Plan: candidate validation and commit coverage
Execution plan
- architecture_applicability: local. Existing runtime, generation snapshot, shared schema, settings, compiler, and runner owners remain intact. No service ownership moves or temporary compatibility layer.
- Spec: https://github.com/wearedevpunks/harness-intelligence/blob/4d61376abe20c88a955e8670a8d6d65a44fce410/apps/wiki/content/docs/project/specs/cli/issue-200-201-219-220-validation/SPEC.md
- Base: 7e147b3300c391db979b87e20c4159a5a03d12cb; branch: team/stefan/cli-update-quick-fixes.
- Worktree: /Users/stefan/Documents/Codex/2026-09-21/hi-quickfix-audit/harness.
- Identity: planning-only for all tasks. Existing GitHub #200/#201/#219/#220 remain requested issue records; no new Linear hierarchy or provider task projection.
- Research: linked spec and adjacent research report; raw evidence in sibling evidence directory.
Initial situation and decisions
Partial staged trees reject valid live targets. Historical archives and unrelated data expand closure; the generator emits a Vitest expression its validator rejects. All planned desired owners broaden update validation. Commit contracts lose successful diagnostics and cannot declare aggregate coverage. Keep exact final-tree validation, bounded required closure, explicit affected targets, and compatible execution metadata. Add only commitGateChecks.repository.{lint,formatCheck}; supplied commands declare authority. Generated warnings are errors; existing commands keep their own policy. No arbitrary config evaluation, generic prepare execution, global cache clearing, consumer lint cleanup, or hosted CI.
Dependency graph
Earliest frontier W1: T1,T2,T3,T4. T6 starts after T10/T3 so copied runtime data fixtures remain stable. T5 starts after T3/T4. T7 starts after T10/T2/T5 so update integration imports remain stable. No whole-wave barrier. Runtime candidate/parser/install changes have one owner; scaffold output has one owner. All fixtures are unique temporary directories. Shared node_modules is read-only after parent preparation; no workers install or patch packages. Parent owns Git index, commits/pushes, plan state, reports, and final build. No worker edits original checkouts or shared skill sources.
Testing and risk controls
Each behavioral slice starts with a real public-result RED, then minimal implementation and GREEN. Existing negative closure and custom command tests stay meaningful. Workers read nearest AGENTS/rules and assigned skills, report commands/results/paths, and never claim mocked tests as built CLI proof. Full repo baseline frozen installs fail on untouched base; isolated no-save Bun 1.3.5 installation and explicit prepare succeeded. Preserve this limitation; do not alter lockfiles to hide it. Cross-scope checks run only after consumed input owners complete. Run targeted tests/type checks, built CLI witnesses, wiki checks, and rule audit. Every commit includes [skip ci]; verify hosted workflows remain absent/skipped.
Unresolved questions
None blocking. The Emera wmf clonefile cause is unproven; preserve concrete diagnostics and documented fresh-cache retry, without claiming a specific corruption repair. Consumer lint debt and CI policy are outside implementation and explicitly documented.
T1: Compose and validate candidate inputs
{
"depends_on": [],
"location": "apps/cli/src/runtime/validation-candidate.ts",
"owned_paths": [
"apps/cli/src/runtime/validation-candidate.ts",
"apps/cli/src/runtime/validation-candidate.test.ts"
],
"read_dependencies": [
"SPEC.md"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W1",
"description": "Exclude unrelated replaced-scaffold archives and accept exact generated Vitest map grammar only. Preserve required dependency closure and all safety rules; support final-candidate composition seam in coordination with T10 runtime owner.",
"validation": "bun run --cwd apps/cli test src/runtime/validation-candidate.test.ts",
"status": "completed",
"log": [
"Parent source/evidence review passed narrowed validator gate. Public API unchanged; final generated-output test reruns after T5."
