Harness Intelligence Wiki
SpecsCLIReliable Scaffold Lifecycle

Scaffold Lifecycle Implementation

Scaffold Lifecycle Implementation

Summary

The accepted nine-task graph is implemented. W1–W6 completed with the selected asset, obligation, recovery, installation, and combined post-sync evidence retained. The original workspace-local resolution report was addressed through the broader deterministic scaffold/update/check lifecycle. No merge or release was performed.

Execution Board

WaveTasksStateRelease condition
W1IP-463CompleteParent Task Gate and A1 passed
W2IP-470, IP-464, IP-465, IP-468CompleteParent task gates and A2 passed
W3IP-466CompleteRecoverable publication task gate passed
W4IP-467, IP-469CompletePortability, handoff, and projection task gates passed
W5IP-471CompleteRoutine installation and Commit Gate proof passed
W6IntegrationCompletePost-sync runtime, acceptance, and architecture proof passed

Final execution04 ran the six actual scaffold/update commands with expected statuses [0, 1, 1, 0, 1, 1]. Public Project Verifier preservation, canonical contracts, CLI types, and focused tests passed. The run found a runtime defect where Oxlint received a path prefix with zero matching files; the bounded scripts.ts fix and its regression test pass.

Steering

The user authorized a fresh local clone of git@github.com:wearedevpunks/skills.git and edits directly on main. /home/stefan/repos/skills is the canonical checkout for this delivery; initial HEAD is 584ea4bddd5bcfcf780baf9fb67ff736ba7d0626. This supersedes the Mac path restriction. Source-first commit, push, sync and exact receipt proof remain required. Releases and consumer repairs remain separate scope.

Architecture Conformance Evidence

Expected W1 ownership:

packages/scaffold       baseline and artifact obligation contracts
apps/cli/src/baseline   selected-asset integrity and compatibility reader
apps/cli/src/scaffold   desired state and authorized materialization
apps/cli/src/update     reconciliation using the same selected identity

W1 repairs preserve receipt-only unknown ownership and project references across skill resets. Parent final-source suite passed 21 tests across three files; CLI types passed. Public verifier preservation passed all three tests with matching recorded input identities. Independent repair rereview resumed after capacity recovered and closed the finding. Two consecutive planner/application probes preserve unknown receipt authority without deletion; source identities stayed stable.

Parent Task Gate and A1 pass. RAC-001 is proved by capability schema/archive and selected-reader evidence; RAC-002 by selected scaffold/update/check bytes, digest failures, authored preservation and absence of installed-template fallback. Parent inspected the package → reader → desired state → receipt dependency path. Ownership matches the declared graph; no temporary seam or migration remains. Public seam changes are the declared capability/obligation metadata and explicit unknown ownership result. The worker released source/build custody and retained cleanup proof. W2 may consume these established responsibilities.

Review: .devpunks/delivery/v43/IP-463/task-local-gate-review.md. Public preservation RED: .devpunks/delivery/v43/IP-451/public-repro.json.

W2 Integration Progress

Independent plan rereview approved the discovered producer/consumer scope corrections without changing the native graph or criteria. T3 owns exact obligation findings from comparison through the check port; T2 explicitly released update/run.ts and its candidate preview call remains intact. T4 owns quality detection/output and root manifest attachment. T6 owns lineage models, baseline declarations and matching native parser validation. Its optional quality diagnostic field carries T4's reason into the existing compiler error.

IP-470 has 34 runtime tests, eight update regressions and an independent candidate-safety review with no actionable finding. IP-464 retains public registry-unavailable RED and source aggregation/obligation GREEN. IP-465 retains actual missing-script/root-manifest and diagnostic REDs. IP-468's native parser integration passed 27 tests, including the eight update regressions; the prior six parser failures remain historical. Final quality diagnostic proof and one coordinated build precede W2 public runtime gates. No final W2 completion claim.

Provider Evidence

Fresh Devpunks reads confirmed both epics, eight Stories and eighteen Tasks in V4.3 with the accepted native graphs. IP-463 was changed to In Progress and read back with its parent IP-459, milestone and native relations preserved. Initial readback is retained in .devpunks/delivery/v43/provider-initial-readback.json.

This work changes CLI, filesystem and agent workflows. No browser UI is changed. Public command and filesystem evidence will substantiate the runtime criteria.

Historical Remaining Work

W1–W4 Task Gates have passed. Complete W5 operational installation and W6 integration; then audit all45 criteria, finish independent review and docs ingest, and reconcile PR/tracker evidence. Task Gates retain bounded evidence; final acceptance remains unassessed.

W2 public repair gates

IP-465 passes its task responsibility gate: current source identities match, repeated plans retain default/custom quality scripts, all four packaged cases pass, disabled policy produces no active pre-commit hook, and a real format check rejects unformatted input without changing 385 file hashes. Installation and operational gate proof remain IP-471.

