164 lines
10 KiB
Markdown
164 lines
10 KiB
Markdown
# Task 15 retained release-gate report — fix round 5 (sanitized)
|
|
|
|
## Final-review fix-round-2 addendum — frozen source `2a9359071257f9b8a71d36ec2bbb25b161003f81`
|
|
|
|
This addendum supersedes the fix-round-1 addendum for current authentication remediation status
|
|
while preserving the fix-round-5 material below as historical provenance.
|
|
|
|
- Authentication remediation status: `PASS`. The three original remediation Important findings
|
|
remain `RESOLVED`; the fix-round-2 fully bounded lifecycle Important is `ADDRESSED`; and the
|
|
temporary Windows diagnostic-matrix Minor is `ADDRESSED`.
|
|
- Overall branch/release readiness is separately `FAIL`, with unavailable external/manual gates
|
|
`PENDING`.
|
|
- Completed exact-source workflow run `32147345625` concluded `failure` on baseline release jobs.
|
|
Its `Windows clone and Compose contract` job (`95744249248`) executed the unfiltered command
|
|
`go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1`; the native step
|
|
passed all three packages: safeio `22.058s`, backup `7.161s`, authstorage `16.088s`.
|
|
- The Windows job failed only afterward in the baseline clone-contract script at
|
|
`scripts/test-windows-clone-contract.ps1:208`, where PowerShell rejects the undelimited
|
|
`$remoteYaml:` variable reference.
|
|
- `LF, Compose, docs, and TypeScript` job `95744249458` reproduced the baseline unset-`TMPDIR`
|
|
failure after unified Compose passed. Linux Docker job `95744249354` reproduced the missing-`rg`
|
|
prerequisite failure; cleanup passed and no image manifest was generated.
|
|
- The skipped Windows Docker Desktop/WSL2 job is recorded as `NOT_RUN` / `BLOCKED`, not FAIL.
|
|
Downstream commands skipped after executed baseline failures use the same classification. The
|
|
matrix contains an explicit native `windows_stagearchive_retained_capability` PASS row.
|
|
- Historical Node/auth/browser/docs PASS and harness/Ruff/Compose FAIL evidence remains bound to
|
|
its recorded source where not rerun. L2, real PSD/manual acceptance, and provider readiness
|
|
remain `PENDING`.
|
|
- Current machine-readable evidence and the requested Task 4 report are recorded in
|
|
`.artifacts/task-15/automated-gates.json` and
|
|
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md`.
|
|
- The full fix-round-2 RED/GREEN and finding disposition is recorded in
|
|
`.superpowers/sdd/2026-08-18-thothii-authentication-remediation/fix-round-2-report.md`.
|
|
- Current automated-gates SHA-256:
|
|
`6c516db5c2064c4a4a2e5f25961b993cd4a8fe020bbbb822fbac7faa0c119599`.
|
|
- Historical unified Docker manifest SHA-256: `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
|
|
|
|
The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the
|
|
requested Task 4 report.
|
|
|
|
- Final tested source commit: `74b062f1a737103524cbe706346cfd65f87cdfd1`.
|
|
- Historical retained source commits: fix-round-2 `fe190e7046acc173f510dddcb32f46ed142858c1`,
|
|
maintenance follow-up `4d230b87afdcd24f02264f8f937c8628b92db05a`, prior final Docker
|
|
source `e20bf33e2a00102192e5be66b178037aeca3a7b1`, and fix-round-4 streamed
|
|
archive privacy `54698e73400a54ce7c3e6c10099e14eb471ce8b9`.
|
|
- Versions: Node contract `v24.16.0`; host default Node `v25.6.1`; Go `go1.26.5`;
|
|
Pi `0.80.3`.
|
|
- Historical automated gate artifact: `.artifacts/task-15/automated-gates.json`;
|
|
SHA-256 `7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f`.
|
|
- Docker image manifest: `.artifacts/task-15/unified-docker-images.json`;
|
|
SHA-256 `9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6`.
|
|
|
|
## Fix-round-5 evidence
|
|
|
|
- PASS, RED then GREEN: `TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap`
|
|
first failed because the creator had not retained its parent before creation. It now opens every
|
|
Unix ancestor once, creates the leaf with `openat(O_NOFOLLOW|O_CREAT|O_EXCL)`, applies and checks
|
|
`0600` by descriptor (`fchmod`/`fstat`), and uses `unlinkat` for creator failure cleanup. The
|
|
deterministic test moves the opened parent, replaces its lexical name with an outside symlink,
|
|
validates the archive under the moved original parent, and proves no outside archive was written.
|
|
- PASS: the Windows implementation uses NT `RootDirectory`-relative traversal for every component
|
|
after the volume root and for final file creation. The retained final parent receives only the
|
|
required child-create right (`FILE_WRITE_DATA` for a file, `FILE_APPEND_DATA` for a directory),
|
|
reparse points are rejected, and the owner-only protected DACL is installed in the same
|
|
`NtCreateFile` operation. The native-Windows test attempts the pre-create parent swap and calls
|
|
`safeio.ValidatePrivateRegular`; it is compiled but not executed on this host.