],
"files edited/created": [],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "passed",
"tdd_target": "Staged mirror targeting live AGENTS and generated backoffice config currently reject; explicit lint target currently broadens to root.",
"red_command": "bun run --cwd apps/cli test src/runtime/validation-candidate.test.ts",
"expected_red_failure": "Staged mirror targeting live AGENTS and generated backoffice config currently reject; explicit lint target currently broadens to root.",
"green_command": "bun run --cwd apps/cli test src/runtime/validation-candidate.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t1-archive-red.log",
"../evidence/t1-parser-red.log"
],
"green_evidence": [
"../evidence/t1-validator-full-green.log: 36 tests",
"../evidence/t1-validator-handoff.md: typecheck, scoped lint, exact hashes"
],
"codebase_design_notes": "runtime candidate result and process runner; no new infrastructure",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T2: Bound generation freshness inputs
{
"depends_on": [],
"location": "apps/cli/src/features/scaffold-state/generation-inputs.ts",
"owned_paths": [
"apps/cli/src/features/scaffold-state/generation-inputs.ts",
"apps/cli/src/features/scaffold-state/generation-inputs.test.ts"
],
"read_dependencies": [
"SPEC.md"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W1",
"description": "Inventory generation/detection filesystem reads; hash actual generation content and discovery topology separately, excluding irrelevant archives and migration payload JSON. Preserve newly introduced package/config discovery, explicit local assets, required symlink targets, bounds, and mutation detection. Keep public snapshot API compatible if possible; report concrete failure detail.",
"validation": "bun run --cwd apps/cli test src/features/scaffold-state/generation-inputs.test.ts",
"status": "completed",
"log": [
"First 12-test/Closed snapshot gate inspected. Parent found missing modern timestamped-directory snapshot.json layout from original issue and missing concrete Unclosed diagnostics; repair worker owns same two paths exclusively.",
"Parent reader audit removed unsupported config-import traversal. 39 tests, types/lint/format and real Harness/Collective Closed probes pass; exact source hashes verified. Earlier import-consumption assertions superseded."
],
"files edited/created": [
"apps/cli/src/features/scaffold-state/generation-inputs.ts",
"apps/cli/src/features/scaffold-state/generation-inputs.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "passed",
"tdd_target": "Irrelevant large migration payload currently exhausts generation closure; its content-only mutation needlessly invalidates generation.",
"red_command": "bun run --cwd apps/cli test src/features/scaffold-state/generation-inputs.test.ts",
"expected_red_failure": "Irrelevant large migration payload currently exhausts generation closure; its content-only mutation needlessly invalidates generation.",
"green_command": "bun run --cwd apps/cli test src/features/scaffold-state/generation-inputs.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t2-producer-red.log"
],
"green_evidence": [
"../evidence/t2-producer-green.log",
"../evidence/t2-producer-handoff.md"
],
"codebase_design_notes": "generation snapshot and freshness adapter",
"review_mode": "cli",
"runtime_validation": "not_required",
"runtime_target": "not_applicable",
"runtime_evidence": "not_applicable",
"runtime_cleanup": "not_applicable"
}T3: Extend shared command contract compatibly
{
"depends_on": [],
"location": "packages/scaffold/src/context-plan.ts",
"owned_paths": [
"packages/scaffold/src/context-plan.ts",
"packages/scaffold/src/context-plan.test.ts",
"packages/scaffold/src/public-scaffold-contract.test.ts"
],
"read_dependencies": [
"SPEC.md"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W1",
"description": "Add optional per-command execution modes files, owner, repository to QualityCommandContract. Retain legacy two-string decode; reject unknown modes and malformed metadata.",
"validation": "bun run --cwd packages/scaffold test src/context-plan.test.ts src/public-scaffold-contract.test.ts",
"status": "completed",
"log": [
"Parent inspected source diff and retained test/type evidence; Task Gate passed."
],
"files edited/created": [
"packages/scaffold/src/context-plan.ts",
"packages/scaffold/src/context-plan.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design",
"effect"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
},
{
"skill": "effect",
"applicable_behavior": "Read opensrc/effect.md and Effect schema guidance; use pinned v4 schema/service APIs and typed failure boundaries."
