Harness Intelligence Wiki
SpecsCLICLI Release Test Caching

CLI Release Test Caching Implementation Notes

Implementation Notes

Summary

  • Post-restack repair refreshes current authority to 88 deterministic files / 969 tests, 16 capability-keyed native files / 304 tests, one ambient uncached file / 39 tests, 105 ordinary files total, 427 frozen baseline titles, and 429 protected/collected titles. Earlier 88/12/1, 89/14/1, 88/15/1, and 390/392 evidence below remains historical.
  • Required-tool failure now preserves ordinary ambient coverage: a development profile missing sh or tar bypasses the entire isolated ambient Turbo invocation and runs directly uncached; complete profiles retain the cache-disabled Turbo ambient task, and protected namespaces remain fail-closed through Turbo.
  • The managed-assets fixture contract now owns a dedicated native file, and the package check executes that entire file without a title filter. The exact title and body are unchanged, fixture update mode remains atomic, and a moved title can no longer turn the gate into a zero-test success.
  • All Turbo-owned CLI build, typecheck, release-test, and attestation package scripts use HI_TEST_NODE_PATH with a local node fallback. Nested Vitest and distribution assertions invoke JavaScript through process.execPath; the test-only Vitest module seam is rejected in protected execution.
  • Protected workflow publication tokens now exist only on the two mutation steps. The release verifier and detached install cannot inherit publication credentials, the install also drops ACTIONS_*, and the protected parent still holds OIDC for the bounded token refresh immediately before the grouped write.
  • Historical W6 froze the then-current 10-file / 390-test title inventory before file splitting; the current authority is the 427-title manifest plus two accepted additions described above.
  • T10 is complete: 88 scaffold contracts are preserved exactly across 44 ordinary orchestration/policy tests and 44 native filesystem/process tests; the final four-file gate and 390-title verifier pass.
  • T12 is complete: all 70 sync-subagents contracts are preserved across 37 deterministic policy tests and 33 native security/timing tests; the parent two-file gate and title verifier pass.
  • T11 is complete: seven mixed suites preserve all 232 assigned titles across deterministic and native files. The global 390-title verifier, scoped quality gates, and repaired canonical context fixture pass; ordinary-only wall time fell 30.36% from 141.80s to 98.75s.
  • Historical T13 through T15 convergence covered 88 deterministic files, 12 capability-keyed native files, and 1 ambient file in a serialized 2/1/1 worker graph; the first run passed in 738.07s and the exact repeat in 356.98s. Those results predate the current 88/16/1 inventory and do not establish current same-SHA reuse.
  • Historical T14 evidence covered the copied-production capability fixture at 19 tests and migrated AC-014 at 23. The current fixture passes 22 tests and 31 assertions in 202.59 seconds, adding missing-sh and missing-tar direct ambient coverage while preserving exact-profile injection, complete-profile FIFO evidence, forced-native coverage, and protected fail-closed routing.
  • At the historical T1-through-T7 checkpoint, release-test policy, receipt v2, the uncached release dispatcher, the cacheable verification graph, static trust routing, isolated acceptance, provider setup, and the full convergence matrix were green. The current publication authority is receipt v3.
  • T8 is ingested into the existing root and routed runbooks. The spec and runbook remain canonical; no duplicate flow or concept page was added.
  • Default local bun run test now excludes the monolithic CLI test task and reuses the exact-once release graph after the cached non-CLI workspace graph. Cacheable CLI groups can hit locally; intentionally uncached groups still execute.
  • GitHub Actions run 31166152553 passed the full suite, but its long-lived PAT remote-cache authentication was rejected and the run completed without authenticated remote reuse. That evidence remains historical. PR replay 31329286573 closes same-repository development OIDC and same-SHA reuse for the corrected PR #113 stack. Protected-main run 31245179530 passed at exact SHA c4dcca3134eace76750fa899f3b581411af094d0; its grouped producer completed build and release:attest 2/2, and its consumer restored both tasks remotely. Fork isolation, protected rejection of a development artifact, and manual-release execution remain pending runtime evidence.
  • Overall-green run 31336682227 refined the development-cache failure boundary by exposing an invalid native replay. Producer attempt 3 completed the 16-file native workload after the short-lived OIDC token had expired, so Turbo could not upload native hash a3ec8697df7cbbb1; exact replay attempt 4 restored deterministic work but missed and reran native. Trusted development CI now runs four fixed, disjoint, exhaustive four-file native partitions. HI_NATIVE_CAPABILITY_PART is hash-tracked, each serial one-worker child receives a fresh pinned OIDC exchange immediately before execution, and missing or invalid required parts fail closed. Forks retain one credential-free complete native run; protected forced-native, ambient, and attestation paths are unchanged. Runtime acceptance remains pending a producer plus exact-SHA replay of this implementation.

