V4.3 Delivery Flow Implementation Plan
V4.3 delivery flow plan
Authority and execution
Implement IP-447–IP-455 under Stories IP-444–IP-446 in milestone 36fa9ecc-0bbe-46c7-873b-1947a4487838, V4.3 Delivery Flow and Scaffold Reliability. The three linked SPECs remain independent acceptance authorities. Scaffold IP-463–IP-471 retain their separate plan; related cross-epic issues are coordination links, not blockers.
task_identity_mode: provider-task;relation_mode: nativethroughout.- Harness root
H:/home/stefan/repos/harness-intelligence; branchteam/stefan/v4.3-delivery-scaffold, basemain, no stack dependency. - Canonical source
S:/home/stefan/repos/skills; checked-outmain, explicitly authorized on 2026-09-06. Discovery HEAD:584ea4bddd5bcfcf780baf9fb67ff736ba7d0626. - Source paths below are relative to
S;H/paths are relative to Harness. Scoped workers perform implementation. Parent owns shared plan/notes, provider reconciliation, canonical commit/push, exact-receipt synchronization, and docs indexes. Source workers neither commit nor sync while other edits are active. - Source-first activation is one compatible producer/consumer revision. T9 measures frozen candidate working bytes through explicit fixture-only selection before canonical commit, push, pin update or synchronization. Only passed admission or a retained human exception permits those publication steps. Failed/inconclusive candidates remain unpushed and unconsumed by Harness. This plan grants no admission exception and introduces no activation flag.
Planning evidence and decisions
create-plan composed grilling, swarm-planner, tdd, codebase-design, show-me, and wait-what. All wording uses writing-for-agents and its skill-mechanics reference. The three grill-status records confirm closed frontiers and accepted R5/R6 decisions; no product question is reopened. parallel-research was considered: this is already a bounded delegated planning lane and nested delegation is unavailable. Parent supplies independent plan-reviewer review before execution.
Fresh mcp__linear_devpunks__get_issue(includeRelations: true) readback on 2026-09-06 verified all nine Tasks, their parent Stories, V4.3 membership, accepted immutable source links, and native blockers. All were Backlog. Source authority is 57f4fdfa0ae4f6a9a04c74f0f8ffbaffea0489cf; shared coordination is ee6caf90b364a4720890a0d5063b3972291463fe. No provider mutation occurred. Parent routes observed lifecycle facts through write-backlog with exact readback.
Discovery read root/wiki/CLI guidance, all three SPECs and grill-status glossaries, coordination/regression records, and the accepted experiment contract in project/research/delivery-phase-flow-optimization-research-report.md. Live canonical source still uses full-wave barriers in implement-spec/references/parallel-orchestration.md, worker-owned plan updates in parallel-worker-brief.md, and portable verify-behavior without Project Verifier references. Existing review-phase/scripts/review-contract.mjs already owns mechanical identity/report operations: extend that seam only where needed. Existing behavior is evidence to reuse, not proof that these accepted gaps are closed.
This is prompt-level native-harness coordination. No delivery runtime, scheduler, lock service, journal, cache, worker branches, or app drivers in the CLI are planned. opensrc/effect.md and opensrc path Effect-TS/effect resolve v4 source (discovered /home/stefan/.opensrc/repos/github.com/Effect-TS/effect/main). Code uses effect and those patterns with installed-version conventions; existing standalone Node mechanical helpers remain established boundaries. New TypeScript uses typed Effects, Schema at boundaries, and deterministic synchronization. No new framework/API dependency is planned.
Architecture contract
architecture_applicability: architecture-bearing: multiple tasks change cross-skill contracts and Project Verifier ownership. Accepted SPEC topology supplies the target; this is not a backend/frontend domain migration.
Declared dependency graph and public seams
These are consumer/owner contracts, not runtime imports. Parent implement-spec owns Task Gates, scope transfer, acceptance, Verification freshness and shared summaries. Review consumes existing Verification evidence. App mechanics live only under project-owned H/.agents/skills/verify-behavior/references/. Scaffold/update preserves those bytes and reaches one preservation rule in hi-cli post-command guidance. Delivery Handoff and CLI Post-Command Handoff remain distinct.
Forbidden ownership: parent implementation edits; reviewers executing or maintaining the Project Verifier; docs ingest writing Feature Maps; shared CLI importing app drivers; disposable packets replacing durable receipts.
Responsibility criteria and architecture waves
| Criterion | Owner and observable assertion | Evidence | Due wave / tasks |
|---|---|---|---|
| RAC-1 | Planning/parent execution release stable dependency-ready work and reconcile summaries before cumulative gates | Skewed graph, changed-input and parent-only history traces | A1: T1,T2,T3 |
| RAC-2 | Portable Verification selects needed project-owned knowledge and falsifiable scenarios | Selection trace and live proof | A1: T4 |
| RAC-3 | Creator/updater prove coverage inside implementation; isolation, cleanup and preservation hold | Smoke proof, mismatch rerun, retirement reconciliation, CLI filesystem proof | A2: T5,T6 |
| RAC-4 | Review consumes frozen primary/challenger facts and keeps incomplete and repair accounting truthful | Seeded review, helper tests, retained report | A3: T7 |
| RAC-5 | Router/handoff retain fresh compact authority and dependency-local recovery | Mode/failure/legacy traces; unchanged historical bytes | A3: T8 |
| RAC-6 | Frozen candidate passes measured admission before canonical publication and exact-receipt Harness consumption | Source SHA, receipt, combined proof, raw matched runs | A4: T9 |
A1 boundary contracts (RAC-1, RAC-2)
→ A2 Verification lifecycle (RAC-3)
→ A3 review and continuity (RAC-4, RAC-5)
→ A4 source-first compatibility and admission (RAC-6)Each checkpoint compares cumulative actual owners, edges, public seams and all due criteria; it reruns affected proof and checks previously met invariants. Parent reconciles shared summaries before checkpoint finalization. These cumulative checks add no provider blockers: unrelated disjoint preparation continues, while dependent consumption of unproved responsibilities waits. Migration ledger: no runtime temporary seams. Mixed source edits remain unpublished T9 candidate work. Only explicit run-owned fixtures may select those bytes before measured admission; ordinary Harness consumers keep the existing source. No inactive runtime selector is assumed. Final migration ledger must be empty.