}
],
"tdd_status": "passed",
"tdd_target": "Explicit execution metadata currently rejected by strict shared decoder.",
"red_command": "bun run --cwd packages/scaffold test src/context-plan.test.ts src/public-scaffold-contract.test.ts",
"expected_red_failure": "Explicit execution metadata currently rejected by strict shared decoder.",
"green_command": "bun run --cwd packages/scaffold test src/context-plan.test.ts src/public-scaffold-contract.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t3-contract-red.log",
"public behavior failed before implementation"
],
"green_evidence": [
"62 package tests and scaffold typecheck pass; focused lint passes with existing warnings"
],
"codebase_design_notes": "shared Effect schema only; no CLI behavior",
"review_mode": "cli",
"runtime_validation": "not_required",
"runtime_target": "not_applicable",
"runtime_evidence": "not_applicable",
"runtime_cleanup": "not_applicable"
}T4: Persist explicit repository quality authority
{
"depends_on": [],
"location": "apps/cli/src/features/project-settings/model.ts",
"owned_paths": [
"apps/cli/src/features/project-settings/model.ts",
"apps/cli/src/features/project-settings/service.ts",
"apps/cli/src/features/project-settings/index.ts",
"apps/cli/src/features/project-settings/service.test.ts"
],
"read_dependencies": [
"SPEC.md"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W1",
"description": "Add optional commitGateChecks.repository with optional nonempty lint and formatCheck commands. Preserve it through reads, initialization, reconfiguration, choice updates, and version stamps. Reject empty repository object. Do not add generated-warning opt-out or alter existing commitGate enablement.",
"validation": "bun run --cwd apps/cli test src/features/project-settings/service.test.ts",
"status": "completed",
"log": [
"Parent inspected source diff and retained test/type evidence; Task Gate passed."
],
"files edited/created": [
"apps/cli/src/features/project-settings/model.ts",
"apps/cli/src/features/project-settings/service.ts",
"apps/cli/src/features/project-settings/index.ts",
"apps/cli/src/features/project-settings/service.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design",
"effect"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
},
{
"skill": "effect",
"applicable_behavior": "Read opensrc/effect.md and Effect schema guidance; use pinned v4 schema/service APIs and typed failure boundaries."
}
],
"tdd_status": "passed",
"tdd_target": "Explicit repository command settings currently lost or rejected.",
"red_command": "bun run --cwd apps/cli test src/features/project-settings/service.test.ts",
"expected_red_failure": "Explicit repository command settings currently lost or rejected.",
"green_command": "bun run --cwd apps/cli test src/features/project-settings/service.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t4-red.log",
"public behavior failed before implementation"
],
"green_evidence": [
"12 tests, CLI typecheck, focused lint pass"
],
"codebase_design_notes": "owning project-settings schema/service",
"review_mode": "cli",
"runtime_validation": "not_required",
"runtime_target": "not_applicable",
"runtime_evidence": "not_applicable",
"runtime_cleanup": "not_applicable"
}T5: Generate explicit command coverage
{
"depends_on": [
"T3",
"T4"
],
"location": "apps/cli/src/features/commit-gate/quality.ts",
"owned_paths": [
"apps/cli/src/features/commit-gate/quality.ts",
"apps/cli/src/features/commit-gate/quality.test.ts",
"apps/cli/src/features/repository-analysis/model.ts",
"apps/cli/src/features/context-planning/compiler.ts",
"apps/cli/src/features/context-planning/compiler.test.ts",
"apps/cli/src/integrations/repository-detector.ts",
"apps/cli/src/integrations/repository-detector.test.ts",
"apps/cli/src/scaffold/output.ts",
"apps/cli/src/scaffold/output.test.ts"
],
"read_dependencies": [
"SPEC.md",
"T3",
"T4"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W2",
"description": "Carry command execution metadata from detection through compiler and generation. New generated Oxlint defaults enforce --max-warnings 0. Generated file commands use explicit {files}; arbitrary scripts execute as owner commands unchanged. Merge declared repository authority before compilation and ensure it creates root coverage even without current root consumer eligibility. Never guess arbitrary root lint subsumption. Preserve settings/defaults and managed output identities.",
"validation": "bun run --cwd apps/cli test src/features/commit-gate/quality.test.ts src/features/context-planning/compiler.test.ts src/scaffold/output.test.ts src/integrations/repository-detector.test.ts",
"status": "completed",
"log": [
"Scoped Codex CLI worker session 55208, retained events ../evidence/t5-worker-events.jsonl.",
"Producer gate passed after confined-settings and read-only format repairs: 140 tests, type/lint/format, stable inputs. Missing caller settings wiring explicitly assigned to T7 platform/update paths; integration remains T7/T8 obligation."
