Harness Intelligence Wiki
Research

Scaffold Integrity Release Readiness Research

Scaffold Integrity Release Readiness Research

Question

What remains between the accepted scaffold-integrity implementation and truthful closure of issues #97, #104, and #105 after the corrected PR stack reached a clean exact-head replay?

Readonly lanes refreshed GitHub, registry, release, implementation, packaging, and acceptance-artifact state at predecessor PR #117 head b5eade12af17a076eec0804daff3f2076e9ad994. One unchanged local packaged-consumer execution supplied the acceptance RED. The subsequent #117 follow-up repaired that validator and added rendered-output integrity evidence; no PR was merged, no package or baseline was published, and no issue was changed.

Trusted facts

Implementation and stack

The surviving stack is PR #109 ef34bc7d, PR #113 7281dad6, PR #116 e284c9aa, then PR #117. Live GitHub readback at the predecessor fixed point reported every PR open, non-draft, clean, and mergeable. Run 31343750838 completed successfully at exact predecessor PR #117 head on producer attempt 1 and exact-SHA replay attempt 2. The acceptance follow-up changes the #117 SHA, so a new exact-head producer and replay remain required. The canceled CI candidate at 3844fab is superseded and supplies no exact-head proof.

The accepted production contracts are present:

  • apps/cli/src/scaffold/json.ts semantically hashes .devpunks/context-plan.json and .devpunks/harness-projection-receipt.json through canonical JSON.
  • apps/cli/src/features/scaffold-update/fixed-managed-recovery.ts converts verified fixed-managed update conflicts into archive-and-replace actions.
  • apps/cli/src/cli/update-command.ts treats a normal non-check update as apply and rejects --check with --write or --yes before invoking the operation.
  • apps/cli/src/data/scripts/sync-subagents.mjs fingerprints the effective available-hook set and rendered provider-output maps as renderedOutputSha256, publishes the committed projection receipt, and refreshes only its matching manifest evidence.
  • Generated sync publication is serialized through a repository-confined lease under .devpunks-cache. A live competing owner fails retryably before receipt mutation; stale recovery validates owner and inode before reclaiming, and no lock artifact remains after completion or failure.
  • Projection health treats expected provider capability limitations and preserved project-owned prompts as neutral durable provenance. Healthy receipt/manifest status remains success with empty scaffoldDegradations; actual projection/application faults and missing managed canonical sources fail, while partial is reserved for a genuine actionable nonfatal anomaly.

Focused lifecycle coverage proves these source contracts in apps/cli/src/update/scaffold-integrity-lifecycle.test.ts, apps/cli/src/update/run.test-cases.test.ts, apps/cli/src/data/scripts/sync-subagents.lifecycle.test.ts, and apps/cli/src/data/scripts/sync-subagents.test.ts.

Release authority

Stable baseline baseline/stable/2026.08.07-scaffold-integrity-convergence resolves to c4dcca3134eace76750fa899f3b581411af094d0. It is immutable predecessor evidence and must never be overwritten; the output-integrity change receives a separate new stable candidate. The predecessor predates renderedOutputSha256, so it cannot satisfy the final #105 installed-consumer row.

The next stable candidate is baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6. It must be published from clean post-merge #117 state before the npm package is published.

apps/cli/package.json declares @punks/cli@3.1.6, but live registry readback returned E404 for that exact version. The registry's latest and next tags remained 3.1.5, and readonly npm whoami returned E401 Unauthorized. Therefore new stable publication, npm publication, published-package identity, and the exact published installed-consumer matrix are not claimable.

Issues #97, #104, and #105 remain open with no closure comments.

Acceptance-artifact RED and repair

The predecessor command bun run validate:consumer-repositories failed at fresh init with:

managed hash differs: .devpunks/context-plan.json

That was a validator defect, not product drift. The predecessor validator used raw byte hashes where production intentionally records semantic canonical hashes for context-plan and projection-receipt JSON. It also required superseded conflict preservation, lacked issue-specific #97/#104/#105 rows, and could only build local source.