Native graph and earliest worker frontiers
| Earliest wave boundary | Tasks | Native prerequisites |
|---|---|---|
| W1 | T1,T2,T3,T4 | None; declared writes are disjoint |
| W2 | T5,T6,T8 | Respectively T4; T4; T2+T3 |
| W3 | T7 | T1+T5+T6 |
| W4 | T9 | T7+T8 |
Recompute after each Task Gate; these are earliest frontiers, not full-wave wait barriers. Dispatch every currently eligible disjoint task allowed by capacity and stable inputs. Capacity one still delegates; capacity zero blocks. Capacity priority: assumption-invalidating work, longest remaining chain, unlock count, then plan order. Record an actual write/read/runtime conflict without inventing a native blocker.
Shared resources are source and Harness working trees, sync receipt, review target, and fixture runtimes. Commits, synchronization and matched benchmark execution are exclusive parent operations. Workers use task-local evidence and run-owned scratch. Capture declared Relevant Input Set identities before and after checks; change invalidates affected proof before dependent release. Overlapping reads alone are permitted. Another active task writing a declared read input requires waiting or rerunning the affected check. Freeze CLI/runtime conditions within each T9 matched comparison; moving scaffold inputs invalidate affected pairs, not all delivery work.
Per-task conventions
Every task has provider identity, native relations and V4.3 membership above; backlog_sync_skip_reason: not_applicable (fresh native readback). Task owned_paths also includes its exclusive S/tests/fixtures/v43/IP-<id>/ subtree. Workers return evidence; parent alone updates PLAN and IMPLEMENTATION-NOTES. Empty evidence fields are pending work, never implicit passes.
Every assigned_skills set includes planning provenance create-plan, grilling, swarm-planner, tdd, codebase-design, show-me, wait-what, writing-for-agents. Every task inherits these two implementation guidance entries exactly once:
writing-for-agents: co-locate contract steps and completion proof; select detail through trigger-specific pointers; preserve one authoritative source and canonical glossary terms.codebase-design: keep behavior behind the task's named public prompt/helper seam, with observable results and explicit owner boundaries.
Executable tasks additionally declare effect and tdd guidance. Planning-only skills remain provenance. Each worker returns exactly one application-evidence record per implementation guidance entry.
Prompt-only tasks use tdd_status: not_applicable: prose contracts are not executable production code. Native-harness scenario traces remain required proof; text tests are supplemental. Adding executable helper behavior changes that task to required before editing, with real public-seam RED/GREEN commands. A test-only delivery simulator cannot replace native execution.
T1: Add early draft-PR visibility and bounded review transition
- depends_on: []
- backlog_item_id: IP-447; backlog_item_url: https://linear.app/devpunks/issue/IP-447; parent_story: IP-446
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/planning/implement-spec/references/lifecycle.md
- owned_paths:
skills/agnostic/planning/implement-spec/references/lifecycle.md,skills/phases/delivery-phase/phases/review.md,tests/v43-draft-review-transition.contract.test.mjs;tests/fixtures/v43/IP-447/ - wave_boundary: W1; architecture_wave: A1
- read_dependencies / Relevant Input Set: Recorded branch/base and provider PR identity; review contract public outcomes; T2 orchestration and T3 reconciliation contracts at validation time. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Reuse one meaningful existing draft PR or create it after the first meaningful pushed in-scope commit. Preserve branch/base/stack and avoid empty visibility commits. Require implementation, task checks, Verification, parent reconciliation, Architecture Checkpoints and final acceptance before Code Review. Preserve one default completed pass, focused ordinary repair, risk-triggered second pass and two-completed-pass ceiling. Interrupted/invalidated attempts are incomplete; during-pass semantic change needs a fresh frozen attempt. Detailed review remains T7.
- acceptance references: Execution AC-015–AC-023, AC-033–AC-036; umbrella AC-033–AC-037.
- validation: Native trace: pre-commit no PR; first meaningful commit creates/reuses exactly one; repeated resume reuses identity; missing acceptance blocks review. Trace ordinary repair, accepted high-risk second pass, incomplete attempt, and refused third completed pass.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-draft-review-transition.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence: H/.devpunks/delivery/v43/IP-447/{contract-test.log,native-verdict.json,native-final-trace.jsonl}; H/.devpunks/delivery/v43/draft-pr-readback.json.
- codebase_design_notes: First meaningful pushed commit → draft PR reuse/create; completed implementation → bounded review handoff. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Native delivery fixture on a run-owned repository plus exact provider readback for authorized real draft visibility.
- runtime_evidence: H/.devpunks/delivery/v43/IP-447/EVIDENCE.md and raw final native trace; actual PR creation and readback in draft-pr-readback.json.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: implement-spec lifecycle / delivery review transition
- integration_surface / public_seam: First meaningful pushed commit → draft PR reuse/create; completed implementation → bounded review handoff
- topology_delta: Separate implementation completion, final acceptance and post-implementation review.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-1]
- status: Complete
- log: Parent gate retained in IMPLEMENTATION-NOTES.md; candidate unpublished. Evidence:
.devpunks/delivery/v43/IP-447/. - files edited/created:
T2: Release work through Task Gates and Active Write Scopes
- depends_on: []
- backlog_item_id: IP-448; backlog_item_url: https://linear.app/devpunks/issue/IP-448; parent_story: IP-446
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/planning/implement-spec/SKILL.md
- owned_paths:
skills/agnostic/planning/implement-spec/SKILL.md,skills/agnostic/planning/implement-spec/references/parallel.md,skills/agnostic/planning/implement-spec/references/parallel-orchestration.md,skills/agnostic/planning/implement-spec/references/architecture-conformance.md,skills/agnostic/planning/create-plan/references/planner-task-graph.md,skills/agnostic/planning/create-plan/references/plan-schema.md,skills/agnostic/planning/swarm-planner/SKILL.md,skills/agnostic/subagents/swarm-planner/SKILL.md,tests/v43-task-frontier.contract.test.mjs,tests/architecture-conformance.contract.test.mjs,tests/wayfinder-lifecycle.contract.test.mjs(sole whole-file writer; receives IP-454 semantic assertions);tests/fixtures/v43/IP-448/ - wave_boundary: W1; architecture_wave: A1
- read_dependencies / Relevant Input Set: Provider blocker graph; accepted scopes/read dependencies/runtime resources; T1 lifecycle and T3 worker brief interfaces at validation time. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Record active writes, declared reads, shared runtime resources and evidence-stability inputs in planning. Parent releases all eligible tasks after each passing gate, protects reserved scopes through failure and cleanup transfer, confines failures to dependent chains, and retains priority/capacity behavior. Every implementation edit stays delegated. A missing/malformed Task Result blocks. Gate input changes invalidate affected evidence and require affected checks before dependent release/finalization. Update architecture-conformance whole-wave wording to block only work that consumes an unproved cumulative responsibility. Preserve cumulative RAC checks, shared-summary reconciliation, migration-ledger closure and zero-drift gates. Keep both currently installed swarm-planner source locations consistent with the canonical planning primitive; introduce no execution service.
