Plan: Reliable Scaffold, Update and Check Lifecycle
Plan: Reliable Scaffold, Update and Check Lifecycle
Overview
Implement the accepted issue-197-scaffold-lifecycle specification in the
existing V4.3 Delivery Flow and Scaffold Reliability iteration. The principal
fix is an explicit, versioned shared-prompt capability: .agents/AGENTS.md is
fully scaffold-owned and is read from the selected baseline asset
archive member data/shared-agents.md, materialized at
baseline.dataRoot/shared-agents.md. The installed npm
CLI's bundled template is never a silent fallback. Root/scoped repository
AGENTS.md files, authored roles, and custom guidance retain their separate
ownership contracts; .claude/CLAUDE.md and .opencode/AGENTS.md remain
mechanical mirrors.
This plan preserves the nine existing provider Tasks and their native eleven blocker edges. No new task graph, service, executor, dependency, or release is introduced. Runtime implementation and release remain unauthorized until the delivery owner starts the plan.
Authority and constraints
Execution resumed 2026-09-06 on the user-prepared integration branch
team/stefan/v4.3-delivery-scaffold at 1e6b2b2ae733f2f84379ab4ac4d9d170177759df,
targeting main. This supersedes the planning branch intent below. The user
authorized implementation and the canonical shared-skills clone at
/home/stefan/repos/skills, with edits directly on main. Native task identities,
acceptance criteria, write reservations, and validation gates remain unchanged.
- Specification:
./SPEC.md(accepted, agent-ready; immutable publication atd2ce164aee1f59755fce84cbff40afed9e4ed087). - Source issue: GitHub issue #197.
- Iteration: V4.3 Delivery Flow and Scaffold Reliability.
- Provider identity: IP-456/IP-457 with Tasks IP-463 through IP-471.
- Branch/base intent:
team/stefan/issue-197-scaffold-architecture, based onb9bb213dc490753020501ef81f42978d1caee89e; verify ancestry before delivery. - Code evidence revision used for path grounding:
4403e1095c22a4bc8f2e9a63bcec60e45cb8c4f8. - Existing source-first reusable skill policy, issue #181 candidate safety and issue #194 receipt validation remain in force.
- First publication of the capability-aware reader requires a compatible CLI and baseline release. Choose the actual version during authorized delivery; do not invent one in this plan. Later prompt-only baseline changes do not require an npm CLI bump.
Architecture and ownership contract
packages/scaffold owns the baseline metadata/schema and the public capability
model. The selected baseline reader resolves and validates the declared asset
path, digest and reader compatibility. The common Context Plan/Scaffold Plan
must carry selected baseline/template identity into materialization and update
comparison. apps/cli owns command orchestration, observation, reconciliation,
candidate validation and truthful result publication.
selected baseline
-> capability metadata + dataRoot/shared-agents.md
-> Context Plan / Scaffold Plan (identity, hash, ownership)
-> observe/check or apply update
-> aliases and projections
-> verified receipt / residual handoffThe shared prompt is a complete baseline-owned managed artifact. A local edit,
missing file or stale prior digest participates in ordinary authorized
reconciliation and may be replaced by the selected baseline. Capability is
explicit: an old baseline without it is an unsupported capability result; a
declared capability with a missing or mismatched asset is an integrity error.
Neither case may read apps/cli's installed shared-agents.md as fallback.
The contract must distinguish content authority from required presence/validity.
Do not generalize this ownership to all files ending in AGENTS.md; do not
use broad kind or path exemptions to skip required checks. Preserve authored
root/scoped guidance and mixed-file entries according to their own contracts.
Provider task graph
| Alias | Provider task | Scope | Depends on |
|---|---|---|---|
| T1 | IP-463 | explicit artifact obligations, shared-prompt capability/reader and reconciliation | — |
| T2 | IP-470 | faithful candidate workspace topology | — |
| T3 | IP-464 | independent health findings and exact unknowns | T1 |
| T4 | IP-465 | quality defaults and repository overrides | T1 |
| T5 | IP-466 | coupled output, receipt and publication recovery | T1 |
| T6 | IP-468 | contract/scope-based invalidation | T1 |
| T7 | IP-467 | portable identity and finite legacy migration | T1, T5 |
| T8 | IP-469 | bounded post-command handoff and deterministic projection proof | T5, T6 |
| T9 | IP-471 | routine quality and Commit Gate installation/proof | T4, T5, T2 |
Native provider blockers are authoritative. The graph has eleven edges: T1→T3, T1→T4, T1→T5, T1→T6, T1→T7, T5→T7, T6→T8, T5→T8, T4→T9, T5→T9 and T2→T9.
Execution waves and write reservations
Tasks are assigned one worker per provider identity. Where apps/cli/src/update/run.ts
or shared baseline models overlap, the owner must finish and publish its seam
before the next task starts; this is sequencing by write reservation, not a new
provider blocker.
| Wave | Tasks | Reservation rule |
|---|---|---|
| W1 | T1 | Establish baseline capability and ownership; reserve shared update and scaffold seams. |
| W2 | T2, T3, T4, T6 | Launch all four disjoint scopes. T2 reserves update/run.ts first, then explicitly releases its bounded reporting producer to T3; T4 reserves output.ts quality planning; T6 reserves model/compiler and explicit baseline declaration producers; reporting stays separate. |
| W3 | T5 | Publish and recover receipts after the shared update reservation clears. |
| W4 | T7, T8 | Launch portable-state recovery and handoff/projection together with disjoint source and test ownership. |
| W5 | T9 | Complete routine installation after shared update and output reservations clear. |
| W6 | integration | Parent validates cumulative public results, provider graph and documentation; workers own any implementation corrections. |
Task contracts
All tasks use task_identity_mode: provider-task, relation_mode: native,
and backlog_sync_skip_reason: (the provider projection is complete). Each
task's backlog_item_id is its IP identifier below; the corresponding URL is
https://linear.app/devpunks/issue/<id>. status is Planned, log,
files edited/created, red_evidence and green_evidence start empty and
are filled by implement-spec. Every task has runtime_validation: required.