The #117 follow-up repairs those defects:

  1. managed context-plan and projection-receipt evidence uses production-equivalent semantic hashing;
  2. fixed managed drift now requires unflagged archive-and-replace with no warning or degradation, while project-owned evidence remains silent;
  3. the six-row matrix covers fresh init, repeated scaffold, semantic context-plan formatting, packaged-bundled fixture/cache freshness, managed archive/replacement, and projection-receipt refresh; the deterministic fixture serves a matching /manifest, but hi check refreshes metadata and archive bytes and verifies the archive's embedded baseline manifest instead of requesting that separate artifact, so manifestRequests: 0 is intentional and this row remains rehearsal evidence rather than published-stable authority;
  4. the #105 row changes a project-authored subagent description and proves all four provider outputs plus renderedOutputSha256 change and restore together while only the receipt manifest entry advances;
  5. deliberate receipt-fingerprint corruption fails closed and restored repeated sync remains byte-stable;
  6. package and baseline authority are independent parameters, permitting a local bundled rehearsal and later exact @punks/cli@3.1.6 plus published stable acceptance; every accepted operation must report empty issues, warnings, and degradations;
  7. expected provider limitations and preserved project-owned prompts remain neutral receipt provenance, legacy degradation bookkeeping refreshes silently, and only actionable anomalies or actual faults affect health.

The final strict local gate is green rehearsal evidence: the focused consumer contract passed 30/30 tests with 121 assertions, and bun run validate:consumer-repositories exited 0 across all six scenarios. Fresh init exited 0 with success; first, repeated, fixed-point, and remote scaffolds exited 0 with projection success and no failed tools; both remote checks exited 0 with status success and empty issues, warnings, and degradations; cleanup reported postCleanup.paths: []. Every scaffold JSON payload contained the complete canonical operation object with success and empty issues, warnings, and degradations; partial or truncated payloads fail the gate. Managed-hash proof covered 230/230 init entries and 229/229 scaffold entries, including legacy and ScaffoldManaged content while skipping only ProjectGenerated. Internal symlinks were validated without following them. The package was local @punks/cli@3.1.6 with bundled/fixture authority, so this cannot substitute for the exact published pair.

The checked-in root supplies matching local evidence: .devpunks/harness-projection-receipt.json reports status success, zero warnings or failures, and renderedOutputSha256 25962b79154a851d925d900ec2027dc1c4975a2c141fedb0d9a9bbf4bba9b9a8; .devpunks/scaffold-manifest.json reports projectionStatus success, an empty scaffoldDegradations collection, and receipt semantic SHA 5e8c2a00c7380ec92bf45450944b1cc2f63ef53ee4d10643d0b49b6a1b228bfd, matching the receipt. This is checked-in root/local evidence, not published baseline proof.

Synthesis

The root-cause implementation and local acceptance harness now describe the same strict health contract. The bundled baseline digest is 1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98. Release authority and fresh final exact-head CI are the remaining boundaries.

The final sequence is fixed:

  1. merge #109, #113, #116, then #117 with fresh authorization;
  2. publish baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6, preserving the 2026.08.07 predecessor unchanged;
  3. publish exact @punks/cli@3.1.6;
  4. run the same six-row matrix with exact registry package plus explicit published stable authority;
  5. retain package identity, argv, JSON, raw and semantic hashes, archive bytes, provider-output hashes, receipt fingerprint, manifest diff, corruption failure, restored idempotence, and cleanup evidence;
  6. attach issue-specific proof and close only rows that pass completely.

Uncertainty and authorization boundary

  • npm authentication is unavailable locally. Release cannot proceed until authority is repaired.
  • Merge, baseline publication, npm publication, and issue comments or closure require fresh user authorization.
  • The credential-free fork miss, protected rejection of development cache artifacts, and manual-release cache path remain separate unclaimed cache evidence. They do not weaken the scaffold behavior proof, but this report does not claim them.
  • The new #117 SHA requires independent review and a fresh exact-head producer plus replay before release authorization. The canceled 3844fab candidate is not evidence.

Next action

Finish independent review and replay the exact final #117 SHA. After fresh authorization, merge the stack, publish the new stable candidate, publish npm 3.1.6, run the identical published-authority matrix, attach issue-specific proof, and close only issues whose complete acceptance evidence passes.

On this page