- acceptance references: Execution AC-001–AC-006, AC-026–AC-028; umbrella AC-014–AC-016, AC-018–AC-024, AC-050.
- validation: Native skewed graph proves fast child starts before unrelated delayed task ends. Exercise failed prerequisite plus independent progress, capacity one/zero, exact scope transfer, read/write conflict, runtime conflict, and changed-input invalidation. Include an architecture-bearing skewed fixture: safe independent work releases after its own Task Gate while work consuming an unproved checkpoint responsibility stays blocked; final checkpoint requires reconciled summaries, cumulative RAC proof, empty expired migration seams and zero drift. Preserve parent Task Gate and dispatch timestamps/handles.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-task-frontier.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence: H/.devpunks/delivery/v43/IP-448/{contract-tests.tap,parent-gates.jsonl,negative-result.md,compatibility-refresh-result.md,cleanup.json}.
- codebase_design_notes: Task Result ready_for_gate|blocked → parent Task Gate passed|repair_required|blocked → Execution Frontier. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Native scoped agents operating on run-owned fixture paths; controlled Deferred/barrier-style injected events rather than arbitrary waits.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: swarm-planner planning primitive / parent implement-spec Task Gates
- integration_surface / public_seam: Task Result ready_for_gate|blocked → parent Task Gate passed|repair_required|blocked → Execution Frontier
- topology_delta: Replace whole-wave release with dependency-granular parent gates and stable Relevant Input Sets.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-1]
- status: Complete
- log: Parent gate retained in IMPLEMENTATION-NOTES.md; RAC-1 cumulative proof passed. Evidence:
.devpunks/delivery/v43/IP-448/. - files edited/created:
T3: Compact task context and reconcile shared records asynchronously
- depends_on: []
- backlog_item_id: IP-449; backlog_item_url: https://linear.app/devpunks/issue/IP-449; parent_story: IP-446
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/planning/implement-spec/references/parallel-worker-brief.md
- owned_paths:
skills/agnostic/planning/implement-spec/references/parallel-worker-brief.md,skills/agnostic/planning/implement-spec/assets/IMPLEMENTATION-NOTES-TEMPLATE.md,skills/agnostic/planning/create-plan/SKILL.md,tests/v43-context-reconciliation.contract.test.mjs;tests/fixtures/v43/IP-449/ - wave_boundary: W1; architecture_wave: A1
- read_dependencies / Relevant Input Set: Accepted Context Pointer/Derived Context Excerpt contracts; T2 plan-schema public fields; architecture checkpoint contract. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Retain identity/dependencies/owned paths/outcome/acceptance pointers/validation/risk gates/status/provider identity inline. Permit bounded derived rationale only with resolvable source identity, freshness and subordinate status. Task Gate release and asynchronous summary reconciliation are distinct; reconcile before Architecture Checkpoints and final acceptance. Preserve TDD/runtime/UI/provider/Verification/architecture gates and exact one-to-one skill evidence.
- acceptance references: Execution AC-007–AC-014, AC-024–AC-025, AC-029–AC-030; umbrella AC-004–AC-005, AC-017–AC-018, AC-043.
- validation: Native worker brief reads only selected pointers; valid attributed excerpt works, stale/unsourced/full-copy material fails closed. Independent dependent dispatch occurs before mechanical shared-summary completion, while cumulative gate waits. File histories prove parent-only mutation.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-context-reconciliation.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence: H/.devpunks/delivery/v43/IP-449/{EVIDENCE.md,TASK-RESULT.json,dispatch-assertions.json,cleanup.json}.
- codebase_design_notes: Compact task kernel and source-attributed Context Pointers → parent-owned shared summary. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Native worker-context and reconciliation fixture with source identities and observable parent/worker write provenance.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: create-plan compact task context / parent implement-spec reconciliation
- integration_surface / public_seam: Compact task kernel and source-attributed Context Pointers → parent-owned shared summary
- topology_delta: Remove full copied authority from briefs and worker ownership of shared summaries.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-1]
- status: Complete
- log: Parent gate and A1 closure retained in IMPLEMENTATION-NOTES.md. Evidence:
.devpunks/delivery/v43/IP-449/. - files edited/created:
T4: Build progressively disclosed Project Verifier references
- depends_on: []
- backlog_item_id: IP-450; backlog_item_url: https://linear.app/devpunks/issue/IP-450; parent_story: IP-444
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/planning/verify-behavior/SKILL.md
- owned_paths:
skills/agnostic/planning/verify-behavior/SKILL.md,tests/v43-project-verifier.contract.test.mjs;tests/fixtures/v43/IP-450/ - wave_boundary: W1; architecture_wave: A1
- read_dependencies / Relevant Input Set: Project Verification SPEC topology; existing portable verify-behavior protocol; selected app evidence. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Define project index, Surface Verification Reference with Launch/Doctor/Drive/Evidence/Cleanup, Feature Map, optional helpers and Cross-App Journey. Keep shared templates/contracts in portable procedure; generated app mechanics only in project-owned references. Index and journey compose pointers without copying app instructions. Each scenario states positive proof and observable falsifier; important behavior includes a relevant negative/failure condition and actual downstream result. Missing knowledge returns coverage gaps, not improvised verified proof. T6 writes project references through lifecycle skills.
