Plan: Cache Trusted CLI Verification Without Caching Release Mutations
Plan: Cache Trusted CLI Verification Without Caching Release Mutations
Plan state
- Status: Post-restack repair, same-repository development reuse, and protected-main grouped reuse are proven. PR replay 31329286573 attempt 2 restored deterministic/native cacheable work at exact PR #113. Protected-main run 31245179530 passed at exact SHA
c4dcca3134eace76750fa899f3b581411af094d0; its grouped producer completedbuildandrelease:attest2/2, and its consumer restored the same 2/2 tasks remotely. This does not prove a credential-free fork miss, protected rejection of a development artifact, or manual-release execution; those remain unobserved. - Authority:
SPEC.mdat immutable commitec377d12cb7d225781e60a4985bf12b0e887e876. - Research:
apps/wiki/content/docs/project/research/cli-verification-caching-plan-research-report.mdat immutable commit967ea8cf1b707e58c6b51b8edd81b8133324974c. - Execution mode: One branch and one PR. Launch every task in a wave concurrently when its
owned_pathsare disjoint. One integration owner controls shared package/Turbo topology. - Backlog: IP-361 epic; IP-362 through IP-365 stories. Native blockers stay unchanged. All five items carry the immutable
a4f73f77execution-plan attachment. - Dirty-worktree rule: Preserve all pre-existing scaffold, skill, lint, docs, and agent changes. Workers may touch only their
owned_paths.
Post-restack repair evidence
- The current ordinary policy is 88 deterministic files / 969 tests, 16 capability-native files / 304 tests, and one ambient uncached file / 39 tests, for 105 files total with serialized 2/1/1 workers.
host-test-capabilities.test.tsnow runs in the native lane. The init-stage scaffold contract that executes generated Node and shell commands also runs instage.native.test.tsthroughHI_TEST_NODE_PATHandHI_TEST_SH_PATH; a hostilePATHwitness proves neither bare executable is resolved.- The managed-assets fixture contract runs as the only test in
managed-assets-fixture.native.test.ts; the package check executes that whole file without a title filter, so moving or renaming the contract cannot silently produce a zero-test success. - Turbo-owned CLI build, typecheck, release-test, and attestation scripts now consume the profiled Node path. Nested Vitest and distribution assertions use
process.execPath, and hostile-PATHcoverage spans the deterministic, update, native, ambient, build, typecheck, and attestation bodies. - Protected publication credentials are step-scoped. Verification and producer-install child environments strip publication tokens, installation also strips GitHub Actions credentials, and the parent retains OIDC only through the cache-authority refresh before the existing grouped build-and-attestation write.
- An incomplete development
ordinary:ambientprofile missing requiredshortarskips the preliminary Turbo build and ambient Turbo task, then executes the real ambient workload directly uncached. Two invocations produce two executions and zero Turbo summaries. Complete profiles retain the cache-disabled Turbo ambient task; protected namespaces retain Turbo and fail closed. - Current focused proof preserves 427 frozen titles and 429 protected/collected titles. The copied-production T14 acceptance passed 22 tests and 31 assertions in 202.59 seconds; repaired runtime/credential boundaries passed 39, host profiling 21, the deterministic build fixture 1, managed split/policy/title tests 12, the deterministic/native stage split 54, and graph/trust/root contracts 32 with 803 assertions.
- Authenticated run
31327081403proves same-repository development portability. Attempt 1 produced deterministic task2131cd5c16dd57ccas a miss in 7m36 and capability-native task5c59e51a183f0c03as a miss in 7m23 while ambient taska90fc7b10a5b2c7bbypassed. Attempt 2 restored the three cacheable update tasks, 4/4 typecheck tasks, deterministic, and native from remote cache; ambient and uncached update task4a3dcdd8030eabe9bypassed. Both attempts were fully green and reported remote caching enabled without authentication or permission warnings.
Goal
Make deterministic CLI build, typecheck, and eligible test evidence reusable across compatible development, same-repository pull-request, protected-main, and release runs. Preserve every test and the accepted release schedule. Reject incompatible or untrusted cache artifacts. Keep npm, dist-tag, Git tag, and GitHub release mutations uncached.
Initial situation
@punks/cli#release:publishis uncached, but its publisher invokes build, tests, and typecheck with nestednpm runcommands. Turbo cannot see or reuse them.- Release tests currently execute 96 update cases in four 24-case wrappers, then 84 ordinary files containing 1,118 tests.
- No ordinary file or registered update case has cache-policy ownership.
- The real child-process shutdown timing assertion in
src/data/scripts/sync-subagents.test.tsusesDate.now()and an OS timeout and must remain uncached. - Build copies root
CHANGELOG.mdandBASELINE_CHANGELOG.mdbut does not hash them. It rewrites the generated bundled identity while that previous generated file is an input and not an output. - CI pins Node 24 and Bun 1.3.5 but does not hash OS, architecture, Node, or Bun identity. Dedicated CLI jobs do not share remote Turbo results.
- No development/protected namespace, signing authority, same-repo credential gate, or cache-behavior acceptance harness exists.
Resolved decision ledger
| Decision | Resolution | Reason |
|---|---|---|
| Ambiguity reduction | Closed from the confirmed grill and agent-ready spec; no new user questions | Product scope, trust, test policy, release routing, and parked work are already explicit |
| Cache boundary | One complete Turbo task per cache policy | Turbo cannot safely cache selected tests inside a mixed process |
| Update schedule | Exactly four first-wave update tasks; three cacheable partitions plus one uncached partition | Preserves four-way release structure while concentrating explicit exceptions |
| Registered update ownership | Every registered case declares cache policy in typed metadata | Avoids title-based policy and makes missing/duplicate declarations fail |
| Ordinary ownership | File-level registry; unknown/new files resolve to uncached and are reported by the inventory contract | Meets safe default without skipping new tests |
| Ordinary schedule | Cacheable and uncached ordinary tasks start together only after all four update tasks finish | Preserves update-before-ordinary ordering while keeping task-level policy honest |
| Timing | Effect-controlled time may be cacheable; the real child-process wall-clock file remains uncached | Matches AC-008 and prior runtime-hardening evidence |
| Runtime identity | A repository wrapper derives OS, architecture, exact Bun, exact Node, and namespace and passes them as hashed Turbo env | Direct Turbo hashing cannot infer all runtime identities itself |
| Relevant host state | Cacheable tasks receive controlled run-owned HOME/TMP/XDG/Git roots; uncontrolled host values stay only in uncached tasks | passThroughEnv does not invalidate cache keys |
| Build inputs | Retain $TURBO_DEFAULT$; add root changelogs and lockfile; exclude only prior generated identity bytes | Minimizes risk of omitting bundled byte inputs |
| Build outputs | Restore dist/** and src/data/bundled-baseline-identity.generated.ts | Both are build products required for equivalent reuse |
| Generated identity | Remains a derived tracked output, excluded from its own input hash | A synchronized release commit can remain clean; changed bundled assets still require committing regenerated output |
| Trust separation | Hash development versus protected, use distinct signing keys, and pin protected Turbo execution to the repository installation | Namespace, signing authority, and pinned execution prevent cross-boundary reuse |
| Forks | Run verification without remote credentials or signing key | GitHub withholds secrets from forks; the workflow must make this explicit |
| Release orchestration | Uncached dispatcher probes npm first; new versions run protected Turbo verification; executor re-probes immediately before publish | Static Turbo dependencies would destroy the fast existing-version path |
| External mutations | Publisher/executor remains cache: false; no mutation is an output | Preserves retry and safety semantics |
| Provider | Vercel OIDC exchanges trusted GitHub job identity for short-lived cache tokens; TURBO_TEAM is a repository variable and signature keys remain GitHub Actions repository secrets | Removes long-lived GitHub PAT wiring while retaining signed development/protected namespaces |
| External reconciliation | Parked | The spec excludes completing partial dist-tag/Git/GitHub state |
Dependency readiness and branch intent
Dependency readiness
No Stack Required.
Remote-cache namespaces, credentials, runtime identity, and signature verification are inside this capability. Actual GitHub secret values and provider access are operational runtime evidence, not a separate code stack.
Branch/base intent
Not applicable. Continue the current delivery branch. Do not create task-level stacked PRs.
Proposed solution shape
Deep modules and seams
- Release test policy: one small module discovers ordinary files, classifies them, and exposes registered-case policy metadata. The interface returns complete task selections and inventory diagnostics. Vitest/Turbo details remain adapters.
- Verification identity wrapper: one root process derives runtime identity and controlled host roots, then invokes Turbo with hashed environment values. CI, local development, and release use the same seam.
- Historical release-evidence design: at the original T2 checkpoint, one CLI module wrote and verified receipt v2 containing measured runtime identity, declared-output presence, and artifact byte digests. That receipt made no self-asserted namespace or protected claim. Pinned Turbo execution, protected signature-key verification, and read-only remote-hit evidence established provenance outside the receipt. The current publication authority is receipt v3.
- Release dispatcher: one uncached process owns npm probe routing. It invokes deterministic Turbo verification only for new versions and enters the mutation executor only after protected evidence exists.
- Acceptance harness: one isolated-worktree contract exercises force, miss, hit, restoration, invalidation, namespace/signature rejection, uncached execution, byte equality, and clean status.
Planned package task graph
update:0 (cacheable) ─┐
update:1 (cacheable) ─┤
update:2 (cacheable) ─┼─> ordinary:cacheable ─┐
update:uncached ──────┘ ├─> test:release:complete
ordinary:uncached ─┘
build ───────────────┐
check-types ─────────┼─> release:attest ─> uncached release executor
test:release:complete┘Typecheck may execute independently of the update/ordinary test chain. The public uncached dispatcher invokes build, check-types, test:release:complete, and release:attest only after the first npm miss.