The following matrix supplies the per-task identity, owned paths and worker
wave fields required by the execution contract:
| Task | backlog_item_id / parent Story | backlog_item_url | owned_paths | wave_boundary |
|---|---|---|---|---|
| T1 | IP-463 / IP-459 | https://linear.app/devpunks/issue/IP-463 | packages/scaffold/src/baseline.ts, packages/scaffold/src/baseline/, packages/scaffold/src/context-plan.ts, apps/cli/scripts/build-baseline.mjs, apps/cli/scripts/build-dist.mjs, apps/cli/src/baseline/, apps/cli/src/content/prompts.ts, apps/cli/src/scaffold/, apps/cli/src/platform/scoped-scaffold-operation.ts, apps/cli/src/update/run.ts, focused tests | W1 |
| T2 | IP-470 / IP-462 | https://linear.app/devpunks/issue/IP-470 | apps/cli/src/runtime/scripts.ts, apps/cli/src/runtime/scripts.test.ts, apps/cli/src/update/run.ts | W2 |
| T3 | IP-464 / IP-459 | https://linear.app/devpunks/issue/IP-464 | apps/cli/src/features/repository-check/application.ts, apps/cli/src/features/repository-check/application.test.ts, apps/cli/src/features/repository-check/port.ts, apps/cli/src/platform/feature-application-operations.ts (repository-check result forwarding only), apps/cli/src/update/run.ts (typed obligationFindings and read-only assessment consumption in comparison/UpdateResult/check return, only after explicit T2 custody release), apps/cli/src/presentation/operation-result/ | W2 |
| T4 | IP-465 / IP-458 | https://linear.app/devpunks/issue/IP-465 | apps/cli/src/scaffold/preflight.ts, apps/cli/src/scaffold/settings-selection.ts, apps/cli/src/features/commit-gate/, apps/cli/src/scaffold/settings-selection.test.ts, apps/cli/src/integrations/repository-detector.ts, apps/cli/src/scaffold/output.ts (quality generation, existing-scope manifest attachment and reviewed check-assessment wrapper only) | W2 |
| T5 | IP-466 / IP-460 | https://linear.app/devpunks/issue/IP-466 | apps/cli/src/features/scaffold-state/, apps/cli/src/scaffold/stage.ts, apps/cli/src/scaffold/output.ts, apps/cli/src/scaffold/output.test.ts, apps/cli/src/update/run.ts, apps/cli/src/update/run.test.ts, packages/scaffold/src/baseline/managed-file.ts | W3 |
| T6 | IP-468 / IP-461 | https://linear.app/devpunks/issue/IP-468 | apps/cli/src/features/context-planning/compiler.ts, apps/cli/src/features/context-planning/compiler.test.ts, apps/cli/src/features/context-planning/index.ts, apps/cli/src/platform/scoped-scaffold-operation.ts, packages/scaffold/src/context-plan.ts, packages/scaffold/src/baseline/capabilities.ts, apps/cli/src/scaffold/models.ts, apps/cli/src/features/repository-analysis/model.ts (QualityCommandEvidence unresolvedReason only), apps/cli/src/data/scripts/sync-subagents.mjs (scopeIssue optional authoring schema validation only), apps/cli/scripts/build-baseline.mjs and apps/cli/src/baseline/bundled.ts (explicit authoring/activation declaration producers only) | W2 |
| T7 | IP-467 / IP-460 | https://linear.app/devpunks/issue/IP-467 | apps/cli/src/features/scaffold-state/, apps/cli/src/update/run.ts, apps/cli/src/update/run.test.ts, packages/scaffold/src/baseline/managed-file.ts | W4 |
| T8 | IP-469 / IP-461 | https://linear.app/devpunks/issue/IP-469 | apps/cli/src/content/handback.test.ts, apps/cli/src/content/, apps/cli/src/data/scripts/harness-projection/, apps/cli/src/data/scripts/sync-subagents.mjs, apps/cli/src/runtime/scripts.test.ts, apps/cli/src/scaffold/output.ts, apps/cli/src/scaffold/output.test.ts, apps/cli/src/features/context-planning/compiler.ts (identity helper import/substitution only), apps/cli/src/features/repository-check/{application.ts,application.test.ts,port.ts} (typed fact mapping only) | W4 |
| T9 | IP-471 / IP-458 | https://linear.app/devpunks/issue/IP-471 | apps/cli/src/integrations/tool-management.ts, apps/cli/src/features/commit-gate/, apps/cli/src/scaffold/output.ts, apps/cli/src/update/run.ts | W5 |
Test write reservations follow the owned-path table. T2 owns apps/cli/src/runtime/scripts.test.ts; T3 owns repository-check tests; T4 owns settings-selection tests; T6 owns compiler tests. In W2, any existing apps/cli/src/update/run.test.ts invocation by T6 is read-only regression execution. T5 and T7 may edit that shared test in their sequential waves; T8 writes apps/cli/src/content/handback.test.ts and only runs existing update tests. T9 may edit update tests after W4. T1 owns baseline and scaffold test additions in W1. Running an existing test does not grant file-write ownership.
W2 ownership amendment (2026-09-06)
W1 T1 Task Gate and A1 passed; its source reservations are released. This amendment grounds the already accepted quality and invalidation responsibilities in their actual producers and consumers. It preserves all nine task identities, eleven native blocker edges, acceptance criteria and architecture-wave gates.
-
T2 exclusively writes runtime/scripts.ts and its test plus update/run.ts until the parent records explicit source-custody release. T3 may then acquire only the update/run.ts comparison, UpdateResult and check-return hunks that produce typed obligationFindings. T3 also exclusively writes repository-check application/tests/port, result presentation, and the repository-check forwarding seam in platform/feature-application-operations.ts. Forward exact findings from observed artifact obligations; the check branch's placeholder reconciliation status planned with empty outcomes/actions is not evidence of pending work. Preserve the common lifecycle contract. T2-to-T3-to-T5 custody is a sequential file reservation, not a new native blocker; disjoint work continues.
-
T4 exclusively writes its quality resolver/integration files, repository-detector.ts, and two bounded scaffold/output.ts seams:
applyLintConfigsconsumesfeatures/commit-gate/quality.ts, and an existing compiled scope receives its detected manifest without losing scope metadata. The latter lets a root scope initially created withmanifest: nullcontribute the resolved Commit Gate. T8 and T9 acquire output.ts only in their later sequential reservations. -
T6 exclusively writes the listed model/compiler/platform files and the explicit authoring/activation declarations produced by build-baseline.mjs and baseline/bundled.ts. It does not write output.ts or change quality contributions. packages/scaffold retains portable schema/model ownership; baseline producers supply explicit revision declarations rather than infer semantics from content.
-
T4 reads the compiled scope shape and T6 contract model; T6 reads the stable T1 capability reader, selected baseline identity, output.ts compiler call and desired-state encoder. T4 preserves scope lineage while attaching manifests. T6 preserves quality contribution interfaces. T3 reads the existing ArtifactObligation and lifecycle comparison contracts, produces typed cause/consumer findings in the comparison result, and forwards those exact findings through UpdateResult and its port/adapter. JSON presentation remains application-owned; generic local-edited diffs or placeholder reconciliation state cannot substitute for observed unknown/invalid/pending obligations. Its adapter file is separate from T6 platform/scoped-scaffold-operation.ts. Record relevant input hashes before and after checks; a changed shared input requires affected checks again. T2 explicitly released update/run.ts custody on 2026-09-06; preserve its executeLintPreview
manifestSource: "live"change. T2 retains runtime/scripts.ts and its test. T3 may acquire the bounded comparison/result/check-return reservation after the focused independent plan review; no concurrent update/run.ts writes are authorized. -
Source custody transfers only after the parent verifies released scopes. Shared builds, generated baseline/dist artifacts, source synchronization and final combined validation remain parent-reserved operations; workers request the needed build and consume its recorded identity. Existing test execution grants no write ownership over shared tests or generated output.
T3 validates AC-007 through actual compareObservedState → runCheck → publicCheckResult in its existing application.test.ts. Before producer/forwarding edits, capture RED for an actual unknown ArtifactObligation beside an independently healthy or changed managed artifact: retain exact status, artifact path, cause and affected producer/consumers with nonzero health even when bytes match. Extend coverage to invalid authored and pending generated obligations; healthy check results must not become pending merely because reconciliation.status is the placeholder planned. After the parent-reserved build, retain real hi check --json output for the obligation fixture and prove repository bytes unchanged. Manually constructed application-only results do not establish production producer/adapter proof.
T4's existing public-planner RED is retained at
.devpunks/delivery/v43/IP-465/defaults-red.log: supported fresh-repository
planning omitted required package scripts. Before repairing existing-scope
manifest attachment, extend the public planner test to prove the missing root
Commit Gate contribution and record its actual RED. Pure resolver tests alone
cannot prove either planner integration.
