# October 3 audit remediation

This record reconciles the [October audit](CODEBASE_AUDIT_2026-10-03.md) against
its fixes. The historical audit and original reproduction evidence remain intact.
The audit base is `b09e4d8d6d583c6711e92ada119536c5b09e1e6e` (v1.3.1).
The owner authorized fixing all findings, committing and pushing source without
a tag. No version, release or deployment is part of this work.

## Finding disposition

| ID | Resulting behavior | Regression evidence |
| --- | --- | --- |
| F01 | Installer intent is HMAC authenticated with a separate private per-user key. Only a protected config recovery inventory grants automatic recovery authority; exact requested destination, hashed backup identity, structure, journal and backup ownership are checked. Public application-parent records, including signed captured records, cannot authorize deletion or rollback. | `transaction_auth_test.go`: forgery, tampering, unrelated sibling, missing key, exact destination scope, writable inventory/backup, legitimate shared-parent recovery and captured post-commit public replay. Native Windows protected-journal and Mac `/Applications` recovery checks. |
| F02 | Web shortcut startup selects an existing regular manager executable or the running portable copy. Creating the shortcut never copies over the installed manager. Windows Script Host runs with owned children and a 30-second bound. | Linux public shortcut bytes/mode/portable tests; native Windows real `cscript.exe` creates the link while retaining an installed-manager sentinel. |
| F03 | Each FFmpeg operation reserves its own private unique staging directories and removes only those directories. Pre-existing `ffmpeg_temp` and `ffmpeg.7z` are preserved. | `ffmpeg_staging_test.go`: success, hash/download failure, cancellation and concurrent unique stages. |
| F04 | Flatpak remote discovery inherits cancellation, has a five-second limit, bounds retained output and queries exact remote names before the commit guard. | Stalled child returns deadline before commit; noisy output fails its limit; command-selection and partial setup regressions. |
| F05 | Updater rollback replay accepts a consumed backup only when the restored live executable matches the authenticated original digest and size, before any identity execution. | Restore-before-journal one/multiple-target replay, corrupted backup, forged live target non-execution and existing recovery tests. |
| F06 | ModernZ migration records intended-result bytes by digest. Recovery restores only matching applied bytes or recognizes an already restored snapshot. Later edits and ambiguous legacy evidence are retained for manual review. | Concurrent edits to existing/new files, repeated already-restored recovery, schema-1 ambiguity and persistence-failure rollback tests. |
| F07 | Unchanged hotkey lines retain quoted whitespace, comments, BOM and individual LF/CRLF endings. Editing or removing one binding preserves the others. | Exact live/backup roundtrip, quoted arguments, direct-field edits and mixed-ending edit/delete regressions. |
| F08 | Restore, rollback, hotkey and preset publication preserve existing file modes/ownership. Windows publication preserves owner and DACL before writing bytes; private new files and backups have protected ACLs at creation. Symlink/nonregular targets are rejected. | Linux 0600 preservation and missing-target snapshot tests; native Windows owner, ordered ACEs, protection, inherited Everyone-read exclusion and concurrent replacement checks. |
| F09 | Existing custom Config dropdown values render as the selected current option. Saving sends changed fields, preserving unrelated values and later local edits. | Actual template/browser and HTTP/file checks for custom choices and unrelated saves. |
| F10 | API omission preserves a setting; an explicitly blank scalar removes its global assignment and restores mpv defaults. Explicitly empty language lists retain `key=` semantics. Profiles/comments and validation-before-write remain intact. | Config document/API tests and actual browser clears, omissions and profile-preservation checks. |
| F11 | Job details subscribes before the GET, reconciles concurrent terminal changes, and cancels obsolete reads. Closed or superseded requests cannot reopen the dialog. | Real browser/SSE success, failure and cancellation during held GETs; modal close, reordered selection and callback cleanup. |
| F12 | Windows ARM64 FFmpeg selects the Aarch64 asset and validates ARM64 PE identity; AMD64/v3 selection uses matching assets. Unsupported architectures fail explicitly. | Archived synthetic ARM64/AMD64 PE fixtures across selection paths and mismatch/error tests. This is not native Windows ARM64 execution coverage. |
| F13 | v3/v4 binaries require the complete cpuid architecture baseline, including OS AVX state. AVX2 alone is insufficient. | Feature-mask tests removing each v3 prerequisite, full v3/v4 recognition and platform-native suites. |
| F14 | A scoped Tailwind CLI override locks `@parcel/watcher` 2.6.0, removing the vulnerable braces/micromatch development chain without downgrading Tailwind. | Clean locked `npm ci`, zero-advisory npm audit, frontend build/vendor tests and a real watch-mode source edit. See [dependency policy](FRONTEND_DEPENDENCIES.md). |
| F15 | A durable terminal outcome precedes authenticated finalization. Only finalized journals retire obsolete executable expectations; unfinished committed transactions keep tamper checks and rollback evidence. | Manual replacement after finalization, blocked outcome persistence with repeated recovery, and existing committed-target tamper tests. This implements the audit's qualified finalization policy. |
| F16 | Adoption refreshes the managed card on terminal success, including completion before its start response. Installed-list responses replace the wrapper correctly. | Slow real-worker/SSE/browser adoption, canonical card identity and unique DOM wrapper checks. |
| F17 | Tar preflight checks cancellation before parsing and within compressed reads, and rejects expanded header budgets before skipping bodies. Hash reads are cancellable. Full inventory validation remains. | Oversized header without body, canceled body skip, already-canceled malformed input/hash, live sentinel and staging checks. |