Deviations From the Plan

  • GitHub cache jobs now use Vercel's repository-scoped OIDC exchange through vercel/setup-turborepo-remote-cache-action@v1.0.0; repository variable TURBO_TEAM supplies the team slug. Development/protected signature values remain separate GitHub Actions repository secrets. The Vercel policy selects GitHub account wearedevpunks and repository harness-intelligence, without an additional workflow or branch restriction. Both classes still use the same Vercel team authority, so independently administered backend authorities remain future trust hardening.
  • T14R rejected the first local capability acceptance fixture because it reproduced routing around counter tasks rather than exercising production topology and a real native workload. It also reopened native input hashing, three shell-driven ordinary files, required tar, one remaining bare Node call, and persisted machine-id link validation.

Surprises and Decisions

  • The retained research inventory was stale after 7fc02210: baseline release and project-settings tests moved to the conservative lane and sync-subagents gained one case. Delivery used the then-live 10-file / 390-test inventory and remeasured after splits.
  • A planning-discovery vitest list --json invocation accidentally treated a source path as its optional JSON output target, replacing one tracked test and leaving an untracked true file. Parent identified both as collected-test JSON, restored the tracked file byte-for-byte from HEAD, removed only the generated file, and standardized all later collection on --json=<explicit-temp-path>.
  • Local capability authority persists an ignored mode-0600 random id at apps/cli/.turbo/host-machine-id and hashes the actual temporary-volume device plus filesystem type. CI requires exact ImageOS and ImageVersion, hashes the filesystem type, and excludes the runner's ephemeral volume device. Both modes retain fresh filesystem probes. Optional missing tools are modeled; missing critical evidence returns an uncached profile.
  • Historical replay debugging exposed ephemeral device-key churn and a 15-second fanout timeout. CI-stable volume-type identity and an explicit 30-second test timeout own those repairs. The later exact-SHA replay in run 31327081403 passed with stable native task identity and remote hits.
  • Run 31336682227 showed that stable hash identity alone was insufficient for the long native upload: the OIDC-exchanged Vercel token expired before the single native task completed. Refreshing once before the same long task would leave the upload at the same lease boundary, so the durable fix partitions only trusted development native execution into four hash-separated children with one fresh exchange per child.
  • Integration review added the previously implicit sh executable to required capability evidence and replaced remaining bare Node calls in native scaffold tests with the profiled exact path. The original frozen inventory treated its 390 titles as an exact required subset and separately registered two legitimate additions; that pre-restack proof was 390 baseline titles preserved, 392 protected, and 392 collected.
  • The frozen title verifier caught one transient duplicated run-scaffold seam during mechanical splitting. Only the duplicate registration was removed; the canonical test body remained in the ordinary file. Final stage/run titles match the pre-split manifest exactly.
  • T11 exposed a stale canonical context provenance fixture left by the earlier bundled-baseline content update. Its only two identity fields were synchronized from 562f... to the current generated a1a9... digest; the behavior assertions and managed-byte fixture stayed unchanged.
  • The immutable execution plan was attached to IP-361 through IP-365 without changing issue bodies, status, or native dependency relations.
  • The available agent-thread cap allowed two workers at once, so T3 reused the completed T2 CLI worker while T1 remained active. The W1 dependency gate was preserved.