T6 also owns the distributed native parser's bounded schema-consumer update
in apps/cli/src/data/scripts/sync-subagents.mjs scopeIssue(). Actual
regression evidence .devpunks/delivery/v43/IP-468/green-matrix.log records six
existing update tests failing with Context scope fields are invalid because
the old exact-key validator rejects optional scope.authoring. Accept that
optional field consistently with packages/scaffold/src/context-plan.ts:
exact {path, kind, contracts, missingContracts}; path/kind are nonempty
strings, contracts contains exact {id, authoringRevision, activationRevision}
records of nonempty strings, and missingContracts contains nonempty strings.
Reject unknown keys and malformed values at every nested level. Scopes without
authoring remain valid.
This reservation changes input validation only; projection behavior and T8 handoff ownership remain unchanged, with any later native-script custody transferred sequentially. T6 uses its existing compiler.test.ts ownership to exercise the actual distributed script through a disposable subprocess fixture: valid optional lineage succeeds, omitted lineage stays compatible, malformed new fields fail before output mutation. Retain real RED/GREEN for that public script result and rerun the existing six update regressions. Do not substitute a duplicated test-only validator or only a package-schema test.
T6's prerequisite Task Gate proves the actual public invalidation/Context Plan
result: affected scope, reason and input identity for the accepted change matrix,
with explicit declared baseline revisions and preserved unrelated scope lineage.
This gate may release native dependent T8. It does not establish complete
AC-032: receipt-bound stale-action evidence, check reporting and update
bounded handoff remain final-unproven until T8 consumes that result with T5
publication state. RAC-006 remains due at A3 with the full T6/T8 public matrix;
the final criterion and Story cannot be marked complete from pure calculation
tests. No cumulative gate or accepted requirement is weakened by distinguishing
prerequisite readiness from final integrated proof.
Each task contract below repeats its exact depends_on and validation. For
every task, reason_not_testable is empty because the behavior is testable
through public CLI seams; red_evidence and green_evidence are intentionally
empty until execution.
Architecture-bearing fields apply to every task as follows. These are the per-task responsibility bindings used by the worker handoff:
| Task | architecture_wave | behavior_owner | integration_surface | public_seam | topology_delta | forbidden_ownership | temporary_seams | responsibility_acceptance_criteria |
|---|---|---|---|---|---|---|---|---|
| T1 | A1 | baseline capability model | CLI baseline resolution/update | selected-baseline reader | add capability-aware shared-prompt source | installed npm prompt, authored scoped files | none planned | RAC-001, RAC-002 |
| T2 | A2 | candidate validation | scaffold/update candidate operation | candidate validation result | preserve workspace executable topology | live consumer state | none | RAC-005 |
| T3 | A2 | health result aggregation | check presentation | check --json | retain independent findings | mutating producers | none | RAC-004 |
| T4 | A2 | quality contract resolution | common scaffold plan | quality contract | resolve defaults and overrides | guessed manager migration | none | RAC-003 |
| T5 | A3 | publication/recovery state | materializer and receipts | receipt/pending result | input-bound recoverable transitions | false completion, second persistence engine | pending evidence | RAC-003, RAC-007 |
| T6 | A3 | dependency invalidation | Context/Scaffold Plan | invalidation result | selective affected-work scheduling | broad reauthoring | none | RAC-006 |
| T7 | A3 | portable migration | receipt/worktree reconciliation | migration result | finite legacy convergence | deleting authored records | none | RAC-007 |
| T8 | A3 | handoff/projection validation | native harness projection | Post-Command Handoff | bounded residual authoring | self-declared completion, independent prompt source | none | RAC-006, RAC-007 |
| T9 | A4 | routine installation proof | runtime setup adapters | operational command result | verified quality/hook setup | bypassing conflicts or receipts | none | RAC-008 |
Skill guidance is attached to each task rather than inherited implicitly:
| Task | Skill guidance (skill: applicable_behavior) |
|---|---|
| T1 | codebase-design: keep capability loading behind one deep public reader seam; tdd: capture public command RED before production changes; simplify: remove only the broad exemption made obsolete; verify-behavior: verify selected asset, ownership and no fallback through command results. |
| T2 | codebase-design: isolate candidate preparation behind a substitutable adapter; tdd: test executable resolution through the public candidate flow; verify-behavior: prove containment, disabled scripts and live-state isolation. |
| T3 | tdd: test observable JSON findings and exit status; simplify: keep independent result aggregation local; verify-behavior: preserve healthy evidence beside exact blockers. |
| T4 | tdd: test defaults, overrides and opt-out through public commands; simplify: keep quality policy separate from artifact ownership; verify-behavior: read back resolved commands and preserved policy. |
| T5 | codebase-design: model publication as input-bound state transitions; tdd: interrupt one public boundary per cycle; verify-behavior: prove receipt truth and resumability. |
| T6 | codebase-design: keep invalidation as a dependency calculation behind the plan compiler seam; tdd: test selective scheduling through update/check; simplify: avoid broad reauthoring triggers. |
| T7 | codebase-design: keep migration finite behind portable identity reconciliation; tdd: test legacy, relocation and repeat behavior publicly; verify-behavior: prove authored retention and local-hook revalidation. |
| T8 | codebase-design: keep handoff residual and projection deterministic; tdd: test authored completion through CLI validation; verify-behavior: prove aliases and receipts agree with accepted state. |
| T9 | codebase-design: keep installer and operational proof behind existing runtime adapters; tdd: test setup and partial failure through public commands; verify-behavior: read back actual hook/dependency operation. |
T1 — IP-463 — explicit artifact obligations and shared-prompt authority
Execution path clarification: T1 also reserves
apps/cli/src/features/scaffold-state/{desired-output.ts,model.ts,compile.ts}
to carry the accepted artifact obligations and selected shared-prompt identity
through the existing common desired-plan seam. This preserves the target
ownership topology; T5/T7 receive the resulting contract in their later waves.
-
depends_on:
[] -
location:
packages/scaffold/src/baseline.ts,packages/scaffold/src/baseline/**,packages/scaffold/src/context-plan.ts,apps/cli/scripts/build-baseline.mjs,apps/cli/scripts/build-dist.mjs,apps/cli/src/baseline/resolve.ts,apps/cli/src/baseline/types.ts,apps/cli/src/content/prompts.ts,apps/cli/src/scaffold/output.ts,apps/cli/src/scaffold/stage.ts,apps/cli/src/platform/scoped-scaffold-operation.ts,apps/cli/src/update/run.ts, and related public tests. -
description: Add versioned explicit shared-prompt capability/path/hash metadata to the existing baseline schema and builders. Read
baseline.dataRoot/shared-agents.md(the archive member isdata/shared-agents.md); validate capability compatibility and integrity. Thread selected baseline identity through desired state/materialization. Mark.agents/AGENTS.mdfully scaffold-owned and reconcile it on authorized update, while preserving root/scoped authored files, custom roles and aliases. Remove the broadagent-promptexemption only where it suppresses this managed obligation. Keep metadata/schema fixtures and published baseline payloads consistent. -
validation: Public scaffold/update/check flows prove AC-001, AC-008–AC-014, AC-037–AC-043 and AC-045. Old metadata returns explicit unsupported capability; declared missing/bad asset returns integrity error; no installed-template fallback. Local shared-file edits are replaced by selected baseline; unchanged repeat is a no-op; authored scoped/root guidance survives. First compatible reader consumes the versioned capability; later prompt-only baseline publication remains consumable without a CLI bump.