Dependency graph and waves
W1: T1 ─┐
T2 ─┼─> W2: T4 ─┬─> W3: T5 ─┐
T3 ─┘ └─> W3: T6 ─┴─> W4: T7 ─> W5: T8| Wave | Tasks | Start condition | Parallelism reason |
|---|---|---|---|
| W1 | T1, T2, T3 | Immediately | Test policy, evidence module, and release dispatcher have disjoint files |
| W2 | T4 | T1, T2, T3 complete | One owner must integrate shared package/Turbo topology |
| W3 | T5, T6 | T4 complete | Workflow/static trust wiring and dynamic cache proof use disjoint files |
| W4 | T7 | T5 and T6 complete | Convergence needs the final graph and CI contract |
| W5 | T8 | T7 complete | Operator docs describe only validated behavior |
Tasks
T1: Own the exact release-test cache policy
- depends_on: []
- location:
apps/cli/src/update,apps/cli/scripts,apps/cli/src/scripts - owned_paths: [
apps/cli/src/update/run.test-cases.test.ts,apps/cli/src/update/run.shard-0.test.ts,apps/cli/src/update/run.shard-1.test.ts,apps/cli/src/update/run.shard-2.test.ts,apps/cli/src/update/run.shard-3.test.ts,apps/cli/src/update/run.shards.test.ts,apps/cli/scripts/release-test-policy.mjs,apps/cli/scripts/release-test-policy.d.mts,apps/cli/src/scripts/release-test-policy.test.ts] - wave_boundary: W1
- description: Add typed
cacheable | uncachedmetadata to every registered update case; partition the four update wrappers into three cacheable shards and one uncached shard without omission or duplication. Add one file-level ordinary registry that discovers all collectable ordinary tests, applies an explicit cacheable allowlist, defaults new files to uncached, and always assigns every file exactly once. Permanently classifysrc/data/scripts/sync-subagents.test.tsuncached. Preserve all 96 update cases and the current ordinary inventory. Do not change worker counts or use title matching for cache policy. - validation: Inventory reports exact disjoint unions, rejects missing/duplicate registered metadata, classifies a synthetic new ordinary file uncached, and retains the real wall-clock file in uncached output.
- status: Complete
- log: RED proved the policy module and update-case cache metadata were absent. GREEN assigns all ordinary files and all 96 registered update cases exactly once, defaults new ordinary files to uncached, and keeps the real child-process wall-clock file uncached. Integration review explicitly admitted the deterministic T2/T3 tests and kept
run-cli-verification.test.tsuncached because direct task execution can still resolve Bun through uncontrolled PATH. Parent W1/W2 validation passed. - files edited/created:
apps/cli/src/update/run.test-cases.test.ts,apps/cli/src/update/run.shard-0.test.ts,apps/cli/src/update/run.shard-1.test.ts,apps/cli/src/update/run.shard-2.test.ts,apps/cli/src/update/run.shard-3.test.ts,apps/cli/src/update/run.shards.test.ts,apps/cli/scripts/release-test-policy.mjs,apps/cli/scripts/release-test-policy.d.mts,apps/cli/src/scripts/release-test-policy.test.ts - backlog_item_id: IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The public release-test policy assigns every ordinary file and registered update case exactly once, with safe uncached defaults.
- red_command:
bun run --cwd apps/cli test -- src/update/run.shards.test.ts src/scripts/release-test-policy.test.ts - expected_red_failure: No cache-policy module or registered-case policy exists; exact cacheable/uncached union and new-file fallback assertions fail.
- green_command:
bun run --cwd apps/cli test -- src/update/run.shards.test.ts src/scripts/release-test-policy.test.ts - reason_not_testable:
- red_evidence: Exact command failed because
release-test-policy.mjsdid not exist; the second RED exposed 192 registrations before cache-policy filtering. - green_evidence: Initial exact command passed 2 files and 6 tests; integration rerun passed 2 files and 7 tests. CLI typecheck, scoped Oxfmt/Oxlint, uncached-wrapper smoke, and autoreview passed. Parent integration command passed 7 files and 21 tests.
- codebase_design_notes:
release-test-policyis the deep policy seam. Filesystem discovery and Vitest registration are adapters; callers consume selections and diagnostics rather than recreating globs. - review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T2: Produce and verify release cache evidence
- depends_on: []
- location:
apps/cli/scripts,apps/cli/src/scripts - owned_paths: [
apps/cli/scripts/release-verification-evidence.mjs,apps/cli/scripts/release-verification-evidence.d.mts,apps/cli/src/scripts/release-verification-evidence.test.ts] - wave_boundary: W1
- description: Historical T2 scope: implement a small evidence module that hashes declared distributable files plus the generated bundled identity, records measured runtime identity, rejects missing outputs, and compares restored bytes to receipt v2 before publication. It must be deterministic and side-effect free except for writing its declared receipt path. Protected provenance remains the wrapper/provider boundary's responsibility rather than a self-asserted receipt field. The current publication authority is receipt v3.
- validation: Public tests prove stable byte manifests, missing-output rejection, byte-tamper rejection, measured-runtime mismatch rejection, and the absence of forgeable
protectedortrustNamespacereceipt fields. - status: Complete
- log: Historical T2 result: added canonical receipt v2 and one public verifier for declared output bytes, generated identity, and measured runtime identity. Protected authority was verified before provider restore and attestation, outside the receipt. The current publication authority is receipt v3.
- files edited/created:
apps/cli/scripts/release-verification-evidence.mjs,apps/cli/scripts/release-verification-evidence.d.mts,apps/cli/src/scripts/release-verification-evidence.test.ts - backlog_item_id: IP-364
- backlog_item_url: https://linear.app/devpunks/issue/IP-364/cli-verification-caching-restore-trusted-reproducible-release-builds
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: Historical T2 target: release receipt v2 proves exact restored artifact bytes and complete measured runtime identity through one public verifier. The current publication authority is receipt v3.
- red_command:
bun run --cwd apps/cli test -- src/scripts/release-verification-evidence.test.ts - expected_red_failure: The evidence module does not exist, so receipt creation and tamper/mismatch assertions fail.
- green_command:
bun run --cwd apps/cli test -- src/scripts/release-verification-evidence.test.ts - reason_not_testable:
- red_evidence: Exact command failed because the release-evidence module did not exist.
- green_evidence: Exact command passed 1 file and 5 tests. CLI typecheck and scoped Oxfmt/Oxlint passed. Parent W1 command passed 5 files and 18 tests.
- codebase_design_notes: The receipt interface hides traversal, hashing, completeness, and identity comparison. The protected wrapper owns cache authority and provider provenance; the receipt verifier owns only runtime/output equivalence.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T3: Split pre-probe release dispatch from external mutation
- depends_on: []
- location:
apps/cli/scripts,apps/cli/src/scripts - owned_paths: [
apps/cli/scripts/publish-release.mjs,apps/cli/scripts/release-dispatcher.mjs,apps/cli/scripts/release-dispatcher.d.mts,apps/cli/src/scripts/publish-release.test.ts,apps/cli/src/scripts/release-dispatcher.test.ts] - wave_boundary: W1
- description: Move initial npm version routing into an uncached dispatcher. Existing versions enter the current tag/GitHub retry behavior without deterministic verification. New versions invoke a single injected verification command, then the mutation executor re-probes npm immediately before publication. Remove nested build/test/typecheck commands from the publisher. Keep npm publish, dist-tag, Git tag, and GitHub release operations uncached and preserve clean-worktree checks.
- validation: Process-contract tests prove existing versions skip verification, new versions verify once, the second npm probe occurs immediately before publish, a race that publishes between probes avoids duplicate publication, and no external mutation occurs after failed verification/evidence.
- status: Complete
- log: Added the pre-probe dispatcher, removed nested deterministic verification from the mutation executor, and added the publication-time npm re-probe/race path.
- files edited/created:
apps/cli/scripts/publish-release.mjs,apps/cli/scripts/release-dispatcher.mjs,apps/cli/scripts/release-dispatcher.d.mts,apps/cli/src/scripts/publish-release.test.ts,apps/cli/src/scripts/release-dispatcher.test.ts - backlog_item_id: IP-365
- backlog_item_url: https://linear.app/devpunks/issue/IP-365/cli-verification-caching-reuse-protected-verification-in-safe-release
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The release public process preserves the existing-version fast path and performs a second npm probe immediately before uncached publication.
- red_command:
bun run --cwd apps/cli test -- src/scripts/publish-release.test.ts src/scripts/release-dispatcher.test.ts - expected_red_failure: Current publisher still runs nested deterministic commands and performs only one npm version probe.
- green_command:
bun run --cwd apps/cli test -- src/scripts/publish-release.test.ts src/scripts/release-dispatcher.test.ts - reason_not_testable:
- red_evidence: Exact command failed because the dispatcher was absent and the publisher retained nested build/test/typecheck behavior.
- green_evidence: Exact command passed 2 files and 7 tests. CLI typecheck and scoped Oxfmt/Oxlint passed. Parent W1 command passed 5 files and 18 tests.
- codebase_design_notes: Dispatcher is the routing seam; mutation executor retains external retry behavior. Verification command injection keeps process orchestration testable without real npm/GitHub calls.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4: Integrate the deterministic Turbo task graph
- depends_on: [T1, T2, T3]
- location: root task configuration and CLI package orchestration
- owned_paths: [
turbo.json,package.json,apps/cli/package.json,apps/cli/scripts/run-release-tests.mjs,apps/cli/src/scripts/run-release-tests.test.ts,apps/cli/scripts/run-cli-verification.mjs,apps/cli/scripts/run-cli-verification.d.mts,apps/cli/src/scripts/run-cli-verification.test.ts,apps/cli/scripts/build-dist.mjs,apps/cli/src/data/bundled-baseline-identity.generated.ts,apps/cli/src/scripts/publish-release.test.ts,scripts/behavior-contract/cli-release-task-graph.test.ts] - wave_boundary: W2
- description: Register the four update tasks, cacheable/uncached ordinary tasks, completion task, cached build/typecheck, protected evidence task, and uncached stable/beta dispatch/executor tasks. Wire the first update wave before both ordinary tasks; keep typecheck independent. Add the runtime-identity wrapper and controlled HOME/TMP/XDG/Git roots. Hash namespace, OS, architecture, exact Bun/Node, relevant env, source/fixtures, root changelogs, root lockfile, and package inputs. Exclude only prior generated identity bytes from build inputs; restore both
dist/**and generated identity. Integrate T2 evidence verification before executor mutation. Public root scripts delegate through Turbo; direct CLI release scripts cannot bypass dispatch. - validation: Turbo dry-run shows exact dependencies, cache flags, hashed env, root inputs, output declarations, no generated-identity input, and uncached mutation tasks. Release-runner tests show four update tasks precede both ordinary tasks. Fresh build leaves synchronized tracked output clean.
- status: Complete
- log: Exposed the four update tasks, two ordinary-policy tasks, completion, build, typecheck, protected attestation, dispatch, and mutation tasks through one runtime-identity wrapper. Parent review added the repository-level signed remote-cache switch before T5.
- files edited/created:
turbo.json,package.json,apps/cli/package.json,apps/cli/scripts/run-release-tests.mjs,apps/cli/src/scripts/run-release-tests.test.ts,apps/cli/scripts/run-cli-verification.mjs,apps/cli/scripts/run-cli-verification.d.mts,apps/cli/src/scripts/run-cli-verification.test.ts,scripts/behavior-contract/cli-release-task-graph.test.ts - backlog_item_id: IP-363, IP-364, IP-365
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory; https://linear.app/devpunks/issue/IP-364/cli-verification-caching-restore-trusted-reproducible-release-builds; https://linear.app/devpunks/issue/IP-365/cli-verification-caching-reuse-protected-verification-in-safe-release
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The resolved Turbo graph exposes complete cache-safe verification and keeps all mutation executors uncached.