  • A fixed ordinary-file count assertion was removed during parent review; the durable contract now proves uniqueness and exact discovered union without freezing a count.
  • T1 integration review admitted the deterministic dispatcher and receipt tests to the cacheable allowlist. run-cli-verification.test.ts remains uncached because direct task execution can still resolve Bun through uncontrolled PATH when the wrapper identity is absent.
  • T4 parent review added remoteCache.signature: true; the workflow-only T5 scope could not safely own that repository policy.
  • T5 routes the four update actions (update:0, update:1, update:2, and update:uncached) across separate parallel CI runners. After all four pass, ordinary:cacheable and ordinary:uncached run on separate dependent runners, followed by one aggregate required check. Same-repository jobs receive OIDC permission and short-lived Vercel cache authority. Forks use a separate credential-free chain because a step-level OIDC condition would still expose GitHub's token endpoint to checked-out fork code. Static workflow contracts are green. PR replay 31329286573 proves the same-repository development chain; protected-main run 31245179530 proves the grouped protected producer and 2/2 remote restoration. Fork isolation, protected rejection of a development artifact, and manual-release execution still need runtime evidence.
  • At the historical T2 checkpoint, receipt v2 contained measured runtime identity and the sorted output manifest only. It deliberately omitted protected and trustNamespace: pinned repository Turbo, rejection of executable overrides, protected namespace/credentials, protected signing-key fingerprint d684883c34a343c2fe6cbfc81936df7155024680df1bcfb6411f21d2b3ae28af, read-only remote REMOTE/HIT summaries, and attestation established protected provenance outside the receipt. The current publication authority is receipt v3.
  • Convergence repairs are recorded at 86450f72, 9727d307, and 0313e748. Review repairs 0f8a7c2f, f1debe39, 0dc0cf16, 27bb88a1, and 087d44a2 make the protected producer run the preliminary full graph with read authority, then execute and upload the exact [build, release:attest] graph with write authority; the release consumer stays read-only and accepts provider hits only. Protected local proof and final review are complete. The producer and consumer signing-key bytes were proven exactly equal without exposing the key. These commits prove repository state, not GitHub Actions execution.
  • T6 parent review rejected synthetic-only uncached evidence; the final harness runs the unchanged real child-process wall-clock assertion twice and retains the synthetic Turbo cache:false proof.
  • The release dispatcher performs the first npm version probe outside Turbo. A new version enters protected deterministic verification; an existing version keeps the fast recovery route. The uncached mutation executor probes npm again immediately before publication and owns all npm, Git tag, and GitHub release mutations.
  • At the historical receipt-v2 checkpoint, the generated bundled-baseline identity was derived build output, excluded from build inputs, restored beside dist/**, and hashed with those outputs before publication. The current publication authority is receipt v3.
  • T7 reproduced cold first-miss collapse when filesystem-heavy shards shared one CI runner: the run timed out and concurrent subprocess teardown surfaced EPIPE. Review rejected the temporary global Turbo --concurrency=2 cap because it violated the accepted four-update parallel wave. CI now preserves that wave across separate runners; no per-case or global test timeout was increased.
  • Default local orchestration uses two sequential Turbo process boundaries. The first excludes @punks/cli; the CLI verification wrapper then owns its build and exact-once release-test graph. Combining the disjoint scopes would either reintroduce @punks/cli#test or require a broader task-graph redesign.
  • The Fumadocs route already registered IMPLEMENTATION-NOTES, but the page lacked required frontmatter. T8 added the routed project metadata and completed ingestion after local convergence.