- acceptance references: Verifier AC-001–AC-003, AC-010–AC-014, AC-033, AC-036–AC-037; umbrella AC-003, AC-040, AC-051.
- validation: Native selection fixture with multiple app references loads only selected app/feature/helper; cross-app journey composes without duplication. Retain positive result/falsifier and important failure downstream proof; missing path returns Uncovered Behavior.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-project-verifier.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence: H/.devpunks/delivery/v43/IP-450/IMPLEMENTATION-EVIDENCE.md, contract-tests.tap, recovery/audit.json and ordered-events.jsonl.
- codebase_design_notes: Selected scenario → index/app/feature/journey/helper pointers → falsifiable observed result. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Live CLI scenario and cross-app fixture only where accepted scenario needs multiple independently runnable surfaces; no app-specific shared drivers.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: verify-behavior portable entrypoint / project-owned references
- integration_surface / public_seam: Selected scenario → index/app/feature/journey/helper pointers → falsifiable observed result
- topology_delta: Establish one portable protocol that consumes progressively disclosed project mechanics.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-2]
- status: Complete
- log: Parent gate and RAC-2 passed after focused recovery/privacy repair. Evidence:
.devpunks/delivery/v43/IP-450/. - files edited/created:
T5: Protect verification isolation, evidence, and ownership boundaries
- depends_on: [T4]
- backlog_item_id: IP-451; backlog_item_url: https://linear.app/devpunks/issue/IP-451; parent_story: IP-444
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/cli/hi-cli/references/post-command-flow.md
- owned_paths:
skills/agnostic/cli/hi-cli/references/post-command-flow.md,skills/phases/docs-ingest-phase/references/wiki-ingest.md,skills/phases/docs-ingest-phase/SKILL.md,tests/v43-verifier-ownership.contract.test.mjs,H/apps/cli/src/scaffold/project-verifier-preservation.test.ts,H/apps/cli/src/content/scaffold-copy.ts;tests/fixtures/v43/IP-451/ - wave_boundary: W2; architecture_wave: A2
- read_dependencies / Relevant Input Set: T4 portable verifier protocol; scaffold IP-463 obligation and IP-467 preservation public seams; current scaffold/update outputs and post-command action rendering. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Execution seam clarification:
renderAgentHandoffMarkdownemits the current-run preserve action pointing to the authoritative hi-cli rule; no duplicate policy or verifier lifecycle invocation. This renderer reservation is exclusive to T5 and preserves the accepted ownership topology. Retain run-owned instances/scratch, Doctor before Drive and renewed readiness after surprising failure, exact secret-safe prerequisites, provenance-bound Cleanup and evidence survival. Check T4 isolation wording and return amendments to its owner if missing. Add the authoritative hi-cli preservation rule and docs-ingest read-only Feature Map boundary. Prove real scaffold/update/post-command generation/application leaves existing verifier files byte-for-byte unchanged and never invokes lifecycle skills. Production artifact obligations remain scaffold ownership; coordinate any failing CLI case with that owner rather than editing its files. - acceptance references: Verifier AC-015, AC-022–AC-030; umbrella AC-003, AC-037. Combined IP-463/IP-467 preservation seam.
- validation: Public CLI/filesystem fixture compares nested reference, Feature Map, helper and journey bytes before/after scaffold, update, no-op and generated handoff. Live proof exercises Doctor failure, unexpected Drive, inaccessible prerequisite, cleanup confinement, retained evidence. Review/docs trace shows no verifier execution or maintenance.
- assigned_skills: inherited planning provenance, effect.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries;
effect: inspect matching opensrc APIs and use typed Effect/Schema boundaries with deterministic tests and established standalone helper conventions;tdd: actual public-result RED before behavior-changing code, then GREEN, one vertical behavior at a time. - tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-verifier-ownership.contract.test.mjs; in H: bun run --cwd apps/cli test -- src/scaffold/project-verifier-preservation.test.ts
- reason_not_testable: Prompt/document contract task with public CLI preservation test addition; production repair belongs to scaffold owner; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence:
- codebase_design_notes: Scaffold/update/post-command outputs → unchanged project-owned verifier bytes; Doctor → Drive → bounded Cleanup. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Real CLI in run-owned temporary consumer fixtures; production repair, if required, remains owning scaffold task.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: Verification preservation boundary / hi-cli authoritative post-command rule
- integration_surface / public_seam: Scaffold/update/post-command outputs → unchanged project-owned verifier bytes; Doctor → Drive → bounded Cleanup
- topology_delta: Make one preservation rule authoritative and keep docs/review outside verifier lifecycle.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-3]
- status: Complete
- log: Final native ownership/local-pointer proof and public CLI3/3; RAC3 cumulative passed. See
.devpunks/delivery/v43/IP-451/and IMPLEMENTATION-NOTES.md. - files edited/created:
T6: Recover Uncovered Surfaces and Behaviors inside implement-spec
- depends_on: [T4]
- backlog_item_id: IP-452; backlog_item_url: https://linear.app/devpunks/issue/IP-452; parent_story: IP-444
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/agnostic/planning/create-verification-skill/
- owned_paths:
skills/agnostic/planning/create-verification-skill/,skills/agnostic/planning/update-verification-skill/,skills/agnostic/planning/implement-spec/references/runtime-product-validation.md,tests/v43-verifier-lifecycle.contract.test.mjs,H/.agents/skills/verify-behavior/references/;tests/fixtures/v43/IP-452/ - wave_boundary: W2; architecture_wave: A2
- read_dependencies / Relevant Input Set: T4 portable protocol; upstream pstack creator/maintainer; selected current code and routed wiki; original acceptance/scenario identities. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Adapt https://github.com/cursor/plugins/blob/main/pstack/skills/create-verification-skill/SKILL.md and maintain-verification-skill/SKILL.md, retaining interview/live proof/cleanup/source reconciliation and recording exact upstream revision. Creator and updater descriptions carry distinct model-invoked triggers. New references have no placeholders and complete Launch/Doctor/Drive/Evidence/Cleanup smoke proof. Add only selected missing behavior, preserve unrelated content, route actual product regression to debugging. Reuse proof only when original authority/code/runtime/scenario match; otherwise run missing proof. Retire obsolete entries only with current source evidence and reconciled references. Full audit is explicit, never docs ingestion. Project app references are authored locally through these skills; do not put project mechanics in reusable source.