|
|
- PASS: `go test ./internal/safeio ./internal/backup -count=1`, `go test -race ./...` across
|
|
`18` packages, `go vet ./...`, and a native host `tht` CLI build. Existing StageArchive
|
|
capacity, lifecycle, rollback, streaming, and cleanup tests remain passing.
|
|
- PASS, compile-only: Windows amd64 static test/build compilation across `18` packages, including
|
|
the retained-handle Windows tests. No Windows executable was run; native execution remains
|
|
PENDING and is not inferred from compilation.
|
|
- PASS on Node `v24.16.0`: the hermetic OIDC/F1 authentication browser smoke passed all current
|
|
`8` checks in `frontend/e2e/auth.spec.ts` and `frontend/e2e/f1.spec.ts`; the runtime sentinel
|
|
leak scan passed.
|
|
- PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose
|
|
contract, and Compose secret-policy contract.
|
|
- PASS: final unified Docker deployment smoke run `20260818070637-66409-30058`, bound exactly to
|
|
source `74b062f1a737103524cbe706346cfd65f87cdfd1`. It exercised maintenance-auth isolation,
|
|
restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.
|
|
|
|
## Sanitized final unified Docker output
|
|
|
|
```text
|
|
== Build and start isolated local Compose distribution ==
|
|
== Recreate offline and retain the validated registry snapshot ==
|
|
== Pull a valid catalog+descriptor metadata update ==
|
|
== Pull a content-only Git Evidence update ==
|
|
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
|
|
== Reject orphan descriptor directories not listed in the catalog ==
|
|
== Reject the retired flat workspace layout and retain the valid snapshot ==
|
|
== Inject a bad pinned Pi candidate and prove automatic rollback ==
|
|
Task 13 full deployment smoke passed.
|
|
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.
|
|
```
|
|
|
|
## Sanitized Docker image identities
|
|
|
|
- `sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d`;
|
|
roles `compose-runtime`, `fixture-runtime`.
|
|
- `sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687`;
|
|
role `compose-runtime`.
|
|
- `sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a`;
|
|
role `compose-runtime`.
|
|
- `sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c`;
|
|
role `compose-runtime`.
|
|
- `sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178`;
|
|
role `rollback-candidate`.
|
|
|
|
For each image, the retained repository-digest component equals the listed image digest. Registry
|
|
names and credentials are deliberately omitted.
|
|
|
|
## Complete observed matrix
|
|
|
|
- PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture
|
|
round-one `6/6`; backend Node 24 round-one suite `75 files / 1081 tests`; frontend Node 24
|
|
round-one suite `61 files / 444 tests`; current Node 24 authentication/F1 browser smoke `8/8`;
|
|
final-source Go race/build `18 packages`; Windows static cross-compile `18 packages`; harness
|
|
round-one suite `921 passed / 4 L2 deselected`; authentication docs round-one gate; shell/Compose
|
|
contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
|
|
- FAIL: Ruff `192` known-baseline errors; MkDocs strict `69` known-baseline warnings; existing
|
|
canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling
|
|
scan against preserved ignored private material.
|
|
- PENDING: native Windows execution because required host prerequisites are unavailable; L2 because
|
|
the configured secret layout is unavailable; real PSD/manual acceptance because no real
|
|
identity/access is available; isolated provider readiness because an unrelated host port is
|
|
occupied.
|
|
|
|
## Final Task 15 review after fix round 5
|
|
|
|
The fresh Terra review verdict is **CHANGES REQUIRED**. The five-round breaker is exhausted; no
|
|
sixth implementation round was started. Two Important findings remain:
|
|
|
|
- `StageArchive` does not retain the opaque parent/directory capability through the complete
|
|
stream and `Close` lifecycle. Staging-directory creation and final cleanup still use pathname
|
|
operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect
|
|
cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and
|
|
native Windows.
|
|
- Windows claim removal closes its validated retained parent handles before calling pathname-based
|
|
`DeleteFile`. Removal must instead remain handle-relative (or delete through the opened handle),
|
|
with a native-Windows ancestor-swap test.
|
|
|
|
The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability,
|
|
and cleanup results above remain valid evidence for source `74b062f1a737103524cbe706346cfd65f87cdfd1`.
|
|
They do not override the final code-review verdict. Native Windows execution remains PENDING.
|
|
|
|
The authentication feature is **not implementation-complete or release-complete** while these code
|
|
findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal
|
|
endpoints, or registry names are retained.
|
|
|
|
## Final whole-branch review
|
|
|
|
The final read-only Terra review of `351361f..39b5453` also returned **CHANGES REQUIRED** and found
|
|
one additional Important issue: the POSIX local-user registry validates file type, link count, and
|
|
mode for `users.yaml` and its parent directory, but does not require ownership by the effective UID.
|
|
A foreign-owned `0600` registry inside a runtime-owned `0700` directory can remain writable by the
|
|
foreign owner and be used to alter credentials or grant the administrator role. The registry must
|
|
enforce effective-UID ownership on every POSIX `lstat`/`fstat` path and add foreign-owner rejection
|
|
coverage.
|
|
|
|
No new Critical issue or load-bearing Minor issue was found. The branch is **not ready to merge**:
|
|
this ownership defect and the two retained-capability cleanup defects above require fixes and renewed
|
|
review, independently of the remaining FAIL/PENDING release gates.
|