Sanity Checks

CheckResultNotes
bun run --cwd apps/wiki check:contentPassPlan and research routing validated before implementation.
bun run --cwd apps/cli test -- src/update/run.shards.test.ts src/scripts/release-test-policy.test.ts src/scripts/release-verification-evidence.test.ts src/scripts/publish-release.test.ts src/scripts/release-dispatcher.test.tsPass5 files, 18 tests; parent W1 validation.
bun run --cwd apps/cli test -- src/update/run.shards.test.ts src/scripts/release-test-policy.test.ts src/scripts/release-verification-evidence.test.ts src/scripts/release-dispatcher.test.ts src/scripts/run-cli-verification.test.ts src/scripts/run-release-tests.test.ts src/scripts/publish-release.test.tsPass7 files, 21 tests; parent W2 integration validation.
bun test ./scripts/behavior-contract/cli-release-task-graph.test.tsPass4 graph/trust tests.
bunx turbo run build check-types test:release:complete --filter=@punks/cli --dry=jsonPassResolved deterministic graph without remote credentials.
bun test ./scripts/behavior-contract/root-suite.test.ts ./scripts/behavior-contract/cache-trust.test.tsPassStatic trust routing passed 14 tests and 340 assertions.
bun test ./scripts/behavior-contract/test-scope.test.ts ./scripts/behavior-contract/root-suite.test.tsPassDefault local caching regression and dry-run graph passed 25 tests and 555 assertions; no full suite was run for this focused repair.
bun test ./scripts/behavior-contract/cli-verification-cache.test.tsPass23 tests, 25 assertions in 16.65 seconds; isolated acceptance and real uncached exception proof.
Clean cold bun run test:release graphPass7/7 tasks, 0 cached, 8m55.684s; update 96/96, ordinary cacheable 1,066/1,066, ordinary uncached 78/78.
Repeat bun run test:release graphPass7/7 tasks, 4 cached, 4m37.526s; expected bypasses: update:uncached, ordinary:uncached, and complete.
Protected cold graph at f1debe39Pass7/7 tasks, 0 cached, 9m6.517s.
Protected producer and release consumerPassPreliminary full graph used remote:r; producer traversed 96 update, 1,066 cacheable ordinary, and 78 uncached ordinary tests, then uploaded exact [build, release:attest] with remote:w; consumer restored 2/2 hits with remote:r; provider assertions passed in 1.316s. Signing-key bytes matched exactly without disclosure.
bun run testPass16/16 root tasks; CLI 92 files and 1,240 tests; 24m18.439s.
bun run checkPass12/12 tasks.
bun run format and git status --shortPass1,454 files formatted; Git status clean in the validation worktree.
Final review and scoped validationPassFinal review clean; delivery-scoped typecheck, lint, and format passed. A root-check rerun was blocked only by unrelated dirty packages/ui/oxlint.config.ts; prior full root test/check/format remained green.
bun run --cwd apps/wiki checkPassT8 projection, Oxlint, and Oxfmt validation passed across the wiki.
bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.mdPassT8 owned documentation is formatted.
git diff --checkPassT8 introduced no whitespace errors.
bun run --cwd apps/cli test -- src/scripts/host-test-capabilities.test.ts src/scripts/verify-test-title-inventory.test.tsPassW6 profiler and title-verifier contracts: 19 tests.
node ./apps/cli/scripts/verify-test-title-inventory.mjs --currentPassHistorical pre-split union contained exactly 390 unique titles from 10 source files.
W6 CLI typecheck, scoped Oxlint/Oxfmt, and git diff --checkPassParent reran both workers' focused quality gates.
T11 mixed-suite split and title inventoryPassParent final gate passed 14 files and 232 tests in 133.94s; 232/232 assigned titles and 390/390 global titles verified. CLI typecheck, scoped Oxlint/Oxfmt, and git diff --check passed. Ordinary-only wall fell 30.36%.
Host executable and title-baseline follow-upPassProfiler, verifier, and scaffold native gates cover required sh, exact profiled launchers, executable-substitution rejection, and cwd-bound local identity publication; 390 baseline titles are preserved with 392 protected and collected. CLI typecheck, scoped Oxlint/Oxfmt, and git diff --check passed.
T13 host-capability graph integrationPassAt that checkpoint, the focused CLI gate passed 42 tests and production policy assigned 88 deterministic, 12 native-capability, and 1 ambient file in serialized lanes. Exact Bun/Node launchers, one profile per top-level action, CLI typecheck, title proof, scoped Oxlint/Oxfmt, and git diff --check passed.
T14 local real-Turbo capability acceptancePassHistorical T14 passed 19/19 and migrated AC-014 passed 23/23. The then-current production policy remained byte-identical; all 12 native paths executed on miss/forced, the hit skipped execution, two real capability witnesses distinguished missing/present mkfifo, ten copied stubs were explicit, and the real ambient witness proved 31/2 then 33/0 under cache-disabled misses.
Forced native inventory after final harness repairPassCache bypass executed all 12 native files and 255 tests successfully in 3m33.765s. The test harness copies profiled executables rather than hardlinking them, so fixture setup cannot mutate the outer executable state.
First complete post-repair CLI verificationPassCompleted in 738.07s. Three update tasks restored from the interrupted producer attempt; update:uncached executed; deterministic missed and passed 88 files / 925 tests; native capability missed and passed 12 files / 255 tests; ambient executed 1 file / 33 tests.
Exact repeat CLI verificationPassCompleted in 356.98s before final formatting. Build, three update tasks, deterministic, and native capability restored; update:uncached, ambient, and the aggregate marker executed. After Oxfmt changed hashed inputs, deterministic c2801d7fed13af73 and native 388adbd9093566b2 each passed on miss and restored immediately on exact repeat.
Final root bun run testPassFinal formatted-state repository suite completed with status 0 in 781.35s. Non-CLI workspaces, behavior contracts, all update shards, 88 deterministic files / 925 tests, 12 native files / 255 tests, and the ambient file passed.
Final root bun run checkPass12/12 workspace checks passed. CLI and wiki lint/format/content validation were green.
Diff-driven changed-file quality sweepPassOxfmt write/check covered all 52 changed supported files; Oxlint covered every changed JavaScript/TypeScript module with zero findings.
Post-restack host-cache repairPassCurrent T14 passed 22/22 with 31 assertions in 202.59s; repaired runtime/credential boundaries passed 39/39, host profiling 21/21, deterministic build fixture 1/1, managed split/policy/title 12/12, stage split 54/54, graph/trust/root 32/32 with 803 assertions, and title authority remains 427/429/429. Lane collection is 88 files / 969 tests, 16 / 304, and 1 / 39. Run 31327081403 proves authenticated same-SHA development reuse.