- red_command:
bun test ./scripts/behavior-contract/cli-release-task-graph.test.ts && bun run --cwd apps/cli test -- src/scripts/run-release-tests.test.ts src/scripts/run-cli-verification.test.ts src/scripts/publish-release.test.ts - expected_red_failure: Root graph lacks policy tasks/runtime identity/changelog inputs/generated output and the current release runner directly invokes Vitest.
- green_command:
bun test ./scripts/behavior-contract/cli-release-task-graph.test.ts && bun run --cwd apps/cli test -- src/scripts/run-release-tests.test.ts src/scripts/run-cli-verification.test.ts src/scripts/publish-release.test.ts && bunx turbo run build check-types test:release:complete --filter=@punks/cli --dry=json - reason_not_testable:
- red_evidence: Exact command failed because the graph contract and runtime wrapper were absent. Parent review RED then proved
remoteCache.signaturewas undefined. - green_evidence: Graph contract passed 4 tests; focused CLI graph/runner tests passed; credential-free Turbo dry JSON resolved successfully; CLI typecheck, scoped Oxfmt/Oxlint, fresh 524-module build, generated-output cleanliness, and diff check passed. Parent integration command passed 7 files and 21 tests.
- codebase_design_notes:
run-cli-verificationis the single adapter from runtime identity/controlled roots to Turbo. Shared task names and topology have one owner to prevent config drift. - review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T5: Wire development and protected cache trust in GitHub Actions
- depends_on: [T4]
- location:
.github/workflows, root behavior contracts - owned_paths: [
.github/workflows/behavior-contract.yml,scripts/behavior-contract/root-suite.test.ts,scripts/behavior-contract/cache-trust.test.ts] - wave_boundary: W3
- description: Route dedicated CLI verification through the shared Turbo graph. Same-repository PR and protected-main jobs exchange GitHub OIDC identity for short-lived Vercel remote-cache tokens, use repository variable
TURBO_TEAM, and retain distinct signature secrets and namespaces. Fork PRs run a separate credential-free chain with no OIDC permission. Remove broad unsigned SHA-prefix restore semantics for CLI verification. Keep least-privilege workflow permissions and never expose an OIDC endpoint or cache authority to fork code. - validation: Static workflow contracts prove exact same-repo/fork job isolation, fork OIDC and credential absence, pinned Vercel setup action, repository-variable team routing, separate namespace/signature secrets, signed remote-cache configuration, pinned runtime identity, and shared task commands rather than direct Vitest invocations.
- status: Same-repository and protected-main grouped reuse complete; fork isolation, cross-namespace rejection, and manual release pending
- log: Replaced direct CLI Vitest/shard jobs and unsigned SHA-prefix Actions cache with shared verification jobs. The later OIDC repair replaced long-lived GitHub PAT/team secrets with Vercel's pinned OIDC setup action and repository variable
TURBO_TEAM. Same-repository and protected jobs receive short-lived authority; forks run a separate no-OIDC chain. Static contracts and local provider operation are green. PR replay31329286573proves the same-repository development path on producer and fresh-runner replay. Protected-main run31245179530passed at exact SHAc4dcca3134eace76750fa899f3b581411af094d0; grouped production and remote restoration each completedbuildandrelease:attest2/2. Fork isolation, protected rejection of a development artifact, and manual-release execution remain unobserved. - files edited/created:
.github/workflows/behavior-contract.yml,scripts/behavior-contract/root-suite.test.ts,scripts/behavior-contract/cache-trust.test.ts - backlog_item_id: IP-362
- backlog_item_url: https://linear.app/devpunks/issue/IP-362/cli-verification-caching-reuse-signed-local-results-in-same-repository
- relation_mode: native
- assigned_skills: [
turborepo,tdd,simplify] - tdd_status: required
- tdd_target: The checked-in workflow gives signed development cache authority only to same-repository PRs and separate authority to protected runs.
- red_command:
bun test ./scripts/behavior-contract/root-suite.test.ts ./scripts/behavior-contract/cache-trust.test.ts - expected_red_failure: Workflow has one unsigned Actions cache shape, no fork predicate, no separate secret names, and direct CLI Vitest jobs.
- green_command:
bun test ./scripts/behavior-contract/root-suite.test.ts ./scripts/behavior-contract/cache-trust.test.ts - reason_not_testable:
- red_evidence: Exact command produced 8 passes and 6 failures for missing trust jobs, predicates, secrets, shared commands, and stale CLI build-env expectations.
- green_evidence: Original exact command passed 14 tests and 340 assertions. The OIDC repair adds static proof for trusted-job exchange, fork job-level isolation, the repository team variable, and removal of long-lived GitHub PAT/team secret references. Scoped Oxfmt/Oxlint, YAML parsing, and diff check pass. Historical run
31166152553proved green uncached CI after PAT authentication failed. Current run31327081403passed twice at exact SHA7a2187f9c461c1a4f3d232e4fa2dce4a1c7256ff; attempt 2 restored the three cacheable update tasks, 4/4 typecheck tasks, deterministic2131cd5c16dd57cc, and native5c59e51a183f0c03remotely while ambient and uncached update work bypassed. - codebase_design_notes: Workflow is an adapter to the repository verification wrapper. Trust classification remains expressed once through namespace and credential inputs.
- review_mode: cli
- runtime_validation: required
- runtime_target: A developer machine produces one signed development-cache entry; the GitHub Actions required same-repository PR check consumes that exact task hash; a fork-equivalent credential-free run misses; a protected run rejects the development entry and uses protected authority.
- runtime_evidence: Same-repository development is accepted from PR replay
31329286573: cacheable deterministic/native work restored remotely on fresh runners, while ambient and uncached update work bypassed. Logs reported remote caching enabled without authentication or permission warnings. Protected-main run31245179530passed at exact SHAc4dcca3134eace76750fa899f3b581411af094d0; grouped production and remote restoration each completedbuildandrelease:attest2/2. Fork credential absence/miss, protected rejection of a development artifact, and manual-release execution still need runtime evidence. - runtime_cleanup: Use branch/run IDs as provenance. Delete only temporary validation branches or cache fixtures created by this delivery; retain required workflow runs.
T6: Prove cache behavior and protected artifact equivalence
- depends_on: [T4]
- location: root behavior-contract acceptance harness
- owned_paths: [
scripts/behavior-contract/cli-verification-cache.test.ts,scripts/behavior-contract/cli-verification-cache-fixture.mjs,scripts/behavior-contract/cli-verification-cache-fixture.d.mts] - wave_boundary: W3
- description: Add an isolated clean-worktree acceptance harness. Prove forced execution, first miss, identical second hit, output deletion/restoration, invalidation for every declared source/fixture/root/env/runtime/lockfile dimension, namespace separation, invalid signature rejection through a test remote-cache adapter or provider fixture, exact inventory, actual uncached exception execution, fresh/cached byte equality, and clean status. Use run-owned temp/cache roots and deterministic cleanup.
- validation: The acceptance contract reports each AC-014 scenario separately and fails if a declared input is not represented. It never mutates the developer's dirty checkout.
- status: Complete
- log: Added an isolated real-Turbo/cache/Git acceptance fixture plus controlled signed-provider seam. Parent review required and obtained two executions of the actual uncached child-process wall-clock test, not only a synthetic uncached task.
- files edited/created:
scripts/behavior-contract/cli-verification-cache.test.ts,scripts/behavior-contract/cli-verification-cache-fixture.mjs,scripts/behavior-contract/cli-verification-cache-fixture.d.mts - backlog_item_id: IP-361, IP-362, IP-363, IP-364, IP-365
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
turborepo,quality-types,codebase-design,tdd,simplify] - tdd_status: required
- tdd_target: One public acceptance harness distinguishes execution, hit, restoration, invalidation, trust rejection, uncached evidence, byte equality, and clean state.
- red_command:
bun test ./scripts/behavior-contract/cli-verification-cache.test.ts - expected_red_failure: No cache acceptance harness or fixture exists, and current graph cannot satisfy restoration/runtime/trust scenarios.
- green_command:
bun test ./scripts/behavior-contract/cli-verification-cache.test.ts - reason_not_testable:
- red_evidence: Exact command failed because no acceptance harness or fixture existed.
- green_evidence: Exact command passed 23 tests and 25 assertions in 16.65 seconds under parent validation. T4 plus T6 integration passed; scoped Oxfmt/Oxlint, diff check, protected byte equivalence, real uncached exception execution, and run-owned cleanup passed.
- codebase_design_notes: The fixture adapter owns temp worktrees, cache server/provider behavior, mutation probes, and cleanup. Assertions observe Turbo summaries, restored files, receipts, and Git status through supported process interfaces.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T7: Converge the full CLI verification surface
- depends_on: [T5, T6]
- location: plan evidence and implementation notes only; production fixes remain in the failing task owner's paths
- owned_paths: [
apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/PLAN.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/meta.json] - wave_boundary: W4
- description: Run focused, release, typecheck, lint, format, behavior-contract, and cache acceptance validation from an isolated clean worktree. Record exact inventory, task summaries, cache hit/miss/restoration evidence, byte digests, clean status, CI runtime evidence, deviations, and cleanup. Reopen the owning task for every failure. Do not hide failures by increasing timeouts or weakening assertions.
- validation: All automated gates pass and the required local-producer-to-PR-consumer, fork-miss, and protected-rejection runtime evidence is attached. Missing credentials keep the task blocked.
