SpecsCLICli Test Runtime Hardening
CLI Test Runtime Hardening Implementation Notes
CLI Test Runtime Hardening Implementation Notes
Summary
- Delivery started from the accepted
PLAN.mdon branchteam/stefan/research-cli-test-hardening, rebased ontoorigin/mainat53a2166dbefore implementation. - T1 completed 18 green profiling commands with identical inventories. Two workers reduced mean ordinary-suite wall time from 348.641s to 170.452s, and full scaffold operations accounted for 94.45%-96.09% of hot-file wall time.
- T2 test-drove explicit bounded ordinary CI. Local evidence was green, but GitHub exposed subprocess starvation; the workflow and T2-specific contract were reverted to serialized ordinary execution.
- T3 introduced a one-shot scoped scaffold operation that prepares either an existing root session or nearest-existing-ancestor authority before inspection and snapshots caller-owned inputs. A distinct absent root is bound only after inspection succeeds. It reduced the stale-skill candidate from two full bundled projections to one. Recording-adapter tests own orchestration/result assertions; a bounded real filesystem witness still owns stale deletion and containment. The final rich plan freezes compiled desired input/state, explicit reset directories, the static deep-owned result, and an opaque one-shot applier, so the exact plan that passes preflight is applied without source traversal or replanning. Final exact-plan coverage is adapter 11/11, output 12/12, and combined 23/23; the earlier adapter 10/10 remains historical evidence.
- T4 routed staged initialization through the same required service. Planning
now retains concrete adapter-owned
StagePlanState, preserves the selected baseline for stage skills, and separates publicScaffoldCapabilitiesfrom the internal filesystem adapter. Stage owns one rich output plan whoseadditionalSkillSelectionfreezes selected-first or bundled-fallback skill bytes, aliases, and reset roots; planned settings freezes initialization and baseline metadata. A truly virtual stage test owns orchestration and commit/ rollback assertions; the consolidated real rerun retains mirror, planned-symlink, and containment evidence. Current evidence is adapter 13/13, output 12/12, combined 25/25, focused settings/fallback 3/3, symlink witnesses 2/2, and full stage 49/49; historical T3 remains 11/11, 12/12, and 23/23. - T5 local convergence passed the full focused, update, release, tooling, and ordinary matrices. Bounded ordinary execution retained the identical 82-file/1,068-test inventory and reduced wall time from 312.63s to 165.75s. GitHub nevertheless exposed subprocess starvation, so T2 scheduling was reverted while retaining the scoped-operation seam.
- Final post-revert local serial validation passed 82 files and 1,068 tests in 316.19s with the same inventory hash. Three corrected GitHub attempts passed serialized ordinary CLI and all four update jobs; only the explicitly excluded wiki projection kept the overall workflow red.
- Private/internal docs ingest updated
docs/README.md,docs/runbooks/hi-cli-scaffolding.md, and the existing.agents/notes/2026-08-04-scaffold-parent-identity.md. Routed Wiki projection was intentionally skipped by scope. Stack status showed an independent branch with no PR stack;stack sync --dry-runwas unsupported, while the defaultstack syncpreview said thedevstack was current. No apply ran. PR #100 is ready for review and its body was refreshed. - Run
31067183663on head3e81a31cpassedcli-tests, all four update jobs, and API, backoffice, and wiki Vercel checks. Behavior Contract was red only at@punks/wiki#check:content, requesting the excluded projection: create routedcli-test-runtime-hardening/PLAN.mdandIMPLEMENTATION-NOTES.md, updateapps/wiki/content/docs/project/specs/.source-projection.json, and update the routedhi-cli-scaffoldingmirror.
Deviations From the Plan
- The source folder has no sibling
SPEC.md. The user explicitly directed delivery to start at implementation and acceptedPLAN.mdas the delivery contract, so this run does not reopen the specification phase. - T3/T4 candidate ownership was factually inverted in the accepted plan:
run.test.tsowns stale regenerated-skill deletion, whilestage.test.tsowns exact-mirror and planned-symlink reruns. The task descriptions were corrected without changing scope, dependencies, or accepted test contracts.
