Harness Intelligence Wiki
SpecsCLIReliable Scaffold Lifecycle

Plan: Reliable Scaffold, Update and Check Lifecycle

Plan: Reliable Scaffold, Update and Check Lifecycle

Overview

Implement the accepted issue-197-scaffold-lifecycle specification in the existing V4.3 Delivery Flow and Scaffold Reliability iteration. The principal fix is an explicit, versioned shared-prompt capability: .agents/AGENTS.md is fully scaffold-owned and is read from the selected baseline asset archive member data/shared-agents.md, materialized at baseline.dataRoot/shared-agents.md. The installed npm CLI's bundled template is never a silent fallback. Root/scoped repository AGENTS.md files, authored roles, and custom guidance retain their separate ownership contracts; .claude/CLAUDE.md and .opencode/AGENTS.md remain mechanical mirrors.

This plan preserves the nine existing provider Tasks and their native eleven blocker edges. No new task graph, service, executor, dependency, or release is introduced. Runtime implementation and release remain unauthorized until the delivery owner starts the plan.

Authority and constraints

Execution resumed 2026-09-06 on the user-prepared integration branch team/stefan/v4.3-delivery-scaffold at 1e6b2b2ae733f2f84379ab4ac4d9d170177759df, targeting main. This supersedes the planning branch intent below. The user authorized implementation and the canonical shared-skills clone at /home/stefan/repos/skills, with edits directly on main. Native task identities, acceptance criteria, write reservations, and validation gates remain unchanged.

  • Specification: ./SPEC.md (accepted, agent-ready; immutable publication at d2ce164aee1f59755fce84cbff40afed9e4ed087).
  • Source issue: GitHub issue #197.
  • Iteration: V4.3 Delivery Flow and Scaffold Reliability.
  • Provider identity: IP-456/IP-457 with Tasks IP-463 through IP-471.
  • Branch/base intent: team/stefan/issue-197-scaffold-architecture, based on b9bb213dc490753020501ef81f42978d1caee89e; verify ancestry before delivery.
  • Code evidence revision used for path grounding: 4403e1095c22a4bc8f2e9a63bcec60e45cb8c4f8.
  • Existing source-first reusable skill policy, issue #181 candidate safety and issue #194 receipt validation remain in force.
  • First publication of the capability-aware reader requires a compatible CLI and baseline release. Choose the actual version during authorized delivery; do not invent one in this plan. Later prompt-only baseline changes do not require an npm CLI bump.

Architecture and ownership contract

packages/scaffold owns the baseline metadata/schema and the public capability model. The selected baseline reader resolves and validates the declared asset path, digest and reader compatibility. The common Context Plan/Scaffold Plan must carry selected baseline/template identity into materialization and update comparison. apps/cli owns command orchestration, observation, reconciliation, candidate validation and truthful result publication.

selected baseline
  -> capability metadata + dataRoot/shared-agents.md
  -> Context Plan / Scaffold Plan (identity, hash, ownership)
  -> observe/check or apply update
  -> aliases and projections
  -> verified receipt / residual handoff

The shared prompt is a complete baseline-owned managed artifact. A local edit, missing file or stale prior digest participates in ordinary authorized reconciliation and may be replaced by the selected baseline. Capability is explicit: an old baseline without it is an unsupported capability result; a declared capability with a missing or mismatched asset is an integrity error. Neither case may read apps/cli's installed shared-agents.md as fallback.

The contract must distinguish content authority from required presence/validity. Do not generalize this ownership to all files ending in AGENTS.md; do not use broad kind or path exemptions to skip required checks. Preserve authored root/scoped guidance and mixed-file entries according to their own contracts.

Provider task graph

AliasProvider taskScopeDepends on
T1IP-463explicit artifact obligations, shared-prompt capability/reader and reconciliation—
T2IP-470faithful candidate workspace topology—
T3IP-464independent health findings and exact unknownsT1
T4IP-465quality defaults and repository overridesT1
T5IP-466coupled output, receipt and publication recoveryT1
T6IP-468contract/scope-based invalidationT1
T7IP-467portable identity and finite legacy migrationT1, T5
T8IP-469bounded post-command handoff and deterministic projection proofT5, T6
T9IP-471routine quality and Commit Gate installation/proofT4, T5, T2

Native provider blockers are authoritative. The graph has eleven edges: T1→T3, T1→T4, T1→T5, T1→T6, T1→T7, T5→T7, T6→T8, T5→T8, T4→T9, T5→T9 and T2→T9.

Execution waves and write reservations

Tasks are assigned one worker per provider identity. Where apps/cli/src/update/run.ts or shared baseline models overlap, the owner must finish and publish its seam before the next task starts; this is sequencing by write reservation, not a new provider blocker.

WaveTasksReservation rule
W1T1Establish baseline capability and ownership; reserve shared update and scaffold seams.
W2T2, T3, T4, T6Launch all four disjoint scopes. T2 reserves update/run.ts first, then explicitly releases its bounded reporting producer to T3; T4 reserves output.ts quality planning; T6 reserves model/compiler and explicit baseline declaration producers; reporting stays separate.
W3T5Publish and recover receipts after the shared update reservation clears.
W4T7, T8Launch portable-state recovery and handoff/projection together with disjoint source and test ownership.
W5T9Complete routine installation after shared update and output reservations clear.
W6integrationParent validates cumulative public results, provider graph and documentation; workers own any implementation corrections.

Task contracts

All tasks use task_identity_mode: provider-task, relation_mode: native, and backlog_sync_skip_reason: (the provider projection is complete). Each task's backlog_item_id is its IP identifier below; the corresponding URL is https://linear.app/devpunks/issue/<id>. status is Planned, log, files edited/created, red_evidence and green_evidence start empty and are filled by implement-spec. Every task has runtime_validation: required. The following matrix supplies the per-task identity, owned paths and worker wave fields required by the execution contract:

Taskbacklog_item_id / parent Storybacklog_item_urlowned_pathswave_boundary
T1IP-463 / IP-459https://linear.app/devpunks/issue/IP-463packages/scaffold/src/baseline.ts, packages/scaffold/src/baseline/, packages/scaffold/src/context-plan.ts, apps/cli/scripts/build-baseline.mjs, apps/cli/scripts/build-dist.mjs, apps/cli/src/baseline/, apps/cli/src/content/prompts.ts, apps/cli/src/scaffold/, apps/cli/src/platform/scoped-scaffold-operation.ts, apps/cli/src/update/run.ts, focused testsW1
T2IP-470 / IP-462https://linear.app/devpunks/issue/IP-470apps/cli/src/runtime/scripts.ts, apps/cli/src/runtime/scripts.test.ts, apps/cli/src/update/run.tsW2
T3IP-464 / IP-459https://linear.app/devpunks/issue/IP-464apps/cli/src/features/repository-check/application.ts, apps/cli/src/features/repository-check/application.test.ts, apps/cli/src/features/repository-check/port.ts, apps/cli/src/platform/feature-application-operations.ts (repository-check result forwarding only), apps/cli/src/update/run.ts (typed obligationFindings and read-only assessment consumption in comparison/UpdateResult/check return, only after explicit T2 custody release), apps/cli/src/presentation/operation-result/W2
T4IP-465 / IP-458https://linear.app/devpunks/issue/IP-465apps/cli/src/scaffold/preflight.ts, apps/cli/src/scaffold/settings-selection.ts, apps/cli/src/features/commit-gate/, apps/cli/src/scaffold/settings-selection.test.ts, apps/cli/src/integrations/repository-detector.ts, apps/cli/src/scaffold/output.ts (quality generation, existing-scope manifest attachment and reviewed check-assessment wrapper only)W2
T5IP-466 / IP-460https://linear.app/devpunks/issue/IP-466apps/cli/src/features/scaffold-state/, apps/cli/src/scaffold/stage.ts, apps/cli/src/scaffold/output.ts, apps/cli/src/scaffold/output.test.ts, apps/cli/src/update/run.ts, apps/cli/src/update/run.test.ts, packages/scaffold/src/baseline/managed-file.tsW3
T6IP-468 / IP-461https://linear.app/devpunks/issue/IP-468apps/cli/src/features/context-planning/compiler.ts, apps/cli/src/features/context-planning/compiler.test.ts, apps/cli/src/features/context-planning/index.ts, apps/cli/src/platform/scoped-scaffold-operation.ts, packages/scaffold/src/context-plan.ts, packages/scaffold/src/baseline/capabilities.ts, apps/cli/src/scaffold/models.ts, apps/cli/src/features/repository-analysis/model.ts (QualityCommandEvidence unresolvedReason only), apps/cli/src/data/scripts/sync-subagents.mjs (scopeIssue optional authoring schema validation only), apps/cli/scripts/build-baseline.mjs and apps/cli/src/baseline/bundled.ts (explicit authoring/activation declaration producers only)W2
T7IP-467 / IP-460https://linear.app/devpunks/issue/IP-467apps/cli/src/features/scaffold-state/, apps/cli/src/update/run.ts, apps/cli/src/update/run.test.ts, packages/scaffold/src/baseline/managed-file.tsW4
T8IP-469 / IP-461https://linear.app/devpunks/issue/IP-469apps/cli/src/content/handback.test.ts, apps/cli/src/content/, apps/cli/src/data/scripts/harness-projection/, apps/cli/src/data/scripts/sync-subagents.mjs, apps/cli/src/runtime/scripts.test.ts, apps/cli/src/scaffold/output.ts, apps/cli/src/scaffold/output.test.ts, apps/cli/src/features/context-planning/compiler.ts (identity helper import/substitution only), apps/cli/src/features/repository-check/{application.ts,application.test.ts,port.ts} (typed fact mapping only)W4
T9IP-471 / IP-458https://linear.app/devpunks/issue/IP-471apps/cli/src/integrations/tool-management.ts, apps/cli/src/features/commit-gate/, apps/cli/src/scaffold/output.ts, apps/cli/src/update/run.tsW5

Test write reservations follow the owned-path table. T2 owns apps/cli/src/runtime/scripts.test.ts; T3 owns repository-check tests; T4 owns settings-selection tests; T6 owns compiler tests. In W2, any existing apps/cli/src/update/run.test.ts invocation by T6 is read-only regression execution. T5 and T7 may edit that shared test in their sequential waves; T8 writes apps/cli/src/content/handback.test.ts and only runs existing update tests. T9 may edit update tests after W4. T1 owns baseline and scaffold test additions in W1. Running an existing test does not grant file-write ownership.

W2 ownership amendment (2026-09-06)

W1 T1 Task Gate and A1 passed; its source reservations are released. This amendment grounds the already accepted quality and invalidation responsibilities in their actual producers and consumers. It preserves all nine task identities, eleven native blocker edges, acceptance criteria and architecture-wave gates.

  • T2 exclusively writes runtime/scripts.ts and its test plus update/run.ts until the parent records explicit source-custody release. T3 may then acquire only the update/run.ts comparison, UpdateResult and check-return hunks that produce typed obligationFindings. T3 also exclusively writes repository-check application/tests/port, result presentation, and the repository-check forwarding seam in platform/feature-application-operations.ts. Forward exact findings from observed artifact obligations; the check branch's placeholder reconciliation status planned with empty outcomes/actions is not evidence of pending work. Preserve the common lifecycle contract. T2-to-T3-to-T5 custody is a sequential file reservation, not a new native blocker; disjoint work continues.

  • T4 exclusively writes its quality resolver/integration files, repository-detector.ts, and two bounded scaffold/output.ts seams: applyLintConfigs consumes features/commit-gate/quality.ts, and an existing compiled scope receives its detected manifest without losing scope metadata. The latter lets a root scope initially created with manifest: null contribute the resolved Commit Gate. T8 and T9 acquire output.ts only in their later sequential reservations.

  • T6 exclusively writes the listed model/compiler/platform files and the explicit authoring/activation declarations produced by build-baseline.mjs and baseline/bundled.ts. It does not write output.ts or change quality contributions. packages/scaffold retains portable schema/model ownership; baseline producers supply explicit revision declarations rather than infer semantics from content.

  • T4 reads the compiled scope shape and T6 contract model; T6 reads the stable T1 capability reader, selected baseline identity, output.ts compiler call and desired-state encoder. T4 preserves scope lineage while attaching manifests. T6 preserves quality contribution interfaces. T3 reads the existing ArtifactObligation and lifecycle comparison contracts, produces typed cause/consumer findings in the comparison result, and forwards those exact findings through UpdateResult and its port/adapter. JSON presentation remains application-owned; generic local-edited diffs or placeholder reconciliation state cannot substitute for observed unknown/invalid/pending obligations. Its adapter file is separate from T6 platform/scoped-scaffold-operation.ts. Record relevant input hashes before and after checks; a changed shared input requires affected checks again. T2 explicitly released update/run.ts custody on 2026-09-06; preserve its executeLintPreview manifestSource: "live" change. T2 retains runtime/scripts.ts and its test. T3 may acquire the bounded comparison/result/check-return reservation after the focused independent plan review; no concurrent update/run.ts writes are authorized.

  • Source custody transfers only after the parent verifies released scopes. Shared builds, generated baseline/dist artifacts, source synchronization and final combined validation remain parent-reserved operations; workers request the needed build and consume its recorded identity. Existing test execution grants no write ownership over shared tests or generated output.

T3 validates AC-007 through actual compareObservedState → runCheck → publicCheckResult in its existing application.test.ts. Before producer/forwarding edits, capture RED for an actual unknown ArtifactObligation beside an independently healthy or changed managed artifact: retain exact status, artifact path, cause and affected producer/consumers with nonzero health even when bytes match. Extend coverage to invalid authored and pending generated obligations; healthy check results must not become pending merely because reconciliation.status is the placeholder planned. After the parent-reserved build, retain real hi check --json output for the obligation fixture and prove repository bytes unchanged. Manually constructed application-only results do not establish production producer/adapter proof.

T4's existing public-planner RED is retained at .devpunks/delivery/v43/IP-465/defaults-red.log: supported fresh-repository planning omitted required package scripts. Before repairing existing-scope manifest attachment, extend the public planner test to prove the missing root Commit Gate contribution and record its actual RED. Pure resolver tests alone cannot prove either planner integration.