- status: Complete for local, same-repository development, and protected-main grouped reuse; fork isolation, cross-namespace rejection, and manual release pending
- log: Focused and isolated cache acceptance passed. After repairs
86450f72,9727d307, and0313e748, the clean cold release graph completed 7/7 tasks with 0 cached in 8m55.684s; the repeat completed 7/7 with 4 cached in 4m37.526s. The expected bypasses wereupdate:uncached,ordinary:uncached, andcomplete. Cold inventory was 96/96 update cases, 1,066/1,066 cacheable ordinary tests, and 78/78 uncached ordinary tests. Full rootbun run testpassed 16/16 tasks, including 92 CLI files and 1,240 tests, in 24m18.439s;bun run checkpassed 12/12;bun run formatformatted 1,454 files and left Git status clean. Review repairs0f8a7c2f,f1debe39,0dc0cf16,27bb88a1, and087d44a2make the protected producer run the preliminary full graph withremote:r, then execute and upload the exact[build, release:attest]graph withremote:w; the release consumer remainsremote:rand accepts provider hits only. The actual protected producer traversed 96 update, 1,066 cacheable ordinary, and 78 uncached ordinary tests successfully. Producer and consumer used a locally proven byte-identical protected signing key without exposing its value. The consumer restored the exact two-task graph with 2/2 remote hits, and provider assertions passed in 1.316s. Final review is clean. A final root-check rerun was blocked only by unrelated dirtypackages/ui/oxlint.config.ts; delivery-scoped typecheck, lint, and format remained green, as did the prior full root test/check/format evidence. Historical run31166152553later passed the full suite after PAT authentication failed. PR replay31329286573closes same-repository development OIDC and exact-SHA reuse. Protected-main run31245179530passed at exact SHAc4dcca3134eace76750fa899f3b581411af094d0, with grouped producer and consumer completing the exact two-task graph 2/2. Fork isolation, protected rejection of a development artifact, and manual-release execution remain unobserved. - files edited/created:
apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/PLAN.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md - backlog_item_id: IP-361
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
autoreview,create-plan,create-spec,implement-spec,simplify] - tdd_status: not_applicable
- tdd_target: Populate durable execution evidence; no new behavior is implemented in this task.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli check && bun run --cwd apps/cli check-types && bun test ./scripts/behavior-contract/root-suite.test.ts ./scripts/behavior-contract/cache-trust.test.ts ./scripts/behavior-contract/cli-verification-cache.test.ts && bun run --cwd apps/cli test:release && bun run check:repo && git diff --check - reason_not_testable: Evidence/bookkeeping task; behavior is proven by the dependent tasks' tests and convergence commands.
- red_evidence:
- green_evidence: Clean cold graph 7/7 with 0 cached in 8m55.684s; repeat graph 7/7 with 4 cached in 4m37.526s; expected uncached bypasses executed. Full root test 16/16, CLI 92 files/1,240 tests; repository check 12/12; format 1,454 files with clean status. Protected producer successfully traversed 96 update, 1,066 cacheable ordinary, and 78 uncached ordinary tests, then uploaded exact
[build, release:attest]viaremote:w; consumer restored 2/2 hits viaremote:r; provider assertions passed in 1.316s. Final review and delivery-scoped typecheck/lint/format passed. The final root-check rerun reached only the unrelated dirtypackages/ui/oxlint.config.tsblocker. - codebase_design_notes: not_applicable
- review_mode: cli
- runtime_validation: required
- runtime_target: Final same-repository PR workflow and protected-main verification path.
- runtime_evidence: A run-owned local developer producer uploads a signed development result and the required same-repository PR consumer restores the identical task hash; the fork-equivalent path has no credentials and misses; protected verification rejects development provenance, uses protected authority, and never restores an external mutation task.
- runtime_cleanup: Preserve CI runs; remove only run-owned temp worktrees, local cache fixtures, and temporary validation branches.
Implementation validation is a reopen loop: any failing focused, graph, acceptance, or runtime gate reopens the owning Tn, applies the fix inside that task's owned_paths, reruns that task's RED/GREEN and all dependent gates, and only then returns to T7. T7 records evidence after every reopened owner is green. Local provider authority, convergence, same-repository GitHub OIDC reuse, and protected-main grouped reuse are proven. Fork isolation, protected rejection of a development artifact, and manual-release execution remain pending.
T8: Ingest the validated operator workflow
- depends_on: [T7]
- location:
docs, routed project wiki, implementation notes - owned_paths: [
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/meta.json] - wave_boundary: W5
- description: Reconcile pre-existing dirty hunks and document the proven local development cache setup, same-repo/fork behavior, protected credentials, release routing, derived generated identity, uncached mutation boundary, exact test-policy ownership, cache evidence commands, and cleanup. Update implementation notes with deviations, runtime proof, review outcomes, and manual operator checklist. Preserve unrelated documentation edits byte-for-byte.
- validation: Root and routed runbooks agree with the resolved task graph and runtime evidence; docs checks and projection checks pass; no secret value appears.
- status: Complete
- log: Root and routed operator documentation now record the converged local cache behavior, corrected Vercel authority, exact verification inventory, and the deferred GitHub Actions evidence boundary. The existing spec and runbook remain canonical; no redundant flow or concept page was created. Ingestion bookkeeping is complete.
- files edited/created:
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/SPEC.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/PLAN.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md,apps/wiki/log.md - backlog_item_id: IP-361
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,create-plan,create-spec,docs-onboarding,implement-spec,improve-codebase-architecture,parallel-research,simplify,tdd,writing-beats,writing-for-agents,writing-fragments,writing-shape] - tdd_status: not_applicable
- tdd_target: Documentation accurately exposes the validated operator workflow and trust boundaries.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/wiki check:content && bun run --cwd apps/wiki check && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md - reason_not_testable: Documentation and implementation-notes task; behavior is already proven by T1 through T7.
- red_evidence:
- green_evidence: Wiki content, wiki lint/format, assigned-document formatting, and whitespace validation pass.
- codebase_design_notes: not_applicable
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
TDD and testing strategy
- Each behavior-changing task starts with its listed public RED and records real output before production edits.
- T1 proves policy through the same registry used by runners, not duplicated test-only lists.
- T2/T3 use process/file interfaces with fake external commands; no real npm, Git tag, or GitHub mutation occurs in tests.
- T4/T5 parse resolved Turbo/workflow behavior and exercise public wrappers.
- T6 uses isolated real processes and files because cache restoration and clean-worktree equivalence cross those boundaries.
- Test counts are evidence, not a permanent numeric threshold. The exact-union contract detects omission/duplication while allowing intentional additions to start uncached.
- Existing ordinary scheduling remains bounded/serialized inside its tasks. This plan changes task caching, not Vitest file concurrency.
Validation gates
Gate after W1
- T1 exact policy union green; 96 update cases retained; ordinary discovery covers the current 84 files; real wall-clock file uncached.
- Historical W1 T2 result: receipt tamper/missing/measured-runtime contracts green; receipt v2 contained no self-asserted namespace or protected fields. The current publication authority is receipt v3.
- T3 existing/new/race/failure routing green; no real mutation.
Gate after W2
- Resolved Turbo graph matches planned dependencies and cache flags.
- Root changelogs and lockfile are inputs; generated identity is output-only.
- Public release scripts reach the dispatcher and cannot bypass protected verification.
- Four update tasks finish before both ordinary tasks; typecheck is independent.
Gate after W3
- Workflow contract proves same-repo/fork/protected credential routing.
- Acceptance harness proves every AC-014 dimension and clean fresh/restored paths.
Final implementation gate
bun run --cwd apps/cli check
bun run --cwd apps/cli check-types
bun run --cwd apps/cli test:release
bun test ./scripts/behavior-contract/root-suite.test.ts ./scripts/behavior-contract/cache-trust.test.ts ./scripts/behavior-contract/cli-verification-cache.test.ts
bun run check:repo
git diff --checkThen run mandatory review-phase. Runtime failures route to debugging-phase; docs changes route to docs-ingest-phase; only after both may closeout update Linear and PR state.
Gate after W5
- Root and routed operator docs match the validated task graph and trust model.
- Implementation notes contain the final runtime proof and manual review checklist.
- Wiki content/projection and formatting checks pass without overwriting unrelated hunks.
Docs-ingest expectations
Update, while preserving unrelated dirty hunks:
docs/README.mddocs/runbooks/hi-cli-scaffolding.mdapps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md- implementation notes in this spec folder
.agents/notes/only for a non-obvious durable operational gotcha
Document local development cache setup, fork behavior, protected credentials, release routing, derived generated identity, uncached mutations, exact test-policy ownership, cache proof commands, and credential-free fallback. Do not publish secret values.
Risks and mitigations
| Risk | Mitigation |
|---|---|
| A developer artifact crosses into release trust | Separate namespace hash and signing keys; pinned protected Turbo; read-only remote REMOTE/HIT proof; receipt byte verification |
| Fork code receives cache or OIDC authority | Separate fork jobs have no id-token: write, Vercel setup action, team, token, or signature; static contract |
| HMAC signature treated as sole producer identity | Combine pinned execution, signature-key fingerprint, credential reach, namespace, complete task hash, remote-hit evidence, restored outputs, attestation, and clean status |
| Generated output self-invalidates | Negate only prior generated identity from inputs and declare it as output |
| Build input narrowing omits bytes | Retain $TURBO_DEFAULT$; add root byte-affecting inputs rather than replacing defaults |
| A mixed test process is cached | Separate task executions and exact policy registry |
| New tests silently become cacheable | Default ordinary discovery to uncached; require update metadata |
| Earlier CI starvation returns | Do not change Vitest worker/file-parallelism policy |
| Acceptance mutates dirty user checkout | Use isolated worktree and run-owned cache/temp roots |
| External Actions infrastructure is unavailable | Preserve local/static/provider proof, record the exact external blocker, and do not claim CI or protected-main execution |
| Shared config workers conflict | T4 alone owns package/Turbo/release-runner topology |
External research used
- Turborepo 2.9.14 upstream source and docs: remote artifact signing, hashed
env, unhashedpassThroughEnv, inputs, outputs, dry-run and summaries. - GitHub Actions official docs: fork PRs do not receive secrets; cache contents are not a trust boundary; privileged triggers must not execute untrusted PR code.
- Current repo/handoffs: current Turbo graph, 96 update cases, 84 ordinary files/1,118 tests, tracked generated identity behavior, prior GitHub subprocess-starvation evidence.
Skill routing
- Planning used
grillingto confirm the frontier was already closed,parallel-researchfor two readonly lanes and a durable report,swarm-plannerfor dependency/write-scope waves,tddfor per-task RED/GREEN contracts,codebase-designfor policy/identity/evidence/dispatcher seams, andturborepofor task/hash/output design. - Implementation workers must read root and CLI scoped guidance and activate every listed
assigned_skillsbefore editing. parallel-researchis not an implementation skill. It was used only during planning.
Backlog sync
- Existing provider projection is current: IP-361 parent; IP-362 through IP-365 child stories; IP-363 and IP-364 block IP-365; IP-362 and IP-365 block IP-361.
- Planning creates no task-level issues.
- After this plan is committed and pushed, use
write-backlogonly to attach the immutable plan URL to IP-361 through IP-365 and record the resulting URL here. Do not alter story scope or blocker relations.
Unresolved questions
- Operational remote-cache credentials: developer machines may retain local Vercel token/team configuration. GitHub Actions uses a Vercel Turborepo CLI OIDC policy scoped to GitHub account
wearedevpunksand repositoryharness-intelligence, with no additional workflow or branch restriction; repository variableTURBO_TEAM; and separate development/protected GitHub Actions repository signature secrets. It no longer stores cache PAT/team secrets. Same-repository and protected jobs exchange short-lived authority, while fork jobs have no OIDC permission or cache credentials. Both trusted classes currently reach the same Vercel team authority, so independently administered backend authorities remain future hardening. PR replay31329286573proves OIDC-authenticated same-repository development reuse. Protected-main run31245179530proves grouped protected production and 2/2 remote restoration at exact SHAc4dcca3134eace76750fa899f3b581411af094d0. Fork isolation, protected rejection of a development artifact, and manual-release execution remain unobserved. - No other planning question remains open. External release-state reconciliation stays explicitly parked.
