Files
ThothII/.superpowers/sdd/2026-08-16-thothii-authentication/task-15-report.md
T

10 KiB

Task 15 retained release-gate report — fix round 5 (sanitized)

Task 4 recertification addendum — frozen source b31b27e5845ffd3adf311429367319beaba263c7

This addendum supersedes the earlier source-bound matrix for current certification while preserving the fix-round-5 material below as historical provenance.

  • Certification status: FAIL / CHANGES_REQUIRED; no tracked source changed after the freeze.
  • Native Windows workflow run 32122302381 was dispatched on the exact frozen SHA and concluded failure. Job Windows clone and Compose contract (95665197885) executed the native safeio/backup test command, which failed; internal/authstorage was not part of that frozen workflow command.
  • Local current results: Go focused/race/vet/build and Windows cross-compile PASS; Node 24 backend 76 files / 1092 tests, frontend 61 files / 444 tests, typechecks/builds and authentication smoke PASS; harness 951 passed / 1 failed / 4 skipped, Ruff 192 errors, and Compose contracts FAIL; authentication docs and shell syntax PASS.
  • The same run's LF, Compose, docs, and TypeScript job (95665197839) failed on an unset TMPDIR in the deployment-coupling scope script after its unified Compose contract passed; this is a baseline/CI contract issue. Its Linux Docker job (95665197846) stopped before deployment because rg was unavailable; cleanup proof passed and no image manifest was generated, so this is an infrastructure prerequisite issue rather than a source-bound Docker result.
  • The remote unified Docker smoke attempt therefore failed before deployment; the existing image manifest below remains historical and is not evidence for the new source.
  • Current machine-readable evidence and the requested Task 4 report are recorded in .artifacts/task-15/automated-gates.json and .superpowers/sdd/2026-08-18-thothii-authentication-remediation/task-4-report.md.
  • Current automated-gates SHA-256: e0cb84185354b740ce97c8d21d365160b321c88722d08cc31b668ec4cab0353c.
  • Historical unified Docker manifest SHA-256: 9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.

The complete sanitized Task 4 matrix and the separate remediation/release verdicts are in the requested Task 4 report.

  • Final tested source commit: 74b062f1a737103524cbe706346cfd65f87cdfd1.
  • Historical retained source commits: fix-round-2 fe190e7046acc173f510dddcb32f46ed142858c1, maintenance follow-up 4d230b87afdcd24f02264f8f937c8628b92db05a, prior final Docker source e20bf33e2a00102192e5be66b178037aeca3a7b1, and fix-round-4 streamed archive privacy 54698e73400a54ce7c3e6c10099e14eb471ce8b9.
  • Versions: Node contract v24.16.0; host default Node v25.6.1; Go go1.26.5; Pi 0.80.3.
  • Historical automated gate artifact: .artifacts/task-15/automated-gates.json; SHA-256 7d9ec93af15510605f1aa7179b26a7ee46d78122f647854300f7a9922057a63f.
  • Docker image manifest: .artifacts/task-15/unified-docker-images.json; SHA-256 9c8dec4546909fd93799dbcf374bcb3a89bc46cfe0fd482472c0cbe757ddf5b6.

Fix-round-5 evidence

  • PASS, RED then GREEN: TestCreateCanonicalNewPrivateFileUsesPinnedParentAfterAncestorSwap first failed because the creator had not retained its parent before creation. It now opens every Unix ancestor once, creates the leaf with openat(O_NOFOLLOW|O_CREAT|O_EXCL), applies and checks 0600 by descriptor (fchmod/fstat), and uses unlinkat for creator failure cleanup. The deterministic test moves the opened parent, replaces its lexical name with an outside symlink, validates the archive under the moved original parent, and proves no outside archive was written.
  • PASS: the Windows implementation uses NT RootDirectory-relative traversal for every component after the volume root and for final file creation. The retained final parent receives only the required child-create right (FILE_WRITE_DATA for a file, FILE_APPEND_DATA for a directory), reparse points are rejected, and the owner-only protected DACL is installed in the same NtCreateFile operation. The native-Windows test attempts the pre-create parent swap and calls safeio.ValidatePrivateRegular; it is compiled but not executed on this host.
  • PASS: go test ./internal/safeio ./internal/backup -count=1, go test -race ./... across 18 packages, go vet ./..., and a native host tht CLI build. Existing StageArchive capacity, lifecycle, rollback, streaming, and cleanup tests remain passing.
  • PASS, compile-only: Windows amd64 static test/build compilation across 18 packages, including the retained-handle Windows tests. No Windows executable was run; native execution remains PENDING and is not inferred from compilation.
  • PASS on Node v24.16.0: the hermetic OIDC/F1 authentication browser smoke passed all current 8 checks in frontend/e2e/auth.spec.ts and frontend/e2e/f1.spec.ts; the runtime sentinel leak scan passed.
  • PASS: shell syntax, unified-smoke safety self-test, default Compose contract, unified Compose contract, and Compose secret-policy contract.
  • PASS: final unified Docker deployment smoke run 20260818070637-66409-30058, bound exactly to source 74b062f1a737103524cbe706346cfd65f87cdfd1. It exercised maintenance-auth isolation, restore, registry lifecycle, bad-candidate rollback, image revalidation, and task-scoped cleanup.