T6 also owns the distributed native parser's bounded schema-consumer update in apps/cli/src/data/scripts/sync-subagents.mjs scopeIssue(). Actual regression evidence .devpunks/delivery/v43/IP-468/green-matrix.log records six existing update tests failing with Context scope fields are invalid because the old exact-key validator rejects optional scope.authoring. Accept that optional field consistently with packages/scaffold/src/context-plan.ts: exact {path, kind, contracts, missingContracts}; path/kind are nonempty strings, contracts contains exact {id, authoringRevision, activationRevision} records of nonempty strings, and missingContracts contains nonempty strings. Reject unknown keys and malformed values at every nested level. Scopes without authoring remain valid.

This reservation changes input validation only; projection behavior and T8 handoff ownership remain unchanged, with any later native-script custody transferred sequentially. T6 uses its existing compiler.test.ts ownership to exercise the actual distributed script through a disposable subprocess fixture: valid optional lineage succeeds, omitted lineage stays compatible, malformed new fields fail before output mutation. Retain real RED/GREEN for that public script result and rerun the existing six update regressions. Do not substitute a duplicated test-only validator or only a package-schema test.

T6's prerequisite Task Gate proves the actual public invalidation/Context Plan result: affected scope, reason and input identity for the accepted change matrix, with explicit declared baseline revisions and preserved unrelated scope lineage. This gate may release native dependent T8. It does not establish complete AC-032: receipt-bound stale-action evidence, check reporting and update bounded handoff remain final-unproven until T8 consumes that result with T5 publication state. RAC-006 remains due at A3 with the full T6/T8 public matrix; the final criterion and Story cannot be marked complete from pure calculation tests. No cumulative gate or accepted requirement is weakened by distinguishing prerequisite readiness from final integrated proof.

Each task contract below repeats its exact depends_on and validation. For every task, reason_not_testable is empty because the behavior is testable through public CLI seams; red_evidence and green_evidence are intentionally empty until execution.

Architecture-bearing fields apply to every task as follows. These are the per-task responsibility bindings used by the worker handoff:

Taskarchitecture_wavebehavior_ownerintegration_surfacepublic_seamtopology_deltaforbidden_ownershiptemporary_seamsresponsibility_acceptance_criteria
T1A1baseline capability modelCLI baseline resolution/updateselected-baseline readeradd capability-aware shared-prompt sourceinstalled npm prompt, authored scoped filesnone plannedRAC-001, RAC-002
T2A2candidate validationscaffold/update candidate operationcandidate validation resultpreserve workspace executable topologylive consumer statenoneRAC-005
T3A2health result aggregationcheck presentationcheck --jsonretain independent findingsmutating producersnoneRAC-004
T4A2quality contract resolutioncommon scaffold planquality contractresolve defaults and overridesguessed manager migrationnoneRAC-003
T5A3publication/recovery statematerializer and receiptsreceipt/pending resultinput-bound recoverable transitionsfalse completion, second persistence enginepending evidenceRAC-003, RAC-007
T6A3dependency invalidationContext/Scaffold Planinvalidation resultselective affected-work schedulingbroad reauthoringnoneRAC-006
T7A3portable migrationreceipt/worktree reconciliationmigration resultfinite legacy convergencedeleting authored recordsnoneRAC-007
T8A3handoff/projection validationnative harness projectionPost-Command Handoffbounded residual authoringself-declared completion, independent prompt sourcenoneRAC-006, RAC-007
T9A4routine installation proofruntime setup adaptersoperational command resultverified quality/hook setupbypassing conflicts or receiptsnoneRAC-008

Skill guidance is attached to each task rather than inherited implicitly:

TaskSkill guidance (skill: applicable_behavior)
T1codebase-design: keep capability loading behind one deep public reader seam; tdd: capture public command RED before production changes; simplify: remove only the broad exemption made obsolete; verify-behavior: verify selected asset, ownership and no fallback through command results.
T2codebase-design: isolate candidate preparation behind a substitutable adapter; tdd: test executable resolution through the public candidate flow; verify-behavior: prove containment, disabled scripts and live-state isolation.
T3tdd: test observable JSON findings and exit status; simplify: keep independent result aggregation local; verify-behavior: preserve healthy evidence beside exact blockers.
T4tdd: test defaults, overrides and opt-out through public commands; simplify: keep quality policy separate from artifact ownership; verify-behavior: read back resolved commands and preserved policy.
T5codebase-design: model publication as input-bound state transitions; tdd: interrupt one public boundary per cycle; verify-behavior: prove receipt truth and resumability.
T6codebase-design: keep invalidation as a dependency calculation behind the plan compiler seam; tdd: test selective scheduling through update/check; simplify: avoid broad reauthoring triggers.
T7codebase-design: keep migration finite behind portable identity reconciliation; tdd: test legacy, relocation and repeat behavior publicly; verify-behavior: prove authored retention and local-hook revalidation.
T8codebase-design: keep handoff residual and projection deterministic; tdd: test authored completion through CLI validation; verify-behavior: prove aliases and receipts agree with accepted state.
T9codebase-design: keep installer and operational proof behind existing runtime adapters; tdd: test setup and partial failure through public commands; verify-behavior: read back actual hook/dependency operation.

T1 — IP-463 — explicit artifact obligations and shared-prompt authority

Execution path clarification: T1 also reserves apps/cli/src/features/scaffold-state/{desired-output.ts,model.ts,compile.ts} to carry the accepted artifact obligations and selected shared-prompt identity through the existing common desired-plan seam. This preserves the target ownership topology; T5/T7 receive the resulting contract in their later waves.

  • depends_on: []

  • location: packages/scaffold/src/baseline.ts, packages/scaffold/src/baseline/**, packages/scaffold/src/context-plan.ts, apps/cli/scripts/build-baseline.mjs, apps/cli/scripts/build-dist.mjs, apps/cli/src/baseline/resolve.ts, apps/cli/src/baseline/types.ts, apps/cli/src/content/prompts.ts, apps/cli/src/scaffold/output.ts, apps/cli/src/scaffold/stage.ts, apps/cli/src/platform/scoped-scaffold-operation.ts, apps/cli/src/update/run.ts, and related public tests.

  • description: Add versioned explicit shared-prompt capability/path/hash metadata to the existing baseline schema and builders. Read baseline.dataRoot/shared-agents.md (the archive member is data/shared-agents.md); validate capability compatibility and integrity. Thread selected baseline identity through desired state/materialization. Mark .agents/AGENTS.md fully scaffold-owned and reconcile it on authorized update, while preserving root/scoped authored files, custom roles and aliases. Remove the broad agent-prompt exemption only where it suppresses this managed obligation. Keep metadata/schema fixtures and published baseline payloads consistent.

  • validation: Public scaffold/update/check flows prove AC-001, AC-008–AC-014, AC-037–AC-043 and AC-045. Old metadata returns explicit unsupported capability; declared missing/bad asset returns integrity error; no installed-template fallback. Local shared-file edits are replaced by selected baseline; unchanged repeat is a no-op; authored scoped/root guidance survives. First compatible reader consumes the versioned capability; later prompt-only baseline publication remains consumable without a CLI bump.

  • review_mode: cli; primary autoreview plus mandatory independent risk challenger.

  • assigned_skills: codebase-design, tdd, simplify, verify-behavior.

  • implementation_skill_guidance: Use a deep baseline capability reader seam; inject/read selected baseline data through the public command path. Preserve existing Effect/version conventions and source-first baseline publication.

  • tdd_status: required for behavior changes.

  • tdd_target: Public scaffold, update and check --json behavior in disposable repositories; test one capability/integrity case at a time.