Host-dependent cache continuation (2026-08-07)
Continuation goal and evidence
Cache the remaining host-dependent ordinary lane without weakening the real filesystem contracts that defend containment, permissions, link semantics, atomic replacement, rollback, substitution, and races. The source of truth is apps/wiki/content/docs/project/research/host-dependent-cli-test-caching-research-report.md at immutable commit 01262a221477f3baa49671a0c3158a20d51461a7. GitHub Actions run 31177385911, attempt 2 measured 516.89 seconds for the then-current eight-file, 340-test lane; stage.test.ts, run.test.ts, and public-output-contract.test.ts accounted for about 78%. At the historical continuation checkpoint, HEAD 7fc02210 had ten files / 390 tests because baseline-release-scripts.test.ts and project-settings.test.ts were conservatively reclassified and sync-subagents.test.ts gained one test. Cold/warm measurements and movable counts at that checkpoint had to use the then-current inventory, not the research estimate.
This continuation remains within AC-001, AC-002, AC-005, AC-006, AC-008, and AC-014. Existing backlog projection is current; IP-362 owns compatible local/CI reuse and IP-363 owns complete test-policy assignment. No task-level backlog items are created.
Resolved continuation decisions
| Decision | Resolution | Reason |
|---|---|---|
| Local authority | Persist a repository-scoped random machine identity at ignored apps/cli/.turbo/host-machine-id; bind it with actual temporary-volume device/filesystem identity and fresh probes | Same-machine reuse is sound without pretending local evidence is portable to CI; deleting the ignored id deliberately rotates authority |
| CI authority | Fingerprint exact GitHub runner image, runtime, executable, kernel, filesystem type, and measured filesystem capabilities; exclude ephemeral volume.device | Reuses equivalent hosted runners without binding the digest to a per-job device identifier |
| Capability boundary | Compute a canonical digest before Turbo starts; declare it in task env; execute exact profiled executable paths | Runtime-created identity is too late, and hashing PATH or tool names is insufficient |
| Test boundary | Split deterministic, controlled-process, native-capability, and genuinely ambient tests by file | Turbo caches complete tasks, so mixed files create avoidable uncached work |
| Scoped doubles | Use the existing recording scoped-operation/filesystem seam for orchestration and policy assertions | Removes full baseline traversal while testing through the same public operation interface |
| Native coverage | Keep real filesystem/process tests for security semantics; cache them only under the complete capability digest | Native does not mean uncacheable when the observed host is part of the key |
| Fresh sentinel | Force the native-capability inventory on protected release and scheduled/manual workflow entrypoints; leave incomplete ambient timing/race sampling uncached | Warm PR/development runs gain reuse while environmental coverage remains deliberate |
| Runner control | Do not add a container or custom runner in this continuation | Capability evidence is the minimum compatible design; stronger runner control remains future hardening if probes prove incomplete |
Continuation dependency graph and waves
W6: T9 ───┐
T9A ──┴─> W7: T10 ─┐
T11 ├─> W8: T13 ─> W9: T14 ─> W10: T14R ─> W11: T15
T12 ┘| Wave | Tasks | Start condition | Parallelism reason |
|---|---|---|---|
| W6 | T9, T9A | Immediately | Capability profiling and title-inventory tooling have disjoint write scopes |
| W7 | T10, T11, T12 | T9A complete | Three test-file families have disjoint write scopes and share the frozen manifest |
| W8 | T13 | T9-T12 complete | One owner must integrate policy, package scripts, Turbo graph, and workflows |
| W9 | T14 | T13 complete | Acceptance proof needs the final task names and cache identity |
| W10 | T14R | T14 complete | Readonly review reopens exact owning tasks; T14 reruns after every repair |
| W11 | T15 | T14R accepted | Documentation and durable evidence describe only reviewed, measured behavior |
T9: Own canonical pre-Turbo host capability identity
- depends_on: []
- location:
apps/cli/scripts,apps/cli/src/scripts - owned_paths: [
apps/cli/scripts/host-test-capabilities.mjs,apps/cli/scripts/host-test-capabilities.d.mts,apps/cli/src/scripts/host-test-capabilities.test.ts] - wave_boundary: W6
- description: Add one deep capability module that resolves and fingerprints exact Node, Bun, Git,
sh,tar, andmkfifoexecutables; records explicit missing capabilities; measures platform, architecture, kernel, runner-image evidence, actual temporary-root filesystem, symlink, hardlink, FIFO, mode, atomic-rename, and case-sensitivity behavior; and emits a canonical digest before Turbo. Local mode persists a random id at ignoredapps/cli/.turbo/host-machine-idand combines it with temporary-volume device/filesystem identity. CI mode requires exact runner-image evidence, hashes filesystem type and measured behavior, excludes ephemeralvolume.device, and never accepts a local machine id. Return exact executable paths for task execution. Do not include secrets or raw home paths in logs. - validation: Public tests prove canonical ordering, stable identical digests, changed executable/capability/image/local-volume-device/filesystem-type misses, CI device stability, local/CI separation, exact-path execution, atomic mode-0600 identity creation under concurrency, deliberate deletion/rotation, and deterministic cleanup. Missing
mkfifo/tarcapability is explicit and distinct. Missing or failed authority-critical evidence (machine id in local mode, filesystem type, runner image in CI mode, kernel, runtime, executable fingerprint, or required filesystem probe) returnscacheable: falseand routes the inventory to ambient uncached execution. - status: Complete after clean T14R
- log: RED proved the profiler module was absent. GREEN added one canonical synchronous pre-Turbo seam with exact resolved tool paths, hashed/redacted tool evidence, local mode-0600 atomic machine identity and actual volume identity, exact CI image authority plus stable filesystem type without ephemeral device identity, filesystem probes, explicit optional-tool absence, and fail-closed critical evidence. Integration review found the native baseline-release suite also consumes
sh; the profiler now treats it as required, exports its exact path, hashes path/fingerprint changes, and fails closed when absent. Parent reran all focused tests, typecheck, lint, format, and whitespace checks. The scoped autoreview helper was attempted but hit its model-manager timeout; mandatory T14R review remains the review authority. - files edited/created:
apps/cli/scripts/host-test-capabilities.mjs,apps/cli/scripts/host-test-capabilities.d.mts,apps/cli/src/scripts/host-test-capabilities.test.ts - backlog_item_id: IP-362
- backlog_item_url: https://linear.app/devpunks/issue/IP-362/cli-verification-caching-reuse-signed-local-results-in-same-repository
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The public capability profiler gives complete equivalent hosts one digest, every result-affecting host change a different digest, and incomplete critical profiles a fail-closed uncached result before Turbo starts.
- red_command:
bun run --cwd apps/cli test -- src/scripts/host-test-capabilities.test.ts - expected_red_failure: The capability profiler does not exist, so stable/mismatch/local-versus-CI identity assertions cannot import or execute it.
- green_command:
bun run --cwd apps/cli test -- src/scripts/host-test-capabilities.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Exact RED exited 1 at import with
Cannot find module '../../scripts/host-test-capabilities.mjs'; zero tests collected. - green_evidence: Parent final focused command passed 16 profiler tests; CLI
tsc --noEmit, scoped Oxlint, scoped Oxfmt, andgit diff --checkpassed. The real persisted identity was mode 0600; a 12-process contract proved single-winner publication, candidate cleanup, and deletion rotation. Dedicatedshwitnesses prove path/fingerprint invalidation and missing-tool fail-closed behavior. - codebase_design_notes: The profiler is the single seam between ambient host state and deterministic Turbo identity. Callers receive canonical evidence, digest, and resolved tool paths; probing, persistence, normalization, and redaction stay internal.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: Remove only probe-owned temporary entries; retain the repository-scoped local machine id unless the explicit rotation scenario deletes it.
T9A: Freeze and verify the pre-split test-title inventory
- depends_on: []
- location:
apps/cli/scripts,apps/cli/src/scripts - owned_paths: [
apps/cli/scripts/verify-test-title-inventory.mjs,apps/cli/scripts/verify-test-title-inventory.d.mts,apps/cli/scripts/host-cache-test-title-inventory.json,apps/cli/src/scripts/verify-test-title-inventory.test.ts] - wave_boundary: W6
- description: Use supported
vitest list --jsoncollection to freeze the full names of every test in the current ten-file / 390-test lane before splitting. Add a small verifier that compares the frozen name multiset with the union collected from replacement files, ignoring absolute file paths but rejecting missing and duplicate baseline names while allowing separately counted new coverage. The manifest is implementation evidence, not a permanent hand-maintained cache policy. - validation: The verifier passes against current files before splitting and fails for one removed, duplicated, or renamed title. It reports exact differences.
- status: Complete after clean T14R
- log: Captured the current pre-split inventory with supported
vitest list --json=<explicit-temp-path>and stored only normalized full titles plus source metadata. Added one verifier that ignores checkout/file relocation but rejects missing, duplicate, and renamed baseline titles with exact diagnostics. T13 added legitimate fail-closed coverage, so the verifier was refined to preserve the immutable 390-title baseline exactly while separately counting additions. Parent reran focused tests, the live verifier, typecheck, lint, format, and whitespace checks. The scoped autoreview helper hit the same model-manager timeout; T14R remains mandatory. - files edited/created:
apps/cli/scripts/verify-test-title-inventory.mjs,apps/cli/scripts/verify-test-title-inventory.d.mts,apps/cli/scripts/host-cache-test-title-inventory.json,apps/cli/src/scripts/verify-test-title-inventory.test.ts - backlog_item_id: IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The public inventory verifier rejects any lost, duplicated, or renamed test while allowing file relocation.
- red_command:
bun run --cwd apps/cli test -- src/scripts/verify-test-title-inventory.test.ts - expected_red_failure: No frozen title manifest or verifier exists.
- green_command:
bun run --cwd apps/cli test -- src/scripts/verify-test-title-inventory.test.ts && node ./apps/cli/scripts/verify-test-title-inventory.mjs --current - reason_not_testable:
- red_evidence: Exact RED exited 1 with
No test files foundbecause the verifier test did not exist. - green_evidence: Parent final focused command passed 5 verifier tests; live verification reported
390 baseline preserved, 391 collected.CLI typecheck, scoped Oxlint, scoped Oxfmt, andgit diff --checkpassed. Removed, renamed, or duplicated baseline titles still fail; added coverage passes and is counted. - codebase_design_notes: The verifier hides Vitest JSON normalization and multiset comparison behind one command used by every split worker and final policy proof.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: Remove only temporary Vitest JSON output.
