Harness Intelligence Wiki
ProjectDomains

CI Verification and Publication Glossary

Canonical language for retained tests, pull-request authority, caching, and publication

CI Verification and Publication Glossary

This glossary defines the shared language for the retained test portfolio and the workflow that carries its authority into publication.

Issue 217's accepted requirements supersede the older PR-only, full-command-only and mandatory Candidate Evidence lookup rules. The linked specification describes the agreed optimization; its implementation is not claimed here.

Terms

High-Signal Test

A test that proves one named capability, public contract, or Safety Invariant and would fail for a meaningful product defect.

Behavioral Test

A test that observes a stable outcome through the nearest owned public seam, one semantic level above the implementation change. Exported application and adapter interfaces qualify when they prove the owned behavior.

Implementation-Shape Test

A test whose result depends on source text, imports, internal call order, line count, test names, fixture versions, or another internal spelling. It does not qualify for the retained portfolio.

Safety Invariant

A rule that prevents corruption, containment escape, secret exposure, partial publication, unrecoverable state, or unsafe cleanup.

CLI Behavioral Test

A Behavioral Test that starts the complete built hi or hint command as an external process and asserts exit status, output, or resulting files.

Focused Test

A test of a bounded owned capability through its exported interface, with meaningful input and outcome assertions. Controlled external dependencies are valid when the dependency's own operation is not the behavior being proved.

Affected Verification

Validation selected from actual changed inputs and their dependent owned surfaces. It contains retained High-Signal Tests and applicable browser proof.

Stable Aggregate Check

The required result that accounts for every applicable Affected Verification result, including intentional skips proven by change selection.

Verification Authority

Evidence authorizing verification claims under the current workflow's input, capability and trust rules. A cached result retains the authority and execution identity of its producer.

Candidate Evidence

An immutable JSON receipt that binds a successful same-repository pull-request run to its exact tested Git tree. It contains no package, build output, cache data, credential, or secret.

Publication Workflow

The protected mutation path that consumes reviewed release intent and current release authority to build, inspect, publish, reconcile and read back external state. Current publication eligibility does not require a prior pull-request Candidate Evidence lookup.

Trusted CI

A run whose code is owned by this repository and may receive signed remote-cache write authority.

Untrusted Fork CI

A contributor-owned pull-request run that may restore safe default-branch cache entries but cannot write trusted cache artifacts.

Relationships

  • Every retained High-Signal Test has a justified proof obligation for a named supported capability, public contract, or Safety Invariant.
  • CLI Behavioral Tests are a subset of Behavioral Tests; different boundaries can justify complementary witnesses for the same capability.
  • Affected Verification contributes to the Stable Aggregate Check.
  • A successful Stable Aggregate Check produces Candidate Evidence for the exact tested Git tree.
  • Candidate Evidence binds to its exact tested tree; its existence does not add a publication prerequisite.

Axioms

  • Verification remains enabled for pull requests and main with correct reuse.
  • Superseded pull-request runs are cancelled.
  • Retained cacheable checks have explicit owners and complete relevant inputs; unrelated documentation is not a product input, while consumed prompts and skills are.
  • Trusted internal pull requests, main, and release verification share signed remote-cache results when task identities match.
  • Untrusted fork code cannot write trusted cache artifacts.
  • CLI Behavioral Tests execute built dist; no installed-tarball execution smoke remains.
  • Real filesystem/application/adapter tests qualify when they exercise the safety boundary being claimed. Faking that boundary cannot establish its behavior.
  • Publication performs package-integrity inspection, not a package test suite.
  • Publication never accepts a green result from a different Git tree.
  • Release mutation is never cacheable and release runs serialize without cancellation.
  • Scheduled verification contains only named external-drift witnesses that pull-request verification cannot establish.
  • All workers are 2-vCPU. Automated macOS jobs are removed without treating Linux proof as macOS evidence.
  • Optimize latency and runner work without a percentage target, monthly ceiling, test-count quota or test sharding.
  • Ordinary release-recovery proof uses a minimal real history. Full historical toolchain replay remains available on demand.

On this page