Scaffold Integrity Release Readiness Research
Scaffold Integrity Release Readiness Research
Question
What remains between the accepted scaffold-integrity implementation and truthful closure of issues #97, #104, and #105 after the corrected PR stack reached a clean exact-head replay?
Readonly lanes refreshed GitHub, registry, release, implementation, packaging, and acceptance-artifact state at predecessor PR #117 head b5eade12af17a076eec0804daff3f2076e9ad994. One unchanged local packaged-consumer execution supplied the acceptance RED. The subsequent #117 follow-up repaired that validator and added rendered-output integrity evidence; no PR was merged, no package or baseline was published, and no issue was changed.
Trusted facts
Implementation and stack
The surviving stack is PR #109 ef34bc7d, PR #113 7281dad6, PR #116 e284c9aa, then PR #117. Live GitHub readback at the predecessor fixed point reported every PR open, non-draft, clean, and mergeable. Run 31343750838 completed successfully at exact predecessor PR #117 head on producer attempt 1 and exact-SHA replay attempt 2. The acceptance follow-up changes the #117 SHA, so a new exact-head producer and replay remain required. The canceled CI candidate at 3844fab is superseded and supplies no exact-head proof.
The accepted production contracts are present:
apps/cli/src/scaffold/json.tssemantically hashes.devpunks/context-plan.jsonand.devpunks/harness-projection-receipt.jsonthrough canonical JSON.apps/cli/src/features/scaffold-update/fixed-managed-recovery.tsconverts verified fixed-managed update conflicts into archive-and-replace actions.apps/cli/src/cli/update-command.tstreats a normal non-check update as apply and rejects--checkwith--writeor--yesbefore invoking the operation.apps/cli/src/data/scripts/sync-subagents.mjsfingerprints the effective available-hook set and rendered provider-output maps asrenderedOutputSha256, publishes the committed projection receipt, and refreshes only its matching manifest evidence.- Generated sync publication is serialized through a repository-confined lease under
.devpunks-cache. A live competing owner fails retryably before receipt mutation; stale recovery validates owner and inode before reclaiming, and no lock artifact remains after completion or failure. - Projection health treats expected provider capability limitations and preserved project-owned prompts as neutral durable provenance. Healthy receipt/manifest status remains
successwith emptyscaffoldDegradations; actual projection/application faults and missing managed canonical sources fail, whilepartialis reserved for a genuine actionable nonfatal anomaly.
Focused lifecycle coverage proves these source contracts in apps/cli/src/update/scaffold-integrity-lifecycle.test.ts, apps/cli/src/update/run.test-cases.test.ts, apps/cli/src/data/scripts/sync-subagents.lifecycle.test.ts, and apps/cli/src/data/scripts/sync-subagents.test.ts.
Release authority
Stable baseline baseline/stable/2026.08.07-scaffold-integrity-convergence resolves to c4dcca3134eace76750fa899f3b581411af094d0. It is immutable predecessor evidence and must never be overwritten; the output-integrity change receives a separate new stable candidate. The predecessor predates renderedOutputSha256, so it cannot satisfy the final #105 installed-consumer row.
The next stable candidate is baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6. It must be published from clean post-merge #117 state before the npm package is published.
apps/cli/package.json declares @punks/cli@3.1.6, but live registry readback returned E404 for that exact version. The registry's latest and next tags remained 3.1.5, and readonly npm whoami returned E401 Unauthorized. Therefore new stable publication, npm publication, published-package identity, and the exact published installed-consumer matrix are not claimable.
Issues #97, #104, and #105 remain open with no closure comments.
Acceptance-artifact RED and repair
The predecessor command bun run validate:consumer-repositories failed at fresh init with:
managed hash differs: .devpunks/context-plan.jsonThat was a validator defect, not product drift. The predecessor validator used raw byte hashes where production intentionally records semantic canonical hashes for context-plan and projection-receipt JSON. It also required superseded conflict preservation, lacked issue-specific #97/#104/#105 rows, and could only build local source.