  • red_command: bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts (run focused existing/new target from apps/cli).

  • expected_red_failure: New capability-aware selected-baseline and shared-file ownership assertions fail against installed-template lookup/broad exemption.

  • green_command: bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts.

  • evidence: RED/GREEN empty until delivery; no runtime evidence claimed here.

  • codebase_design_notes: Public baseline capability reader is the seam; metadata validation and asset loading stay behind it. Avoid a second registry or fallback adapter.

  • runtime_validation: required

  • runtime_procedure: Disposable supported repositories and selected baseline archives; capability, digest, path and CLI compatibility read back.

  • runtime_target: .agents/AGENTS.md, aliases, baseline metadata, Context/Scaffold Plan, manifest and receipts.

  • runtime_evidence: Empty pending delivery.

  • runtime_cleanup: Remove disposable candidates and preserve consumer worktrees.

  • status: Complete

  • log: ``

  • files edited/created: ``

  • parent_gate_evidence: .devpunks/delivery/v43/IP-463/task-local-gate-review.md. Parent accepted A1 capability/reader and public preservation proof; source custody released. See IMPLEMENTATION-NOTES.md A1 checkpoint; later cumulative integration remains pending.

T2 — IP-470 — faithful candidate topology

  • depends_on: []
  • location: apps/cli/src/runtime/scripts.ts, candidate validation modules/tests, apps/cli/src/update/run.ts candidate staging seams.
  • description: Validate planned manifests, lockfiles, workspace links, configuration and executable topology in an isolated candidate. Reproduce the effect-tsgo scenario or retain a clearly equivalent fixture. Preserve issue #181 containment, disabled lifecycle scripts, cleanup and live-state isolation.
  • validation: AC-033–AC-036; candidate resolves workspace-local executable as ordinary planned install does, distinguishes lint warnings from installation/configuration/process/cleanup failures, and never mutates live consumer state.
  • review_mode: cli; primary plus independent risk challenger.
  • assigned_skills: codebase-design, tdd, verify-behavior.
  • implementation_skill_guidance: Test through the public candidate/scaffold operation seam; retain candidate isolation and failure classification.
  • tdd_status: required; tdd_target: disposable real Bun monorepo candidate validation.
  • red_command: bun run --cwd apps/cli test -- src/runtime/scripts.test.ts.
  • expected_red_failure: Workspace-local executable and planned topology assertions fail before the candidate fix.
  • green_command: bun run --cwd apps/cli test -- src/runtime/scripts.test.ts.
  • evidence: Empty pending delivery.
  • codebase_design_notes: Candidate preparation is an adapter behind the public validation operation; do not patch live package manifests.
  • runtime_validation: required
  • runtime_procedure: Isolated candidate with symlink containment and scripts disabled.
  • runtime_target: candidate workspace, executable resolution, cleanup.
  • runtime_evidence: Empty pending delivery.
  • runtime_cleanup: Delete candidate and restore fixture temporary state.
  • status: Complete
  • parent_gate_evidence: .devpunks/delivery/v43/IP-470/parent-task-gate.json; cumulative W2/A2 is .devpunks/delivery/v43/scaffold-w2-a2-gate.json.

T3 — IP-464 — independent health report

  • depends_on: [T1]
  • location: repository-check application/presentation/port, operation-result schemas, adapter forwarding, and update/run.ts typed obligationFindings comparison/result/check-return seam after T2 custody release.
  • description: Aggregate independent observations without invoking mutating producers. Preserve healthy findings when one component is unavailable; report exact causes, affected consumers and unknown/pending obligations with nonzero status. Preserve typed obligationFindings from the production comparison through UpdateResult and port/adapter; classify actual observed obligations rather than placeholder planned reconciliation or generic local-edited diffs.
  • validation: AC-001, AC-002, AC-006, AC-007; check is read-only and does not call scaffold/update.
  • review_mode: cli; primary plus challenger.
  • assigned_skills: tdd, simplify, verify-behavior.
  • implementation_skill_guidance: Keep independent component results observable through the public JSON result.
  • tdd_status: required; tdd_target: blocked-quality plus independently stale shared-prompt check, and actual compareObservedState obligation findings retained through runCheck/publicCheckResult with healthy independent evidence.
  • red_command: bun run --cwd apps/cli test -- src/features/repository-check/application.test.ts.
  • expected_red_failure: Blocked component suppresses or misstates independent guidance findings.
  • green_command: bun run --cwd apps/cli test -- src/features/repository-check/application.test.ts.
  • evidence: Empty pending delivery.
  • codebase_design_notes: Result aggregation is the deep reporting module; producers remain non-mutating adapters.
  • runtime_validation: required
  • runtime_procedure: hi check --json fixture matrix.
  • runtime_target: findings, exit status, repository bytes.
  • runtime_evidence: Empty pending delivery.
  • runtime_cleanup: Preserve fixture authored files; remove only temporary repository.
  • status: Complete
  • parent_gate_evidence: .devpunks/delivery/v43/IP-464/parent-task-gate.json; cumulative W2/A2 is .devpunks/delivery/v43/scaffold-w2-a2-gate.json.

W2 independent check assessment amendment

The accepted AC-006 public matrix still fails: an ambiguous Quality Command Contract aborts compilation before independent shared-artifact comparison. Retained evidence is .devpunks/delivery/v43/IP-464/public-ambiguous-quality.json and quality-red-assertion.log, captured against packaged executable SHA 784e942981996cbb17dd455a93f79427e05a4437db42eb053572d5e82dbf04b3. The fixture combines a locked npm repository, explicit conflicting format aliases and stale .agents/AGENTS.md; the public result loses that independent drift. This amendment completes the existing AC-006 responsibility.

Use the existing compiler → compileScaffoldContextPlan in scaffold/output.ts → runUpdate check seam. There is no scaffold/context-plan.ts file and no new planner or extraction is assigned. An explicit read-only assessment result retains independently assessable Context Plan content together with typed blocked Quality Command Contract consumers and their exact scope/reason. Only that check assessment may omit an unresolved Commit Gate contribution; ordinary compilation and every mutating scaffold/update path retain the existing fail-closed typed error. A partial assessment cannot become a valid mutation plan or completion receipt.

OwnerBounded source reservationReady condition
T6 / IP-468Existing context-planning/compiler.ts, compiler.test.ts, index.ts and scaffold/models.ts: typed check-assessment result and compiler branch over the existing contribution calculationPublic compiler RED/GREEN proves independent content retained, exact blocked consumer emitted, normal compile still rejects
T4 / IP-465Existing scaffold/output.ts compileScaffoldContextPlan input assembly/forwarding seam and owned settings-selection.test.ts onlyConsume T6's frozen typed contract; explicit assessment uses the same scope/selection/baseline input assembly, normal wrapper behavior unchanged
T3 / IP-464Existing update/run.ts check-call/result/comparison hunks, repository-check port/application/tests, adapter forwarding and presentationConsume frozen compiler/wrapper contracts, retain independent drift and typed blocked dependency findings in actual check output

These are sequential contract-readiness and exclusive file reservations inside existing task identities, not new provider blocker edges. T6 freezes the assessment result before T4 integrates the wrapper; T3 then integrates check consumption. Independent disjoint work continues. T4/T6 prior task gate evidence remains a record of its matched snapshot; new assessment work requires its own focused evidence before consumption and cumulative acceptance. Keep all source edits for this amendment frozen until the independent plan review passes.

