Harness Intelligence Wiki
SpecsCLIIssue 215 — Manifest-Driven Update

Issue 215 — Safe and Fast Manifest-Driven Updates

Direct execution plan from the approved requirements grill

Issue 215 — Safe and Fast Manifest-Driven Updates

Issue 224 managed lint amendment

The approved managed lint spec extends the selection/candidate and cache contracts below for managed JS/TS lint. Saved exact lint.scopes/lint.exclude authorize software ownership; discovery and workspace membership supply candidates only. Root/custom/rootless owners remain supported. Wiki, explicit exclusions, and unselected embedded package boundaries are outside managed lint/format, while ordinary tests remain eligible.

Candidate lint uses the same derived owner/cwd/explicit effective config/local tool/threshold route as the live managed entrypoints. Include scopes/exclusions, routes, transitive project policy, generated config and presets/plugins, lockfile/toolchain, and applicable source/typed/runtime inputs in affected proof. A changed shared input invalidates its actual consumers. Prepared Installation reuse remains separate from Validation Result reuse; incomplete reuse identity requires fresh validation, while an incomplete or escaping candidate blocks dependent adoption.

Preserve compatible authored JSON/JSONC at its original project-owned path; oxlint.project.json is the convention for new policy. Preview complete dependent config/policy/command/hook/dependency changes and retirements. Findings remain preview warnings; operational/config/tool/authority failures block activation. Preserve opaque custom commands and name their conflicts. Activate through the existing coherent reconciliation/recovery boundary; retire only receipt-owned, unmodified obsolete assets after verified policy preservation. Independent work keeps truthful receipts. Read-only health must distinguish stale policy, selection, route conflicts, findings, and operational failures; baseline identity is not live route correctness.

The execution state, task statuses, cache/provider run evidence, and outstanding post-merge/local↔CI proof below remain issue 215's historical record. This amendment changes neither those results nor their limits and does not claim issue 224's final T6/T7 gates passed.

Execution contract

State: implementation and PR producer/consumer/later-run proof are complete. A4 is blocked only on the post-merge actual main/release and authenticated local↔CI matrix; A5 documentation and migration-ledger work is complete but follows A4. No publication is authorized or claimed. Source issue: #215. Discovery revision: 1ee7f8b72f8fe116ad74aa15923238d3b985c751.

The user approved Q1–Q13 and explicitly requested this plan without compiling a spec. The closed grill and decision log are the requirements authority. This file embeds the execution requirements; supplementary reports provide deeper evidence. There is intentionally no SPEC.md. If an execution wrapper assumes one, consume this approved direct-plan handoff rather than inventing a spec.

  • task_identity_mode: planning-only throughout. T1–T12 are execution identities. Issue #215 is context, not twelve provider Tasks. Backlog projection is skipped because the user requested direct planning without a spec or provider projection.
  • architecture_applicability: architecture-bearing: planning, candidate execution, durable caches, remote transport, command composition, and CI identities change together.
  • Branch/Base Intent: discovery occurred on detached HEAD. Before implementation, check current worktree changes and create an isolated team/stefan/issue-215-manifest-driven-update branch from the verified intended base, preserving these artifacts. Reconcile newer code against this plan; do not reset other work. No commit, push, merge, release, provider setting change, or implementation is part of plan creation.
  • Workflow: satisfy G0; launch every unblocked task with disjoint owned paths; each worker performs its own RED→GREEN slices; parent validates each architecture checkpoint before advancing. All statuses/evidence start empty or planned.
  • Skills: create-plan, grilling, parallel-research, swarm-planner, tdd, codebase-design, show-me, and wait-what shaped this plan. The approved frontier is empty. Per-task skills below identify implementation obligations separately. T11 retains tdd as planning provenance for its non-behavior harness classification; it has no implementation TDD guidance because product behavior is covered by its upstream tasks.
  • Root and scoped guidance inspected: AGENTS.md, apps/cli/AGENTS.md, apps/cli/src/AGENTS.md, apps/wiki/AGENTS.md, docs/AGENTS.md. No further scoped AGENTS files were found in the planned source/CI/script paths. Preserve existing repository conventions; no skills or agent guidance are changed.

Problem and evidence

The reported delay is from submitting hi update to its first output. Existing production composition resolves the Baseline before entering runUpdate, sets emitOutput:false, and only presents the final result. Earlier progress therefore needs to start at the command boundary.

The candidate copier in apps/cli/src/runtime/scripts.ts recursively excludes only .git and node_modules. Isolated Node 24 socket and FIFO reproductions throw ERR_INTERNAL_ASSERTION: Unreachable code. A main checkout contains 52 GB in .devpunks/delivery, of which 15 GB survives those exclusions. These numbers are disk usage, not measured copied bytes. Repeated desired-state planning, wiki/docs staging, unconditional tool setup, installation, and validation add work.

Other issue cases: alias-root containment compares lexical and canonical paths; preparation failures are reported as configuration failures; plain-text Oxlint stdout can disappear; bootstrap subprocess diagnostics are discarded; Python-containing repositories use different workspace predicates during scaffold and check. Existing changedFiles is a planned list, even when some operations fail.

Evidence lives in the safety report, cache-access report, and planning report. These reports distinguish observed facts from pending validation. Earlier read-only command attempts failed on a missing bundled NestJS asset or incompatible Effect resolution; they are not end-to-end benchmarks.

