Cross-Thread Stack Reconstruction Research
Cross-Thread Stack Reconstruction Research
Context
This report reconstructs the scaffold-integrity work after PR #108 supplied a stale branch topology. Readonly lanes compared live pull-request records, immutable base/head/merge OIDs, tree equality, composite patch IDs, semantic diffs, closure evidence, and authenticated CI logs. The surviving stack is PR #109, then #113, then #116, then this docs PR #117.
Trusted claims
Correct stack
| Order | Node | Recorded base | Current evidence |
|---|---|---|---|
| 1 | PR #109 | main@c4dcca3134eace76750fa899f3b581411af094d0 | Head ef34bc7dbae74edf5ab056ab3934841fe42b68f1. |
| 2 | PR #113 | PR #109 head | Head 7281dad6d700a2aac477b4d23734fee1899fa866. |
| 3 | PR #116 | PR #113 head 7281dad6d700a2aac477b4d23734fee1899fa866 | Head e284c9aa28f881d75180ffea22a9bc3052c2708b, containing 9233faaf, its runbook projection, and refreshed canonical catalog goldens. This fixes a newly found obsolete remediation copy; it is not a port from #108. |
| 4 | PR #117 | PR #116 head e284c9aa28f881d75180ffea22a9bc3052c2708b | Pre-lineage-correction head 57d0e929efb62e11f34108f2589876d37431c81d; the mutable post-correction PR head is intentionally not recorded as a self-hash. |
The required merge order is #109, #113, #116, then #117. PR #108 remains closed and superseded; its recorded branch topology is evidence to audit, not an authority for downstream work.
Prior-thread lineage
| Artifact | Recorded base | Recorded head or source | Merge evidence | Closure or disposition |
|---|---|---|---|---|
| PR #100 | main@30c8fef0b32e45933ef2fea3f960e781c9cac3d3 | 712312da814f86ebfbf8dfe1b602e10c8dfddf0f | Actual squash merge 89cd741c6d39d5ebf6445cf99ec1ec8869bb2640 | Merged. This is the mainline parent for the scaffold implementation. |
| PR #106 | PR #100 branch at b1665ab4ef341132ef2a7cbba21b4b85f3ffd886 | bbb6b7c9629a252ce7316461506b7d3ac7fc6242 | Unmerged. Synthetic GitHub merge candidate fd8f6897eeb724baf994aea8ce4a5e4c7546b6f2; not an actual merge. | Closed as research-only work, superseded by implementation PR #108. |
| PR #108 | PR #100 branch at 712312da814f86ebfbf8dfe1b602e10c8dfddf0f | 809fc31140a3ab0b5b6107910bda91b5daaf450b | Never merged; no merge OID. | Superseded by #112 from the same reviewed head, rebased directly onto main after #100 merged. GitHub could not detach the stale stack while closed child #110 remained. |
| PR #110 | stale PR #108 branch at 5c9b65dde2203fde83cb46db97a2ba6e5377d624 | b5a63e911b0207fa9a3818075817cc0bd846af9a | Unmerged. Synthetic GitHub merge candidate 9a7894f1cf55666b253944d3b1ae815ebbe0542a; not an actual merge. | Closed as an accidental duplicate; #109 is canonical. The recorded base is not an ancestor of the head; their merge-base is PR #106 head bbb6b7c9629a252ce7316461506b7d3ac7fc6242. |
| PR #112 | main after #100 | Source 403cb7e49955e5f61354907c237b134bd5856aa7 | Actual squash merge 7a88d0856831cba0bf9d38f0ccce3d6711d9c8e8 | Source and merge trees both equal 69480bb20063ced5c14181a2b25b14a76ec0694b; composite patch ID 3036fdad. Already merged; port nothing. |
| PR #114 | 7a88d0856831cba0bf9d38f0ccce3d6711d9c8e8 | Source 1d46ee626977a881f5c5d92e96122995ef3407a5 | Actual squash merge 3f5f9622188ec96529b1efea3cd759b6a283d92d | Source and merge trees both equal 4f8266d18836c851f635d64aa7a7412448aa479c. Already merged; port nothing. |
| PR #115 | 3f5f9622188ec96529b1efea3cd759b6a283d92d | Source 5932db87fa494e68d05ef92792b9ff81aca73c6e | Actual squash merge c4dcca3134eace76750fa899f3b581411af094d0 | Source and merge trees both equal bf2c1e9ceaf438a64ab69a292e8d471e6a8dd934. Already merged; port nothing. |
fa9bd6bb8ddd8f82b9befbf5dd6a542bd09ee22e | stale pre-correction docs history | docs-only residual | Not merged. | Conflicts on PR #113 history. Re-author current claims; do not cherry-pick. |
PRs #109 and #113 descend from main at c4dcca31, so they already contain the complete scaffold-integrity implementation from #112/#114/#115. Semantic comparison found zero scaffold implementation left to port.
Verification and cache contracts to preserve
Run 31329286573, attempt 2 is the exact authenticated same-repository development replay for PR #113. Its logs prove:
- deterministic remote hit
2131cd5c16dd57cc; - capability-native remote hit
34dff8138ee694e7; - ambient bypass
a90fc7b10a5b2c7b; update:uncachedbypass4a3dcdd8030eabe9;- 88 deterministic files / 969 tests, 16 native files / 304 tests, and 1 ambient file / 39 tests;
- exact Node
24.19.0, Bun1.3.5, and bound tool identity; - the dedicated native managed-assets fixture gate.
No authentication or permission warning appeared in that development replay. It does not prove protected-main or fork reuse.
Tree equality for #114 and #115 proves that their protected-graph, OIDC-refresh, grouped producer/restore, and credential-confinement code reached main unchanged. Protected push run 31245179530, job 93074963111 supplies the separate protected-main runtime evidence at exact SHA c4dcca3134eace76750fa899f3b581411af094d0: the grouped producer executed build and release:attest, and the restore consumer restored both tasks remotely. Fork runtime reuse remains unclaimed.
Release and issue boundary
The stable baseline baseline/stable/2026.08.07-scaffold-integrity-convergence targets c4dcca31. Registry readback for @punks/cli@3.1.6 returned E404 on 2026-08-09. Installed-consumer convergence is therefore unproven. Issues #97, #104, and #105 remain open.
Uncertainty and conflicts
- Mutable branch names and historical PR bases disagree with the corrected immutable topology. Commit OIDs, tree equality, patch IDs, and semantic diffs take precedence.
fa9bd6bbcontains useful closeout source material, but its pre-correction ancestry and stale “final docs head” claims make direct reuse unsafe.- Run 31329286573 proves the same-repository development cache path only. Protected-main runtime evidence comes from run 31245179530; fork reuse remains unclaimed.
- Stable-baseline publication does not prove npm publication or the installed-consumer acceptance matrix.
Selected next route
Keep #109, #113, #116, and #117 open and mergeable in that order. Do not create another scaffold implementation PR because no #108-derived implementation remains to port. After the stack merges with fresh authorization, verify the existing stable baseline's ancestry and readback, repair npm authority, publish CLI 3.1.6 without republishing the baseline, run the fresh installed-consumer matrix, and attach issue-specific evidence before closing #97, #104, or #105.