- acceptance references: Verifier AC-004–AC-009, AC-016–AC-021, AC-031–AC-032, AC-034–AC-035, AC-038–AC-039.
- validation: Native creator performs one live CLI Reference Smoke Proof with evidence surviving cleanup. Exercise ready/blocked creator, each updater result, targeted preservation, source-backed retirement, matching proof reuse and mismatch rerun. Original affected acceptance remains blocked until required proof exists.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-verifier-lifecycle.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence:
- codebase_design_notes: Uncovered Surface → Reference Smoke Proof; Uncovered Behavior → unchanged|updated|blocked|product-failure. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Harness CLI app reference in project-owned directory; missing-surface/behavior fixtures are run-owned and preserve unrelated maps.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: implement-spec coverage recovery / model-invoked creator and updater
- integration_surface / public_seam: Uncovered Surface → Reference Smoke Proof; Uncovered Behavior → unchanged|updated|blocked|product-failure
- topology_delta: Create/repair project-owned executable knowledge only on demand inside implementation.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-3]
- status: Complete
- log: Ten native cases plus focused final-source recovery; RAC3 cumulative passed. See
.devpunks/delivery/v43/IP-452/and IMPLEMENTATION-NOTES.md. - files edited/created:
T7: Run one frozen review epoch with focused repair validation
- depends_on: [T1, T5, T6]
- backlog_item_id: IP-453; backlog_item_url: https://linear.app/devpunks/issue/IP-453; parent_story: IP-445
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/phases/review-phase/
- owned_paths:
skills/phases/review-phase/,skills/agnostic/quality/autoreview/,tests/review-phase-graph.contract.test.mjs,tests/v43-frozen-review.contract.test.mjs;tests/fixtures/v43/IP-453/ - wave_boundary: W3; architecture_wave: A3
- read_dependencies / Relevant Input Set: T1 review transition; T5/T6 Verification boundary and retained proof; frozen Git bounds/target/source set/lineage; existing review helper public functions. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Primary covers Standards (including security), skill adherence, architecture, simplify and Spec; challenger receives same prepared facts without primary conclusions. Capacity one executes sequential independent roles. Outcomes clean/findings require completed assigned coverage; incomplete may carry candidates and never completes pass. Parent deduplicates, verifies every distinct claim, assigns stable IDs/severity/routes, preserves provenance and owns report without a default extra discovery pass. Semantic changes during review invalidate snapshot; retention-only retry reuses matching complete local report. Preserve valid legacy five-lens report identities/ordinals. Ordinary accepted after-pass repair gets focused validation and affected Verification only; accepted high-risk change permits second completed pass, never third without human direction. Reuse prepared target and existing mechanical helpers, preserving matching complete evidence.
- acceptance references: Umbrella AC-028–AC-037, AC-047, AC-052–AC-054; Execution AC-033–AC-036; Verifier AC-028.
- validation: First public-helper RED: incomplete challenger must prevent validateRetainedPass/completed-pass accounting despite clean primary. Native seeded cross-file review proves all five obligations, mandatory challenger independence, incomplete candidates, parent dedup and route/severity, semantic invalidation, retention retry, ordinary repair and risk second pass. Tests cannot stand in for actual reviewers.
- assigned_skills: inherited planning provenance, effect.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries;
effect: inspect matching opensrc APIs and use typed Effect/Schema boundaries with deterministic tests and established standalone helper conventions;tdd: actual public-result RED before behavior-changing code, then GREEN, one vertical behavior at a time. - tdd_status: required
- tdd_target: Incomplete primary/challenger coverage cannot count as a completed clean pass through the existing public review helper.
- red_command:
node --test tests/review-phase-graph.contract.test.mjs tests/v43-frozen-review.contract.test.mjs - expected_red_failure: New public-result assertion shows incomplete challenger incorrectly admitted or completed-pass allowance miscounted. Capture the actual failure; refine the first regression to an observed current gap if this assertion already passes.
- green_command: node --test tests/review-phase-graph.contract.test.mjs tests/v43-frozen-review.contract.test.mjs
- reason_not_testable:
- red_evidence:
- green_evidence:
- codebase_design_notes: One frozen Review Packet → primary + independent challenger Lens Results → adjudicated retained report. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Native primary/challenger on frozen seeded bundles with retained packet hashes, lens results and report bytes.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: review-phase prepared facts / autoreview primary / parent retained report
- integration_surface / public_seam: One frozen Review Packet → primary + independent challenger Lens Results → adjudicated retained report
- topology_delta: Replace redundant review passes with complete five-obligation primary and mandatory independent risk challenge.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-4]
- status: Complete
- log: Parent verified 26 source hashes, 40 public tests and retained native review proof; RAC4 task seam passed, cumulative A3 awaits integration repair. See
.devpunks/delivery/v43/IP-453/and IMPLEMENTATION-NOTES.md. - files edited/created:
T8: Carry compact continuity through routing, failure, and handoff
- depends_on: [T2, T3]
- backlog_item_id: IP-454; backlog_item_url: https://linear.app/devpunks/issue/IP-454; parent_story: IP-445
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: skills/phases/delivery-phase/ (excluding phases/review.md, owned by T1)
- owned_paths:
skills/phases/delivery-phase/ (excluding phases/review.md, owned by T1),skills/agnostic/generic/handoff/,tests/v43-delivery-continuity.contract.test.mjs,tests/agent-workflow-contract.test.mjs,tests/handback.contract.test.mjs;tests/fixtures/v43/IP-454/ - wave_boundary: W2; architecture_wave: A3
- read_dependencies / Relevant Input Set: T2 Task Gate/frontier and T3 pointer/reconciliation contracts; current phase artifacts, bounds/Git identity; T7 result seam when validating review integration. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Implement packet/pointer/Phase Result/Task Result/Gate/handoff producer-consumer continuity. Select always-loaded facts/boundaries, current workflow contracts, and triggered optional skills with identities/freshness. Warm only under matching goal/bounds/next-action/Git/evidence; trust change cold-routes. Resolve missing/stale/malformed/ambiguous pointer through one bounded named-authority refresh, otherwise exact blocked proof. Narrow phase/HITL/review/resume/closeout stop as requested. Dependency-local failure reserves scope until proved transfer. New actionable evidence permits repair; useful discriminating diagnosis may continue; stagnant repair or scope/gate/access/human decision routes handback. Handoff contains compact durable pointers, explicit unknowns, no persisted packet. Read-time legacy normalization preserves bytes/report identities and blocks unreconstructable authority. Distinguish scaffold Post-Command Handoff.