Gate-dependent output is not independently provable from an omitted contribution. Carry the blocked consumer/dependency information through comparison: affected hook, generated configuration, projection or receipt obligations remain blocked/unknown with exact cause and consumer identity. They cannot be classified current, healthy, absent-by-design or safely removable merely because assessment omitted their unresolved contribution. Independently assessable baseline-managed shared content still receives its actual drift/health result. Use existing obligation/dependency evidence; do not infer completion from placeholder reconciliation state or introduce a parallel dependency registry.

Required proof, in order:

  1. T6 records actual public compiler assessment RED before implementation: incomplete/ambiguous quality plus independently valid shared contribution yields typed blocked consumer and independent content. The same input through normal compilation still fails with its exact Quality Command Contract error. Unrelated compiler failures remain failures rather than broad recovery.
  2. T4 records wrapper RED/GREEN with identical detected scopes and baseline: assessment retains the shared output comparison input, ordinary scaffold compilation refuses the unresolved quality contract, explicit user policy remains unchanged. Run the existing owned settings-selection tests.
  3. T3 reruns the retained mixed public fixture through the parent-built CLI: check --baseline bundled --json reports both exact blocked quality and stale .agents/AGENTS.md, preserving independent healthy findings and nonzero status. Gate-dependent outputs remain blocked/unknown. A healthy quality fixture still reports ordinary health without false blockers.
  4. Retain paired normal scaffold/update refusal and byte-hash readback proving explicit scripts/configuration, live shared bytes, hooks and completion receipts were not mutated by check or advanced through unresolved quality. Run compiler.test.ts, settings-selection.test.ts, repository-check/application.test.ts and the affected existing update regressions, then parent checks source/build identities and cumulative AC-006 evidence.

Final W2/A2 and full acceptance remain pending until this public mixed-case proof and the other declared cumulative gates pass. No quality gate is relaxed by returning more truthful read-only findings.

W2 exact quality diagnostic amendment

T4 owns the existing features/commit-gate/quality.ts resolver and repository-detector producer: when explicit format mapping is unsafe or ambiguous, carry its actual reason as QualityCommandEvidence.unresolvedReason. T6 owns the optional readonly string field in apps/cli/src/features/repository-analysis/model.ts and the existing commitGateContributionFor consumer in compiler.ts. Append that reason to IncompleteQualityCommandContract.message while retaining scope identity and missing-field detail. The existing error schema stays unchanged. This is an AC-004 diagnostic correction inside the accepted quality contract; no new requirement, provider edge or execution owner is introduced.

T4 retained actual public planner diagnostic RED in .devpunks/delivery/v43/IP-465/diagnostic-red.log: four cases report only an incomplete root Quality Command Contract. Its owned settings-selection.test.ts exercises compileScaffoldContextPlan: unsafe and ambiguous explicit format mappings report the root scope and exact resolver reason rather than only a missing formatCheck label. T6 verifies the typed consumer retains that reason, with unchanged behavior when no reason is present. After their disjoint producer/type/consumer edits, rerun the public diagnostic cases to GREEN and prove explicit scripts/configuration remain unchanged on refusal. Neither worker acquires the other's files; source identity changes require affected checks again. Pure resolver tests alone cannot prove the public diagnostic.

T6 native-parser validation already follows the subprocess contract: its owned compiler.test.ts forks Node, imports the actual distributed validateCanonicalContextPlan public API, and passes serialized compiled Context Plan input through stdin. Retained RED is .devpunks/delivery/v43/IP-468/red-native-subprocess.log. Valid optional lineage, omitted lineage and malformed nested fields remain required, alongside existing update regressions and parent-built runtime proof.

T4 — IP-465 — quality defaults

  • depends_on: [T1]

  • location: quality command resolution, scaffold/update planning, dependency/configuration tests.

  • description: Resolve supported defaults plus explicit repository overrides, include required scripts/dependencies/lint configuration, preserve ambiguous manager policy and read-only format checks. Integrate the quality resolver through repository detection and output.ts applyLintConfigs. Attach a detected manifest to an existing compiled root scope while preserving its metadata, so root Commit Gate contributions reach the public plan.

  • validation: AC-001, AC-003–AC-005. Prove the actual public plan carries supported root scripts/dependencies/config and preserves explicit overrides; include the compiled-root manifest attachment case, not only pure resolver results.

  • review_mode: cli; primary plus challenger.

  • assigned_skills: tdd, simplify, verify-behavior.

  • implementation_skill_guidance: Keep policy resolution separate from artifact ownership and shared-prompt loading.

  • tdd_status: required; tdd_target: public-plan missing defaults and compiled-root Commit Gate contribution, custom override, ambiguous mapping and opt-out. Retain defaults-red.log and capture root-contribution RED before that repair.

  • red_command: bun run --cwd apps/cli test -- src/scaffold/settings-selection.test.ts.

  • expected_red_failure: Missing supported quality setup or guessed override behavior.

  • green_command: bun run --cwd apps/cli test -- src/scaffold/settings-selection.test.ts.

  • evidence: Empty pending delivery.

  • codebase_design_notes: Quality contract resolver is a small policy seam consumed by the common plan.

  • runtime_validation: required

  • runtime_procedure: Fresh supported repository and explicit override fixture.

  • runtime_target: scripts, dependencies, lint config, hook policy.

  • runtime_evidence: Empty pending delivery.

  • runtime_cleanup: Remove disposable repository.

  • status: Complete

  • parent_gate_evidence: .devpunks/delivery/v43/IP-465/parent-task-gate.json. Parent task-responsibility gate passed at the retained source identities; operational installation proof remains IP-471 and final acceptance is unassessed. See IMPLEMENTATION-NOTES.md W2 public repair gates.

T5 — IP-466 — recoverable publication

  • depends_on: [T1]
  • location: scaffold/update materialization, manifest/receipt/pending evidence modules and tests.
  • description: Make output, verification, receipt and adopted-manifest transitions recoverable. Bind proof to selected baseline/template identity and actual observed output; preserve completed independent actions and avoid producer loops or false completion.
  • validation: AC-017–AC-020, AC-031–AC-032 and AC-044. Interrupt each boundary, resume unchanged inputs, verify pending evidence and truthful readback.
  • review_mode: cli; primary plus challenger.
  • assigned_skills: codebase-design, tdd, verify-behavior.
  • implementation_skill_guidance: Use existing receipt/pending infrastructure; expose a resumable operation rather than a second persistence engine.
  • tdd_status: required; tdd_target: interruption/recovery at output, verification, receipt and manifest boundaries.
  • red_command: bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts.
  • expected_red_failure: Interrupted shared-prompt publication can claim success or reschedule unrelated work.
  • green_command: bun run --cwd apps/cli test -- src/update/run.test.ts src/scaffold/output.test.ts src/scaffold/settings-selection.test.ts.
  • evidence: Empty pending delivery.
  • codebase_design_notes: Publication is a state transition seam with input-bound evidence; filesystem writes remain local adapters.
  • runtime_validation: required
  • runtime_procedure: Restarted command against partial and prior-valid states.
  • runtime_target: shared prompt, aliases, manifest, projection receipt and pending handoff.
  • runtime_evidence: Empty pending delivery.
  • runtime_cleanup: Remove partial disposable fixture after collecting evidence.
  • status: Complete
  • parent_gate_evidence: .devpunks/delivery/v43/IP-466/parent-task-gate.json; source03/runtime07b19 with retained native fault/recovery proof.