IP-468 passes its task responsibility gate after the repaired CLI completes scaffold, ordinary-source update and repeat; emitted plans converge without invalidation for ordinary source edits. The parent inspected the shared capability type-alias lint-only delta; its runtime schema is unchanged. Full AC-032 remains IP-469's downstream receipt/check/update/handoff responsibility.

W2/A2 remains pending. IP-470's inherited-root-configuration repair passed independent real-Bun rereview and 38 tests; final packaged proof awaits the next coordinated build. IP-464's required concurrent blocked-quality plus stale-shared fixture found that quality planning failure suppresses independent artifact comparison; actual RED and repair scope are retained with its worker. No dependent publication task is released yet.

W2/A2 gate closure

IP-464 final packaged runtime 4e81a57b8f7239c8668453b9b89811e122b3f066410240700784194b85b8e739 preserves independent drift, suppresses blocked dependent actions, and rejects strict mutation without filesystem changes. Parent checked source identities and retained runtime evidence; focused independent findings are closed. W2/A2 passes through .devpunks/delivery/v43/scaffold-w2-a2-gate.json. Release IP-466 in W3; final acceptance remains unassessed.

Scoped authoring archive agreement

bun run --cwd apps/cli baseline:build passed. Parent read the actual tar member and compared its complete scoped-authoring capability with the live bundled compiler input and every contract in retained public before/ordinary/repeat plans. All agree; .devpunks/delivery/v43/IP-468/archive-authoring-readback.json retains archive and plan hashes. This closes declaration consistency only; bounded authoring completion and final acceptance remain pending.

W3 recovery Task Gate

IP466 passes its bounded Task Gate on source03/runtime 07b19b65b44da2eca4bdf70016a1e94d102e955f323f3409a5c0129adae2a332. Publication retains prior adoption and verified independent work through interruption, regenerates damaged mechanical proof without preserving corruption, and reports damaged proof in read-only checks. Native missing/corrupt/stale repair and repeat pass; the supplemental missing-only case begins and ends with an observed empty no-op. Two focused independent reviews close source findings; prior native defects and their repairs remain retained. See .devpunks/delivery/v43/IP-466/parent-task-gate.json. Release disjoint IP467/IP469 W4; operational installation and final acceptance remain pending.

W5/W6 closure

IP-471 is complete in the local implementation. Execution03 retains operational installation proof for the resolved quality and commit-gate setup: fixtures supply lock evidence, the installed Lefthook package, an executable local binary, and an executable hook, while portability validation uses a real cloned checkout. The final full CLI suite passed 573/573 tests, including the focused successors for the earlier stale installation fixtures.

The final post-lint binding records zero lint or type errors at commit 0c25a3f36bbe3e88f32bcc725dd0fee294339116. Final acceptance is closed at 170 accepted_satisfied and four excepted_not_passed, with zero unassessed criteria and zero unresolved obligations. AC-044–AC-047 remain exceptions. This local completion does not assert a Linear Done transition or provider push.

Final post-lint proof binding

The final post-lint check binds commit 0c25a3f36bbe3e88f32bcc725dd0fee294339116 and tree 8945d7abce41b709809ca7540d9fd64a6025760d in .devpunks/delivery/v43/FINAL-POST-LINT-BINDING.json. Clean-worktree root lint and check-only formatting passed with zero lint or type errors. The affected run passed lint and formatting and completed 22/27 Turbo tasks on two attempts; both attempts timed out in the same unrelated API baseline-ledger-cutover no-redeploy test under parallel load. A focused rerun passed that file's 16/16 tests in 5.11 seconds.

Release classification also passed with status 0, releaseKind: none, classificationError: null, and both baseline and npm publication requirements false.

The commits after execution03 contain lint-safe test assertion and typing refactors. They leave the V4.3 source behavior unchanged, so execution03 remains the product proof. Its acceptance result is unchanged: 170 accepted_satisfied, four excepted_not_passed, zero unassessed, and zero unresolved obligations. AC-044–AC-047 remain excepted_not_passed. No merge or release is part of this binding.

Provider-only script runtime portability repair

GitHub Actions run 34376179881 passed root static verification and every deployment check at pushed head 451c799875ecf5ac812d8683f2c552a4fc08946a, but Affected Verification failed when ten scaffold/update cases launched generated sync-subagents.mjs scripts. All ten failures were spawnSync node ENOENT. The script runner had replaced the base environment with {}, which discarded the PATH installed by actions/setup-node; local OS command lookup fallback had hidden the defect.

The repair defaults an omitted script environment to process.env and keeps an explicit environment authoritative. Its regression test proves inherited PATH lookup and explicit empty-environment isolation. The focused runtime suite, CLI typecheck, touched-file lint and check-only formatting, and git diff --check passed locally. A repaired exact-head provider run is still required before provider closeout. This operational portability repair does not change the accepted product ledger: 170 criteria remain accepted_satisfied, AC-044–AC-047 remain the four excepted_not_passed benchmark criteria, and none was relabeled as passed.

On this page