's `LF, Compose, docs, and TypeScript` job (`95665197839`) failed on an unset `TMPDIR`
|
|
in the deployment-coupling scope script after its unified Compose contract passed; this is a
|
|
baseline/CI contract issue. Its Linux Docker job (`95665197846`) stopped before deployment because
|
|
`rg` was unavailable; cleanup proof passed and no image manifest was generated, so this is an
|
|
infrastructure prerequisite issue rather than a source-bound Docker result.
|
|
- The remote unified Docker smoke attempt therefore failed before deployment; the existing image
|
|
manifest below remains historical and is not evidence for the new source.
|
|
- Current machine-readable evidence and the requested Task 4 report are recorded in
|
|
`.artifacts/task-15/automated-gates.json` and
|
|
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
|
|
- Current automated-gates SHA-256: `e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c`.
|
|
- Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
|
|
|
|
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the
|
|
requested Task 4 report.
|
|
|
|
- Final tested source commit: `74b062f1a737103524cbe706346cfd65f87cdfd1`.
|
|
- Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`,
|
|
maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, prior final Docker
|
|
source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, and fix-round-4 streamed
|
|
archive privacy `54698e73400a54ce7c3e6c10099e14eb471ce8b9`.
|
|
- Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`;
|
|
Pi `0.80.3`.
|
|
- Historical automated gate artifact: `.artifacts/task-15/automated-gates.json`;
|
|
SHA-256 `7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`.
|
|
- Docker image manifest: `.artifacts/task-15/unified-docker-images.json`;
|
|
SHA-256 `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
|
|
|
|
## Fix-round-5 evidence
|
|
|
|
- PASS, RED then GREEN: `TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap`
|
|
first failed because the creator had not retained its parent before creation. It now opens every
|
|
Unix ancestor once, creates the leaf with `openat(O_NOFOLLOW|O_CREAT|O_EXCL)`, applies and checks
|
|
`0600` by descriptor (`fchmod`/`fstat`), and uses `unlinkat` for creator failure cleanup. The
|
|
deterministic test moves the opened parent, replaces its lexical name with an outside symlink,
|
|
validates the archive under the moved original parent, and proves no outside archive was written.
|
|
- PASS: the Windows implementation uses NT `RootDirectory`-relative traversal for every component
|
|
after the volume root and for final file creation. The retained final parent receives only the
|
|
required child-create right (`FILE_WRITE_DATA` for a file, `FILE_APPEND_DATA` for a directory),
|
|
reparse points are rejected, and the owner-only protected DACL is installed in the same
|
|
`NtCreateFile` operation. The native-Windows test attempts the pre-create parent swap and calls
|
|
`safeio.ValidatePrivateRegular`; it is compiled but not executed on this host.
|
|
- PASS: `go test ./internal/safeio ./internal/backup -count=1`, `go test -race ./...` across
|
|
`18` packages, `go vet ./...`, and a native host `tht` CLI build. Existing StageArchive
|
|
capacity, lifecycle, rollback, streaming, and cleanup tests remain passing.
|
|
- PASS, compile-only: Windows amd64 static test/build compilation across `18` packages, including
|
|
the retained-handle Windows tests. No Windows executable was run; native execution remains
|
|
PENDING and is not inferred from compilation.
|
|
- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed all current
|
|
`8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; the runtime sentinel
|
|
leak scan passed.
|
|
- PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose
|
|
contract, and Compose secret-policy contract.
|
|
- PASS: final unified Docker deployment smoke run `20260818070637-66409-30058`, bound exactly to
|
|
source `74b062f1a737103524cbe706346cfd65f87cdfd1`. It exercised maintenance-auth isolation,
|
|
restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
|
|
|
|
## Sanitized final unified Docker output
|
|
|
|
```text
|
|
== Build and start isolated local Compose distribution ==
|
|
== Recreate offline and retain the validated registry snapshot ==
|
|
== Pull a valid catalog+descriptor metadata update ==
|
|
== Pull a content-only Git Evidence update ==
|
|
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
|
|
== Reject orphan descriptor directories not listed in the catalog ==
|
|
== Reject the retired flat workspace layout and retain the valid snapshot ==
|
|
== Inject a bad pinned Pi candidate and prove automatic rollback ==
|
|
Task 13 full deployment smoke passed.
|
|
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.
|
|
```
|
|
|
|
## Sanitized Docker image identities
|
|
|
|
- `sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d`;
|
|
roles `compose-runtime`, `fixture-runtime`.
|
|
- `sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687`;
|
|
role `compose-runtime`.
|
|
- `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`;
|
|
role `compose-runtime`.
|
|
- `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`;
|
|
role `compose-runtime`.
|
|
- `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`;
|
|
role `rollback-candidate`.
|
|
|
|
For each image, the retained repository-digest component equals the listed image digest. Registry
|
|
names and credentials are deliberately omitted.
|
|
|
|
## Complete observed matrix
|
|
|
|
- PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture
|
|
round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24
|
|
round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`;
|
|
final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness
|
|
round-one suite `921 passed / 4 L2 deselected`; authentication docs round-one gate; shell/Compose
|
|
contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
|
|
- FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing
|
|
canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling
|
|
scan against preserved ignored private material.
|
|
- PENDING: native Windows execution because required host prerequisites are unavailable; L2 because
|
|
the configured secret layout is unavailable; real PSD/manual acceptance because no real
|
|
identity/access is available; isolated provider readiness because an unrelated host port is
|
|
occupied.
|
|
|
|
## Final Task 15 review after fix round 5
|
|
|
|
The fresh Terra review verdict is **CHANGES REQUIRED**. The five-round breaker is exhausted; no
|
|
sixth implementation round was started. Two Important findings remain:
|
|
|
|
- `StageArchive` does not retain the opaque parent/directory capability through the complete
|
|
stream and `Close` lifecycle. Staging-directory creation and final cleanup still use pathname
|
|
operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect
|
|
cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and
|
|
native Windows.
|
|
- Windows claim removal closes its validated retained parent handles before calling pathname-based
|
|
`DeleteFile`. Removal must instead remain handle-relative (or delete through the opened handle),
|
|
with a native-Windows ancestor-swap test.
|
|
|
|
The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability,
|
|
and cleanup results above remain valid evidence for source `74b062f1a737103524cbe706346cfd65f87cdfd1`.
|
|
They do not override the final code-review verdict. Native Windows execution remains PENDING.
|
|
|
|
The authentication feature is **not implementation-complete or release-complete** while these code
|
|
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
|
|
endpoints, or registry names are retained.
|
|
|
|
## Final whole-branch review
|
|
|
|
The final read-only Terra review of `351361f..39b5453` also returned **CHANGES REQUIRED** and found
|
|
one additional Important issue: the POSIX local-user registry validates file type, link count, and
|
|
mode for `users.yaml` and its parent directory, but does not require ownership by the effective UID.
|
|
A foreign-owned `0600` registry inside a runtime-owned `0700` directory can remain writable by the
|
|
foreign owner and be used to alter credentials or grant the administrator role. The registry must
|
|
enforce effective-UID ownership on every POSIX `lstat`/`fstat` path and add foreign-owner rejection
|
|
coverage.
|
|
|
|
No new Critical issue or load-bearing Minor issue was found. The branch is **not ready to merge**:
|
|
this ownership defect and the two retained-capability cleanup defects above require fixes and renewed
|
|
review, independently of the remaining FAIL/PENDING release gates.
|