],
"files edited/created": [
"apps/cli/src/features/commit-gate/quality.ts",
"apps/cli/src/features/commit-gate/quality.test.ts",
"apps/cli/src/features/repository-analysis/model.ts",
"apps/cli/src/features/context-planning/compiler.ts",
"apps/cli/src/features/context-planning/compiler.test.ts",
"apps/cli/src/integrations/repository-detector.ts",
"apps/cli/src/integrations/repository-detector.test.ts",
"apps/cli/src/scaffold/output.ts",
"apps/cli/src/scaffold/output.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "passed",
"tdd_target": "Generated contracts lack modes/root declarations; Oxlint default allows warnings.",
"red_command": "bun run --cwd apps/cli test src/features/commit-gate/quality.test.ts src/features/context-planning/compiler.test.ts src/scaffold/output.test.ts src/integrations/repository-detector.test.ts",
"expected_red_failure": "Generated contracts lack modes/root declarations; Oxlint default allows warnings.",
"green_command": "bun run --cwd apps/cli test src/features/commit-gate/quality.test.ts src/features/context-planning/compiler.test.ts src/scaffold/output.test.ts src/integrations/repository-detector.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t5-repair-format-red.log",
"../evidence/t5-repair-settings-red.log"
],
"green_evidence": [
"../evidence/t5-repair-suite-green.log",
"../evidence/t5-repair-handoff.md"
],
"codebase_design_notes": "compiler and managed output producer remain CLI owned",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T6: Enforce explicit staged coverage and diagnostics
{
"depends_on": [
"T10",
"T3"
],
"location": "apps/cli/src/data/scripts/commit-gate-runner.mjs",
"owned_paths": [
"apps/cli/src/data/scripts/commit-gate-runner.mjs",
"apps/cli/src/data/scripts/commit-gate-runner.d.ts",
"apps/cli/src/data/scripts/commit-gate-runner.test.ts"
],
"read_dependencies": [
"SPEC.md",
"T3"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W2",
"description": "Interpret optional execution modes compatibly. Read staged statuses including deleted and old rename paths; keep present file arguments separate. Execute owner/repository commands verbatim, expand only explicit file placeholders, reject uncovered root/deletion paths with actionable instructions. Repository kind subsumes subordinate same-kind checks; deduplicate identical invocation. Preserve all successful stdout/stderr once in stable contract order and existing failure details. Legacy contracts readable with legacy invocation but cannot silently succeed with zero selected coverage.",
"validation": "bun run --cwd apps/cli test src/data/scripts/commit-gate-runner.test.ts",
"status": "completed",
"log": [
"Native scoped worker dispatch after T10/T2/T5/T3 current dependency gates; shared dependencies read-only, private fixtures.",
"Parent accepted 26 real Git/process tests and stable runner/test hashes; see t6-handoff.md. Forced MJS type-aware lint remains non-clean; normal configured checks and syntax pass."
],
"files edited/created": [],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "required",
"tdd_target": "Success warnings discarded; root-only/deletion commits silently succeed; aggregate script arguments are guessed.",
"red_command": "bun run --cwd apps/cli test src/data/scripts/commit-gate-runner.test.ts",
"expected_red_failure": "Success warnings discarded; root-only/deletion commits silently succeed; aggregate script arguments are guessed.",
"green_command": "bun run --cwd apps/cli test src/data/scripts/commit-gate-runner.test.ts",
"reason_not_testable": "",
"red_evidence": [],
"green_evidence": [],
"codebase_design_notes": "generated Node process public boundary",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T7: Integrate affected update validation
{
"depends_on": [
"T10",
"T2",
"T5"
],
"location": "apps/cli/src/features/scaffold-update/validation-plan.ts",
"owned_paths": [
"apps/cli/src/features/scaffold-update/validation-plan.ts",
"apps/cli/src/features/scaffold-update/validation-plan.test.ts",
"apps/cli/src/update/run.ts",
"apps/cli/src/update/run.test.ts",
"apps/cli/src/platform/scoped-scaffold-operation.ts",
"apps/cli/src/platform/scoped-scaffold-operation.test.ts",
"apps/cli/src/integrations/repository-detector.ts",
"apps/cli/src/integrations/repository-detector.test.ts"
],
"read_dependencies": [
"SPEC.md",
"T1",
"T2"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W2",
"description": "Derive validation plan from actual reconciliation changes, separately selecting installation roots and lint targets. Guidance-only updates perform bytes/links/freshness without unrelated install/lint. Package script-only changes validate manifest/references; actual dependencies/config/hooks validate affected owning scopes. Resolve workspace/catalog consumers under owning installation, retain shared config consumers. Preserve concrete generation/config/install diagnostics; emit apply events only when publication attempted. Keep documented clear-cache/cache-off retry without speculative global-cache mutation. Pass already-validated settings into context-plan compilation in update and scoped scaffold adapters; detector must remain independent of settings I/O.",