T6 — IP-468 — scoped invalidation

  • depends_on: [T1]

  • location: context-plan/scaffold-plan invalidation, skill/baseline identity handling, update planning and tests.

  • description: Track delivered skill content separately from explicit authoring/activation revisions and workspace/selected-skill membership. Extend portable Context Plan/capability and CLI plan models, expose invalidation through the existing planning public seam, and declare explicit revisions in normal bundled/archive baseline producers. Schedule only affected scoped work. Shared-prompt content changes refresh the scaffold-owned file without triggering broad scoped reauthoring. Preserve output.ts quality ownership with T4. Update only the distributed sync-subagents.mjs scopeIssue schema consumer for optional authoring lineage, with exact nested validation and malformed-input rejection.

  • validation: AC-023–AC-027 and the T6 invalidation contribution to AC-032; prove skill-body-only, contract-only, scope-change, ordinary-source and legacy-baseline cases through the actual public plan result. T6 prerequisite readiness releases T8 only after scope/reason/input identity proof. Full AC-032 stays pending until T8 integration proves receipt-bound stale evidence, check reporting and bounded update handoff; RAC-006 remains due at A3. The distributed parser accepts valid/omitted authoring lineage and rejects malformed nested fields through real script execution; existing update regressions return GREEN.

  • review_mode: cli; primary plus challenger.

  • assigned_skills: codebase-design, tdd, simplify.

  • implementation_skill_guidance: Keep semantic invalidation lineage in the common plan; keep filesystem hashes in receipts/managed state.

  • tdd_status: required; tdd_target: selective invalidation matrix and no-op repeat.

  • red_command: bun run --cwd apps/cli test -- src/features/context-planning/compiler.test.ts src/update/run.test.ts.

  • expected_red_failure: Prompt content change causes broad reauthoring or ordinary source edits schedule work.

  • green_command: bun run --cwd apps/cli test -- src/features/context-planning/compiler.test.ts src/update/run.test.ts.

  • evidence: Empty pending delivery.

  • codebase_design_notes: Invalidation is a dependency calculation exposed through the real public plan compiler result, using portable explicit revision declarations. Pure calculation tests support that responsibility but do not prove downstream receipt/check/handoff acceptance.

  • runtime_validation: required

  • runtime_procedure: update/check --json on changed input fixtures.

  • runtime_target: selected scoped guidance, authoring actions and native projections.

  • runtime_evidence: Empty pending delivery.

  • runtime_cleanup: Remove temporary fixtures.

  • status: Complete

  • parent_gate_evidence: .devpunks/delivery/v43/IP-468/parent-task-gate.json. Parent task-responsibility gate passed at the retained source identities; full AC-032 remains IP-469 integration; archive declaration consistency passed in .devpunks/delivery/v43/IP-468/archive-authoring-readback.json. See IMPLEMENTATION-NOTES.md W2 public repair gates.

T7 — IP-467 — portable migration

  • depends_on: [T1, T5]
  • location: receipt/manifest migration, portable identity and worktree verification modules/tests.
  • description: Migrate known legacy state once, retain authored material, ignore irrelevant formatting/order/location changes, and reverify machine-local hooks after relocation while preserving behavior-significant order.
  • validation: AC-016, AC-021, AC-022; next unchanged update is a no-op.
  • review_mode: cli; primary plus challenger.
  • assigned_skills: codebase-design, tdd, verify-behavior.
  • implementation_skill_guidance: Migration is finite and input-bound; do not rewrite retained workflow records.
  • tdd_status: required; tdd_target: legacy, moved-worktree, formatting/order and repeated-update cases.
  • red_command: bun run --cwd apps/cli test -- src/update/run.test.ts.
  • expected_red_failure: Legacy migration repeats or loses authored material.
  • green_command: bun run --cwd apps/cli test -- src/update/run.test.ts.
  • evidence: .devpunks/delivery/v43/IP-467/parent-task-gate.json; source source-freeze-10.json and final W4 reviews retain exact identities.
  • codebase_design_notes: Portable identity parser/migrator is a deep module behind receipt reconciliation.
  • runtime_validation: required
  • runtime_procedure: Moved disposable worktree and legacy receipt fixture.
  • runtime_target: receipts, manifests, hooks and authored records.
  • runtime_evidence: .devpunks/delivery/v43/IP-469/native-proof/execution-d779d846/ACCEPTANCE.json; task gate preserves prior portability/handoff/recovery runtime provenance.
  • runtime_cleanup: All bounded native roots removed after retained readback.
  • status: Complete.

T8 — IP-469 — bounded handoff and projection

  • depends_on: [T5, T6]
  • location: post-command handoff, agent-authored output validation, native projection and receipt publication modules/tests.
  • description: Emit residual actions with exact scope, trigger, input identity, allowed outputs and completion evidence. Validate authored results and mechanical aliases before proof; preserve authored guidance and custom roles. Keep source-first reusable skill changes.
  • validation: AC-008 and AC-028–AC-032; no-op stale prose does not reschedule completed work. Consume T6 invalidation scope/reason/input identity with T5 receipt state and prove affected stale evidence in check plus bounded update handoff before AC-032/RAC-006 completion. Capability reader/archive compatibility is owned and verified by T1.
  • review_mode: cli; primary plus challenger.
  • assigned_skills: codebase-design, tdd, verify-behavior.
  • implementation_skill_guidance: Handoff is a bounded residual contract; deterministic CLI validation remains the completion authority.
  • tdd_status: required; tdd_target: authored output, alias projection, stale handoff and first-reader compatibility cases.
  • red_command: bun run --cwd apps/cli test -- src/content/handback.test.ts src/update/run.test.ts.
  • expected_red_failure: Handoff lacks input-bound completion evidence or aliases/proof diverge.
  • green_command: bun run --cwd apps/cli test -- src/content/handback.test.ts src/update/run.test.ts.
  • evidence: .devpunks/delivery/v43/IP-469/parent-task-gate.json; source source-freeze-05.json and final W4 reviews retain exact identities.
  • codebase_design_notes: Handoff parser/validator is a small public seam over deterministic projection.
  • runtime_validation: required
  • runtime_procedure: scaffold/update followed by handoff completion and check readback.
  • runtime_target: .agents/AGENTS.md, aliases, native definitions, receipt.
  • runtime_evidence: .devpunks/delivery/v43/IP-469/native-proof/execution-d779d846/ACCEPTANCE.json; task gate preserves prior portability/handoff/recovery runtime provenance.
  • runtime_cleanup: All bounded native roots removed after retained readback.
  • status: Complete.

T9 — IP-471 — routine installation and Commit Gate proof

  • depends_on: [T4, T5, T2]

  • location: quality/dependency installation, Lefthook runner/configuration, operational readback and tests.

  • description: Complete authorized routine setup and verify actual commands, dependencies and hook operation. Preserve conflicting manager policy and truthful partial progress; leave only unresolved interpretation work.

  • validation: AC-003–AC-005, AC-020, AC-029 and AC-031; fresh supported repository reaches working setup and failures preserve completed independent actions.