Surprises and Decisions
origin/mainadvanced after planning. The plan-only branch was rebased before any implementation work began.- A discarded profiler pre-sample placed
TMPDIRinside the worktree and correctly disturbed tests that require a path outside Git. The profiler moved run-owned roots to system temp, removed the invalid sample, and reran cleanly. - T1's attribution gate passed: repeated full scaffold operations, not direct
subprocesses, dominate the selected
runandstageassertions. - Wave 2 review required fresh one-shot plans, inspection-bound stable inputs, and direct typed error propagation before T4. Both adapters and their shared contract now enforce those invariants.
- Wave 3 review rejected a scanner-cause regression, recording-only stage parity, and seeded-once tests mislabeled as idempotency. The scanner diff was removed, stage semantics now share a real/recording contract, and a real two-operation rerun is retained.
- Mandatory closeout review required stable pre-inspection root authority,
caller-input snapshots, concrete stage plan state, selected-baseline
preservation, an internal filesystem adapter separated from public
ScaffoldCapabilities, and a stage orchestration test with no host fixture. Final review then found a deletion/rollback race. The resolved design prepares existing-root or ancestor authority without mutation, creates and binds a distinct absent root only after successful inspection, and leaves failed inspection non-mutating. Mandatory review blockers are resolved. One platform limitation remains parked: Nodemkdirfollowed bylstatcannot atomically prove ownership against an exact intervening replacement without native no-replace publication; the plan does not claim fail-closed for that window. - The first structured autoreview raised a P2 on exact-plan integrity: apply could
still derive output beyond the plan preflight had approved. The correction
moved compiled desired input/state, explicit reset directories, the static
result including a deep-owned baseline summary, and the opaque one-shot
applier into the plan. Tests remove source bytes after planning, exercise a
stale reset directory, mutate the original summary, and attempt replay; apply
uses the frozen plan, performs no source traversal or replanning, preserves
the frozen summary, and rejects replay. Structured autoreview on
d58f638dthen returned P1 because stage replanned and read live stage-skill source, and P2 because scoped settings read a live baseline version. Stage now owns and consumes one rich output plan:additionalSkillSelectioncaptures selected-first or bundled-fallback bytes, aliases, and exact reset roots for preflight; the old post-commit copy is gone. Planned settings carries initialization and baseline metadata, and scoped settings reads thescaffoldOutputbaseline. Both final manual rereviews were clean. The third structured autoreview on head911a73e1was CLEAN with no actionable findings and rated the overall patch correct at0.91. It confirmed retained plans and one-shot lifecycle, root authority, stage-skill snapshotting, settings metadata, rollback boundary, and serialized CI remain consistent. - The stage-skill correction had a public RED: after planning, the selected
skill source was removed. Old apply failed. Exact error:
Could not locate baseline asset. The independent scoped-settings RED expected baseline version3.1.3but received the mutated-after-plan value. The stage metadata regression became GREEN within the first correction and is not misreported as RED. - GitHub attempt 1 passed all four update jobs but failed the bounded ordinary
job with one Vitest timeout and three
spawnSync node ETIMEDOUTfailures. The same run caught a forbidden runtime barrel; the public feature root now owns its service contract and Effect-v4 validation passes 94/94.