The #117 follow-up repairs those defects:
- managed context-plan and projection-receipt evidence uses production-equivalent semantic hashing;
- fixed managed drift now requires unflagged archive-and-replace with no warning or degradation, while project-owned evidence remains silent;
- the six-row matrix covers fresh init, repeated scaffold, semantic context-plan formatting, packaged-bundled fixture/cache freshness, managed archive/replacement, and projection-receipt refresh; the deterministic fixture serves a matching
/manifest, buthi checkrefreshes metadata and archive bytes and verifies the archive's embedded baseline manifest instead of requesting that separate artifact, somanifestRequests: 0is intentional and this row remains rehearsal evidence rather than published-stable authority; - the #105 row changes a project-authored subagent description and proves all four provider outputs plus
renderedOutputSha256change and restore together while only the receipt manifest entry advances; - deliberate receipt-fingerprint corruption fails closed and restored repeated sync remains byte-stable;
- package and baseline authority are independent parameters, permitting a local bundled rehearsal and later exact
@punks/cli@3.1.6plus published stable acceptance; every accepted operation must report empty issues, warnings, and degradations; - expected provider limitations and preserved project-owned prompts remain neutral receipt provenance, legacy degradation bookkeeping refreshes silently, and only actionable anomalies or actual faults affect health.
The final strict local gate is green rehearsal evidence: the focused consumer contract passed 30/30 tests with 121 assertions, and bun run validate:consumer-repositories exited 0 across all six scenarios. Fresh init exited 0 with success; first, repeated, fixed-point, and remote scaffolds exited 0 with projection success and no failed tools; both remote checks exited 0 with status success and empty issues, warnings, and degradations; cleanup reported postCleanup.paths: []. Every scaffold JSON payload contained the complete canonical operation object with success and empty issues, warnings, and degradations; partial or truncated payloads fail the gate. Managed-hash proof covered 230/230 init entries and 229/229 scaffold entries, including legacy and ScaffoldManaged content while skipping only ProjectGenerated. Internal symlinks were validated without following them. The package was local @punks/cli@3.1.6 with bundled/fixture authority, so this cannot substitute for the exact published pair.
The checked-in root supplies matching local evidence: .devpunks/harness-projection-receipt.json reports status success, zero warnings or failures, and renderedOutputSha256 25962b79154a851d925d900ec2027dc1c4975a2c141fedb0d9a9bbf4bba9b9a8; .devpunks/scaffold-manifest.json reports projectionStatus success, an empty scaffoldDegradations collection, and receipt semantic SHA 5e8c2a00c7380ec92bf45450944b1cc2f63ef53ee4d10643d0b49b6a1b228bfd, matching the receipt. This is checked-in root/local evidence, not published baseline proof.
Synthesis
The root-cause implementation and local acceptance harness now describe the same strict health contract. The bundled baseline digest is 1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98. Release authority and fresh final exact-head CI are the remaining boundaries.
The final sequence is fixed:
- merge #109, #113, #116, then #117 with fresh authorization;
- publish
baseline/stable/2026.08.10-projection-receipt-output-integritywith compatibility=3.1.6, preserving the 2026.08.07 predecessor unchanged; - publish exact
@punks/cli@3.1.6; - run the same six-row matrix with exact registry package plus explicit published
stableauthority; - retain package identity, argv, JSON, raw and semantic hashes, archive bytes, provider-output hashes, receipt fingerprint, manifest diff, corruption failure, restored idempotence, and cleanup evidence;
- attach issue-specific proof and close only rows that pass completely.
Uncertainty and authorization boundary
- npm authentication is unavailable locally. Release cannot proceed until authority is repaired.
- Merge, baseline publication, npm publication, and issue comments or closure require fresh user authorization.
- The credential-free fork miss, protected rejection of development cache artifacts, and manual-release cache path remain separate unclaimed cache evidence. They do not weaken the scaffold behavior proof, but this report does not claim them.
- The new #117 SHA requires independent review and a fresh exact-head producer plus replay before release authorization. The canceled
3844fabcandidate is not evidence.
Next action
Finish independent review and replay the exact final #117 SHA. After fresh authorization, merge the stack, publish the new stable candidate, publish npm 3.1.6, run the identical published-authority matrix, attach issue-specific proof, and close only issues whose complete acceptance evidence passes.