"validation": "bun run --cwd apps/cli test src/features/scaffold-update/validation-plan.test.ts src/update/run.test.ts",
"status": "completed",
"log": [
"Parent caller audit assigns missing validated-settings plumbing in scoped scaffold operation and update to T7 after T5; no concurrent writer owns platform scope.",
"Native scoped worker dispatch after T10/T2/T5/T3 current dependency gates; shared dependencies read-only, private fixtures.",
"Parent selection probe exposed missing pnpm-workspace.yaml patterns. Scope extended to extract the existing pure parser and caller confined-read wiring after the running full gate; no active competing owner. Focused caller RED/GREEN required.",
"Retained review pr222-r1: optionalDependencies missing from caller dependency edges. T7 owns narrow RED/GREEN correction; T8 reruns affected built CLI proof using new frozen distribution. Unaffected prior proof retained; review_count1/repair_count1.",
"Retained review pr222-r1 resolved by minimal optional-dependency edge correction, stable focused RED/GREEN/static gates and actual rebuilt CLI positive/negative consumer proof. One full review/one focused repair; no remaining findings. PR-ready provider readback recorded in final delivery handoff; no merge/release."
],
"files edited/created": [],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "required",
"tdd_target": "Handoff-only update currently selects repository-wide dependencies/lint; blocked publication emits apply completed.",
"red_command": "bun run --cwd apps/cli test src/features/scaffold-update/validation-plan.test.ts src/update/run.test.ts",
"expected_red_failure": "Handoff-only update currently selects repository-wide dependencies/lint; blocked publication emits apply completed.",
"green_command": "bun run --cwd apps/cli test src/features/scaffold-update/validation-plan.test.ts src/update/run.test.ts",
"reason_not_testable": "",
"red_evidence": [],
"green_evidence": [],
"codebase_design_notes": "update orchestration consumes candidate/freshness APIs",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T8: Prove built behavior and document operations
{
"depends_on": [
"T5",
"T6",
"T7",
"T11",
"T12"
],
"location": "docs/README.md",
"owned_paths": [
"docs/README.md",
"docs/runbooks/hi-cli-scaffolding.md",
"apps/wiki/content/docs/project/specs/cli/issue-200-201-219-220-validation/IMPLEMENTATION-NOTES.md",
"apps/cli/src/data/bundled-baseline-identity.generated.ts",
"apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md",
".agents/skills/verify-behavior/references/README.md",
".agents/skills/verify-behavior/references/cli/README.md",
".agents/skills/verify-behavior/references/cli/features/README.md",
".agents/skills/verify-behavior/references/cli/features/candidate-update.md",
".agents/skills/verify-behavior/references/cli/features/commit-coverage.md",
".agents/skills/verify-behavior/references/cli/helpers/commit-coverage.mjs"
],
"read_dependencies": [
"SPEC.md",
"T5",
"T6",
"T7"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W3",
"description": "Build normally, validate public schema/managed output and targeted behavior suites, exercise built CLI in isolated fixtures/consumers, document authority settings, warning policy, candidate scope, preparation, diagnostics, fresh-cache retry, and authoritative consumer CI commands. Record before/after and untouched-main evidence. Reconcile tests/fixtures only through their owning workers.",
"validation": "bun run --cwd apps/cli build; bun run --cwd apps/cli check-types; bun run --cwd apps/wiki check:content; bun run --cwd packages/scaffold check-types; explicit managed-file/public-output contracts; real pinned Oxlint precedence witness; node apps/wiki/scripts/sync-content.mjs",
"status": "completed",
"log": [
"Built immutable CLI verified: guidance-only, missing-input no-publication, actual owning install, generated Vitest/Effect, 11 shipped runner scenarios, generated warning rejection. Cleanup and source/runtime identities pass; acceptance and limitations reconciled in IMPLEMENTATION-NOTES.",
"Retained review pr222-r1: optionalDependencies missing from caller dependency edges. T7 owns narrow RED/GREEN correction; T8 reruns affected built CLI proof using new frozen distribution. Unaffected prior proof retained; review_count1/repair_count1.",
"Retained review pr222-r1 resolved by minimal optional-dependency edge correction, stable focused RED/GREEN/static gates and actual rebuilt CLI positive/negative consumer proof. One full review/one focused repair; no remaining findings. PR-ready provider readback recorded in final delivery handoff; no merge/release."
