Open issue quick-fix ranking: 2026-09-21
Open issue quick-fix ranking: 2026-09-21
Recommendation
Start with #219 for the smallest coherent whole-issue fix. For the smallest independent patches, exclude irrelevant scaffold archives from candidate discovery (#220) and surface successful commit-check diagnostics (#200/#201). These are partial fixes and do not justify closing their parent issues.
Effort bands below are source-based judgments, not delivery promises. No product fix was implemented.
| Priority | Scope | Likely effort | Reason and validation boundary |
|---|---|---|---|
| 1 | #219: valid guidance mirrors rejected | Small to medium | Localized staged/live input composition problem. Preserve containment, missing-target refusal, cycles, and pending-authoring semantics. Smallest whole-issue candidate. |
| 2 | #220: archived scaffold inputs | Small | Installed CLI reproduces validation of an obsolete archived Oxlint config. Prune irrelevant historical backups while retaining genuinely required explicit dependencies. Audit both candidate and generation-input observation. |
| 3 | #220: generated Oxlint config rejected | Small to medium | Generator emits a preset callback that the candidate parser rejects. Align the generated representation with supported declarative syntax and prove equivalent preset rule/file matching. Do not broadly permit arbitrary executable configuration. |
| 4 | #200/#201: invisible successful diagnostics | Very small isolated patch | Runner discards stdout/stderr from commands exiting zero. Preserve diagnostics without changing exit semantics. Does not establish a zero-warning policy or root coverage. |
| 5 | #200/#201: complete commit-gate behavior | Medium to large | Aggregate/file command semantics, root ownership, deletions, overlap, warning policy, and consumer CI must agree. Simply adding deletions or deepest-owner selection would introduce correctness gaps. |
| 6 | #199, #215 | Uncertain verification effort | #199 still needs the real tsgolint consumer replay. #215 retains authenticated cross-context cache acceptance. Neither is an established small code fix. |
| 7 | #217 and the rest of #220 | Large | Test cost instrumentation, fixture isolation and scheduling; or broad update input/install scope and performance. Neither fits a quick patch. |
Installed CLI evidence
Confirmed executable /Users/stefan/.bun/bin/hi, version 5.1.1. Created detached worktrees from Harness 7e147b3300c391db979b87e20c4159a5a03d12cb and Collective Intelligence 254fc154520525ccae866814788799ef8e053585. Used isolated XDG_CACHE_HOME directories and disabled advisory startup update checks. Original dirty changes were excluded from the worktrees. No shared dependency links or original-tree installs were used.
Both Harness trials ran:
hi update --baseline stable --cache off --write --yes --json --progress| Trial | Observed result |
|---|---|
| Harness tracked checkout | Exit 1 after 24.62 seconds; applied: false, zero completed files. Candidate preparation rejected .devpunks/replaced-scaffold/100b633c39028a69e75579170a466766b6fa3966eaeec8ba3377457074f8ab5e/packages/auth/oxlint.config.ts as outside the declarative subset. No install, patch, or lint invocation ran. |
| Harness after moving its archive outside the disposable worktree | Exit 1 after 19.99 seconds; applied: false, zero completed files. Same declarative-subset rejection now points to apps/backoffice/oxlint.config.ts. No install, patch, or lint invocation ran. The archive was restored afterward. |
| Collective tracked checkout | Exit 1: missing .devpunks/scaffold-manifest.json, because that setup state is ignored by Git. |
Collective with copied ignored .devpunks state | Exit 1 after 27.16 seconds: Recorded context evidence drifted: .devpunks/context-plan.json. This is a setup blocker, not a reproduction or resolution of #199. |
The Harness trials identify two independent blockers within #220. Neither constitutes a successful update or a broad performance benchmark. CLI progress also emitted the apply phase despite final applied: false; that is a distinct reporting concern already included in #220.
Raw stdout, stderr, command arguments, exit codes, and durations are retained in the sibling audit evidence directory outside the worktree. The Collective scaffold preparation trial produced no stdout/stderr before its 150-second timeout; the probe terminated it after a five-second grace period (155.01 seconds total, exit -9). This is an inconclusive setup timeout and does not establish consumer updater success.
Focused #219 source reproduction
The current runtime composition resolves the staged tree before constructing the live/staged union. Its link resolver immediately refuses missing targets.
A temporary fixture called the unchanged source resolver with valid root and nested CLAUDE.md -> AGENTS.md mirrors:
- Complete live tree: accepted both mirrors.
- Staged overlay with mirrors and targets supplied only by the live tree: rejected root
CLAUDE.mdwithrequired symlink target is missing. - Composed tree containing those same live and staged inputs: accepted both mirrors.
This confirms the structural failure seam and a narrow regression target. It is source-level diagnostic evidence, not an installed-CLI consumer reproduction or a verified repair. Keep tests for genuine dangling links, escaping links, cycles, and pending scope authoring when fixing composition.
Other source evidence
- Generated preset-local rules use a callback; the validator accepts only constrained declarative expressions. Existing generated-wiki acceptance coverage does not prove the preset-local branch.
- Candidate pruning and generation-input pruning omit
replaced-scaffold. - Commit runner mixes file and aggregate command semantics and retains only nonzero-exit diagnostics. Warning visibility is independent; deletion/root/deduplication changes are coupled.
Work log and boundaries
Two reused readonly research lanes assessed candidate failure scope and commit-gate/performance scope. The coordinator ran isolated CLI trials, the mirror fixture, and synthesized this report. No issue was changed or closed during this follow-up.
- HI-CLI-001 and HI-CLI-003: pass for readonly ownership inspection; no product responsibilities moved.
- HI-DOCS-001 and HI-WIKI-001: pass; report retained under project research in the separate Harness worktree, with explicit navigation.
- HI-WIKI-003: frontmatter and dated wiki log provided; owning content check and targeted formatting check passed.
- Other mutation rules: not applicable. No product, contract, shared-skill, or release changes. Changelogs unchanged; release classification none.
- Original checkouts: Git status, tracked diff hashes, and pre-existing untracked file hashes compared against the starting inventory and remained unchanged. All diagnostic writes stayed in disposable worktrees or the audit directory.
Delivery research synthesis
The user accepted end-to-end delivery on 2026-09-21. Three independent research lanes examined candidate composition, generated configuration/install closure, and commit coverage. They agree on final-tree link authority, exact generated Vitest merge support, and explicit command execution modes. Reducing package roots alone is insufficient: installation roots and lint targets must be separated. Generation content inputs also need independent narrowing while preserving discovery witnesses.
The four quick fixes span #219, #220, and overlapping #200/#201; full closure includes their remaining reusable requirements. Consumer lint debt and CI policy remain separately owned. The selected design and binary acceptance criteria are retained in the delivery spec. The wmf clonefile cause remains unproven; no cache-corruption claim is made. Existing controlled Effect preparation must be tested before changing it.
Alternatives rejected: eager overlay-only link validation, globally disabling validation, raising byte limits, evaluating arbitrary config callbacks, and guessing that every root lint script subsumes workspace policy.