- acceptance references: Umbrella AC-004–AC-027, AC-041–AC-043, AC-049–AC-050; Execution AC-031–AC-032.
- validation: Native mode matrix and failure-resume fixture: same-task warm; handoff/bounds/Git/source changes cold; every pointer failure; exactly one refresh; no duplicate proven mutation; independent progress; diagnosis evidence vs stagnant repair; all common Phase Result outcomes; legacy bytes unchanged.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-delivery-continuity.contract.test.mjs
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence:
- codebase_design_notes: Delivery Context Packet and Phase Result → warm continuation or cold reconstruction. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Native delivery-mode and frozen failed-task recovery fixtures with mutation identity/readback and source freshness.
- runtime_evidence: Pending; retain task scenario, authority/code/runtime identities, actual action/result/falsifier, side effects, evidence pointer and cleanup outcome.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: delivery-phase router / compact durable handoff
- integration_surface / public_seam: Delivery Context Packet and Phase Result → warm continuation or cold reconstruction
- topology_delta: Normalize valid legacy authority at read time and bound recovery without durable disposable state.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-5]
- status: Complete
- log: Final-source native proof,23 stable inputs and150-file cleanup; RAC5 passed. See
.devpunks/delivery/v43/IP-454/and IMPLEMENTATION-NOTES.md. - files edited/created:
T9: Prove source-first compatibility and measured default admission
- depends_on: [T7, T8]
- backlog_item_id: IP-455; backlog_item_url: https://linear.app/devpunks/issue/IP-455; parent_story: IP-445
- task_identity_mode: provider-task; relation_mode: native; backlog_sync_skip_reason: not_applicable (fresh native readback)
- location: tests/v43-source-admission.contract.test.mjs
- owned_paths:
tests/v43-source-admission.contract.test.mjs,tests/fixtures/v43/admission/,H/apps/cli/scripts/sync-skills-repo.mjs (source pin only),H/apps/wiki/content/docs/project/specs/cli/delivery-phase-flow-optimization/ADMISSION-EVIDENCE.md;tests/fixtures/v43/IP-455/ - wave_boundary: W4; architecture_wave: A4
- read_dependencies / Relevant Input Set: Every T1–T8 producer/consumer; exact canonical source tree; sync pin/receipt; scaffold explicit authoring/activation contracts; frozen CLI/runtime/tool/model/fixture identities. Include governing SPEC selectors and current owned-source identities; freeze them across each validation.
- shared_runtime_resources: task-local scratch/evidence; shared source/Harness tree and review/sync identity as applicable, subject to plan stability rules.
- description: Audit all cross-skill producers and consumers, including leaf traces, legacy normalization, R5/R6 excerpts/instruction selection/read conflicts/verifier proof/review changes. Return specific amendments to previous task owners before source publication. Stage 1 freezes the complete candidate working-byte content hash and selects it only in explicit run-owned comparison fixtures; execute measured admission before canonical commit/push or Harness pin/sync. Stage 2 is eligible only after passed admission or a retained human exception: parent commits/pushes canonical main, reads back the SHA, delegates the pin update, then syncs Harness and verifies exact receipt/tree correspondence to the measured content hash. Failed/inconclusive admission leaves the candidate unpushed/unconsumed. Semantic source changes rerun affected pairs before publication. Classify skill-body vs explicit contract/scope changes with scaffold IP-468/IP-469; ordinary Markdown changes do not imply broad reauthoring. Execute the unchanged five accepted experiments with complete real metrics, matched pair count and assurance parity. Failed/inconclusive leaves optimized defaults inactive. Retain atomic proof and exhaustive AC matrix; no static snapshot or simulated scheduler performance claim.
- acceptance references: Umbrella AC-001–AC-003, AC-038–AC-054; all Verifier AC-001–AC-039 and Execution AC-001–AC-036 traceable through owning task evidence.
- validation: Exact source HEAD/pushed main/pin/receipt/distributed source comparison; producer/consumer compatibility; legacy byte identity; combined scaffold preservation/no-op/recovery. Actual three-pair matched experiments, extend disagreement to five then inconclusive; complete metrics and seeded defect assurance. Admission procedure below is mandatory.
- assigned_skills: inherited planning provenance.
- implementation_skill_guidance: inherited writing-for-agents and codebase-design entries.
- tdd_status: not_applicable
- tdd_target: Native prompt-contract behavior described in validation; no production runtime edit assigned.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command: node --test tests/v43-source-admission.contract.test.mjs; in H: bun run --cwd apps/cli test -- src/scripts/sync-skills-repo.test.ts
- reason_not_testable: Prompt/document contract task; required native scenario validation above supplies behavior proof.
- red_evidence:
- green_evidence:
- codebase_design_notes: Frozen candidate working-byte hash → fixture-only measured admission → eligible canonical main SHA → exact Harness receipt/tree closure. Keep this public seam observable; no parallel test-only execution engine.
- review_mode: cli
- runtime_validation: required
- runtime_target: Real native Codex controlled runs, canonical git readback, exact Harness sync receipt and frozen combined CLI fixtures.
- runtime_evidence: Terminal inconclusive benchmark retained; canonical publication and override-free synchronization completed; post-sync execution04 passed its expected public-command and focused validation contracts.
- runtime_cleanup: Remove only task run-owned scratch/process handles after retaining proof outside cleanup targets; preserve user/provider resources and project references.