T10: Separate scaffold orchestration from native filesystem contracts
- depends_on: [T9A]
- location:
apps/cli/src/scaffold,apps/cli/src/testing - owned_paths: [
apps/cli/src/scaffold/stage.test.ts,apps/cli/src/scaffold/stage.native.test.ts,apps/cli/src/scaffold/run.test.ts,apps/cli/src/scaffold/run.native.test.ts,apps/cli/src/testing/scoped-scaffold-operation.ts] - wave_boundary: W7
- description: Move stage/run containment, root replacement, symlink/hardlink, permissions, atomic replacement, rollback, substitution, generated-child, and race contracts into native files without changing assertions. Convert selection, callback snapshot, pack policy, settings, routing, provenance, and failure-policy cases to the existing recording scoped-operation adapter and bounded synthetic baselines. Preserve public
runScaffold/runStageScaffoldbehavior and remove complete-baseline materialization only where filesystem semantics are not the subject. - validation: Both deterministic and native files pass independently; test titles are neither lost nor duplicated; native files retain every listed security behavior; cold deterministic runtime is recorded.
- status: Complete after clean T14R
- log: Split 54 stage and 34 run contracts by named behavior with exact test bodies/titles/assertions preserved. Ordinary files retain 24 stage and 20 run orchestration/policy contracts; native files retain 30 stage and 14 run containment, substitution, link, permission, atomic replacement, rollback, race, and generated-child contracts. The existing recording seam was sufficient and required no helper change. Frozen inventory caught one transient duplicated run registration; the worker removed only that duplicate before completion. Integration review then routed every native Node process through
HI_TEST_NODE_PATHwith the actualprocess.execPathfallback. Parent reran the native pair and focused quality gates. Scoped autoreview timed out at five minutes without findings; T14R remains mandatory. - files edited/created:
apps/cli/src/scaffold/stage.test.ts,apps/cli/src/scaffold/stage.native.test.ts,apps/cli/src/scaffold/run.test.ts,apps/cli/src/scaffold/run.native.test.ts - backlog_item_id: IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,tdd] - tdd_status: not_applicable
- tdd_target: Test-only boundary migration preserves observable scaffold behavior while separating deterministic and native execution.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli test -- src/scaffold/stage.test.ts src/scaffold/stage.native.test.ts src/scaffold/run.test.ts src/scaffold/run.native.test.ts && node ./apps/cli/scripts/verify-test-title-inventory.mjs --current - reason_not_testable: This task relocates existing behavioral tests and substitutes an existing test adapter; it changes no production behavior. Exact inventory and independent execution are the proof.
- red_evidence:
- green_evidence: Parent final four-file gate passed 88 tests; the post-review native pair passed 44/44 inside the 65-test profiler/verifier/native gate. The frozen baseline inventory passed 390/390 with one separately counted new T13 test; CLI typecheck, scoped Oxlint/Oxfmt, and whitespace checks passed. Pre-split stage was 89.99s wall and run 67.23s wall. The worker's intermediate ordinary-only measurements were stage 63.05s and run 49.18s before the final generated-child relocations; final cold/warm graph timing is deferred to T14.
- codebase_design_notes: Test through the public scaffold-operation seam. The recording adapter earns its depth by replacing traversal/materialization while preserving plan and materialize observations; native adapters remain the authority for actual filesystem semantics.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T11: Split mixed baseline, context, public-output, and verification tests
- depends_on: [T9A]
- location:
apps/cli/src/baseline,apps/cli/src/features/project-settings,apps/cli/src/features/context-planning,apps/cli/src/cli,apps/cli/src/scripts - owned_paths: [
apps/cli/src/baseline/resolve.test.ts,apps/cli/src/baseline/resolve.native.test.ts,apps/cli/src/baseline/baseline-release-scripts.test.ts,apps/cli/src/baseline/baseline-release-scripts.native.test.ts,apps/cli/src/features/project-settings/project-settings.test.ts,apps/cli/src/features/project-settings/project-settings.native.test.ts,apps/cli/src/features/context-planning/public-context-contract.test.ts,apps/cli/src/features/context-planning/public-context-contract.native.test.ts,apps/cli/src/cli/public-output-contract.test.ts,apps/cli/src/cli/public-output-contract.native.test.ts,apps/cli/src/scripts/run-cli-verification.test.ts,apps/cli/src/scripts/run-cli-verification.native.test.ts,apps/cli/src/scripts/build-dist.test.ts,apps/cli/src/scripts/build-dist.native.test.ts] - wave_boundary: W7
- description: Replace avoidable host
tarfixture construction with repository-owned deterministic bytes or a controlled in-process fixture. Split baseline release and project-settings deterministic/scoped-adapter assertions from their real Git/Bun/sh/tar, concurrency, rollback, permissions, symlink, FIFO, and hardlink contracts. Isolate the context FIFO contract, real verification worktree/Bun-install/typecheck contract, build-output link semantics, and any genuinely native public-output case. Keep controlled PATH stubs and built-CLI process contracts in deterministic or capability-keyed files. Use bounded context/scaffold doubles where the assertion concerns policy rather than materialization. Native tests that invoke profiled tools consume the exact paths exported by T9/T13 rather than resolving bare names. - validation: Every original title is assigned once; deterministic fixtures are byte-stable; unsupported FIFO cannot cache a skipped pass for a capable host; exact resolved tools are injectable or consumed from T9; both partitions pass independently.
- status: Complete after clean T14R
- log: Split seven mixed suites into deterministic and native pairs while preserving all 232 assigned titles. Replaced host
tarfixture construction with deterministic in-process archive bytes and made native tool calls accept T13's exact-path environment. The frozen global inventory caught no loss or duplication. A pre-existing canonical context fixture still named the prior bundled digest; only itsdigestandsha256fields were synchronized to the current generated identity. Parent reran the context pair and inventory after that repair. The scoped autoreview helper exceeded five minutes and was terminated without findings; T14R remains the mandatory independent review fallback. - files edited/created:
apps/cli/src/baseline/resolve.test.ts,apps/cli/src/baseline/resolve.native.test.ts,apps/cli/src/baseline/baseline-release-scripts.test.ts,apps/cli/src/baseline/baseline-release-scripts.native.test.ts,apps/cli/src/features/project-settings/project-settings.test.ts,apps/cli/src/features/project-settings/project-settings.native.test.ts,apps/cli/src/features/context-planning/public-context-contract.test.ts,apps/cli/src/features/context-planning/public-context-contract.native.test.ts,apps/cli/src/cli/public-output-contract.test.ts,apps/cli/src/cli/public-output-contract.native.test.ts,apps/cli/src/scripts/run-cli-verification.test.ts,apps/cli/src/scripts/run-cli-verification.native.test.ts,apps/cli/src/scripts/build-dist.test.ts,apps/cli/src/scripts/build-dist.native.test.ts,apps/cli/test-fixtures/public-output/context-outcome.json - backlog_item_id: IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,tdd,turborepo] - tdd_status: not_applicable
- tdd_target: Test-only partitioning eliminates avoidable host inputs and isolates real tool/filesystem behavior without changing production results.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli test -- src/baseline/resolve.test.ts src/baseline/resolve.native.test.ts src/baseline/baseline-release-scripts.test.ts src/baseline/baseline-release-scripts.native.test.ts src/features/project-settings/project-settings.test.ts src/features/project-settings/project-settings.native.test.ts src/features/context-planning/public-context-contract.test.ts src/features/context-planning/public-context-contract.native.test.ts src/cli/public-output-contract.test.ts src/cli/public-output-contract.native.test.ts src/scripts/run-cli-verification.test.ts src/scripts/run-cli-verification.native.test.ts src/scripts/build-dist.test.ts src/scripts/build-dist.native.test.ts && node ./apps/cli/scripts/verify-test-title-inventory.mjs --current - reason_not_testable: This is test-fixture control and file partitioning. Existing public behavior assertions plus exact inventory provide the proof.
- red_evidence:
- green_evidence: Parent final gate passed all 14 split files and 232 tests in 133.94s; scoped inventory proved 232 expected and 232 collected titles with no differences; global inventory passed 390/390. CLI typecheck, scoped Oxlint/Oxfmt, and
git diff --checkpassed. Ordinary-only wall time fell from 141.80s to 98.75s, a 30.36% reduction. - codebase_design_notes: Archive construction and host executable resolution become explicit adapters. Policy tests consume deterministic fixtures; narrowly named native files own host semantics.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: Remove all run-owned worktrees and temporary fixture roots.
T12: Separate subagent projection policy from native mutation races
- depends_on: [T9A]
- location:
apps/cli/src/data/scripts - owned_paths: [
apps/cli/src/data/scripts/sync-subagents.test.ts,apps/cli/src/data/scripts/sync-subagents.native.test.ts] - wave_boundary: W7
- description: Move the non-contiguous FIFO, hardlink, descriptor, containment, substitution, permission, target-recreation, and race contracts into a native file by named contract rather than line range. Keep deterministic projection, provider, prompt, hook, fallback-policy, and error-classification assertions in the ordinary file. Preserve the real child-process wall-clock assertion as ambient uncached unless its timing boundary becomes controlled during implementation. Native tests consume exact profiled executable paths where they launch host tools.
- validation: Original titles are assigned once; native security and ambient timing contracts execute directly; deterministic policy tests do not require special files or ambient race timing; both files pass independently.
- status: Complete after final T14R repair
- log: Split the non-contiguous file by named contract into 37 deterministic projection/policy tests and 33 native security/timing tests. Native owns FIFO, hardlink, descriptor, containment, substitution, permission, target recreation, race, and real wall-clock behavior. Node and
mkfifocalls accept T13's exact-path environment with standalone bare fallbacks. Parent reran the final two-file gate, 390-title verifier, lint, format, and whitespace checks. - files edited/created:
apps/cli/src/data/scripts/sync-subagents.test.ts,apps/cli/src/data/scripts/sync-subagents.native.test.ts - backlog_item_id: IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,tdd] - tdd_status: not_applicable
- tdd_target: Test-only partitioning keeps every native mutation contract while making projection and policy tests independent of host special-file capabilities.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli test -- src/data/scripts/sync-subagents.test.ts src/data/scripts/sync-subagents.native.test.ts && node ./apps/cli/scripts/verify-test-title-inventory.mjs --current - reason_not_testable: This task moves existing public behavior contracts between files without changing runtime code.