-
review_mode:
cli; primary autoreview plus mandatory independent risk challenger. -
assigned_skills:
codebase-design,tdd,simplify,verify-behavior. -
implementation_skill_guidance: Use a deep baseline capability reader seam; inject/read selected baseline data through the public command path. Preserve existing Effect/version conventions and source-first baseline publication.
-
tdd_status:
requiredfor behavior changes. -
tdd_target: Public
scaffold,updateandcheck --jsonbehavior in disposable repositories; test one capability/integrity case at a time. -
red_command:
bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts(run focused existing/new target fromapps/cli). -
expected_red_failure: New capability-aware selected-baseline and shared-file ownership assertions fail against installed-template lookup/broad exemption.
-
green_command:
bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts. -
evidence: RED/GREEN empty until delivery; no runtime evidence claimed here.
-
codebase_design_notes: Public baseline capability reader is the seam; metadata validation and asset loading stay behind it. Avoid a second registry or fallback adapter.
-
runtime_validation:
required -
runtime_procedure: Disposable supported repositories and selected baseline archives; capability, digest, path and CLI compatibility read back.
-
runtime_target:
.agents/AGENTS.md, aliases, baseline metadata, Context/Scaffold Plan, manifest and receipts. -
runtime_evidence: Empty pending delivery.
-
runtime_cleanup: Remove disposable candidates and preserve consumer worktrees.
-
status:
Complete -
log: ``
-
files edited/created: ``
-
parent_gate_evidence:
.devpunks/delivery/v43/IP-463/task-local-gate-review.md. Parent accepted A1 capability/reader and public preservation proof; source custody released. See IMPLEMENTATION-NOTES.md A1 checkpoint; later cumulative integration remains pending.
T2 — IP-470 — faithful candidate topology
- depends_on:
[] - location:
apps/cli/src/runtime/scripts.ts, candidate validation modules/tests,apps/cli/src/update/run.tscandidate staging seams. - description: Validate planned manifests, lockfiles, workspace links, configuration and executable topology in an isolated candidate. Reproduce the
effect-tsgoscenario or retain a clearly equivalent fixture. Preserve issue #181 containment, disabled lifecycle scripts, cleanup and live-state isolation. - validation: AC-033–AC-036; candidate resolves workspace-local executable as ordinary planned install does, distinguishes lint warnings from installation/configuration/process/cleanup failures, and never mutates live consumer state.
- review_mode:
cli; primary plus independent risk challenger. - assigned_skills:
codebase-design,tdd,verify-behavior. - implementation_skill_guidance: Test through the public candidate/scaffold operation seam; retain candidate isolation and failure classification.
- tdd_status:
required; tdd_target: disposable real Bun monorepo candidate validation. - red_command:
bun run --cwd apps/cli test -- src/runtime/scripts.test.ts. - expected_red_failure: Workspace-local executable and planned topology assertions fail before the candidate fix.
- green_command:
bun run --cwd apps/cli test -- src/runtime/scripts.test.ts. - evidence: Empty pending delivery.
- codebase_design_notes: Candidate preparation is an adapter behind the public validation operation; do not patch live package manifests.
- runtime_validation:
required - runtime_procedure: Isolated candidate with symlink containment and scripts disabled.
- runtime_target: candidate workspace, executable resolution, cleanup.
- runtime_evidence: Empty pending delivery.
- runtime_cleanup: Delete candidate and restore fixture temporary state.
- status:
Complete - parent_gate_evidence:
.devpunks/delivery/v43/IP-470/parent-task-gate.json; cumulative W2/A2 is.devpunks/delivery/v43/scaffold-w2-a2-gate.json.
T3 — IP-464 — independent health report
- depends_on:
[T1] - location: repository-check application/presentation/port, operation-result schemas, adapter forwarding, and update/run.ts typed obligationFindings comparison/result/check-return seam after T2 custody release.
- description: Aggregate independent observations without invoking mutating producers. Preserve healthy findings when one component is unavailable; report exact causes, affected consumers and unknown/pending obligations with nonzero status. Preserve typed obligationFindings from the production comparison through UpdateResult and port/adapter; classify actual observed obligations rather than placeholder planned reconciliation or generic local-edited diffs.
- validation: AC-001, AC-002, AC-006, AC-007;
checkis read-only and does not call scaffold/update. - review_mode:
cli; primary plus challenger. - assigned_skills:
tdd,simplify,verify-behavior. - implementation_skill_guidance: Keep independent component results observable through the public JSON result.
- tdd_status:
required; tdd_target: blocked-quality plus independently stale shared-prompt check, and actual compareObservedState obligation findings retained through runCheck/publicCheckResult with healthy independent evidence. - red_command:
bun run --cwd apps/cli test -- src/features/repository-check/application.test.ts. - expected_red_failure: Blocked component suppresses or misstates independent guidance findings.
- green_command:
bun run --cwd apps/cli test -- src/features/repository-check/application.test.ts. - evidence: Empty pending delivery.
- codebase_design_notes: Result aggregation is the deep reporting module; producers remain non-mutating adapters.
- runtime_validation:
required - runtime_procedure:
hi check --jsonfixture matrix. - runtime_target: findings, exit status, repository bytes.
- runtime_evidence: Empty pending delivery.
- runtime_cleanup: Preserve fixture authored files; remove only temporary repository.
- status:
Complete - parent_gate_evidence:
.devpunks/delivery/v43/IP-464/parent-task-gate.json; cumulative W2/A2 is.devpunks/delivery/v43/scaffold-w2-a2-gate.json.
W2 independent check assessment amendment
The accepted AC-006 public matrix still fails: an ambiguous Quality Command
Contract aborts compilation before independent shared-artifact comparison.
Retained evidence is
.devpunks/delivery/v43/IP-464/public-ambiguous-quality.json and
quality-red-assertion.log, captured against packaged executable SHA
784e942981996cbb17dd455a93f79427e05a4437db42eb053572d5e82dbf04b3.
The fixture combines a locked npm repository, explicit conflicting format
aliases and stale .agents/AGENTS.md; the public result loses that independent
drift. This amendment completes the existing AC-006 responsibility.
Use the existing compiler → compileScaffoldContextPlan in scaffold/output.ts
→ runUpdate check seam. There is no scaffold/context-plan.ts file and no new
planner or extraction is assigned. An explicit read-only assessment result
retains independently assessable Context Plan content together with typed
blocked Quality Command Contract consumers and their exact scope/reason.
Only that check assessment may omit an unresolved Commit Gate contribution;
ordinary compilation and every mutating scaffold/update path retain the
existing fail-closed typed error. A partial assessment cannot become a valid
mutation plan or completion receipt.
| Owner | Bounded source reservation | Ready condition |
|---|---|---|
| T6 / IP-468 | Existing context-planning/compiler.ts, compiler.test.ts, index.ts and scaffold/models.ts: typed check-assessment result and compiler branch over the existing contribution calculation | Public compiler RED/GREEN proves independent content retained, exact blocked consumer emitted, normal compile still rejects |
| T4 / IP-465 | Existing scaffold/output.ts compileScaffoldContextPlan input assembly/forwarding seam and owned settings-selection.test.ts only | Consume T6's frozen typed contract; explicit assessment uses the same scope/selection/baseline input assembly, normal wrapper behavior unchanged |
| T3 / IP-464 | Existing update/run.ts check-call/result/comparison hunks, repository-check port/application/tests, adapter forwarding and presentation | Consume frozen compiler/wrapper contracts, retain independent drift and typed blocked dependency findings in actual check output |
These are sequential contract-readiness and exclusive file reservations inside existing task identities, not new provider blocker edges. T6 freezes the assessment result before T4 integrates the wrapper; T3 then integrates check consumption. Independent disjoint work continues. T4/T6 prior task gate evidence remains a record of its matched snapshot; new assessment work requires its own focused evidence before consumption and cumulative acceptance. Keep all source edits for this amendment frozen until the independent plan review passes.
