Harness Intelligence Wiki
Research

Issues 203–207 Fix Audit

Issues 203–207 Fix Audit

Scope and conclusion

Five independent readonly lanes audited one issue each at Harness commit 346a0a3b25c58e3f2b9a5b50f8a00f47aa8a409f, before the requested minor-version release preparation. All five fixes are present in the distributable. This is a payload conclusion, not proof that existing consumers or this checkout's active skill copies have already been refreshed. No merge or publication is claimed by this report.

The exact-head hosted CI run 35006682596 passed Root Static Verification, all 16 affected tasks, and Stable Aggregate Check. Its Candidate Evidence binds that head to tree 6633999d4be59a014ef2faf7ae7796eff11ada37. Later release-metadata changes require their own final-head validation.

Issue findings and evidence

Readonly laneConclusion and fresh evidenceOwning sources
#203: scaffold convergenceStatic acceptance-criterion mapping confirms the ownership/convergence repairs. The fresh focused attempt recorded 3 passed, 1 environment-bootstrap failure, and 55 skipped after an agent-browser install handled failure. That failure is not an assertion about managed-artifact behavior; this attempt is not a fully green fresh regression run. Exact-head hosted CI above passed.Spec, implementation evidence and acceptance mapping; apps/cli/src/update/run.test.ts, apps/cli/src/update/wiki-alignment-owner.test.ts, apps/cli/src/update/planned-wiki.test.ts.
#204: portable commit gatesActive-worktree resolution and visible launch diagnostics are fixed. Fresh focused coverage passed 28/28; the runner also passed 9/9 without ambient Git identity. The linked-worktree fixture now supplies repository-local synthetic identity and checks Git setup success.Spec; apps/cli/src/data/scripts/commit-gate-runner.mjs, its declaration, and commit-gate-runner.test.ts.
#205: Effect backend internal modulesCanonical checks passed 3/3 and Harness synchronization coverage passed 1/1. Audited bundled files equal canonical source at 0519d685213a8085928bde8a5d744fcd6737c931, including the accepted private services/<capability>/binding.ts placement.Spec; apps/cli/skills/frameworks/effect/effect-backend-structure/, apps/cli/src/scripts/sync-skills-repo.test.ts, apps/cli/.devpunks-cache/skills-sync.json.
#206: skill activation boundariesCanonical activation checks passed 8/8 and Harness coverage passed 6/6. All seven audited bundled files equal the canonical source revision above.Spec; canonical tests/skill-activation-boundaries.contract.test.mjs, bundled apps/cli/skills/, and the synchronization receipt.
#207: verification recovery skillsThe supported-browser retry passed 3 files / 5 tests, covering registration, default selection, materialization, and preservation of project-owned verifier references.Spec, implementation evidence; apps/cli/src/data/catalog/verification-registration.test.ts, apps/cli/src/content/verification-recovery-skills.test.ts.

Claim-level source locations

All line references below belong to the audited head; later edits may shift them.

  • #203: apps/cli/src/update/run.ts:1684–1767,3544,3690, apps/cli/src/scaffold/stage.ts:629–647, and apps/cli/src/scaffold/output.ts:886–894,2053–2057,4248–4278 establish the ownership and convergence behavior. The fresh attempt failed at apps/cli/src/update/run.test.ts:1747 during agent-browser bootstrap after reporting applied=false, changes=[], and degradations=[]; it did not reach the managed-behavior assertion.
  • #204: apps/cli/src/data/scripts/commit-gate-runner.mjs:20–33,49,69,78,109–114 owns root discovery, owner cwd, and launch diagnostics. Its sibling commit-gate-runner.test.ts:93,166,204,254,273,301 and apps/cli/src/scaffold/output.test.ts:58–76 exercise the contract; apps/cli/src/scaffold/output.ts:3468,3472 supplies portable generated paths.
  • #205: apps/cli/skills/frameworks/effect/effect-backend-structure/references/layout.md:42–53, its SKILL.md:16,25, and apps/cli/skills/frameworks/effect/effect-service-design/SKILL.md:10 establish private module layout and service-design ownership. The linked spec's AC-001 reconciliation records the accepted binding placement. Canonical tests/backend-structure-composition.contract.test.mjs provides the 3/3 check.
  • #206: apps/cli/skills/frameworks/react/react-doctor/SKILL.md:3, apps/cli/skills/agnostic/quality/tdd/SKILL.md:3, apps/cli/skills/agnostic/planning/verify-behavior/agents/openai.yaml:2, apps/cli/skills/phases/debugging-phase/SKILL.md:47, apps/cli/skills/agnostic/planning/implement-spec/SKILL.md:78, and apps/cli/src/scaffold/output.ts:3649 define activation and verification boundaries. This audit does not claim a replay of the original ci-app model interaction.
  • #207: apps/cli/src/data/catalog/skills.ts:105,593, apps/cli/src/data/catalog/packs.ts:258,265, and apps/cli/src/features/repository-analysis/pack-selection.ts:178 register and select the recovery skills. The linked spec at line 51, apps/cli/src/scaffold/project-verifier-preservation.test.ts:222, and apps/cli/skills/agnostic/planning/verify-behavior/SKILL.md:34 retain project ownership. The successful retry used the existing Chromium executable override; the initial attempt failed only tool readiness.

The canonical source is wearedevpunks/skills at 0519d685, pinned by refs/tags/sync/release-issues-203-207-0519d68. This source-sync tag is not a product release.

Installation boundary and remaining uncertainty

Tracked active .agents/skills copies for #205 and #206 remain stale at the audited head. This does not contradict bundled parity: apps/cli/scripts/build-baseline.mjs:237 copies the fixed apps/cli/skills tree into the baseline. Publication alone does not rewrite a current checkout or an existing consumer.

Use the scaffolding runbook for the documented targeted skill update and inspect its resulting diff and byte parity. Preserve project-owned verify-behavior references; do not overwrite local scenario authority while refreshing managed recovery skills. Do not use a broad update merely to repair active copies when its preview includes unrelated managed drift. Existing #204 consumers likewise need a baseline update to obtain the corrected managed runner; their old installed runner is not repaired by this audit.

No unresolved acceptance-design choice was identified by these five lanes. The #203 fresh local bootstrap limitation remains explicitly separate from the passing exact-head hosted verification. Release publication, consumer reconciliation, and final-head CI after version/changelog changes are subsequent actions, not inferred outcomes.

Next action

Prepare the authorized minor-version npm and baseline notes, validate the resulting release candidate, and perform the separately authorized squash/publication workflow. Keep this report tied to its audited head and retain provider readback for the eventual merge and both release products.

On this page