  • review_mode: cli; primary plus challenger.

  • assigned_skills: codebase-design, tdd, verify-behavior.

  • implementation_skill_guidance: Install through existing runtime adapters and verify operational state, never by receipt declaration alone.

  • tdd_status: required; tdd_target: fresh setup, opt-out, conflict and partial failure.

  • red_command: bun run --cwd apps/cli test -- src/update/run.test.ts.

  • expected_red_failure: Planned quality/hook setup is not installed or proof advances without live verification.

  • green_command: bun run --cwd apps/cli test -- src/update/run.test.ts.

  • evidence: .devpunks/delivery/v43/IP-471/work-start-readback.json; W4 release is scaffold-w4-gate.json.

  • codebase_design_notes: Runtime installer is an adapter behind the common plan; keep policy resolution and proof separate.

  • runtime_validation: required

  • runtime_procedure: Fresh repository with actual dependency and hook command readback.

  • runtime_target: package manifest, lockfile, scripts, Lefthook runner/config and receipt.

  • runtime_evidence: Final installation, public command, and post-sync execution04 evidence retained under .devpunks/delivery/v43/.

  • runtime_cleanup: Remove disposable repository and candidate artifacts.

  • status: Complete; final proof includes expected command statuses [0, 1, 1, 0, 1, 1] and the focused regression for the zero-file Oxlint prefix defect.

  • additional_reserved_paths: apps/cli/src/platform/commit-gate-capabilities.ts, apps/cli/src/cli/commit-gate-command.ts and direct tests if operational verification requires them; parent reservation follows retained preflight.

  • live_entrypoint_reservation: apps/cli/src/scaffold/stage.ts and direct stage tests for the post-materialization installation call. IP-471/native-red/RESULT.json confirms absent local binaries, active hook and CLI proof after fresh scaffold/update. Keep isolated candidate artifact generation separate from live installation.

  • W5 worker custody: scaffold_t5 exclusively owns platform/commit-gate-capabilities.ts and direct tests; scaffold_t7 owns live setup orchestration and the remaining T9 reservations. Coordinate observation contracts before cross-file changes; parent combines source freezes and controls builds.

  • W5 source-review repair custody: scaffold_t5 exclusively owns features/commit-gate/quality.ts and new direct quality.test.ts for read-only formatter contract validation; scaffold_t7 owns setup/index/output/update and their direct tests. Preserve source-freeze01/build01 and source reviews; parent rebuilds after repaired source freezes.

  • fresh_selection_reservation: scaffold_t7 may edit features/context-planning/compiler.ts, integrations/repository-detector.ts and direct tests to detect an explicitly declared supported package manager without a lock and plan the existing Commit Gate contribution for a resolved supported manager and quality contract before the initial lockfile exists. OUT-002/AC-003 requires fresh setup; live installation must produce and verify actual dependency state before proof. Preserve unresolved manager/quality blockers.

  • W5 diagnostic reservation: After failed packaged build03 first-scaffold proof, scaffold_t7 owns instrumentation in platform/feature-application-operations.ts, platform/scoped-scaffold-operation.ts, existing features/commit-gate/setup.ts and update/run.ts. This wave gathers runtime evidence only; implementation follows a confirmed cause. scaffold_t3 owns the isolated reproduction driver/evidence under IP-471/debug-fresh-scaffold. Parent owns builds and runtime release; retain prior freezes and failed execution evidence. See .devpunks/delivery/v43/IP-471/debug-fresh-scaffold/STATE.json.

  • W5 confirmed-path repair: Diagnostic execution-0a31b18d/runtime.ndjson confirms public repository scaffold omits live setup despite receiving five planned dependencies. scaffold_t7 owns platform/scoped-scaffold-operation.ts, its direct tests and adapter for the existing live setup call and truthful operational failure handling. Keep instrumentation through before/after proof. Update/compiler/output remain frozen while scaffold_t3 assesses the independently confirmed late wiki planning omission. Parent controls builds and reviews.

  • H1 setup contract alignment: T7 may narrow features/commit-gate/setup.ts input to its consumed dependencies/files/context plan and actual Commit Gate policy, allowing the public path’s existing compiled catalog. Preserve setup behavior and policy authority; validate stage/update callers and direct setup tests. Retain failed initial type/test attempts as diagnostic history.

  • W5 disjoint lint repair: scaffold_t5 owns only scaffold/output.test.ts for the twelve retained current-goal lint errors. Preserve assertions and test behavior; retain focused lint/test proof. Other source freezes remain authoritative at their recorded hashes.

  • W5 update-test lint custody: After the nineteen output tests and independent lint review passed, T5 owns only existing update/run.test.ts for its twenty-one retained lint errors. T3 uses new focused H4 test files. Preserve assertions, ordering and exact scenario coverage; parent reviews final hashes and validation.

  • W5 same-operation workspace repair: scaffold_t3 owns update/run.ts and focused helper/tests to compile the wiki package that update already elects to generate into the same desired dependency/topology plan before installation. Existing output/compiler seams may receive a minimal planned-manifest overlay; coordinate any additional path before writing. output.test.ts stays with T5 and public scaffold platform files with T7. This repair preserves public scaffold file selection; the specification does not independently require fresh scaffold to create a wiki. Runtime evidence is execution-0a31b18d/runtime.ndjson lines 4–6. Preserve independent workspace coverage and the first post-completion no-op oracle.

  • Independent candidate diagnostic: T7 owns runtime/scripts.test.ts and instrumentation-only runtime/scripts.ts for the H4-exposed independent-package path under IP-470. Use ordinary versus candidate installation/command proof without inventing root workspace membership. Source mutations and runtime execution wait for T5’s matched-test production freeze release. Parent chooses repair only after runtime evidence; task-local evidence lives under .devpunks/delivery/v43/IP-470/independent-candidate-diagnostic/.

  • Current disjoint repair wave: T3 owns integrations/repository-detector.ts and direct tests for declared-member supported manager inheritance before a lock exists, with explicit child and lock provenance controls. T5 owns only the scoped-proof fixture in update/run.test.ts: retain unknown-to-known-via-lock intent, compatible TS5.7.3, exact authority/proof/no-op assertions. T7 owns runtime/scripts.ts and direct tests for candidate-relative installation failure context after H5 review. Runtime diagnosis is retained in H4-SETUP-DIAGNOSIS; TS7/utils peer failure stays truthful and production dependency versions remain unchanged. Parent controls combined build and native release.

Architecture applicability

architecture_applicability: architecture-bearing. The work changes the baseline schema, selected-baseline reader, common plan model, command orchestration, update reconciliation, candidate adapter and receipt/handoff composition across packages/scaffold and apps/cli. A local-task classification would hide these cross-owner edges.

Target Ownership Topology

packages/scaffold baseline schema + capability metadata
  -> apps/cli baseline reader/resolution/materialization
  -> Context Plan / Scaffold Plan
  -> check, update, scaffold and candidate adapters
  -> managed output, aliases, receipt and residual handoff

packages/scaffold owns portable baseline metadata/schema. apps/cli owns filesystem asset reading, capability validation, command policy, observation, writes, candidate isolation and operational proof. The selected baseline is the only shared-prompt source. Repository authored root/scoped guidance remains outside that managed artifact.