Gate-dependent output is not independently provable from an omitted contribution. Carry the blocked consumer/dependency information through comparison: affected hook, generated configuration, projection or receipt obligations remain blocked/unknown with exact cause and consumer identity. They cannot be classified current, healthy, absent-by-design or safely removable merely because assessment omitted their unresolved contribution. Independently assessable baseline-managed shared content still receives its actual drift/health result. Use existing obligation/dependency evidence; do not infer completion from placeholder reconciliation state or introduce a parallel dependency registry.
Required proof, in order:
- T6 records actual public compiler assessment RED before implementation: incomplete/ambiguous quality plus independently valid shared contribution yields typed blocked consumer and independent content. The same input through normal compilation still fails with its exact Quality Command Contract error. Unrelated compiler failures remain failures rather than broad recovery.
- T4 records wrapper RED/GREEN with identical detected scopes and baseline: assessment retains the shared output comparison input, ordinary scaffold compilation refuses the unresolved quality contract, explicit user policy remains unchanged. Run the existing owned settings-selection tests.
- T3 reruns the retained mixed public fixture through the parent-built CLI:
check --baseline bundled --jsonreports both exact blocked quality and stale.agents/AGENTS.md, preserving independent healthy findings and nonzero status. Gate-dependent outputs remain blocked/unknown. A healthy quality fixture still reports ordinary health without false blockers. - Retain paired normal scaffold/update refusal and byte-hash readback proving explicit scripts/configuration, live shared bytes, hooks and completion receipts were not mutated by check or advanced through unresolved quality. Run compiler.test.ts, settings-selection.test.ts, repository-check/application.test.ts and the affected existing update regressions, then parent checks source/build identities and cumulative AC-006 evidence.
Final W2/A2 and full acceptance remain pending until this public mixed-case proof and the other declared cumulative gates pass. No quality gate is relaxed by returning more truthful read-only findings.
W2 exact quality diagnostic amendment
T4 owns the existing features/commit-gate/quality.ts resolver and
repository-detector producer: when explicit format mapping is unsafe or
ambiguous, carry its actual reason as QualityCommandEvidence.unresolvedReason.
T6 owns the optional readonly string field in
apps/cli/src/features/repository-analysis/model.ts and the existing
commitGateContributionFor consumer in compiler.ts. Append that reason to
IncompleteQualityCommandContract.message while retaining scope identity and
missing-field detail. The existing error schema stays unchanged. This is an
AC-004 diagnostic correction inside the accepted quality contract; no new
requirement, provider edge or execution owner is introduced.
T4 retained actual public planner diagnostic RED in
.devpunks/delivery/v43/IP-465/diagnostic-red.log: four cases report only an
incomplete root Quality Command Contract. Its owned settings-selection.test.ts
exercises compileScaffoldContextPlan:
unsafe and ambiguous explicit format mappings report the root scope and exact
resolver reason rather than only a missing formatCheck label. T6 verifies the
typed consumer retains that reason, with unchanged behavior when no reason is
present. After their disjoint producer/type/consumer edits, rerun the public
diagnostic cases to GREEN and prove explicit scripts/configuration remain
unchanged on refusal. Neither worker acquires the other's files; source
identity changes require affected checks again. Pure resolver tests alone
cannot prove the public diagnostic.
T6 native-parser validation already follows the subprocess contract: its owned
compiler.test.ts forks Node, imports the actual distributed
validateCanonicalContextPlan public API, and passes serialized compiled
Context Plan input through stdin. Retained RED is
.devpunks/delivery/v43/IP-468/red-native-subprocess.log. Valid optional
lineage, omitted lineage and malformed nested fields remain required, alongside
existing update regressions and parent-built runtime proof.
T4 — IP-465 — quality defaults
-
depends_on:
[T1] -
location: quality command resolution, scaffold/update planning, dependency/configuration tests.
-
description: Resolve supported defaults plus explicit repository overrides, include required scripts/dependencies/lint configuration, preserve ambiguous manager policy and read-only format checks. Integrate the quality resolver through repository detection and output.ts applyLintConfigs. Attach a detected manifest to an existing compiled root scope while preserving its metadata, so root Commit Gate contributions reach the public plan.
-
validation: AC-001, AC-003–AC-005. Prove the actual public plan carries supported root scripts/dependencies/config and preserves explicit overrides; include the compiled-root manifest attachment case, not only pure resolver results.
-
review_mode:
cli; primary plus challenger. -
assigned_skills:
tdd,simplify,verify-behavior. -
implementation_skill_guidance: Keep policy resolution separate from artifact ownership and shared-prompt loading.
-
tdd_status:
required; tdd_target: public-plan missing defaults and compiled-root Commit Gate contribution, custom override, ambiguous mapping and opt-out. Retain defaults-red.log and capture root-contribution RED before that repair. -
red_command:
bun run --cwd apps/cli test -- src/scaffold/settings-selection.test.ts. -
expected_red_failure: Missing supported quality setup or guessed override behavior.
-
green_command:
bun run --cwd apps/cli test -- src/scaffold/settings-selection.test.ts. -
evidence: Empty pending delivery.
-
codebase_design_notes: Quality contract resolver is a small policy seam consumed by the common plan.
-
runtime_validation:
required -
runtime_procedure: Fresh supported repository and explicit override fixture.
-
runtime_target: scripts, dependencies, lint config, hook policy.
-
runtime_evidence: Empty pending delivery.
-
runtime_cleanup: Remove disposable repository.
-
status:
Complete -
parent_gate_evidence:
.devpunks/delivery/v43/IP-465/parent-task-gate.json. Parent task-responsibility gate passed at the retained source identities; operational installation proof remains IP-471 and final acceptance is unassessed. See IMPLEMENTATION-NOTES.md W2 public repair gates.
T5 — IP-466 — recoverable publication
- depends_on:
[T1] - location: scaffold/update materialization, manifest/receipt/pending evidence modules and tests.
- description: Make output, verification, receipt and adopted-manifest transitions recoverable. Bind proof to selected baseline/template identity and actual observed output; preserve completed independent actions and avoid producer loops or false completion.
- validation: AC-017–AC-020, AC-031–AC-032 and AC-044. Interrupt each boundary, resume unchanged inputs, verify pending evidence and truthful readback.
- review_mode:
cli; primary plus challenger. - assigned_skills:
codebase-design,tdd,verify-behavior. - implementation_skill_guidance: Use existing receipt/pending infrastructure; expose a resumable operation rather than a second persistence engine.
- tdd_status:
required; tdd_target: interruption/recovery at output, verification, receipt and manifest boundaries. - red_command:
bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts. - expected_red_failure: Interrupted shared-prompt publication can claim success or reschedule unrelated work.
- green_command:
bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts. - evidence: Empty pending delivery.
- codebase_design_notes: Publication is a state transition seam with input-bound evidence; filesystem writes remain local adapters.
- runtime_validation:
required - runtime_procedure: Restarted command against partial and prior-valid states.
- runtime_target: shared prompt, aliases, manifest, projection receipt and pending handoff.