- red_evidence:
- green_evidence: Parent final gate passed 2 files / 70 tests in 40.33s; global title verifier passed 390/390; scoped Oxlint/Oxfmt and
git diff --checkpassed. Worker baseline was 49.86s wall; ordinary-only was 23.53s wall and native-only 22.03s wall. - codebase_design_notes: Native mutation semantics remain tested through the generated script's public process boundary. Deterministic projection policy stays local to its existing test seam.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: Remove every test-owned repository and outside witness root.
T13: Integrate deterministic, capability-keyed, forced-native, and ambient tasks
- depends_on: [T9, T10, T11, T12]
- location: root Turbo/workflow contracts and CLI verification orchestration
- owned_paths: [
turbo.json,apps/cli/package.json,apps/cli/scripts/release-test-policy.mjs,apps/cli/scripts/release-test-policy.d.mts,apps/cli/scripts/run-release-tests.mjs,apps/cli/scripts/run-cli-verification.mjs,apps/cli/scripts/run-cli-verification.d.mts,apps/cli/src/scripts/release-test-policy.test.ts,apps/cli/src/scripts/run-release-tests.test.ts,.github/workflows/behavior-contract.yml,scripts/behavior-contract/cli-release-task-graph.test.ts,scripts/behavior-contract/cache-trust.test.ts,scripts/behavior-contract/root-suite.test.ts] - wave_boundary: W8
- description: Extend the exact file registry to
deterministic,native-capability, andambient-uncachedpolicies with safe uncached defaults and no missing/duplicate assignment. Add package tasks and Turbo nodes for capability-keyed native reuse and cache-disabled forced-native execution. Compute T9 identity before Turbo, declare the digest and authority mode in taskenv, pass exact tool paths, and keep local and CI authority values disjoint. Preserve the total Vitest worker bound. A complete local/CI profile runs the capability-keyed task; incomplete/error profiles fail closed to ambient uncached execution. Run the forced native inventory in protected release plus scheduled/manual workflow paths; ordinary PR/development paths may restore the capability-keyed task. Ambient tests always execute. T13 owns the workflow dispatch surface later invoked by T14's same-SHA proof. - validation: Policy and graph contracts prove exact inventory, safe defaults, declared hash env, no simultaneous duplicate worker wave, supported/unsupported key separation, local/CI separation, protected/scheduled forced execution, and unchanged release ordering.
- status: Complete after clean T14R
- log: RED proved the old two-lane policy rejected all deterministic/native/ambient classifications and the runner rejected all four new actions. GREEN assigns 91 deterministic files, 9 capability-keyed native files, and 1 ambient file with unknown files defaulting ambient uncached. The wrapper profiles before Turbo, hashes authority/digest plus result-affecting process environment, passes exact tool paths, and routes incomplete critical profiles to direct uncached native execution. Normal development and same-repository PRs may restore native results; protected production, scheduled, and release/manual paths execute forced-native. The graph serializes deterministic, native, and ambient groups at worker caps 2/1/1. Parent review added required
sh, exact Node boundaries, locale/timezone hashing under--only, and exact tool propagation into ambient execution. Scoped autoreview exceeded five minutes without output; T14R remains mandatory. - files edited/created:
turbo.json,apps/cli/package.json,apps/cli/scripts/release-test-policy.mjs,apps/cli/scripts/release-test-policy.d.mts,apps/cli/scripts/run-release-tests.mjs,apps/cli/scripts/run-cli-verification.mjs,apps/cli/scripts/run-cli-verification.d.mts,apps/cli/src/scripts/release-test-policy.test.ts,apps/cli/src/scripts/run-release-tests.test.ts,apps/cli/src/scripts/run-cli-verification.test.ts,.github/workflows/behavior-contract.yml,scripts/behavior-contract/cli-release-task-graph.test.ts,scripts/behavior-contract/cache-trust.test.ts,scripts/behavior-contract/root-suite.test.ts - backlog_item_id: IP-362, IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-362/cli-verification-caching-reuse-signed-local-results-in-same-repository; https://linear.app/devpunks/issue/IP-363/cli-verification-caching-preserve-the-full-release-test-inventory
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The public release-test graph assigns every file exactly once and reuses native results only when pre-Turbo host capability identity matches.
- red_command:
bun run --cwd apps/cli test -- src/scripts/release-test-policy.test.ts src/scripts/run-release-tests.test.ts && bun test ./scripts/behavior-contract/cli-release-task-graph.test.ts ./scripts/behavior-contract/cache-trust.test.ts - expected_red_failure: Current policy has only cacheable/uncached groups, no capability digest in the Turbo hash, and no forced-native sentinel path.
- green_command:
bun run --cwd apps/cli test -- src/scripts/release-test-policy.test.ts src/scripts/run-release-tests.test.ts && bun test ./scripts/behavior-contract/cli-release-task-graph.test.ts ./scripts/behavior-contract/cache-trust.test.ts ./scripts/behavior-contract/root-suite.test.ts && bunx turbo run test:release:complete --filter=@punks/cli --dry=json - reason_not_testable:
- red_evidence: Exact policy RED failed 5/5 on the missing three-way API; runner RED rejected all four new action names.
- green_evidence: Parent final focused CLI gate passed 3 files / 20 tests; behavior contracts passed 31 tests / 717 assertions; the title verifier preserved all 390 baseline titles and collected 391 total; CLI typecheck, Turbo dry graph, scoped Oxlint/Oxfmt, and
git diff --checkpassed. - codebase_design_notes:
release-test-policyremains the assignment seam;run-cli-verificationremains the sole pre-Turbo environment adapter. Forced execution is a second execution mode over the same native inventory, not duplicate ownership. - review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T14: Prove capability cache correctness and measure cold/warm behavior
- depends_on: [T13]
- location: root behavior-contract acceptance harness
- owned_paths: [
scripts/behavior-contract/cli-host-capability-cache.test.ts,scripts/behavior-contract/cli-host-capability-cache-fixture.mjs,scripts/behavior-contract/cli-host-capability-cache-fixture.d.mts,scripts/behavior-contract/cli-verification-cache.test.ts,scripts/behavior-contract/cli-verification-cache-fixture.mjs,scripts/behavior-contract/cli-verification-cache-fixture.d.mts] - wave_boundary: W9
- description: Extend isolated real-Turbo acceptance proof for the host-capability task and migrate the existing cache-acceptance fixture from the superseded two-lane policy. Demonstrate first matching run miss, exact repeat hit, changed capability miss, explicit unsupported-versus-supported separation, local-versus-CI miss, incomplete-profile uncached fallback, execution of ambient and forced-native paths, exact title/file inventory, cleanup, and same code/test/input identity. Record cold time after scoped doubles and warm exact-SHA replay time. Invoke the T13 workflow twice for the same SHA/runner class and record equal capability-keyed native Turbo task hashes plus miss-then-hit summaries.
HI_HOST_CAPABILITY_DIGESTremains a declared hashed task input; the public task hash is the supported non-secret equality proof, so workflow logs do not emit the private digest value. Workflow edits remain owned by T13 and any failure reopens it. - validation: Each acceptance scenario reports separately; summaries prove the expected task hash/status/source; no skipped FIFO pass can satisfy a capable consumer; the fixture never mutates the developer checkout.
- status: Complete after clean T14R
- log: Migrated the existing AC-014 fixture to deterministic/native/ambient policy and added a separate isolated real-Turbo capability fixture. The public Turbo summaries prove a first native miss, identical local hit with the same task hash, capability/image/optional-support separation, direct uncached fallback for an incomplete profile, ambient and forced execution on every invocation, stable code/input identity, exact inventory, and run-owned cleanup. Parent reran both acceptance suites. Bun's absent-file RED returned zero with
had no matches; this is recorded as absence evidence rather than a nonzero test failure. Scoped autoreview returned no findings but confidence zero; T14R remains the independent review authority. GitHub same-SHA replay was pending at this checkpoint and was later closed for the same-repository development path by run31327081403. - files edited/created:
scripts/behavior-contract/cli-host-capability-cache.test.ts,scripts/behavior-contract/cli-host-capability-cache-fixture.mjs,scripts/behavior-contract/cli-host-capability-cache-fixture.d.mts,scripts/behavior-contract/cli-verification-cache.test.ts,scripts/behavior-contract/cli-verification-cache-fixture.mjs - backlog_item_id: IP-361, IP-362, IP-363
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,tdd,turborepo] - tdd_status: required
- tdd_target: A real Turbo fixture proves that only equivalent host capabilities share native-test success.
- red_command:
bun test ./scripts/behavior-contract/cli-host-capability-cache.test.ts - expected_red_failure: No host-capability acceptance fixture exists and current native tests always bypass cache.
- green_command:
bun test ./scripts/behavior-contract/cli-host-capability-cache.test.ts - reason_not_testable:
- red_evidence: Exact command found no T14 test file and printed Bun's
had no matches; Bun exited zero despite collecting no proof. - tdd_deviation: The intended absence RED was not observed because Bun exits zero when the explicit test file is missing. No pre-fix checkout was retained from which to recover a real failing public assertion. T14 therefore relies on its subsequently implemented production-copy acceptance and is not represented as ordinary RED/GREEN-compliant TDD.
- green_evidence: Parent combined acceptance gate passed 39 tests: T14 16/16 and migrated AC-014 23/23. The real fixture observed a cold miss at 165.59ms and identical local hit at 163.76ms with the same public task hash and
LOCALsource. Inventory reported 390 baseline titles, 391 collected tests, 91 deterministic files, 9 native files, and 1 ambient file. Scoped Oxlint/Oxfmt andgit diff --checkpassed. - codebase_design_notes: The fixture owns synthetic host evidence and cache roots; assertions observe supported wrapper/Turbo summaries rather than private hash internals.
- review_mode: cli
- runtime_validation: required
- runtime_target: Local exact-SHA producer/replay and GitHub same-runner-class producer/replay.
- runtime_evidence: Local isolated real-Turbo proof covers same code/input identity, first miss, identical local hit, stable hash, changed-capability/optional-support/local-CI misses, direct uncached fallback, ambient and forced execution, and cleanup. PR replay
31329286573proves a capability-native remote hit on a fresh runner and an ambient bypass for the corrected PR #113 stack. Because the task declaresHI_HOST_CAPABILITY_DIGESTas a hashed environment input, equal task hashes are the supported equality evidence without recording the private digest, raw host identity, or secrets. Protected-main run31245179530separately proves groupedbuildplusrelease:attestproduction and 2/2 remote restoration at exact SHAc4dcca3134eace76750fa899f3b581411af094d0. Fork isolation, protected rejection of a development artifact, and manual-release execution remain unobserved. - runtime_cleanup: Delete only fixture-owned cache/temp roots; retain workflow run evidence.
