Files
2026-09-30 20:30:56 +03:00

129 lines
5.5 KiB
Markdown

# Task 1.3 Baseline Evidence
## Status
This file records the best available historical baseline for task 1.3 and its
reproducibility limits. It does not claim that a pre-change image was rerun during
this change, and it does not convert current tests into pre-change evidence.
An immutable rerun of the exact pre-change source and image is unavailable. On
2026-09-18, the reviewer explicitly accepted this documentary baseline and waived
that rerun requirement. Task 1.3 therefore relies on the historical record below;
current regression results remain separately identified as post-change evidence.
## Historical pre-change record
The repository's [`DOCKER_MIGRATION.md`](../../../DOCKER_MIGRATION.md), under
"Current Verified Evidence," records a final run on 2026-09-15. It reports:
- The selected container regression suite completed with **578 passed** and
**7 expected Windows-only tests skipped on Linux**, with no failures recorded.
- The selected suite used test image
`sha256:4ce11325728ba3e58e6643c1c8e800f317179d5c7c50e7e80568b58f62dbdfd0`.
- The separate six-test `docker/test_verify.py` suite passed on Windows and WSL
Linux; those six tests were not included in the 578 count.
- The recorded offline E2E passed its result/check gates and removed its owned
resources. This is contextual historical evidence, not a rerun for task 1.3.
The `add-minimal-remote-scan-workers` OpenSpec change was created on 2026-09-17,
after that recorded run. The preserved records contain no pre-existing failure
for the cited 578-test selection to list separately. "No recorded failure" means
only that no failure record was found; it is not proof that no unrecorded attempt
failed.
## Reproducibility limits
- The old test image is unavailable and was not retrieved, rebuilt, or executed.
Current Docker runs use new, dedicated test image identities.
- This workspace has no commit history. On 2026-09-18, `git status` reported
`No commits yet on master` and every repository path as untracked; `git log`
failed because the branch has no commits.
- `WORKSPACE.md` names a source-side provenance commit, but also states that this
source-only snapshot includes modified and selected untracked files and did not
copy source Git history. It is not an immutable tree for either 2026-09-15 or
the moment immediately before the 2026-09-17 OpenSpec change.
- The image digest and prose result are therefore useful historical evidence but
cannot independently reconstruct or rerun the claimed chronology from this
repository.
## Current expanded selection
The current reviewed allowlist is the `SELECTION` mapping in
`tests/container_unit.py`. On 2026-09-18, its stdlib-only selection check reported
**33 modules and 649 test definitions**, with no runner skips at declaration time;
pytest parametrization may expand the executed count.
The current mapping selects:
```text
test_docker_foundation.py
test_container_runtime.py
test_owned_process.py
test_owned_process_linux.py
test_owned_process_boundary.py
test_runtime_bootstrap_authority.py
test_supervisor_foreground_shutdown.py
test_supervisor_startup_rollback.py
test_supervisor_managed_postgres_gate.py
test_observer_only_coordinated_shutdown.py
test_supervisor_safety.py
test_postgres_runtime.py
test_container_security.py
test_runtime_security.py
test_postgres_empty_initialization.py
test_container_migration_paths.py
test_container_provider_portability.py
test_container_e2e_helpers.py
test_container_import.py
test_container_import_config.py
test_container_projection_recovery.py
test_result_bundle_v2.py
test_pipeline_cutover_invariants.py
test_custom_provider_detector_compatibility.py
test_scan_execution.py
test_synthetic_llm_pipeline.py
test_worker_api.py
test_worker_api_runtime.py
test_worker_assignment.py
test_worker_package.py
test_remote_worker_db.py
test_admin_api.py
test_edge_deployment.py
```
The remote-worker, package, administration, edge, synthetic-pipeline, and bundle
modules in this current selection postdate the historical baseline. Their
presence demonstrates current review scope, not pre-change execution.
## Current post-change evidence
The expanded selection and isolated end-to-end gates were rerun on 2026-09-19.
They validate the completed implementation but do not replace the historical
pre-change baseline:
```text
python -I -S -B tests/container_unit.py --check-selection
container-unit: AST OK; 33 modules, 650 test definitions, no runner skips (parametrizations expand in pytest)
isolated Linux container selection
867 passed, 7 expected platform skips
wsl.exe -d Ubuntu-24.04 -- python3 docker/verify.py
E2E passed; project truf-worker-test-99b193a64f46a0002e34da9c5ff8029a; artifacts removed
python -B docker/verify_packaged_workers.py ...
Windows/Linux packaged-worker E2E passed; run 348d24046fb7b8d4; cleanup complete; foreign Docker state unchanged
Windows package manifest sha256 f0bbbbf79d9f5f3f17440a60561b307fa7bafd312ab6110b14098ff90755f8e6
Linux worker image manifest list sha256 888bffc5519fd3a27cb52d20eaea1143f89ac9779bb2e4b0d998e450583c57a0
python -B docker/verify_edge_e2e.py --timeout-seconds 1200
Edge/fail2ban E2E passed; run 597b3ff7826055e1; cleanup complete; foreign Docker state unchanged
openspec validate add-minimal-remote-scan-workers --strict --no-interactive
Change 'add-minimal-remote-scan-workers' is valid
```
The current runs used only random or dedicated test-owned identities and verified
that foreign container and volume metadata remained unchanged. No current result
is represented as historical or pre-change evidence.