- runtime_evidence: Empty pending delivery.
- runtime_cleanup: Remove partial disposable fixture after collecting evidence.
- status:
Complete - parent_gate_evidence:
.devpunks/delivery/v43/IP-466/parent-task-gate.json; source03/runtime07b19 with retained native fault/recovery proof.
T6 — IP-468 — scoped invalidation
-
depends_on:
[T1] -
location: context-plan/scaffold-plan invalidation, skill/baseline identity handling, update planning and tests.
-
description: Track delivered skill content separately from explicit authoring/activation revisions and workspace/selected-skill membership. Extend portable Context Plan/capability and CLI plan models, expose invalidation through the existing planning public seam, and declare explicit revisions in normal bundled/archive baseline producers. Schedule only affected scoped work. Shared-prompt content changes refresh the scaffold-owned file without triggering broad scoped reauthoring. Preserve output.ts quality ownership with T4. Update only the distributed sync-subagents.mjs scopeIssue schema consumer for optional authoring lineage, with exact nested validation and malformed-input rejection.
-
validation: AC-023–AC-027 and the T6 invalidation contribution to AC-032; prove skill-body-only, contract-only, scope-change, ordinary-source and legacy-baseline cases through the actual public plan result. T6 prerequisite readiness releases T8 only after scope/reason/input identity proof. Full AC-032 stays pending until T8 integration proves receipt-bound stale evidence, check reporting and bounded update handoff; RAC-006 remains due at A3. The distributed parser accepts valid/omitted authoring lineage and rejects malformed nested fields through real script execution; existing update regressions return GREEN.
-
review_mode:
cli; primary plus challenger. -
assigned_skills:
codebase-design,tdd,simplify. -
implementation_skill_guidance: Keep semantic invalidation lineage in the common plan; keep filesystem hashes in receipts/managed state.
-
tdd_status:
required; tdd_target: selective invalidation matrix and no-op repeat. -
red_command:
bun run --cwd apps/cli test -- src/features/context-planning/compiler.test.ts src/update/run.test.ts. -
expected_red_failure: Prompt content change causes broad reauthoring or ordinary source edits schedule work.
-
green_command:
bun run --cwd apps/cli test -- src/features/context-planning/compiler.test.ts src/update/run.test.ts. -
evidence: Empty pending delivery.
-
codebase_design_notes: Invalidation is a dependency calculation exposed through the real public plan compiler result, using portable explicit revision declarations. Pure calculation tests support that responsibility but do not prove downstream receipt/check/handoff acceptance.
-
runtime_validation:
required -
runtime_procedure:
update/check --jsonon changed input fixtures. -
runtime_target: selected scoped guidance, authoring actions and native projections.
-
runtime_evidence: Empty pending delivery.
-
runtime_cleanup: Remove temporary fixtures.
-
status:
Complete -
parent_gate_evidence:
.devpunks/delivery/v43/IP-468/parent-task-gate.json. Parent task-responsibility gate passed at the retained source identities; full AC-032 remains IP-469 integration; archive declaration consistency passed in.devpunks/delivery/v43/IP-468/archive-authoring-readback.json. See IMPLEMENTATION-NOTES.md W2 public repair gates.
T7 — IP-467 — portable migration
- depends_on:
[T1, T5] - location: receipt/manifest migration, portable identity and worktree verification modules/tests.
- description: Migrate known legacy state once, retain authored material, ignore irrelevant formatting/order/location changes, and reverify machine-local hooks after relocation while preserving behavior-significant order.
- validation: AC-016, AC-021, AC-022; next unchanged update is a no-op.
- review_mode:
cli; primary plus challenger. - assigned_skills:
codebase-design,tdd,verify-behavior. - implementation_skill_guidance: Migration is finite and input-bound; do not rewrite retained workflow records.
- tdd_status:
required; tdd_target: legacy, moved-worktree, formatting/order and repeated-update cases. - red_command:
bun run --cwd apps/cli test -- src/update/run.test.ts. - expected_red_failure: Legacy migration repeats or loses authored material.
- green_command:
bun run --cwd apps/cli test -- src/update/run.test.ts. - evidence:
.devpunks/delivery/v43/IP-467/parent-task-gate.json; sourcesource-freeze-10.jsonand final W4 reviews retain exact identities. - codebase_design_notes: Portable identity parser/migrator is a deep module behind receipt reconciliation.
- runtime_validation:
required - runtime_procedure: Moved disposable worktree and legacy receipt fixture.
- runtime_target: receipts, manifests, hooks and authored records.
- runtime_evidence:
.devpunks/delivery/v43/IP-469/native-proof/execution-d779d846/ACCEPTANCE.json; task gate preserves prior portability/handoff/recovery runtime provenance. - runtime_cleanup: All bounded native roots removed after retained readback.
- status: Complete.
T8 — IP-469 — bounded handoff and projection
- depends_on:
[T5, T6] - location: post-command handoff, agent-authored output validation, native projection and receipt publication modules/tests.
- description: Emit residual actions with exact scope, trigger, input identity, allowed outputs and completion evidence. Validate authored results and mechanical aliases before proof; preserve authored guidance and custom roles. Keep source-first reusable skill changes.
- validation: AC-008 and AC-028–AC-032; no-op stale prose does not reschedule completed work. Consume T6 invalidation scope/reason/input identity with T5 receipt state and prove affected stale evidence in check plus bounded update handoff before AC-032/RAC-006 completion. Capability reader/archive compatibility is owned and verified by T1.
- review_mode:
cli; primary plus challenger. - assigned_skills:
codebase-design,tdd,verify-behavior. - implementation_skill_guidance: Handoff is a bounded residual contract; deterministic CLI validation remains the completion authority.
- tdd_status:
required; tdd_target: authored output, alias projection, stale handoff and first-reader compatibility cases. - red_command:
bun run --cwd apps/cli test -- src/content/handback.test.ts src/update/run.test.ts. - expected_red_failure: Handoff lacks input-bound completion evidence or aliases/proof diverge.
- green_command:
bun run --cwd apps/cli test -- src/content/handback.test.ts src/update/run.test.ts. - evidence:
.devpunks/delivery/v43/IP-469/parent-task-gate.json; sourcesource-freeze-05.jsonand final W4 reviews retain exact identities. - codebase_design_notes: Handoff parser/validator is a small public seam over deterministic projection.
- runtime_validation:
required - runtime_procedure: scaffold/update followed by handoff completion and check readback.
- runtime_target:
.agents/AGENTS.md, aliases, native definitions, receipt. - runtime_evidence:
.devpunks/delivery/v43/IP-469/native-proof/execution-d779d846/ACCEPTANCE.json; task gate preserves prior portability/handoff/recovery runtime provenance. - runtime_cleanup: All bounded native roots removed after retained readback.
- status: Complete.
T9 — IP-471 — routine installation and Commit Gate proof
-
depends_on:
[T4, T5, T2] -
location: quality/dependency installation, Lefthook runner/configuration, operational readback and tests.
-
description: Complete authorized routine setup and verify actual commands, dependencies and hook operation. Preserve conflicting manager policy and truthful partial progress; leave only unresolved interpretation work.
-
validation: AC-003–AC-005, AC-020, AC-029 and AC-031; fresh supported repository reaches working setup and failures preserve completed independent actions.
-
review_mode:
cli; primary plus challenger. -
assigned_skills:
codebase-design,tdd,verify-behavior. -
implementation_skill_guidance: Install through existing runtime adapters and verify operational state, never by receipt declaration alone.