No user-interface surface changes are planned; CLI, task-graph, workflow, and operator-documentation evidence applies.

Runtime Validation Evidence

TaskScenario and targetPublic actionCorrelation or provenanceObserved result and durable evidenceStatus or exact blocker
T5/T7Local Vercel remote-cache authority and reusePull the configured environment; run release graphVercel team dev-punks; cold and repeat summariesLocal pull reported remote caching enabled. Clean cold graph completed 7/7 with 0 cached in 8m55.684s; repeat completed 7/7 with 4 cached in 4m37.526s. Expected uncached bypasses executed.Accepted local provider and convergence evidence
T5/T7Protected producer-to-release-consumer reuseProduce protected evidence, then consume read-onlyExact protected graph and final two-task graphProducer ran the preliminary full graph with remote:r, traversing 96 update, 1,066 cacheable ordinary, and 78 uncached ordinary tests successfully, then uploaded exact [build, release:attest] with remote:w. Consumer restored 2/2 remote hits with remote:r; provider assertions passed in 1.316s. Signing-key bytes matched exactly without disclosure.Accepted protected local proof
T5/T7Same-repository PR, fork, and protected-main CIExecute the checked-in GitHub Actions workflowExact SHA, run attempts, capability-keyed task hashes, and cache sourcesPR replay 31329286573 restored deterministic/native cacheable work remotely for exact PR #113 while ambient and uncached update work bypassed. The native task declares HI_HOST_CAPABILITY_DIGEST as a hashed input, so its equal public task hash is the supported non-secret capability-equality proof. Protected-main run 31245179530 passed at exact SHA c4dcca3134eace76750fa899f3b581411af094d0; its grouped producer completed build and release:attest 2/2, and its consumer restored both remotely.Same-repository and protected grouped reuse accepted; fork miss, cross-namespace rejection, and manual release pending
T14/T15Local host-capability producer and exact replayRun the complete CLI wrapper twice after reviewStable local capability authority and exact task hashesFirst complete post-repair run passed in 738.07s; exact repeat passed in 356.98s. After Oxfmt changed hashed inputs, final deterministic/native runs missed, passed, then restored on exact repeat. Forced native and ambient remained cache-disabled. Final formatted-state root bun run test passed in 781.35s.Accepted local miss/hit and full-suite evidence

Acceptance Criteria Status

CriterionStatusNotes
AC-001Implemented; same-repository runtime greenLocal provider reuse and authenticated PR replay 31329286573 prove compatible same-repository reuse.
AC-002Implemented and locally greenLocal invalidation acceptance proves declared input and runtime-identity mismatches miss.
AC-003Partially proven; fork runtime pendingAuthenticated development and same-repository reuse are proven. Static routing removes fork credentials, but a credential-free fork miss is not observed.
AC-004Partially proven; cross-namespace and manual-release runtime pendingProtected-main run 31245179530 proves grouped 2/2 protected production and restoration. It does not prove that protected verification rejects a development artifact or that a manual release follows the protected route.
AC-005 through AC-014Implemented and locally greenPolicy, full inventory, graph, dispatcher, receipt, restoration, invalidation, uncached execution, byte equality, clean-state acceptance, full root tests, repository checks, and formatting all passed.