Sanitized final unified Docker output

== Build and start isolated local Compose distribution ==
== Recreate offline and retain the validated registry snapshot ==
== Pull a valid catalog+descriptor metadata update ==
== Pull a content-only Git Evidence update ==
== Reject catalog/descriptor metadata mismatch and retain the valid snapshot ==
== Reject orphan descriptor directories not listed in the catalog ==
== Reject the retired flat workspace layout and retain the valid snapshot ==
== Inject a bad pinned Pi candidate and prove automatic rollback ==
Task 13 full deployment smoke passed.
Task 13 cleanup proof: no labeled containers, volumes, networks, or images remain for 20260818070637-66409-30058.

Sanitized Docker image identities

  • sha256:2d7b19491c7eb8c119c3cedb390aaeb2ff5593f6fc43ab66c317565560da6d7d; roles compose-runtime, fixture-runtime.
  • sha256:3b6c31a5d8f8fc58fa3233391b6175bd2fbc793eebb44d5e285ecc6e02e9e687; role compose-runtime.
  • sha256:57f573b47f1f71ebb445789f279fe3e596a8beab182f7cf486db9205bad87c5a; role compose-runtime.
  • sha256:75eab8c4ba42096724fdcfde8b4de0b5713d529dde32f285a1f86fdcb2c9e50c; role compose-runtime.
  • sha256:c3cbe1cc1aa588a64951ac6286e0df7b27fe2e6324b1001c619bb358770c0178; role rollback-candidate.

For each image, the retained repository-digest component equals the listed image digest. Registry names and credentials are deliberately omitted.

Complete observed matrix

  • PASS: Task 13 lifecycle carry-ins; retained-handle owner-private restore staging; provider fixture round-one 6/6; backend Node 24 round-one suite 75 files / 1081 tests; frontend Node 24 round-one suite 61 files / 444 tests; current Node 24 authentication/F1 browser smoke 8/8; final-source Go race/build 18 packages; Windows static cross-compile 18 packages; harness round-one suite 921 passed / 4 L2 deselected; authentication docs round-one gate; shell/Compose contracts; final unified Docker smoke; five-image traceability; and Docker cleanup.
  • FAIL: Ruff 192 known-baseline errors; MkDocs strict 69 known-baseline warnings; existing canonical/workspace install wording checks; existing Pi model-policy check; deployment-coupling scan against preserved ignored private material.
  • PENDING: native Windows execution because required host prerequisites are unavailable; L2 because the configured secret layout is unavailable; real PSD/manual acceptance because no real identity/access is available; isolated provider readiness because an unrelated host port is occupied.

Final Task 15 review after fix round 5

The fresh Terra review verdict is CHANGES REQUIRED. The five-round breaker is exhausted; no sixth implementation round was started. Two Important findings remain:

  • StageArchive does not retain the opaque parent/directory capability through the complete stream and Close lifecycle. Staging-directory creation and final cleanup still use pathname operations, so an ancestor swap after creation can strand the secret-bearing archive or redirect cleanup. Deterministic StageArchive swap-and-cleanup coverage is still required on Unix and native Windows.
  • Windows claim removal closes its validated retained parent handles before calling pathname-based DeleteFile. Removal must instead remain handle-relative (or delete through the opened handle), with a native-Windows ancestor-swap test.

The focused/full Go, cross-compile, Node 24, browser, Compose, Docker lifecycle, image-traceability, and cleanup results above remain valid evidence for source 74b062f1a737103524cbe706346cfd65f87cdfd1. They do not override the final code-review verdict. Native Windows execution remains PENDING.

The authentication feature is not implementation-complete or release-complete while these code findings and the required FAIL/PENDING gates remain. No secret values, real identities, internal endpoints, or registry names are retained.

Final whole-branch review

The final read-only Terra review of 351361f..39b5453 also returned CHANGES REQUIRED and found one additional Important issue: the POSIX local-user registry validates file type, link count, and mode for users.yaml and its parent directory, but does not require ownership by the effective UID. A foreign-owned 0600 registry inside a runtime-owned 0700 directory can remain writable by the foreign owner and be used to alter credentials or grant the administrator role. The registry must enforce effective-UID ownership on every POSIX lstat/fstat path and add foreign-owner rejection coverage.

No new Critical issue or load-bearing Minor issue was found. The branch is not ready to merge: this ownership defect and the two retained-capability cleanup defects above require fixes and renewed review, independently of the remaining FAIL/PENDING release gates.