-
tdd_status:
required; tdd_target: fresh setup, opt-out, conflict and partial failure. -
red_command:
bun run --cwd apps/cli test -- src/update/run.test.ts. -
expected_red_failure: Planned quality/hook setup is not installed or proof advances without live verification.
-
green_command:
bun run --cwd apps/cli test -- src/update/run.test.ts. -
evidence:
.devpunks/delivery/v43/IP-471/work-start-readback.json; W4 release isscaffold-w4-gate.json. -
codebase_design_notes: Runtime installer is an adapter behind the common plan; keep policy resolution and proof separate.
-
runtime_validation:
required -
runtime_procedure: Fresh repository with actual dependency and hook command readback.
-
runtime_target: package manifest, lockfile, scripts, Lefthook runner/config and receipt.
-
runtime_evidence: Final installation, public command, and post-sync execution04 evidence retained under
.devpunks/delivery/v43/. -
runtime_cleanup: Remove disposable repository and candidate artifacts.
-
status:
Complete; final proof includes expected command statuses[0, 1, 1, 0, 1, 1]and the focused regression for the zero-file Oxlint prefix defect. -
additional_reserved_paths:
apps/cli/src/platform/commit-gate-capabilities.ts,apps/cli/src/cli/commit-gate-command.tsand direct tests if operational verification requires them; parent reservation follows retained preflight. -
live_entrypoint_reservation:
apps/cli/src/scaffold/stage.tsand direct stage tests for the post-materialization installation call.IP-471/native-red/RESULT.jsonconfirms absent local binaries, active hook and CLI proof after fresh scaffold/update. Keep isolated candidate artifact generation separate from live installation. -
W5 worker custody:
scaffold_t5exclusively ownsplatform/commit-gate-capabilities.tsand direct tests;scaffold_t7owns live setup orchestration and the remaining T9 reservations. Coordinate observation contracts before cross-file changes; parent combines source freezes and controls builds. -
W5 source-review repair custody:
scaffold_t5exclusively ownsfeatures/commit-gate/quality.tsand new directquality.test.tsfor read-only formatter contract validation;scaffold_t7owns setup/index/output/update and their direct tests. Preserve source-freeze01/build01 and source reviews; parent rebuilds after repaired source freezes. -
fresh_selection_reservation:
scaffold_t7may editfeatures/context-planning/compiler.ts,integrations/repository-detector.tsand direct tests to detect an explicitly declared supported package manager without a lock and plan the existing Commit Gate contribution for a resolved supported manager and quality contract before the initial lockfile exists. OUT-002/AC-003 requires fresh setup; live installation must produce and verify actual dependency state before proof. Preserve unresolved manager/quality blockers. -
W5 diagnostic reservation: After failed packaged build03 first-scaffold proof,
scaffold_t7owns instrumentation inplatform/feature-application-operations.ts,platform/scoped-scaffold-operation.ts, existingfeatures/commit-gate/setup.tsandupdate/run.ts. This wave gathers runtime evidence only; implementation follows a confirmed cause.scaffold_t3owns the isolated reproduction driver/evidence underIP-471/debug-fresh-scaffold. Parent owns builds and runtime release; retain prior freezes and failed execution evidence. See.devpunks/delivery/v43/IP-471/debug-fresh-scaffold/STATE.json. -
W5 confirmed-path repair: Diagnostic
execution-0a31b18d/runtime.ndjsonconfirms public repository scaffold omits live setup despite receiving five planned dependencies.scaffold_t7ownsplatform/scoped-scaffold-operation.ts, its direct tests and adapter for the existing live setup call and truthful operational failure handling. Keep instrumentation through before/after proof. Update/compiler/output remain frozen whilescaffold_t3assesses the independently confirmed late wiki planning omission. Parent controls builds and reviews. -
H1 setup contract alignment: T7 may narrow
features/commit-gate/setup.tsinput to its consumed dependencies/files/context plan and actual Commit Gate policy, allowing the public path’s existing compiled catalog. Preserve setup behavior and policy authority; validate stage/update callers and direct setup tests. Retain failed initial type/test attempts as diagnostic history. -
W5 disjoint lint repair:
scaffold_t5owns onlyscaffold/output.test.tsfor the twelve retained current-goal lint errors. Preserve assertions and test behavior; retain focused lint/test proof. Other source freezes remain authoritative at their recorded hashes. -
W5 update-test lint custody: After the nineteen output tests and independent lint review passed, T5 owns only existing
update/run.test.tsfor its twenty-one retained lint errors. T3 uses new focused H4 test files. Preserve assertions, ordering and exact scenario coverage; parent reviews final hashes and validation. -
W5 same-operation workspace repair:
scaffold_t3ownsupdate/run.tsand focused helper/tests to compile the wiki package that update already elects to generate into the same desired dependency/topology plan before installation. Existing output/compiler seams may receive a minimal planned-manifest overlay; coordinate any additional path before writing.output.test.tsstays with T5 and public scaffold platform files with T7. This repair preserves public scaffold file selection; the specification does not independently require fresh scaffold to create a wiki. Runtime evidence isexecution-0a31b18d/runtime.ndjsonlines 4–6. Preserve independent workspace coverage and the first post-completion no-op oracle. -
Independent candidate diagnostic: T7 owns
runtime/scripts.test.tsand instrumentation-onlyruntime/scripts.tsfor the H4-exposed independent-package path under IP-470. Use ordinary versus candidate installation/command proof without inventing root workspace membership. Source mutations and runtime execution wait for T5’s matched-test production freeze release. Parent chooses repair only after runtime evidence; task-local evidence lives under.devpunks/delivery/v43/IP-470/independent-candidate-diagnostic/. -
Current disjoint repair wave: T3 owns
integrations/repository-detector.tsand direct tests for declared-member supported manager inheritance before a lock exists, with explicit child and lock provenance controls. T5 owns only the scoped-proof fixture inupdate/run.test.ts: retain unknown-to-known-via-lock intent, compatible TS5.7.3, exact authority/proof/no-op assertions. T7 ownsruntime/scripts.tsand direct tests for candidate-relative installation failure context after H5 review. Runtime diagnosis is retained inH4-SETUP-DIAGNOSIS; TS7/utils peer failure stays truthful and production dependency versions remain unchanged. Parent controls combined build and native release.
Architecture applicability
architecture_applicability: architecture-bearing. The work changes the
baseline schema, selected-baseline reader, common plan model, command
orchestration, update reconciliation, candidate adapter and receipt/handoff
composition across packages/scaffold and apps/cli. A local-task
classification would hide these cross-owner edges.
Target Ownership Topology
packages/scaffold baseline schema + capability metadata
-> apps/cli baseline reader/resolution/materialization
-> Context Plan / Scaffold Plan
-> check, update, scaffold and candidate adapters
-> managed output, aliases, receipt and residual handoffpackages/scaffold owns portable baseline metadata/schema. apps/cli owns
filesystem asset reading, capability validation, command policy, observation,
writes, candidate isolation and operational proof. The selected baseline is the
only shared-prompt source.
Repository authored root/scoped guidance remains outside that managed artifact.
Declared Dependency Graph
Allowed module edges are packages/scaffold schema -> CLI baseline reader ->
Context/Scaffold Plan -> command materialization/check -> receipt/presentation,
plus the candidate adapter consuming the common plan. The baseline package must
not import CLI command orchestration; the CLI must not read an installed prompt
as a fallback; check must not invoke mutating update; native aliases must
consume the managed shared file and never become an independent source. The
graph is acyclic. Provider task blockers are tracked separately below.