Sanity Checks
| Check | Result | Notes |
|---|---|---|
git rebase origin/main | Passed | Branch now starts from 53a2166d |
| T1 serial profiler, three samples | Passed | 28 focused-run tests, 49 focused-stage tests, 80 files/1,062 ordinary tests in every sample |
| T1 two-worker profiler, three samples | Passed | Same inventories; mean ordinary wall time 170.452s |
T1 cleanup and git diff --check | Passed | Disposable scripts, hooks, reports, debug log, and temporary roots removed |
| T2 focused RED | Passed | Failed before workflow edit because --fileParallelism was absent |
| T2 root behavior contract | Passed | 11 tests, 286 assertions |
| T2 bounded ordinary suite | Passed | 80 files, 1,062 tests, 170.40s |
| T3 exact feature/adapter/run suite | Passed | 3 files, 32 tests, 50.03s |
| T3 CLI typecheck/lint/format/diff | Passed | Typed errors and one-shot lifecycle clean |
| Historical adapter contract | Passed | 10/10 in 15.95s; deferred binding, snapshots, stage state, and adapter split covered |
| Historical T3 exact-plan adapter | Passed | 11/11; rich frozen plan and one-shot lifecycle covered |
| Historical T3 output contract | Passed | 12/12; source removal, reset directories, deep-owned summary, and replay covered |
| Historical T3 combined | Passed | 23/23 |
| Current T4 adapter contract | Passed | 13/13 in 21.79s |
| Current T4 output contract | Passed | 12/12 in 9.73s |
| Current T4 adapter/output combined | Passed | 25/25 in 32.29s |
| Current T4 focused settings/fallback | Passed | Settings version and selected/bundled fallback 3/3 |
| Current T4 symlink witnesses | Passed | 2/2 |
| Final confined filesystem | Passed | 28/28 in 2.97s |
| Final run | Passed | 30/30 in 49.40s |
| Historical pre-stage-plan full stage | Passed | 49/49 in three chunks at 28.58s, 55.30s, and 4.51s |
| Current T4 full stage | Passed | 49/49 |
| Final alias and typed contracts | Passed | Alias 3/3 in 356ms; typed failures 2/2 in 477ms |
| Final Effect-v4 surface | Passed | 94/94 in 6.82s |
| Final root behavior contract | Passed | 10/10 with 280 assertions in 4.07s |
| Final CLI/tooling gates | Passed | Build bundled 521 modules; typecheck, check, diff, and audits green |
| Two final manual rereviews | Passed | Both clean after the stage/settings correction |
Structured autoreview d58f638d | Failed review | P1 stage live-source/replanning and P2 live settings baseline version |
Third structured autoreview 911a73e1 | Passed | CLEAN; no actionable findings; overall patch correct 0.91 |
| T5 four independent wrappers | Passed | 23 each; 92/92 unique in union |
| T5 release runner | Passed | Four-worker update phase then two-worker ordinary phase, 429.33s total |
| T5 serial/bounded controls | Passed | Identical 82-file/1,068-test inventory; 312.63s vs 165.75s |
| T5 GitHub bounded ordinary | Failed safely | Four of 1,070 tests failed from subprocess starvation; T2 reverted |
| T5 final local serialized ordinary | Passed | 82 files/1,068 tests, 316.19s; inventory unchanged |
| T5 corrected GitHub serialized samples | Passed | Three 82-file/1,070-test CLI jobs and twelve 23/23 update jobs |
| T5 Effect-v4 public surface | Passed | 94/94; no forwarding-root whitelist |
| T6 evidence/docs closeout | Passed | Canonical docs record retained architecture and current serialized/four-wrapper CI topology |
| Docs ingest | Passed | Root docs and existing scaffold-parent-identity note updated; routed projection skipped |
| Stack inspection | Passed | Independent branch/no PR stack; default preview said dev current; no apply |
| PR #100 | Passed | Ready for review; body refreshed |
Run 31067183663 | External red | In-scope jobs green; only excluded @punks/wiki#check:content projection requests remain |
UI Evidence Links
No UI surface is changed by this plan.
Runtime Validation Evidence
| Task | Scenario and target | Public action | Correlation or provenance | Expected result | Observed result and durable evidence | Cleanup | Status or exact blocker |
|---|---|---|---|---|---|---|---|
| T1 | Local ordinary suite and isolated hot-file runs | Ran three serial and three workers-2 profiler samples with exact update exclusions | SHA 63b9cbf9; inventory hashes recorded in PLAN.md | Identical behavior inventories and causal performance evidence | All 18 commands passed; bounded mean 170.452s versus serial 348.641s; full operations consumed 94.45%-96.09% of focused wall | All run-owned roots and disposable diagnostics removed | Passed |
| T2 | GitHub Actions ordinary and update jobs | Ran bounded ordinary and four exact update jobs on PR #100 | Run 31054456710, attempt 1, head 9fe7cb57 | Every bounded sample green with four independent update jobs | Four update jobs passed 23/23; ordinary failed 4/1,070 from timeout/starvation | Diagnostic logs recorded; external reports removed | T2 scheduling reverted |