F01 intentionally changes recovery compatibility. Unsigned legacy records and all
public sibling records are preserved and require manual recovery; the application
does not promote them into private authority. Recovery never recreates a missing
authentication key. Keep that original key and private inventory through recovery.
A shared application parent such as `/Applications` is supported because it no
longer holds authoritative intent. Administrators and same-user malware remain
outside this cross-user file-trust boundary.

## Additional candidates addressed

All actionable cleanup and performance candidates in the audit were reviewed.
The [71-symbol disposition inventory](qa/2026-10-03/remediation/deadcode-dispositions.json)
records why each common application-unreachable symbol was removed or retained.
Exported compatibility APIs, real failure-injection seams, license accessors and
generator tooling were not deleted merely because the application entry point
does not reach them.

| Candidate | Disposition |
| --- | --- |
| Old job seeding and status helpers | Removed unused `seedActiveJobs`, obsolete UI detector, unused status helpers and output-string concatenation. Supported job cancellation/admission/start APIs remain. |
| Whole-file config API | Retained and deprecated `WriteConfig`; deterministic serialization and line/key validation added. User-document edits use the shared profile-preserving editor. |
| Runtime test assets | Embed inventory excludes frontend test sources while retaining offline runtime assets. |
| Duplicate downloads | Installer transfer/limit/cleanup behavior shares `HTTPDownloader`; updater progress and no-progress paths share completion handling. Contextual injection remains. |
| Package parsing and operations | Discovery uses shared bounded, locale-stable package queries. Pacman epochs remain intact. Duplicate legacy Linux and macOS nonstreaming operation implementations and test-only wrappers were removed. |
| Backup retention | Hotkeys, script options and installer use one regular-file-only retention policy. Literal parent directories are scanned with basename matching, including bracket-containing paths. Symlinks and unrelated files are retained. |
| UI capabilities | Web, TUI and template data use canonical `constants.SupportsMPVOverlay` and `IsPackageManaged`; duplicate method tables removed. |
| Generator writes | Fixed-name temporary writer replaced by shared unique-temp durable file publication. |
| Settings requests | One coherent `/api/settings` read initializes settings; destination refresh still preserves newer local edits. |
| Job summaries | List/SSE snapshots omit unused output copies. Focused benchmark: 491.9 ns / 3,360 B / 2 allocations versus 46,262 ns / 363,810 B / 13 allocations for detail snapshots. These are allocation measurements, not whole-app latency claims. |
| Backup enumeration | Contextual app-update checks skip unused backup scans; TUI explicitly requests the useful inventory. The deprecated compatibility API retains its combined result. |
| CPU/GPU probes | FFmpeg CPU cache performs CPU-only detection. Pure-Go macOS codec inference reuses the already detected GPU model instead of another `system_profiler` call. |
| Long-session logs | Writer rotates during the session at 10 MiB, retains one archive, bounds oversized records, serializes clear/flush and retries failed reopen. Existing oversized historical archives remain until replaced. |
| Archive work | Cancellation and early budget checks repaired. Two-pass inventory validation deliberately remains; no speculative removal of security checks or unmeasured archive speed claim. |
| Interrupted IINA attach | Cleanup is registered before attach, discovers only owned mounts, uses an independent bounded lifetime, and retains staging when detach fails. A disposable native DMG verifies cleanup after actual mount creation and a simulated post-attach cancellation/deadline result. |
| Idle Tasks | Polling continues while idle; two real browser tabs observe subsequently started jobs and terminal results. Destroy cancels timers/reads. |
| Public proof constructor | Caller-supplied manifests are signature/schema/channel/lifecycle checked before minting update authority; altered signed metadata is rejected. |
| Frontend teardown | Language-priority listeners, instance registrations and timers are removed on destruction. Real Alpine callback identity and htmx duplicate-wrapper defects found during remediation were fixed. |
| TUI observations/mutations/display | Contextual observations are registered before command dispatch, canceled and joined at exit. Preset mutations use the owned guarded stream, block navigation/new admission until drained, and render untrusted comments through terminal sanitization. |