T14R: Review and reopen owning tasks
- depends_on: [T14]
- location: readonly review across T9-T14 owned paths
- owned_paths: []
- wave_boundary: W10
- description: Run mandatory findings-first code, architecture, cache-soundness, and simplification review. This task edits nothing. Every accepted finding reopens its original T9-T14 owner and uses that task's exact
owned_paths; rerun the owner's GREEN command and all dependent gates through T14 after each repair. T14R completes only when the refreshed review is clean or every remaining finding is explicitly out of scope with evidence. - validation: Review covers fail-closed identity, executable/path binding, file/title inventory, Turbo hashes, concurrency, forced sentinels, security-test retention, workflow trust, cleanup, and unnecessary complexity. Post-repair T14 evidence is current.
- status: Complete; final targeted review clean
- log: Findings-first review iterated until clean across Standards, Spec, and architecture/cache-soundness lenses. Accepted repairs covered CI default authority, stable executable sampling, cwd-bound identity publication, exact Bun/Node/Git/Tar execution, one protected profile, inside-task pre/post tool validation before Turbo success, explicit absent-
mkfifopropagation, exact protected provenance/install tools, direct incomplete-profile fallback guarded from Turbo, and controlled-root cleanup. Final targeted review found no P0-P2 issues. - files edited/created:
- backlog_item_id: IP-361
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,improve-codebase-architecture,review,simplify,turborepo] - tdd_status: not_applicable
- tdd_target: Readonly review gate; behavioral repairs reuse the owning task's RED/GREEN contract.
- red_command:
- expected_red_failure:
- green_command:
bun test ./scripts/behavior-contract/cli-host-capability-cache.test.ts && node ./apps/cli/scripts/verify-test-title-inventory.mjs --current - reason_not_testable: Readonly review and routing task.
- red_evidence:
- green_evidence: Final dependent T14 passed 19/19 in 105.51s; AC-014 passed 23/23; policy/wrapper/runner passed 22/22; graph/trust passed 22/22 with 462 assertions; title authority passed 390 baseline / 392 protected / 392 collected; CLI typecheck, scoped Oxfmt/Oxlint, and
git diff --checkpassed. Final targeted review was clean. - codebase_design_notes: Review checks that one deep profiler and one policy seam own complexity; findings must not create parallel identity logic.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T15: Converge and document host-dependent caching
- depends_on: [T14R]
- location: durable plan/notes plus root and routed CLI runbooks
- owned_paths: [
apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/PLAN.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md,docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/log.md] - wave_boundary: W11
- description: Execute focused tests, forced native inventory, first-miss/second-hit/changed-capability acceptance, full CLI verification, behavior contracts, typecheck, lint, scoped formatting, and wiki checks after T14R is clean. Document the capability fields, fail-closed behavior, local identity creation/rotation, local/CI authority split, sentinel schedule, diagnostics, exact retained native semantics, and measured cold/warm results. Update implementation notes and this plan with exact evidence and deviations.
- validation: All acceptance evidence from the handoff is recorded; docs match the reviewed task graph; formatting, lint, typecheck, behavior contracts, full local CLI verification, and wiki content checks pass.
- status: Complete for local, same-repository development, and protected-main grouped reuse; fork isolation, cross-namespace rejection, and manual release pending
- log: Convergence completed after a delivery-internal debug loop fixed two test-harness-only nested execution leaks: the standalone incomplete-profile fixture now removes inherited Turbo task context and signed expectations, and the native wrapper copies profiled executables instead of hardlinking them and mutating their
ctime. Production guards were unchanged. Forced native execution passed 12 files / 255 tests with cache bypass in 3m33.765s. The first complete post-repair graph passed in 738.07s: three update tasks restored from the interrupted producer attempt,update:uncachedexecuted, deterministic missed and passed 88 files / 925 tests, native capability missed and passed 12 files / 255 tests, and ambient executed 1 file / 33 tests. The exact repeat passed in 356.98s with build, three update tasks, deterministic, and native capability restored; onlyupdate:uncached, ambient, and the aggregate marker executed. After Oxfmt changed hashed CLI bytes, the final formatted-state deterministic and native tasks passed on misses and restored immediately on repeat under hashesc2801d7fed13af73and388adbd9093566b2. The final formatted-state rootbun run testpassed in 781.35s, and rootbun run checkpassed 12/12 tasks. Operator docs describe the reviewed 88/12/1 policy, 2/1/1 worker caps, capability authority, exact-tool validation, protected provenance, and 390/392/392 title authority. Diff-driven Oxfmt and Oxlint passed over every changed supported file. Historical external replay attempts exposed ephemeral device-key churn and a 15-second fanout timeout, repaired through CI-stable volume-type identity and an explicit 30-second timeout. The current 88/16/1 graph passed authenticated PR replay31329286573: deterministic and native work restored remotely, while ambient and uncached update work bypassed as designed. Protected-main run31245179530passed at exact SHAc4dcca3134eace76750fa899f3b581411af094d0, with grouped producer and consumer completingbuildandrelease:attest2/2. Fork isolation, protected rejection of a development artifact, and manual-release execution remain open. - files edited/created:
apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/PLAN.md,apps/wiki/content/docs/project/specs/cli/cli-release-test-caching/IMPLEMENTATION-NOTES.md,docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/log.md - backlog_item_id: IP-361
- backlog_item_url: https://linear.app/devpunks/issue/IP-361/cli-verification-caching-cache-deterministic-verification-across
- relation_mode: native
- assigned_skills: [
autoreview,codebase-design,docs-onboarding,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,tdd,writing-beats,writing-for-agents,writing-fragments,writing-shape] - tdd_status: not_applicable
- tdd_target: Durable evidence and operator documentation accurately describe reviewed behavior; dependent tasks own behavioral RED/GREEN proof.
- red_command:
- expected_red_failure:
- green_command:
bun test ./scripts/behavior-contract/cli-host-capability-cache.test.ts ./scripts/behavior-contract/cli-release-task-graph.test.ts ./scripts/behavior-contract/cache-trust.test.ts && node ./apps/cli/scripts/run-cli-verification.mjs test && node ./apps/cli/scripts/run-cli-verification.mjs ordinary:native:forced && bun run --cwd apps/cli check-types && bun run check && bunx oxfmt --check $(git diff --name-only --diff-filter=ACMR) && bun run --cwd apps/wiki check:content && git diff --check - reason_not_testable: Review, convergence, documentation, and evidence bookkeeping task; runtime behavior is proven by T9, T13, and T14.
- red_evidence:
- green_evidence: Historical final T14 acceptance passed 19/19; forced native passed 12 files / 255 tests with cache bypass in 3m33.765s; first complete post-repair verification passed in 738.07s; exact repeat passed in 356.98s with five reusable CLI task classes restored and required uncached tasks executed. After Oxfmt changed hashed inputs, final deterministic 88/925 and native 12/255 producer runs passed and their exact repeats restored; final formatted-state root
bun run testpassed in 781.35s; rootbun run checkpassed 12/12. Historical title authority remained 390 baseline / 392 protected / 392 collected. Current T14 passes 22/22 with 31 assertions, current title authority is 427/429/429, PR replay31329286573proves authenticated same-repository producer/replay, and protected-main run31245179530proves grouped 2/2 production and remote restoration. Changed-file Oxfmt/Oxlint andgit diff --checkpassed. - codebase_design_notes: not_applicable
- review_mode: cli
- runtime_validation: required
- runtime_target: Full local CLI verification plus the authenticated GitHub development/protected verification graph.
- runtime_evidence: Historical local evidence is complete for the pre-restack graph. The pre-format convergence graph passed in 738.07s and repeated in 356.98s. After Oxfmt changed hashed inputs, deterministic miss
c2801d7fed13af73passed 88/925 and the identical repeat hit; native capability miss388adbd9093566b2passed 12/255 and the identical repeat hit. Forced-native and ambient remained cache-disabled. Final formatted-state rootbun run testpassed in 781.35s. That historical policy was 88/12/1 files with 390/392/392 title authority. For the current 88/16/1 graph, authenticated PR replay31329286573restored update, typecheck, deterministic, and native work remotely while ambient and uncached update work bypassed. Logs reported remote caching enabled without authentication or permission warnings. Protected-main run31245179530separately passed at exact SHAc4dcca3134eace76750fa899f3b581411af094d0; its grouped producer completedbuildandrelease:attest2/2, and its consumer restored the same 2/2 tasks remotely. Fork isolation, protected rejection of a development artifact, and manual-release execution remain unobserved. - runtime_cleanup: Preserve CI runs and plan evidence; remove only run-owned worktrees, cache fixtures, and temporary probe roots.
Continuation risks and mitigations
| Risk | Mitigation |
|---|---|
| Capability profile omits an observed host fact | Keep ambient cases uncached, force native sentinels, and treat any discovered omission as a cache-identity bug that reopens T9/T13 |
| Required capability evidence is unavailable or a probe errors | Run development native and ambient coverage directly uncached with no reusable result; protected namespaces retain Turbo and fail closed |
| Research inventory is stale at implementation HEAD | Use the checked-in title manifest and live discovery as authority; the historical pre-split baseline was ten files / 390 tests and every rebase must be remeasured |
| Unsupported FIFO caches a skipped pass | Encode explicit missing/present probe state and prove the two states use different task hashes |
| Executable changes after profiling | Execute the exact resolved path and include its content digest/version; do not re-resolve through mutable PATH |
| Local evidence crosses into CI | Hash authority mode and local machine/volume identity; CI rejects local mode before Turbo |
| File splitting loses or duplicates tests | Compare discovered titles and exact policy union before/after; safe-default every new file to ambient uncached |
| Scoped doubles erase security evidence | Move only orchestration/policy cases; maintain an explicit native-semantic inventory and forced sentinel |
| Turbo siblings recreate worker starvation | Serialize deterministic, capability-native, and ambient groups or otherwise cap aggregate Vitest workers at the existing bound |
| GitHub runner image evidence changes | Deliberate miss; never normalize away the image revision to gain hits |
Continuation planning notes
grilling: no new question round was required. The existing spec and the user's acceptance of the research recommendation close the product frontier.parallel-research: reused the fresh immutable report; repeating research was intentionally skipped.codebase-design: capability profiling is one deep pre-Turbo seam; scoped operation and native filesystem adapters remain separate authorities.tdd: T9, T13, and T14 carry public RED/GREEN tracer bullets. Test-only file partition tasks use exact inventory and independent execution instead of fabricated RED evidence.swarm-planner: W6 freezes independent capability and title-inventory seams; W7 launches every disjoint split scope; shared policy/topology has one W8 owner; W10 is an edit-free review/reopen gate.backlog_sync: skipped. This continuation remains within the retained IP-361/IP-362/IP-363 projection and requires no story mutation.unresolved_questions: none. A digest-pinned container or versioned custom runner remains an optional future hardening step, not a blocker.