Responsibility Acceptance Criteria
| Criterion | Owner | Observable assertion | Evidence | Architecture wave |
|---|---|---|---|---|
| RAC-001 | packages/scaffold | Versioned capability, archive asset path and digest decode through one public baseline seam. | T1 focused baseline tests and metadata readback | A1 |
| RAC-002 | apps/cli baseline/update | Selected baseline asset is materialized as scaffold-owned .agents/AGENTS.md; no npm fallback. | T1 public scaffold/update/check matrix | A1 |
| RAC-003 | Context/Scaffold Plan | Prompt identity and ownership flow into desired state and receipts. | T1/T5 plan and receipt assertions | A2 |
| RAC-004 | check/report | Independent findings retain exact blocked and healthy component evidence. | T3 JSON result matrix | A2 |
| RAC-005 | candidate adapter | Candidate uses planned workspace topology and preserves live state. | T2 disposable monorepo | A2 |
| RAC-006 | invalidation/handoff | Prompt-only changes refresh the managed file without broad scoped reauthoring; authored scopes survive. | T6/T8 selective update matrix | A3 |
| RAC-007 | publication/receipt | Partial work and recovery are input-bound and cannot claim unapplied output. | T5 interruption matrix | A3 |
| RAC-008 | installation/proof | Routine quality and hook setup is operationally verified before completion. | T9 fresh repository readback | A4 |
Architecture Waves
| Wave | Topology delta | Entry | Criteria due | Checkpoint |
|---|---|---|---|---|
| A1 | Establish capability reader and scaffold-owned shared-prompt authority. | none | RAC-001, RAC-002 | Verify selected baseline asset and no fallback. |
| A2 | Connect plan, check, candidate and quality consumers to the common seam. | A1 | RAC-003, RAC-004, RAC-005 | Recheck ownership edges and public results. |
| A3 | Add invalidation, publication recovery and bounded projection proof. | A2 | RAC-006, RAC-007 | Recheck cumulative receipts, aliases and handoff. |
| A4 | Complete operational installation and final convergence. | A3 | RAC-008 | Verify all acceptance criteria and empty migration ledger. |
Public Seam Contract
The affected consumer-facing seams are the scaffold, update and check --json commands; selected-baseline resolution; Context/Scaffold Plan output;
candidate validation; projection receipt; and Post-Command Handoff. Their
owners and allowed consumers are apps/cli command modules, baseline
resolution, plan compiler, candidate runtime, and receipt/presentation modules
respectively. Downstream work must amend this contract before changing a seam.
Migration Ledger
No temporary seam is planned. T1 removes the installed-template lookup as the shared-prompt authority and removes the broad shared-file preservation exemption. Unsupported capability remains a durable explicit result required by AC-041, not a migration adapter. The ledger is therefore empty at plan start and must remain empty at final closure.
Validation gates
Before advancing each edge, the worker records focused RED and GREEN evidence,
public command output, changed paths and preservation checks. The parent then
validates the complete native graph and the full acceptance matrix (AC-001
through AC-045), including all shared-prompt capability cases. Run formatting,
git diff --check, the wiki content check and the relevant CLI Vitest suite.
Final runtime evidence must include both known consumer targets (collective- intelligence and /ci-emera) or equivalent disposable reproductions, with
exact baseline/CLI versions, selected asset identity, before/after shared
prompt bytes, aliases and receipts. Do not claim issue #197 is fixed until the
workspace executable topology and shared-prompt update behavior both pass.
The task-level coverage ledger is explicit so no accepted criterion is lost in the provider projection:
| Criteria | Task owner(s) |
|---|---|
| AC-001, AC-002 | T1, T3, T5 |
| AC-003, AC-004, AC-005 | T4, T9 |
| AC-006, AC-007 | T3 |
| AC-008, AC-009, AC-010, AC-011, AC-012, AC-013, AC-014, AC-015 | T1, T3 |
| AC-016, AC-021, AC-022 | T7 |
| AC-017, AC-018, AC-019, AC-020 | T5, T9 |
| AC-023, AC-024, AC-025, AC-026, AC-027 | T6 |
| AC-032 | T6 prerequisite invalidation; T8 integrated receipt/check/handoff proof |
| AC-028, AC-029, AC-030, AC-031 | T8, T9 |
| AC-033, AC-034, AC-035, AC-036 | T2 |
| AC-037, AC-038, AC-039, AC-040, AC-041, AC-042, AC-043 | T1 |
| AC-044 | T5 |
| AC-045 | T1 |
Release classification follows changed changelog paths. The first capability reader publication is a compatible CLI/baseline release decision; later prompt-only baseline updates remain baseline work. No release is executed by this plan.
Unresolved questions
- Actual compatible version numbers and publication commit are delivery-time facts; preserve the schema's compatibility range and read back the selected baseline metadata.
- Exact module/field names are implementation choices inside the public capability seam; do not add a second registry or fallback source.
- Exact root cause of the original #197 failure remains an evidence target until reproduced in a disposable real install.
Resolved decision ledger
.agents/AGENTS.mdis wholly scaffold-owned.- Its selected content authority is
baseline.dataRoot/shared-agents.md; the published archive stores that asset asdata/shared-agents.md. - The installed npm CLI template is never a silent fallback.
- Root/scoped authored guidance and custom roles retain their own protection.
- Existing nine provider Tasks and eleven native blocker edges remain intact.
- Shared prompt content changes do not trigger broad scoped reauthoring.
- Receipts attest observed, input-bound completion only.
- Parent coordinates, reviews, validates and advances waves; workers own the implementation scopes above.
W3 publication ownership clarification
T5 also owns scaffold/output.ts, scaffold/output.test.ts and update/run.test.ts for the already accepted initial scaffold and update publication boundaries. W2 has released these reservations; T8 receives the resulting output seam in W4. This serial ownership clarification implements T5’s existing materialization and interruption tests without changing requirements or dependencies.
W4 test reservations
T7 owns update/run.test.ts; T8 owns scaffold/output.test.ts and content tests. These extend each existing production seam to its tests without changing dependencies. T7 can make the equivalent T3-owned optional-boolean lint correction inside its run.ts reservation and retain the repository-check regression. All other source overlap returns to the parent.
W4 projection publisher reservation
T8 owns the existing sync-subagents.mjs completion/publisher entrypoint and runtime/scripts.test.ts for its accepted bounded authoring/projection proof. T6/T2 released these paths; T7 has no overlapping reservation. Runtime production adapters remain outside T8 ownership unless separately coordinated. Canonical reusable skills remain frozen and source-first.
W4 bounded-authoring consumer coordination
T8 owns one portable authoring helper under harness-projection plus its declaration file. Existing compiler identity calculation imports that helper; T7 normalization preserves set-valued authoring contracts/missingContracts and behavior-significant contribution order. T8 freezes a compact assessment API before T7 consumes it. T7 remains sole update/run.ts writer and integrates current desired-plan/receipt assessment into existing observation and residual handoff routing. T8 maps any new typed facts through repository-check only as needed; the update observer remains the single filesystem assessment.
This is a producer→consumer handoff within W4: T7 continues independent portable/migration work while awaiting the helper; T8 continues projection/publisher work while T7 wires the observer. Both native Tasks retain their original acceptance ownership. IP469 gate requires paired helper/publisher/update/check evidence. Existing T5 recovery, T3 independent diagnostics and T2 candidate safety remain required. Shared build occurs only after affected source reservations freeze.