],
"files edited/created": [],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"show-me",
"verify-behavior",
"update-verification-skill"
],
"implementation_skill_guidance": [
{
"skill": "show-me",
"applicable_behavior": "Present retained results with exact status and concise evidence."
},
{
"skill": "verify-behavior",
"applicable_behavior": "Drive the frozen built CLI and unchanged shipped runner in isolated repositories; retain actual output, side effects, negative outcomes and cleanup."
},
{
"skill": "update-verification-skill",
"applicable_behavior": "Repair only project-owned verification references for uncovered candidate-update and commit-coverage paths; preserve unrelated references and prove the selected recipes live."
}
],
"tdd_status": "not_applicable",
"tdd_target": "not_applicable",
"red_command": "not_applicable",
"expected_red_failure": "not_applicable",
"green_command": "bun run --cwd apps/cli build; bun run --cwd apps/cli check-types; bun run --cwd apps/wiki check:content",
"reason_not_testable": "Docs, integration validation and delivery bookkeeping; behavioral tests are owned by prerequisite tasks.",
"red_evidence": [],
"green_evidence": [],
"codebase_design_notes": "built executable, docs and evidence",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T9: Review and close out delivery
{
"depends_on": [
"T8"
],
"location": "PR and evidence",
"owned_paths": [],
"read_dependencies": [
"SPEC.md",
"T8"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W4",
"description": "One full delivery review pass; second only for a qualifying risk change after repair, scoped repairs, final local checks, PR links and provider CI readback. Classify release from changed changelogs; no release publication requested. Close issue records only with complete scope evidence, stating branch/main/release state truthfully.",
"validation": "git diff --check; gh pr view; gh run list",
"status": "completed",
"log": [
"Implementation acceptance complete. Formal frozen primary/challenger review and retained report next; leave PR ready/unmerged per user. Final state will be recorded in the delivery handoff and retained report.",
"Retained review pr222-r1 resolved by minimal optional-dependency edge correction, stable focused RED/GREEN/static gates and actual rebuilt CLI positive/negative consumer proof. One full review/one focused repair; no remaining findings. PR-ready provider readback recorded in final delivery handoff; no merge/release."
],
"files edited/created": [],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"show-me"
],
"implementation_skill_guidance": [
{
"skill": "show-me",
"applicable_behavior": "Present retained results with exact status and concise evidence."
}
],
"tdd_status": "not_applicable",
"tdd_target": "not_applicable",
"red_command": "not_applicable",
"expected_red_failure": "not_applicable",
"green_command": "git diff --check; gh pr view; gh run list",
"reason_not_testable": "Docs, integration validation and delivery bookkeeping; behavioral tests are owned by prerequisite tasks.",
"red_evidence": [],
"green_evidence": [],
"codebase_design_notes": "review and provider readback",
"review_mode": "cli",
"runtime_validation": "not_required",
"runtime_target": "not_applicable",
"runtime_evidence": "not_applicable",
"runtime_cleanup": "not_applicable"
}Plan review
Integration repair T11 (2026-09-21)
T7's public update test exposed a remaining consumer of T3's quality schema:
sync-subagents.mjs rejects the new optional execution metadata. T11 owns
only that packaged validator and sync-subagents-validator.test.ts; it follows
T3 and runs beside T6/T7 with disjoint writes. Keep legacy contracts valid and
reject malformed modes/extra fields. TDD RED/GREEN uses the owning validator
suite; T8 consumes T11 only after its gate. No scope or contract redesign.
