10 KiB
Task 15 retained release-gate report — fix round 5 (sanitized)
Final-review fix-round-2 addendum — frozen source 2a9359071257f9b8a71d36ec2bbb25b161003f81
This addendum supersedes the fix-round-1 addendum for current authentication remediation status while preserving the fix-round-5 material below as historical provenance.
- Authentication remediation status:
PASS. The three original remediation Important findings remainRESOLVED; the fix-round-2 fully bounded lifecycle Important isADDRESSED; and the temporary Windows diagnostic-matrix Minor isADDRESSED. - Overall branch/release readiness is separately
FAIL, with unavailable external/manual gatesPENDING. - Completed exact-source workflow run
32147345625concludedfailureon baseline release jobs. ItsWindows clone and Compose contractjob (95744249248) executed the unfiltered commandgo test ./internal/safeio ./internal/backup ./internal/authstorage -count=1; the native step passed all three packages: safeio22.058s, backup7.161s, authstorage16.088s. - The Windows job failed only afterward in the baseline clone-contract script at
scripts/test-windows-clone-contract.ps1:208, where PowerShell rejects the undelimited$remoteYaml:variable reference. LF, Compose, docs, and TypeScriptjob95744249458reproduced the baseline unset-TMPDIRfailure after unified Compose passed. Linux Docker job95744249354reproduced the missing-rgprerequisite failure; cleanup passed and no image manifest was generated.- The skipped Windows Docker Desktop/WSL2 job is recorded as
NOT_RUN/BLOCKED, not FAIL. Downstream commands skipped after executed baseline failures use the same classification. The matrix contains an explicit nativewindows_stagearchive_retained_capabilityPASS row. - Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to
its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness
remain
PENDING. - Current machine-readable evidence and the requested Task 4 report are recorded in
.artifacts/task-15/automated-gates.jsonand.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md. - The full fix-round-2 RED/GREEN and finding disposition is recorded in
.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md. - Current automated-gates SHA-256:
6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599. - Historical unified Docker manifest SHA-256:
9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the requested Task 4 report.
- Final tested source commit:
74b062f1a737103524cbe706346cfd65f87cdfd1. - Historical retained source commits: fix-round-2
fe190e7046acc173f510dddcb32f46ed142858c1, maintenance follow-up4d230b87afdcd24f02264f8f937c8628b92db05a, prior final Docker sourcee20bf33e2a00102192e5be66b178037aeca3a7b1, and fix-round-4 streamed archive privacy54698e73400a54ce7c3e6c10099e14eb471ce8b9. - Versions: Node contract
v24.16.0; host default Nodev25.6.1; Gogo1.26.5; Pi0.80.3. - Historical automated gate artifact:
.artifacts/task-15/automated-gates.json; SHA-2567d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f. - Docker image manifest:
.artifacts/task-15/unified-docker-images.json; SHA-2569c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.
Fix-round-5 evidence
- PASS, RED then GREEN:
TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwapfirst failed because the creator had not retained its parent before creation. It now opens every Unix ancestor once, creates the leaf withopenat(O_NOFOLLOW|O_CREAT|O_EXCL), applies and checks0600by descriptor (fchmod/fstat), and usesunlinkatfor creator failure cleanup. The deterministic test moves the opened parent, replaces its lexical name with an outside symlink, validates the archive under the moved original parent, and proves no outside archive was written. - PASS: the Windows implementation uses NT
RootDirectory-relative traversal for every component after the volume root and for final file creation. The retained final parent receives only the required child-create right (FILE_WRITE_DATAfor a file,FILE_APPEND_DATAfor a directory), reparse points are rejected, and the owner-only protected DACL is installed in the sameNtCreateFileoperation. The native-Windows test attempts the pre-create parent swap and callssafeio.ValidatePrivateRegular; it is compiled but not executed on this host. - PASS:
go test ./internal/safeio ./internal/backup -count=1,go test -race ./...across18packages,go vet ./..., and a native hostthtCLI build. Existing StageArchive capacity, lifecycle, rollback, streaming, and cleanup tests remain passing. - PASS, compile-only: Windows amd64 static test/build compilation across
18packages, including the retained-handle Windows tests. No Windows executable was run; native execution remains PENDING and is not inferred from compilation. - PASS on Node
v24.16.0: the hermetic OIDC/F1 authentication browser smoke passed all current8checks infrontend/e2e/auth.spec.tsandfrontend/e2e/f1.spec.ts; the runtime sentinel leak scan passed. - PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract.
- PASS: final unified Docker deployment smoke run
20260818070637-66409-30058, bound exactly to source74b062f1a737103524cbe706346cfd65f87cdfd1. It exercised maintenance-auth isolation, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
Sanitized final unified Docker output
== Build and start isolated local Compose distribution ==
== Recreate offline and retain the validated registry snapshot ==
== Pull a valid catalog+descriptor metadata update ==
== Pull a content-only Git Evidence update ==
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
== Reject orphan descriptor directories not listed in the catalog ==
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.
Sanitized Docker image identities
sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d; rolescompose-runtime,fixture-runtime.sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687; rolecompose-runtime.sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a; rolecompose-runtime.sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c; rolecompose-runtime.sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178; rolerollback-candidate.
For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted.
Complete observed matrix
- PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture
round-one
6/6; backend Node 24 round-one suite75 files / 1081 tests; frontend Node 24 round-one suite61 files / 444 tests; current Node 24 authentication/F1 browser smoke8/8; final-source Go race/build18 packages; Windows static cross-compile18 packages; harness round-one suite921 passed / 4 L2 deselected; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup. - FAIL: Ruff
192known-baseline errors; MkDocs strict69known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material. - PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied.
Final Task 15 review after fix round 5
The fresh Terra review verdict is CHANGES REQUIRED. The five-round breaker is exhausted; no sixth implementation round was started. Two Important findings remain:
StageArchivedoes not retain the opaque parent/directory capability through the complete stream andCloselifecycle. Staging-directory creation and final cleanup still use pathname operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and native Windows.- Windows claim removal closes its validated retained parent handles before calling pathname-based
DeleteFile. Removal must instead remain handle-relative (or delete through the opened handle), with a native-Windows ancestor-swap test.
The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability,
and cleanup results above remain valid evidence for source 74b062f1a737103524cbe706346cfd65f87cdfd1.
They do not override the final code-review verdict. Native Windows execution remains PENDING.
The authentication feature is not implementation-complete or release-complete while these code findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.
Final whole-branch review
The final read-only Terra review of 351361f..39b5453 also returned CHANGES REQUIRED and found
one additional Important issue: the POSIX local-user registry validates file type, link count, and
mode for users.yaml and its parent directory, but does not require ownership by the effective UID.
A foreign-owned 0600 registry inside a runtime-owned 0700 directory can remain writable by the
foreign owner and be used to alter credentials or grant the administrator role. The registry must
enforce effective-UID ownership on every POSIX lstat/fstat path and add foreign-owner rejection
coverage.
No new Critical issue or load-bearing Minor issue was found. The branch is not ready to merge: this ownership defect and the two retained-capability cleanup defects above require fixes and renewed review, independently of the remaining FAIL/PENDING release gates.