Files
ThothII/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md
T

4.0 KiB

Task 15 retained release-gate report — fix round 3 (sanitized)

  • Final tested source commit: e20bf33e2a00102192e5be66b178037aeca3a7b1.
  • Fix-round-2 commits retained unchanged: fe190e7046acc173f510dddcb32f46ed142858c1 and follow-up 4d230b87afdcd24f02264f8f937c8628b92db05a.
  • Versions: Node contract v24.16.0; host default Node v25.6.1; Go go1.26.5; Pi 0.80.3.
  • Automated gate artifact: .artifacts/task-15/automated-gates.json; SHA-256 af835ab5eb37951881cc526a9576eb5789af510e0e4f2806d4d8ed080fb70fba.
  • Docker image manifest: .artifacts/task-15/unified-docker-images.json; SHA-256 835790fbff5980c494c32f4473b46675ce7d568e7e6e39e30000ff0400b4dbb7.

Fix-round-3 evidence

  • PASS: backup staging RED/GREEN focused set 4/4; full backup package; full Go race and build across 18 packages. Staging now uses the repository safeio owner-only directory mechanisms, rejects a symlinked installation ancestor on Unix, and includes a Windows-only owner-DACL test.
  • PASS: Windows amd64 static test/build cross-compile across 18 packages. Native execution of the Windows-only ACL test was not available and is therefore PENDING, not PASS.
  • PASS on Node v24.16.0: deterministic provider security fixture 6/6; authentication smoke 8/8 across frontend/e2e/auth.spec.ts and authenticated frontend/e2e/f1.spec.ts. The runtime sentinel was the exact fixture OIDC client secret and group bearer, and the retained output leak scan passed.
  • PASS: shell syntax, unified-smoke safety self-tests, default/unified Compose contracts, and Compose secret policy.
  • PASS: final unified Docker deployment smoke run 20260818054002-16619-2452, bound to source commit e20bf33e2a00102192e5be66b178037aeca3a7b1. It exercised the maintenance authentication isolation check, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
  • PASS: Docker image traceability for all 5 images exercised by the final unified run. The authentication browser smoke exercised no Docker images and is explicitly retained as an empty image set.

Sanitized Docker image identities

  • sha256:2008d4ef3b7c37ff2504a5257a3e946650795c1dbd16706fd22792e5503cbfa6; roles compose-runtime, fixture-runtime.
  • sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a; role compose-runtime.
  • sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c; role compose-runtime.
  • sha256:98b79ea45d588a71ba2a5218e4b56365cb55dd00eead4a8fd5a4381b1bb0d79d; role compose-runtime.
  • sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178; role rollback-candidate.

For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted.

Complete observed matrix

  • PASS: Task13 lifecycle carry-ins; platform-private restore staging; provider fixture 6/6; backend Node24 round-1 suite 75 files / 1081 tests; frontend Node24 round-1 suite 61 files / 444 tests; current authentication/F1 browser smoke 8/8; Go race/build 18 packages; Windows static cross-compile 18 packages; harness round-1 suite 921 passed / 4 L2 deselected; authentication docs round-1 gate; shell/Compose contracts; unified Docker smoke; five-image traceability; Docker cleanup.
  • FAIL: Ruff 192 known-baseline errors; MkDocs strict 69 known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material.
  • PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied.

The authentication feature is not release-complete while required FAIL or PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.