T8 documentation drafting and project-owned verifier recipe authoring can run while T6/T7 settle; final claims and runtime proof remain gated on frozen implementation. Parent reserves build, Git, wiki projection and acceptance.
Readonly reviewer confirmed T1–T4 scopes disjoint and releasable. Added T1→T6 to prevent copying a changing runner fixture; added T5→T7 so update tests consume stable compiler/output sources. Remaining final validation detail under review.
Plan review completed: W1 released; all findings applied. Parent reserves generated baseline identity and runbook projection. T8 owns explicit public-output/managed/schema checks and pinned Oxlint process witness.
T10: Compose runtime candidate and select lint targets
{
"depends_on": [
"T1"
],
"location": "apps/cli/src/runtime/scripts.ts",
"owned_paths": [
"apps/cli/src/runtime/scripts.ts",
"apps/cli/src/runtime/scripts.test.ts",
"apps/cli/src/runtime/validation-candidate.ts",
"apps/cli/src/runtime/validation-candidate.test.ts"
],
"read_dependencies": [
"apps/cli/src/runtime/validation-candidate.ts",
"apps/cli/src/data/scripts/**"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "W2",
"description": "Compose final live/staged/removal candidate before link validation; preserve live manifests when selected, raw link chains, target replacement, and consulted input mutation witnesses. Separate explicit lint targets from installation roots. Preserve controlled Effect preparation and concrete startup diagnostics. Coordinate any required validator API with T1 owner; no validator writes. Parent transferred finalized T1 validator files to T10 to implement the required deferred-link inventory and raw-link copy seam, preserving strict default validation. No other worker writes these files.",
"validation": "bun run --cwd apps/cli test src/runtime/scripts.test.ts",
"status": "completed",
"log": [
"Scoped Codex CLI worker session 5347, retained events ../evidence/t10-worker-events.jsonl. T1 validator source frozen; no API change.",
"T10 genuine mirror RED captured. Scoped worker requested required validator seam; parent expanded ownership within accepted requirements after T1 author stopped edits. No product decision or human approval needed.",
"Parent source review and complete 160-test runtime gate passed. Four paths frozen; exact hashes match worker and parent checks. Worker stopped. T6/T7 released."
],
"files edited/created": [
"apps/cli/src/runtime/scripts.ts",
"apps/cli/src/runtime/scripts.test.ts",
"apps/cli/src/runtime/validation-candidate.ts",
"apps/cli/src/runtime/validation-candidate.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "passed",
"tdd_target": "Valid staged mirrors targeting live authored guidance reject before candidate composition; explicit lint targets broaden to root.",
"red_command": "bun run --cwd apps/cli test src/runtime/scripts.test.ts",
"expected_red_failure": "Valid staged mirrors targeting live authored guidance reject before candidate composition; explicit lint targets broaden to root.",
"green_command": "bun run --cwd apps/cli test src/runtime/scripts.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t10-final-handoff.md"
],
"green_evidence": [
"../evidence/t10-parent-full.log: 160 passed, zero skipped",
"../evidence/t10-parent-full-stability.json",
"../evidence/t10-final-handoff.md"
],
"codebase_design_notes": "runtime candidate result and process runner; no new infrastructure",
"review_mode": "cli",
"runtime_validation": "required",
"runtime_target": "Built CLI / generated runner in unique isolated repository",
"runtime_evidence": "Process exit, stdout/stderr, file changes, unchanged source checkout; integrated witness recorded by T8",
"runtime_cleanup": "Remove only task-owned fixtures; retain evidence, preserve originals"
}T1 scope transfer: parser/closure stays with candidate_runtime_fix; scripts.ts/scripts.test.ts assigned to T10, released after T1 API gate. No simultaneous validator writers. T6 waits T10 validation because it copies runner fixtures; T7 also consumes T10.
