Issues 203–207 Fix Audit
Issues 203–207 Fix Audit
Scope and conclusion
Five independent readonly lanes audited one issue each at Harness commit 346a0a3b25c58e3f2b9a5b50f8a00f47aa8a409f, before the requested minor-version release preparation. All five fixes are present in the distributable. This is a payload conclusion, not proof that existing consumers or this checkout's active skill copies have already been refreshed. No merge or publication is claimed by this report.
The exact-head hosted CI run 35006682596 passed Root Static Verification, all 16 affected tasks, and Stable Aggregate Check. Its Candidate Evidence binds that head to tree 6633999d4be59a014ef2faf7ae7796eff11ada37. Later release-metadata changes require their own final-head validation.
Issue findings and evidence
| Readonly lane | Conclusion and fresh evidence | Owning sources |
|---|---|---|
| #203: scaffold convergence | Static acceptance-criterion mapping confirms the ownership/convergence repairs. The fresh focused attempt recorded 3 passed, 1 environment-bootstrap failure, and 55 skipped after an agent-browser install handled failure. That failure is not an assertion about managed-artifact behavior; this attempt is not a fully green fresh regression run. Exact-head hosted CI above passed. | Spec, implementation evidence and acceptance mapping; apps/cli/src/update/run.test.ts, apps/cli/src/update/wiki-alignment-owner.test.ts, apps/cli/src/update/planned-wiki.test.ts. |
| #204: portable commit gates | Active-worktree resolution and visible launch diagnostics are fixed. Fresh focused coverage passed 28/28; the runner also passed 9/9 without ambient Git identity. The linked-worktree fixture now supplies repository-local synthetic identity and checks Git setup success. | Spec; apps/cli/src/data/scripts/commit-gate-runner.mjs, its declaration, and commit-gate-runner.test.ts. |
| #205: Effect backend internal modules | Canonical checks passed 3/3 and Harness synchronization coverage passed 1/1. Audited bundled files equal canonical source at 0519d685213a8085928bde8a5d744fcd6737c931, including the accepted private services/<capability>/binding.ts placement. | Spec; apps/cli/skills/frameworks/effect/effect-backend-structure/, apps/cli/src/scripts/sync-skills-repo.test.ts, apps/cli/.devpunks-cache/skills-sync.json. |
| #206: skill activation boundaries | Canonical activation checks passed 8/8 and Harness coverage passed 6/6. All seven audited bundled files equal the canonical source revision above. | Spec; canonical tests/skill-activation-boundaries.contract.test.mjs, bundled apps/cli/skills/, and the synchronization receipt. |
| #207: verification recovery skills | The supported-browser retry passed 3 files / 5 tests, covering registration, default selection, materialization, and preservation of project-owned verifier references. | Spec, implementation evidence; apps/cli/src/data/catalog/verification-registration.test.ts, apps/cli/src/content/verification-recovery-skills.test.ts. |
Claim-level source locations
All line references below belong to the audited head; later edits may shift them.
- #203:
apps/cli/src/update/run.ts:1684–1767,3544,3690,apps/cli/src/scaffold/stage.ts:629–647, andapps/cli/src/scaffold/output.ts:886–894,2053–2057,4248–4278establish the ownership and convergence behavior. The fresh attempt failed atapps/cli/src/update/run.test.ts:1747during agent-browser bootstrap after reportingapplied=false,changes=[], anddegradations=[]; it did not reach the managed-behavior assertion. - #204:
apps/cli/src/data/scripts/commit-gate-runner.mjs:20–33,49,69,78,109–114owns root discovery, owner cwd, and launch diagnostics. Its siblingcommit-gate-runner.test.ts:93,166,204,254,273,301andapps/cli/src/scaffold/output.test.ts:58–76exercise the contract;apps/cli/src/scaffold/output.ts:3468,3472supplies portable generated paths. - #205:
apps/cli/skills/frameworks/effect/effect-backend-structure/references/layout.md:42–53, itsSKILL.md:16,25, andapps/cli/skills/frameworks/effect/effect-service-design/SKILL.md:10establish private module layout and service-design ownership. The linked spec's AC-001 reconciliation records the accepted binding placement. Canonicaltests/backend-structure-composition.contract.test.mjsprovides the 3/3 check. - #206:
apps/cli/skills/frameworks/react/react-doctor/SKILL.md:3,apps/cli/skills/agnostic/quality/tdd/SKILL.md:3,apps/cli/skills/agnostic/planning/verify-behavior/agents/openai.yaml:2,apps/cli/skills/phases/debugging-phase/SKILL.md:47,apps/cli/skills/agnostic/planning/implement-spec/SKILL.md:78, andapps/cli/src/scaffold/output.ts:3649define activation and verification boundaries. This audit does not claim a replay of the original ci-app model interaction. - #207:
apps/cli/src/data/catalog/skills.ts:105,593,apps/cli/src/data/catalog/packs.ts:258,265, andapps/cli/src/features/repository-analysis/pack-selection.ts:178register and select the recovery skills. The linked spec at line 51,apps/cli/src/scaffold/project-verifier-preservation.test.ts:222, andapps/cli/skills/agnostic/planning/verify-behavior/SKILL.md:34retain project ownership. The successful retry used the existing Chromium executable override; the initial attempt failed only tool readiness.
The canonical source is wearedevpunks/skills at 0519d685, pinned by refs/tags/sync/release-issues-203-207-0519d68. This source-sync tag is not a product release.
Installation boundary and remaining uncertainty
Tracked active .agents/skills copies for #205 and #206 remain stale at the audited head. This does not contradict bundled parity: apps/cli/scripts/build-baseline.mjs:237 copies the fixed apps/cli/skills tree into the baseline. Publication alone does not rewrite a current checkout or an existing consumer.
Use the scaffolding runbook for the documented targeted skill update and inspect its resulting diff and byte parity. Preserve project-owned verify-behavior references; do not overwrite local scenario authority while refreshing managed recovery skills. Do not use a broad update merely to repair active copies when its preview includes unrelated managed drift. Existing #204 consumers likewise need a baseline update to obtain the corrected managed runner; their old installed runner is not repaired by this audit.
No unresolved acceptance-design choice was identified by these five lanes. The #203 fresh local bootstrap limitation remains explicitly separate from the passing exact-head hosted verification. Release publication, consumer reconciliation, and final-head CI after version/changelog changes are subsequent actions, not inferred outcomes.
Next action
Prepare the authorized minor-version npm and baseline notes, validate the resulting release candidate, and perform the separately authorized squash/publication workflow. Keep this report tied to its audited head and retain provider readback for the eventual merge and both release products.