# Validation — initial web preview 2026-09-29: - `npm run typecheck`: passed. - `npm run build`: passed. Vite reports a large inherited editor bundle; splitting the editor into a lazy-loaded chunk is a future performance improvement. - `npm test`: 8 tests passed (7 HTTP/media integrations + 1 error-presentation test). - Browser smoke test against `scripts/ui-fixture.mjs`, which never contacts Athena: sign-in; new project; reload and reopen saved project; Gen Space renders backend model options; synthetic native API failure shows a recoverable error dialog; timeline editor opens; synthetic 1-second clip upload/import returns dimensions and thumbnail in the asset library. - Source LTX-Athena working-tree changes left untouched. Not verified yet: Docker image build/run on Debian, real LTX generation through Athena Deck's selected Video endpoint, remote file permissions/mount paths, long-running job recovery/cancellation, all editor interactions and all LTX modes. No Athena service was started, stopped or reconfigured during this port. The synthetic fixture uses a fixed public test password and isolated temporary media storage on loopback port 18118. Never deploy that fixture as the real service. Production start (`server/index.mjs`) requires an operator-provided password file. ## Athena deployment — 2026-09-29 Docker image built successfully on Athena (Debian), including TypeScript and Vite checks. `ltx-deskweb` starts with UID 1000, read-only root filesystem, no GPU or Docker socket, 2 CPUs / 1 GiB limit, host-loopback binding on 8118. Verified: GUI HTTP 200; login/session/logout; forwarding to Deck's health endpoint; synthetic text upload and readback through shared input storage (test file removed); Deck's actual Unix-socket helper inventory returns `ltx-deskweb` as `running`. Existing Medium, TTS, WireGuard and Deck remain running; LTX remains stopped. Real video generation was not requested or tested in this deployment. ## Shared-input permission fix — 2026-09-29 A real I2V request exposed a cross-container permission error: private uploads (0600 in a 0750 UID/GID-1000 directory) were invisible to LTX's UID/GID-0 process because its container drops all Linux capabilities. Same bind mount/path did not imply read permission. The API reported this as “Image file not found”. Dedicated DeskWEB input directory now uses UID 1000 / GID 0, mode 2750; uploads, asset copies and thumbnails use 0640. Athena GUI runs as 1000:0 with capabilities still dropped. Only existing DeskWEB-owned input files had their permissions corrected; no other media directory, backend container or GPU service was changed. Validation: build/typecheck and all 8 tests pass; integration tests now assert 0640 on uploads, copies (including a 0600 source) and thumbnails. On Athena the reported image's existence/read permission was verified from inside LTX without opening its content. A fresh synthetic upload was also checked from LTX and then removed. Only the GUI was recreated; real image generation remains a user retry.