Objective
Close private-pilot account sync readiness.
Notes: Documented fail-closed private-pilot readiness matrix and operator runbook in research/findings/private-pilot-readiness-t292.md. Existing isolation, backup/restore, auth/evaluator, browser-error, and FEATURE_COMPLETION evidence pass bounded preflight; t293 observability/rollback and t294 measured host selection remain hard launch blockers. Focused suite: 9 passed; live PostgreSQL test cannot run because this image exposes pg_config but lacks initdb/postgres OS user.
Approach
Reuses existing report research/findings/private-pilot-readiness-t292.md — tables/metrics preserved verbatim via source_report pointer. Body below summarizes grounded evidence from that report and adjacent artifacts.
Files / code / data changed
- No commit SHA confidently associated with
t292in sampled log [reconstructed — uncertain]. - Source report:
research/findings/private-pilot-readiness-t292.md - Task-history entry:
research/findings/task-history.json#t292
Results
Key table from source report (preserved):
| Boundary | Existing evidence | Private-pilot disposition |
|---|---|---|
| Browser fallback and merge | t289 covers disabled configuration, sign-in, read-only preview, explicit local-wins confirmation, errors, sign-out, JSON export/restore, and Chromium integration. | Pass. Require each participant to export JSON before first sync; never infer remote deletion. |
| Account isolation | t290 exercises anonymous denial, two-user RLS CRUD and deduplication against ephemeral PostgreSQL. | Pass for preflight. Repeat the two-user probe against the provisioned project before invitations. |
| Portable recovery | t290 restores a data-only dump into a fresh database and documents ordering and validation. | Pass for preflight. A real encrypted off-site export and restore rehearsal is a launch gate, not an assumption. |
| Authentication | Browser tokens remain in memory; the evaluator verifies signature, issuer, audience, and subject against Supabase JWKS. | Pass for invited accounts. Self-sign-up is out of scope. Account creation and recovery are operator-assisted through Supabase; verify one recovery before invitations. |
| Evaluator safety | t291 proves authentication, 16 KiB bodies, per-subject rate limiting, two-worker capacity, a 45-second server timeout, exact-origin CORS, bounded event logs, and 60-second browser failure UX. | Pass for host benchmarking only. In-memory limits reset on restart and are appropriate only for the small invited cohort. t294 must measure cold/warm behavior and cost before launch. |
| Discoverability and errors | The catalog links the Custom Meta builder; configured account sync and remote evaluation reuse the existing workflow and preserve local configuration on failure. | Pass. Run the browser smoke checks against the deployed origins before invitations. |
| Logs, spend, rollback | t293 defines credential-free signals, redaction/retention, measurable stop thresholds, RPO/RTO, deletion, spend, and timed rollback acceptance. | Specification passes; t295 must record live evidence against every gate before invitations. |
Conclusions and metrics are in research/findings/private-pilot-readiness-t292.md; see detail page for preserved tables/metrics.
Conclusions
[reconstructed — uncertain] Outcome inferred from status done and task note.
Problems / follow-ups
- See source report or PR discussion for follow-ups. No unsupported follow-ups fabricated.
Links
- Task-history:
research/findings/task-history.jsonidt292 - Findings:
research/findings/private-pilot-readiness-t292.md