## Independent review and validation follow-ups

Independent source review found and corrected mixed-newline tokenization, preset
navigation/admission overlap, full-path backup globbing, and elevated Windows
default-owner assumptions. The Windows factory now explicitly sets the process
user as owner. Native replacement tests exposed transient NTFS rename conflicts;
publication retries only sharing/locking/access conflicts for a bounded second
with write-through replacement, preserving the original on failure.

Windows may add the informational `AUTO_INHERITED` control bit when setting a
DACL. The native comparison ignores only that bit and checks owner, protection
and ordered ACEs/rights/SIDs. This follows Microsoft's documented
[automatic inheritance behavior](https://learn.microsoft.com/en-us/windows/win32/secauthz/automatic-propagation-of-inheritable-aces).

The integrated browser run initially exposed an ambiguous legacy confirmation
selector after the new adoption fixture populated a real card. The selector now
targets the confirmation button; the full suite passes. Native tests also exposed
Linux-only method/path/architecture fixtures and POSIX command assumptions;
those fixtures were made portable without treating cross-compilation as a native
pass. Windows log clearing now uses a separate write-capable handle, checked
against the writer's owned file, because append-only handles lack truncation
rights. Repeated clear after rotation preserves the backup and later append
records. The retained shell-command seam uses native Windows command syntax and
portable real-process tests. Initial failures remain in the evidence alongside
corrected runs.

Final transcript review also found that the new observation-shutdown fixture
could accept joined cancellation after a renderer panic from missing display
state. The fixture now initializes valid display state and explicitly rejects
Bubble Tea's panic sentinel before checking cancellation; focused race and native
runs verify normal shutdown and worker joining.

An intermediate focused preset test unintentionally accessed the workspace
agent's home config when eager worker ownership replaced lazy scheduling. The
available pre-write backup and current file match SHA256
`ae02e90723a6a21c2e5a76e5b10c7828c5a9d36bea536a0c40a5ca2a294cde4d`.
Both artifacts are retained; earlier state is not inferred from that match.
The regression now isolates native config paths and drains the real worker.
Final combined and native QA use disposable profiles.

## Validation and remaining coverage

Final check results, native transcripts, binary hashes and review notes are linked
from the [remediation evidence index](qa/2026-10-03/remediation/README.md).
The matrix there distinguishes repository checks, actual OS execution and waived
hardware coverage.

The accepted Windows ARM64 beta gap includes unverified ARM/Qualcomm/NVIDIA GPU
identification and acceleration. Intel Mac native execution remains waived.
Synthetic PE fixtures and six-target builds do not close either gap. Native QA
here verifies affected disposable recovery/config/process behavior; it is not a
new signed-release, Gatekeeper/notarization, publisher-service or complete player
download/install/update/uninstall acceptance claim.

The Windows updater suite still skips POSIX-shell helper/crash and child-health
fixtures. F05/F15 crash replay is exercised on Linux and the native Mac; native
Windows tests exercise actual replacement/restoration, private keys/journals,
tamper refusal, signed selection/replay and outcome persistence. These scopes
must not be described as exhaustive Windows helper crash coverage.

Windows and Apple signing, future desktop/htmx work, database investigation and
protected mirror-publication tasks remain separate Atlas work. No external
signer policy or deployment gate was marked complete by this code remediation.