- behavior_owner: Canonical-source compatibility / parent synchronization / measured admission
- integration_surface / public_seam: Frozen candidate working-byte hash → fixture-only measured admission → eligible canonical main SHA → exact Harness receipt/tree closure
- topology_delta: Publish only after passing measured admission or retained human exception, then verify the exact receipt and the published tree against the measured candidate bytes.
- forbidden_ownership: Plan-wide forbidden edges; no writes outside assigned paths.
- temporary_seams: none; candidate source remains unactivated until T9 compatible publication.
- responsibility_acceptance_criteria: [RAC-6]
- status: Complete; AC-044–AC-047 remain
excepted_not_passedunder the retained human exception. - log: The benchmark ended inconclusive. Canonical skills
mainwas published ate9286c375963a5af33a730d79c4fff04a76e469a; override-free receipt/tree equality and post-sync execution04 passed. No merge or release occurred. - files edited/created:
Integration regression repair reservations
Independent integration triage found nine introduced failures within the accepted delivery contracts. Preserve the existing native graph and criteria while repairing these failures through their current owners:
| Owner | Source/test responsibility | Write reservation |
|---|---|---|
| T8 / IP-454 | Restore actual bounded routing behavior, repair agent-workflow and handback assertions, and supply the semantic assertions for wayfinder cases at discovery lines 244, 325 and 337 | Existing T8 source scope plus tests/agent-workflow-contract.test.mjs and tests/handback.contract.test.mjs; no wayfinder file writes |
| T2 / IP-448 | Repair architecture-conformance assertions for affected-work eligibility rather than obsolete global-wave waits; repair wayfinder cases at discovery lines 295 and 348 while preserving IP-449's disclosed required fields | tests/architecture-conformance.contract.test.mjs and sole whole-file ownership of tests/wayfinder-lifecycle.contract.test.mjs |
Line numbers identify the triaged cases at discovery; resolve their test names against the current file before editing. T8 sends its routing assertions and observed source behavior to T2, who alone applies all wayfinder test changes. Treat that handoff as a shared-file reservation, not a new native blocker. T2 confirms IP-449's required task/skill/evidence fields remain reachable through their disclosed authoritative references; a changed location is not permission to remove an obligation. T8 restores the routing semantics before updating expectations. Neither owner weakens assertions to make an unchanged failure pass.
Retain actual failing integration output, then run the focused canonical-source commands after the corresponding source/test repairs:
- T8:
node --test tests/agent-workflow-contract.test.mjs tests/handback.contract.test.mjs. - T2:
node --test tests/architecture-conformance.contract.test.mjs tests/wayfinder-lifecycle.contract.test.mjs.
The shared wayfinder GREEN must include both owners' semantic cases. Parent compares relevant source identities before accepting the combined results and reruns affected checks after further source changes. Seven unchanged research failures remain evidence-backed prior debt; this reservation adds no research source or test scope. Report those separately from the nine introduced failures and retain the baseline comparison rather than presenting the full suite as green while they remain.
T9 controlled admission procedure
The accepted five experiment families remain unchanged. Run small and medium Full Delivery; skewed dependency release; copied versus pointer-based worker context; frozen review bundles (small, medium, large sparse, large connected, with seeded defects); and failure/handoff recovery. Include the accepted Project Verifier covered/uncovered/blocked paths within the relevant delivery/recovery fixtures. R5/R6 adds contract coverage to these fixtures, not new experiments or admission gates.
Planning verified codex-cli 0.153.4 at /home/stefan/.local/bin/codex. codex exec --help supports --json, --model, -c model_reasoning_effort=..., --cd and --output-last-message. Local session event_msg/token_count records expose input_tokens, cached_input_tokens, output_tokens, and reasoning_output_tokens. Therefore actual native runs have an available execution and usage source; complete per-fixture collection still needs proof. Do not infer complete observability from CLI availability.
- Freeze accepted fixture goals, seeded defects, baseline source SHA, candidate working-byte content hash, fixture Git tree, model, reasoning, native configuration/tool inventory, CLI/runtime dependencies and injected delays. Record identities in the task's admission fixture manifest. Baseline uses pre-change prompt contracts. Candidate fixtures explicitly select an immutable copy of the complete candidate working bytes and record its content manifest/hash; they do not read a newly published canonical commit or a synchronized Harness installation. Before admission, leave canonical candidate edits uncommitted/unpushed and the Harness source pin and synchronized assets unchanged. This is fixture-only selection, not a new runtime flag or executor. Use independent run-owned fixture repositories, not implementation-worker worktrees or changes to canonical source.
- Prove telemetry collection on the first actual comparison run before spending the remaining pairs. Execute the native CLI with an argument vector equivalent to
codex exec --json --model <frozen-model> -c model_reasoning_effort=<frozen-setting> --cd <fixture-root> --output-last-message <evidence>/result.md -, with exact fixture instructions on stdin and stdout/stderr retained separately. Use the existing authorized harness configuration; preserve the same tool/capacity settings within each pair. Neither prompt variant gets extra source authority, helper capabilities, accepted scope, or changed assurance gates. Only fixture-owned repository mutations are allowed. - Correlate emitted thread/session identities to native rollout records. Record total input, cached input, derived noncached input, output and reasoning tokens for root and every descendant; count each record once and retain raw source pointers. Count resumptions, compactions, shell/provider/wait/spawn/follow-up operations, and actual loaded bytes from retained events and file-load evidence. Record root first-to-last active elapsed time separately from waits and child elapsed time. Missing attribution, missing required token categories, or missing loaded-byte evidence remains unknown, never zero. Redact sensitive payloads while retaining the metric provenance and identities.
- Execute three matched baseline/candidate pairs for every fixture, keeping the frozen inputs and injected events equal within each pair. If the fixture's evidence disagrees, extend to five pairs, then classify remaining disagreement as
inconclusive. Avoid pretending synthetic test timing is native delivery timing. A model/tool/runtime/source mismatch invalidates affected pairs and requires replacement matched runs. - Record assurance outcomes alongside cost/time: every applicable task/architecture/runtime/UI/provider/Verification/final-acceptance/report gate; no overlapping writes; independent progress; no duplicate proven mutation; pointer freshness; the fixture source content hash (published receipt is proved in Stage 2); proof reuse eligibility; relevant failure downstream result; obsolete-entry reconciliation; all review coverage outcomes. Seeded review parity requires no missed critical/high defect, equal-or-better per-axis recall, severity/route correctness, complete lenses, unchanged target freshness and valid retained-report evidence.