Manual Review Checklist

AreaCheckHow to performExpected result
Local developmentVerify with development authority onlySet HI_CACHE_NAMESPACE=development plus local Turbo token, team, and development signature key, then run bun run testWorkspace and deterministic CLI tasks upload or hit; uncached CLI tasks execute
GitHub OIDCInspect a same-repository or protected cache jobConfirm the Vercel OIDC action precedes Turbo, uses vars.TURBO_TEAM, and the job alone grants id-token: writeThe action supplies a short-lived cache token; the matching signature secret and namespace remain
Fork boundaryInspect a fork pull-request runConfirm the selected fork job chain has no OIDC permission, setup action, team, token, or signature keyFork code has no remote read/write authority or GitHub OIDC endpoint and misses remotely
Protected boundaryInspect a protected-main run after a development producerCompare task identities, cache summaries, and restored outputs without logging credentialsDevelopment provenance is rejected; protected authority supplies any accepted result
Release dispatcherExercise existing-version and new-version probes without publishing a new test versionUse the focused dispatcher/publisher tests and inspect the recorded routeExisting versions skip deterministic gates; new versions verify; the mutation executor re-probes npm
Receipt and outputsRun protected verification in an isolated clean worktreeDelete restored outputs between runs, rerun, compare receipt digests, then run git status --porcelaindist/**, generated identity, and receipt restore byte-identically; status stays clean
Test policyRun the policy and graph contracts after adding or moving a testCheck ordinary file classification and registered update-case metadataEvery test is assigned exactly once; new ordinary tests default uncached

Pre-existing Issues

  • The worktree contains unrelated scaffold, skill, lint, documentation, and agent changes. Delivery preserves them and stages only task-owned files.

Out of Scope Observations

  • External release-state reconciliation remains parked by the spec.

Remaining Work

  • Capture a producer plus exact-SHA replay for the four native partitions and verify four remote hits with no authentication or permission warning. The earlier unpartitioned same-repository proof remains historical; run 31336682227 is explicit negative lease-expiry evidence.
  • Capture fork-isolation, protected rejection of a development artifact, and manual-release runtime evidence. Protected-main grouped production and restoration are proven by run 31245179530 at exact SHA c4dcca3134eace76750fa899f3b581411af094d0.

Steering

DateFeedbackChanges
2026-08-06Execute the accepted plan in full parallelBegan plan-derived worker waves with all currently unblocked disjoint tasks.
2026-08-07Resume after intervening review repairsFinal T14R reopened T11/T12/T14: bind baseline tests to exact profiled tool executables through one isolated tool bin, and prove ambient FIFO contracts skip only when the exact mkfifo capability is unavailable.
2026-08-07Repair final T14R findingsBaseline native builds now expose only exact profiled Git/Tar symlinks through one run-owned tool bin, including a hostile sibling collision regression. Ambient native FIFO tests skip exactly two titles when the exact mkfifo path is absent and execute all 33 tests when present. The final copied-production T14 acceptance passed 19/19 with production policy unchanged and all 12 native paths represented.
2026-08-08Complete local convergenceDelivery-internal runtime evidence found two nested test-fixture leaks without weakening production guards. Final forced native, first complete, exact repeat, full root test, root check, and changed-file Oxfmt/Oxlint gates passed.
2026-08-09Prove same-SHA GitHub reuseAuthenticated PR replay 31329286573 restored deterministic/native cacheable work for exact PR #113 while ambient and uncached work bypassed. Protected-main run 31245179530 passed at exact SHA c4dcca3134eace76750fa899f3b581411af094d0; grouped production and remote restoration each completed build and release:attest 2/2. Fork isolation, cross-namespace rejection, and manual-release execution remain open.
2026-08-10Bound development cache-token leasesRun 31336682227 proved that the single native task outlived its OIDC cache token and could not upload. The accepted repair splits only trusted development native execution into four fixed hash-tracked partitions, refreshes pinned OIDC immediately before each child, preserves full fork fallback and protected topology, and leaves runtime producer/replay acceptance pending.

On this page