Declared Dependency Graph

Allowed module edges are packages/scaffold schema -> CLI baseline reader -> Context/Scaffold Plan -> command materialization/check -> receipt/presentation, plus the candidate adapter consuming the common plan. The baseline package must not import CLI command orchestration; the CLI must not read an installed prompt as a fallback; check must not invoke mutating update; native aliases must consume the managed shared file and never become an independent source. The graph is acyclic. Provider task blockers are tracked separately below.

Responsibility Acceptance Criteria

CriterionOwnerObservable assertionEvidenceArchitecture wave
RAC-001packages/scaffoldVersioned capability, archive asset path and digest decode through one public baseline seam.T1 focused baseline tests and metadata readbackA1
RAC-002apps/cli baseline/updateSelected baseline asset is materialized as scaffold-owned .agents/AGENTS.md; no npm fallback.T1 public scaffold/update/check matrixA1
RAC-003Context/Scaffold PlanPrompt identity and ownership flow into desired state and receipts.T1/T5 plan and receipt assertionsA2
RAC-004check/reportIndependent findings retain exact blocked and healthy component evidence.T3 JSON result matrixA2
RAC-005candidate adapterCandidate uses planned workspace topology and preserves live state.T2 disposable monorepoA2
RAC-006invalidation/handoffPrompt-only changes refresh the managed file without broad scoped reauthoring; authored scopes survive.T6/T8 selective update matrixA3
RAC-007publication/receiptPartial work and recovery are input-bound and cannot claim unapplied output.T5 interruption matrixA3
RAC-008installation/proofRoutine quality and hook setup is operationally verified before completion.T9 fresh repository readbackA4

Architecture Waves

WaveTopology deltaEntryCriteria dueCheckpoint
A1Establish capability reader and scaffold-owned shared-prompt authority.noneRAC-001, RAC-002Verify selected baseline asset and no fallback.
A2Connect plan, check, candidate and quality consumers to the common seam.A1RAC-003, RAC-004, RAC-005Recheck ownership edges and public results.
A3Add invalidation, publication recovery and bounded projection proof.A2RAC-006, RAC-007Recheck cumulative receipts, aliases and handoff.
A4Complete operational installation and final convergence.A3RAC-008Verify all acceptance criteria and empty migration ledger.

Public Seam Contract

The affected consumer-facing seams are the scaffold, update and check --json commands; selected-baseline resolution; Context/Scaffold Plan output; candidate validation; projection receipt; and Post-Command Handoff. Their owners and allowed consumers are apps/cli command modules, baseline resolution, plan compiler, candidate runtime, and receipt/presentation modules respectively. Downstream work must amend this contract before changing a seam.

Migration Ledger

No temporary seam is planned. T1 removes the installed-template lookup as the shared-prompt authority and removes the broad shared-file preservation exemption. Unsupported capability remains a durable explicit result required by AC-041, not a migration adapter. The ledger is therefore empty at plan start and must remain empty at final closure.

Validation gates

Before advancing each edge, the worker records focused RED and GREEN evidence, public command output, changed paths and preservation checks. The parent then validates the complete native graph and the full acceptance matrix (AC-001 through AC-045), including all shared-prompt capability cases. Run formatting, git diff --check, the wiki content check and the relevant CLI Vitest suite.

Final runtime evidence must include both known consumer targets (collective- intelligence and /ci-emera) or equivalent disposable reproductions, with exact baseline/CLI versions, selected asset identity, before/after shared prompt bytes, aliases and receipts. Do not claim issue #197 is fixed until the workspace executable topology and shared-prompt update behavior both pass.

The task-level coverage ledger is explicit so no accepted criterion is lost in the provider projection:

CriteriaTask owner(s)
AC-001, AC-002T1, T3, T5
AC-003, AC-004, AC-005T4, T9
AC-006, AC-007T3
AC-008, AC-009, AC-010, AC-011, AC-012, AC-013, AC-014, AC-015T1, T3
AC-016, AC-021, AC-022T7
AC-017, AC-018, AC-019, AC-020T5, T9
AC-023, AC-024, AC-025, AC-026, AC-027T6
AC-032T6 prerequisite invalidation; T8 integrated receipt/check/handoff proof
AC-028, AC-029, AC-030, AC-031T8, T9
AC-033, AC-034, AC-035, AC-036T2
AC-037, AC-038, AC-039, AC-040, AC-041, AC-042, AC-043T1
AC-044T5
AC-045T1

Release classification follows changed changelog paths. The first capability reader publication is a compatible CLI/baseline release decision; later prompt-only baseline updates remain baseline work. No release is executed by this plan.

Unresolved questions

  • Actual compatible version numbers and publication commit are delivery-time facts; preserve the schema's compatibility range and read back the selected baseline metadata.
  • Exact module/field names are implementation choices inside the public capability seam; do not add a second registry or fallback source.
  • Exact root cause of the original #197 failure remains an evidence target until reproduced in a disposable real install.

Resolved decision ledger

  • .agents/AGENTS.md is wholly scaffold-owned.
  • Its selected content authority is baseline.dataRoot/shared-agents.md; the published archive stores that asset as data/shared-agents.md.
  • The installed npm CLI template is never a silent fallback.
  • Root/scoped authored guidance and custom roles retain their own protection.
  • Existing nine provider Tasks and eleven native blocker edges remain intact.
  • Shared prompt content changes do not trigger broad scoped reauthoring.
  • Receipts attest observed, input-bound completion only.
  • Parent coordinates, reviews, validates and advances waves; workers own the implementation scopes above.

W3 publication ownership clarification

T5 also owns scaffold/output.ts, scaffold/output.test.ts and update/run.test.ts for the already accepted initial scaffold and update publication boundaries. W2 has released these reservations; T8 receives the resulting output seam in W4. This serial ownership clarification implements T5’s existing materialization and interruption tests without changing requirements or dependencies.

W4 test reservations

T7 owns update/run.test.ts; T8 owns scaffold/output.test.ts and content tests. These extend each existing production seam to its tests without changing dependencies. T7 can make the equivalent T3-owned optional-boolean lint correction inside its run.ts reservation and retain the repository-check regression. All other source overlap returns to the parent.

W4 projection publisher reservation

T8 owns the existing sync-subagents.mjs completion/publisher entrypoint and runtime/scripts.test.ts for its accepted bounded authoring/projection proof. T6/T2 released these paths; T7 has no overlapping reservation. Runtime production adapters remain outside T8 ownership unless separately coordinated. Canonical reusable skills remain frozen and source-first.

W4 bounded-authoring consumer coordination

T8 owns one portable authoring helper under harness-projection plus its declaration file. Existing compiler identity calculation imports that helper; T7 normalization preserves set-valued authoring contracts/missingContracts and behavior-significant contribution order. T8 freezes a compact assessment API before T7 consumes it. T7 remains sole update/run.ts writer and integrates current desired-plan/receipt assessment into existing observation and residual handoff routing. T8 maps any new typed facts through repository-check only as needed; the update observer remains the single filesystem assessment.

This is a producer→consumer handoff within W4: T7 continues independent portable/migration work while awaiting the helper; T8 continues projection/publisher work while T7 wires the observer. Both native Tasks retain their original acceptance ownership. IP469 gate requires paired helper/publisher/update/check evidence. Existing T5 recovery, T3 independent diagnostics and T2 candidate safety remain required. Shared build occurs only after affected source reservations freeze.

On this page