| T3 | Local scoped operation and stale-file split | Ran shared adapter, output, virtual caller, and bounded real deletion contracts | Working tree after exact-plan correction | The same rich plan passes preflight and apply with no apply-time traversal/replanning; frozen reset/result state and one-shot use hold | Historical adapter 10/10; final adapter 11/11; output 12/12; combined 23/23; source-removal, stale-reset, summary-mutation, and replay proof green | Temporary filesystem fixtures cleaned by tests | Passed |
| T4 | Local staged operation and commit boundary | Ran stage-owned rich-plan, planned-settings, fallback, symlink, and full-stage contracts | Working tree after stage/settings correction | Stage consumes one preflighted plan; skill selection and settings metadata remain frozen; commit boundary holds | Historical T3 11/12/23; current adapter 13/13 in 21.79s, output 12/12 in 9.73s, combined 25/25 in 32.29s; focused 3/3, symlinks 2/2, stage 49/49 | Temporary filesystem fixtures cleaned by tests | Passed; TDD partial/not-met |
| T5 | Local and GitHub convergence | Ran focused, wrappers, release, tooling, matched controls, diagnostic bounded CI, and three corrected samples | Heads 9fe7cb57 and 4ad8a9b9; merge de14b84e | Identical inventories, preserved release topology, evidence-based scheduling decision | Final local serial 82/1,068 in 316.19s; three GitHub serial jobs 82/1,070; all twelve update jobs 23/23; bounded CI rejected | External reports/logs removed; run-owned roots absent | Passed; T2 scheduling reverted |
Acceptance Criteria Status
| Criterion | Status | Notes |
|---|---|---|
| Reduce repeated full-baseline filesystem work without weakening real filesystem contracts | Passed | T3/T4 split orchestration and retain bounded real OS/security witnesses |
| Prove bounded ordinary CI with threshold-free evidence | Passed | Evidence rejected bounded GitHub scheduling; serialized CI restored |
| Preserve update and release topology | Passed | Four wrappers and release two-phase runtime proof green |
| Keep canonical docs aligned with retained behavior | Passed | Canonical docs now cover the retained scoped-operation architecture, one serialized ordinary CI job, four exact update-wrapper jobs, and local-only test:parallel |
Manual Review Checklist
| Area | Check | How to perform | Expected result |
|---|---|---|---|
| CLI tests | Re-run the final serialized ordinary command | Completed with the exact post-revert workflow command | 82 files/1,068 tests passed in 316.19s without starvation |
Debug Assessment
| Hypothesis | Result | Captured runtime evidence |
|---|---|---|
| A. Two-worker ordinary execution caused subprocess starvation | CONFIRMED | GitHub attempt 1 failed four ordinary tests: one Vitest timeout and three spawnSync node ETIMEDOUT failures. All four update jobs were green. |
| B. Update shards overlapped or repeated work | REJECTED | Four exact wrappers each passed 23/23; their 92-test union was unique. |
| C. Serialized ordinary execution contained a behavior regression | REJECTED | The local serialized 82-file/1,068-test inventory and three GitHub 82-file/1,070-test inventories were green. |
| D. A generic timeout increase alone would fix the incident | REJECTED / narrowed | Timeout increases do not address spawn starvation; the reverted serialized topology passed. |
Root cause was resource contention and subprocess starvation under the bounded two-worker ordinary GitHub experiment. The fix reverted only T2 ordinary scheduling to serialized execution while retaining four exact update jobs. Existing local and GitHub runtime evidence verifies that outcome. No extra instrumentation was added during debug assessment because captured CI logs had already proven the incident before this phase.
Delivery State
- Delivery is complete with no in-scope blocker. Mandatory review blockers are
resolved. The Node
mkdir-to-lstatexact replacement window remains a parked platform limitation and is not claimed fail-closed. T4's TDD contract remains partial/not-met because the mandated target was absent during the purported RED run, while its later GREEN evidence is retained. Both manual rereviews are clean. After the non-cleand58f638dreview was fixed, structured autoreview on911a73e1was CLEAN with no actionable findings and overall patch correctness0.91. Debug assessment is closed; docs ingest and PR #100 preparation are complete. Run31067183663leaves only the explicitly excluded routed Wiki projection as an external blocker. No final branch head is asserted before the parent commit.
Steering
| Date | Feedback | Changes |
|---|---|---|
| 2026-08-05 | Start from implementation in full parallel | Accepted the reviewed plan as the delivery contract and preserved its worker waves |