T11: Align packaged contract validator
{
"depends_on": [
"T3"
],
"location": "apps/cli/src/data/scripts/sync-subagents.mjs",
"owned_paths": [
"apps/cli/src/data/scripts/sync-subagents.mjs",
"apps/cli/src/data/scripts/sync-subagents-validator.test.ts"
],
"read_dependencies": [
"SPEC.md",
"T3 completed source/handoff"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "integration repair",
"description": "Accept optional strict execution metadata in the packaged context-plan validator; preserve legacy compatibility and malformed metadata rejection. Recover only intended narrow patch after proven hook contamination.",
"validation": "bun run --cwd apps/cli test src/data/scripts/sync-subagents-validator.test.ts",
"status": "completed",
"log": [
"Parent accepted local gate; full managed-asset/runtime proof remains T8. See ../evidence/t11-handoff.md."
],
"files edited/created": [
"apps/cli/src/data/scripts/sync-subagents.mjs",
"apps/cli/src/data/scripts/sync-subagents-validator.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "recovered",
"tdd_target": "Accept optional strict execution metadata in the packaged context-plan validator; preserve legacy compatibility and malformed metadata rejection. Recover only intended narrow patch after proven hook contamination.",
"red_command": "bun run --cwd apps/cli test src/data/scripts/sync-subagents-validator.test.ts",
"expected_red_failure": "New explicit modes rejected",
"green_command": "bun run --cwd apps/cli test src/data/scripts/sync-subagents-validator.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t11-red.log"
],
"green_evidence": [
"../evidence/t11-recovery-final17.log"
],
"codebase_design_notes": "runtime candidate result and process runner; no new infrastructure",
"review_mode": "cli",
"runtime_validation": "parent T8",
"runtime_target": "Built CLI/generated contracts",
"runtime_evidence": "Parent T8 frozen distribution proof",
"runtime_cleanup": "Parent T8 isolated fixture cleanup"
}T12: Align generated default expectations
{
"depends_on": [
"T5"
],
"location": "apps/cli/src/scaffold/output-root-materialization.test.ts",
"owned_paths": [
"apps/cli/src/scaffold/output-root-materialization.test.ts"
],
"read_dependencies": [
"SPEC.md",
"T5 completed source/handoff"
],
"shared_runtime_resources": "read-only prepared node_modules; unique task temporary fixtures; parent owns build and Git index",
"relevant_input_set": "git diff and hashes of owned paths plus completed dependency task output before/after validation",
"wave_boundary": "integration repair",
"description": "Update exactly two stale generated default lint expectations. Preserve custom command input and assertion.",
"validation": "bun run --cwd apps/cli test src/scaffold/output-root-materialization.test.ts",
"status": "completed",
"log": [
"Parent accepted local gate; full managed-asset/runtime proof remains T8. See ../evidence/t12-handoff.md."
],
"files edited/created": [
"apps/cli/src/scaffold/output-root-materialization.test.ts"
],
"task_identity_mode": "planning-only",
"backlog_item_id": "not_applicable",
"backlog_item_url": "not_applicable",
"relation_mode": "unprojected",
"backlog_sync_skip_reason": "User selected existing GitHub issues; no provider Task projection retained or requested.",
"assigned_skills": [
"tdd",
"codebase-design"
],
"implementation_skill_guidance": [
{
"skill": "tdd",
"applicable_behavior": "Capture genuine public-result RED before each behavior change; retain GREEN and negative safety cases."
},
{
"skill": "codebase-design",
"applicable_behavior": "Keep behavior behind existing owning public seam; no pass-through abstraction or ownership move."
}
],
"tdd_status": "passed",
"tdd_target": "Update exactly two stale generated default lint expectations. Preserve custom command input and assertion.",
"red_command": "bun run --cwd apps/cli test src/scaffold/output-root-materialization.test.ts",
"expected_red_failure": "Two old oxlint defaults disagree with strict generated output",
"green_command": "bun run --cwd apps/cli test src/scaffold/output-root-materialization.test.ts",
"reason_not_testable": "",
"red_evidence": [
"../evidence/t8-output-tests.log"
],
"green_evidence": [
"../evidence/t12-green.log"
],
"codebase_design_notes": "runtime candidate result and process runner; no new infrastructure",
"review_mode": "cli",
"runtime_validation": "parent T8",
"runtime_target": "Built CLI/generated contracts",
"runtime_evidence": "Parent T8 frozen distribution proof",
"runtime_cleanup": "Parent T8 isolated fixture cleanup"
}