- Derive assurance-constrained Pareto admission from the retained matched measurements. Faster or cheaper execution cannot compensate for assurance regression. Return
passed,failed, orinconclusive, retaining raw runs, pair identities, metric derivations, uncertainty and the default activation state inADMISSION-EVIDENCE.md.failedorinconclusiveleaves candidate changes unpushed and unconsumed by Harness and retains the evidence; only an explicit retained human exception can accept the measured tradeoff and authorize Stage 2. Passing admission permits Stage 2 but does not replace its source/readback/receipt gates. This task remains incomplete when its accepted admission outcome is unproved.
No universal percentage, token, worker, delay or retry threshold is introduced. If the native harness cannot expose a required metric or execution capability, record that exact missing observation, finish independent compatible-source work, and hand the admission boundary to the parent. Do not silently remove the metric, weaken admission, or claim the full iteration complete.
Source-first and combined-version proof
T9 has two ordered stages. Stage 1: candidate proof follows T1–T8 gates and source integration review. Freeze a path/content manifest and hash of the complete candidate working bytes, select that immutable content only in run-owned fixtures, and complete the actual matched-run admission procedure above. Keep canonical candidate changes uncommitted/unpushed and Harness source pin/assets unchanged until admission passes or an explicit retained human exception is present. Failed/inconclusive results retain evidence and leave Stage 2 blocked.
Stage 2: eligible source publication and consumption starts only with that admission evidence or retained exception. Rehash the candidate and require equality with the measured manifest; semantic changes require rerunning affected pairs first. Parent confirms canonical main, commits with conventional syntax, pushes, and reads back the exact SHA. Verify the published source tree matches the measured candidate path/content manifest. A scoped worker then updates the existing source pin in H/apps/cli/scripts/sync-skills-repo.mjs; parent runs bun run sync:skills in H and verifies apps/cli/.devpunks-cache/skills-sync.json names that exact SHA. Compare synchronized distributed source with the published and measured tree, preserving project-owned verifier references. Synchronization immediately copies assets; there is no inactive selector, so it cannot precede Stage 1 admission. Successful commands without content/receipt correspondence are insufficient.
The parent reserves H/apps/cli/src/scaffold/project-verifier-preservation.test.ts for T5. Scaffold owns production obligation/recovery code and its existing tests. Before iteration completion, exercise combined Project Verifier preservation, shared managed guidance refresh then no-op, authored-byte preservation, and failed-candidate truthful proof from REGRESSION-COVERAGE.md. Distinguish selected baseline.dataRoot/shared-agents.md from archive data/shared-agents.md. Keep the scaffold runtime fixed within each admission pair. An ordinary shared Markdown edit is not evidence of an authoring/activation contract change.
Validation, review and closeout
Run each task's named focused checks first, then all canonical node --test tests/*.test.mjs once the compatible source is integrated. Native scenario results remain required even if text tests pass. For touched CLI tests/helpers, run bun run --cwd apps/cli test -- src/scaffold/project-verifier-preservation.test.ts src/scripts/sync-skills-repo.test.ts and bun run --cwd apps/cli check-types; run broader affected scaffold checks through that plan. Actual behavior-changing code requires RED then GREEN through its public seam; a test-only fixture is not proof of the corresponding production action.
Before completion, parent reconciles a criterion-by-criterion evidence matrix for umbrella AC-001–AC-054, Verifier AC-001–AC-039, and Execution AC-001–AC-036, preserving separate leaf identities. The task acceptance references provide ownership; overlap requires one reusable evidence pointer with matching authority/code/runtime/scenario, not duplicate tests. Each row records authoritative criterion, owning task, observed action/result/falsifier, durable proof, freshness and passed/blocked status. Any unproved criterion keeps its Task/Story incomplete.
After implementation, Verification, shared-record reconciliation, architecture closure and final acceptance, route one frozen full change through comprehensive autoreview primary and mandatory independent risk-focused challenger. Parent adjudicates and retains the report. Incomplete coverage stays incomplete. Repairs receive focused checks and affected Verification; a second completed pass requires the accepted risk trigger. Do not exceed two completed passes without human direction.
Parent delegates docs closeout under docs-ingest-phase, with writing-for-agents for agent-facing text: update docs/README.md, docs/runbooks/hi-cli-scaffolding.md, and the relevant existing wiki harness/execution-modes/sequential-and-parallel-delivery.mdx, harness/validation-and-tools/project-verifier.mdx, and project-verification-flow.mdx. Describe implemented behavior and admission state truthfully; Feature Maps are readonly to docs ingestion. Reconcile observed Linear lifecycle facts without changing task identities or native blockers. Run or consult release classification for any release-bearing diff; this delivery does not authorize publication or consumer repairs.
Risks, unresolved inputs and planning handoff
- Source contracts are interdependent. Disjoint file edits permit parallel work, while changed declared reads invalidate affected gate evidence. T9 catches producer/consumer disagreement before one canonical revision is consumed.
- Prompt checks can pass without real behavior. Every task requires the stated native/public scenario and retained result; T9 needs actual matched native measurements.
- Existing behavior may already satisfy a proposed RED case. Inspect current public behavior and choose an actual accepted failing case; never fabricate failure or rename a green check RED.
- Upstream pstack content must be read at its actual fetched revision and its compatible procedure preserved. Access failure blocks only affected adaptation proof until resolved; no invented replacement procedure.
- Plan review is pending parent independent
plan-reviewerassessment. No unresolved product decision was found. Future missing metric/provider/runtime access is an exact execution blocker, not authorization to lower a gate.
The show-me graphs above preserve owners, native blockers and earliest frontiers. wait-what language pass: the parent sends independent tasks to scoped workers, checks each result, and releases safe dependent work. Verification proves the product; Code Review examines the frozen change. The source revision reaches Harness only after its contracts agree, and optimized defaults require measured admission. No accepted decision changed during simplification.