Requirements and acceptance ledger

IDApproved requirementOwning tasks / proof
R1 (Q1)Derive desired Managed Artifacts from Baseline inventories, settings, workspace topology, Scaffold Manifest, and actual hashes at known managed paths. Source-only edits still invalidate relevant validation.T1, T9, T10
R2 (Q2)Retain shared scaffold/check/update desired state, project ownership, verifier references, disabled lifecycle scripts, confinement, verified recovery, receipts, and truthful partial completion.T1, T2, T8–T10
R3 (Q3)Build a complete isolated Validation Candidate from selected inputs. Prune irrelevant evidence/runtime trees before traversal. Expand only to affected workspaces and their required dependencies; if completeness or containment remains unproven, block dependent adoption.T2, T8, T10
R4 (Q4,Q7)Include persistent Prepared Installation and Validation Result caches now, with separate exact-input identities, warning replay, and no successful entries for operational failures.T3, T8, T10
R5 (Q5)Preserve existing JSON fields and meanings; add explicit planned/completed outcomes and useful subprocess diagnostics.T2, T4, T9, T10
R6 (Q6)Emit human progress before expensive baseline/repository work; keep JSON stdout one final document, with opt-in progress on stderr. Record phase durations.T4, T9, T10
R7 (Q8)Reuse compatible entries across repositories and worktrees from storage outside consumer repositories; every invocation checks live ownership and required tool readiness.T3, T8–T11
R8 (Q9)Bound disposable caches, support eviction/corruption rebuild/cold fallback/bypass/clear, explain misses, publish atomically, and protect concurrent readers/writers.T3, T4, T7–T11
R9 (Q10)Measure first output, total time, phases, visited/copied/hashed work, install/lint executions and reuse. No hard latency, maximum duration, speedup, or later numeric-target approval gate. Storage bounds and correctness gates still apply.T10
R10 (Q11)Share signed Turbo artifacts across eligible branches, worktrees, trusted same-repo PRs, main, release verification, and CI runs using correct credentials/access. Preserve meaningful runtime/platform/environment differences.T5, T6, T11
R11 (Q12)Optional remote transport also covers updater caches. Ordinary hi update works without Turbo or login using local/cold paths. Use the existing artifact provider; keep updater/Turbo artifact contracts separate.T3, T7–T11
R12 (Q13)Reuse only if every result-affecting input is represented or controlled. Otherwise perform fresh validation and explain the miss. Location/branch labels alone must not partition equivalent inputs.T3, T5, T8, T11
R13 (Q2,Q7,Q11)A cache hit does not prove current installation readiness, successful writes, adopted Scaffold Manifest, receipts, or external publication. Publication mutations remain uncached and publication credentials isolated.T6, T8–T11

Canonical language

Baseline is selected Harness scaffold content and contribution definitions. Scaffold Manifest records adopted state and ownership. Context Plan is neutral contribution intent; Scaffold Plan is desired files, links, dependency/configuration changes and ownership. Managed Artifact obligations follow the manifest and desired plan. Validation Candidate is the isolated proposed repository state. Prepared Installation is dependency/toolchain state for a resolved installation context, including approved patches. Validation Result is completed findings/evidence for one validation context. Cache Entry is disposable derived content/evidence.

An uncertain cache identity means validate fresh. An incomplete or uncontained candidate means block dependent adoption. Ignore status is never ownership authority. Cached findings are separate from applied-write authority.

Solution and constraints

Selection and candidate construction

One shared desired-state decision feeds scaffold, check, and update. Read managed paths directly, hashing current content to detect edits/deletions. Reuse a resolved plan within one invocation only while its settings/topology/input identity remains valid; recheck write preconditions before applying it.

Candidate selection starts from required root configuration, lockfiles, selected workspace manifests, target source/configuration, referenced verifier files, local dependency closure and executable-config imports. Include ignored or untracked files when required by these inputs. Metadata from Git or ripgrep can accelerate enumeration but cannot establish ownership or completeness. AST tooling is not required for inventory selection and cannot prove arbitrary dynamic configuration complete.

Prune irrelevant archives, delivery evidence, sockets and runtime outputs before descending. Use lstat/canonical containment for selected entries; skip irrelevant special files, but fail with a precise path/type if a required input is unsupported. Canonicalize the candidate root and resolved child paths consistently; test symlink aliases and genuine escapes. Do not copy the entire repository when resolution is uncertain. Return input-resolution failure when bounded expansion cannot produce a complete candidate.

Retain the existing mutation witness around candidate execution, including relevant config/lock/source inputs; do not mistake it for a cache key. Candidate temporary roots and private installations are owned resources cleaned on success, failure and interruption. Recheck input identity before publication to catch changes during preparation.

Cache contract

The feature owns eligibility, identities and completion semantics. Storage adapters own filesystem/network mechanics. Deterministic identity functions are pure; resource-bearing adapters may use the existing Effect composition pattern. Keep this capability in the CLI: no new API control plane or shared package is needed.

Cache kindRequired semantic identityReuse obligation
Prepared InstallationCache/schema and installation recipe version; resolved manifests/lockfile; package manager/runtime/platform/ABI as relevant; registry/install configuration; local dependency content and topology; tool versions and approved patch content/outcomeResolve lock changes before frozen install; scripts remain disabled; patch privately; verify restored executables/links are contained and operational.
Validation ResultPrepared Installation identity plus complete validation source/config/import inputs, validator/recipe versions, options, controlled semantic environment and relevant host capabilitiesStore completed normalized findings, including warnings; replay deterministically before presentation sampling. Unknown dynamic inputs give a reasoned miss.
Turbo taskReal task inputs/outputs, tool/runtime identities, controlled semantic environment and actual capability identity for host-dependent tasksEquivalent contexts share a hash; meaningful differences miss. Actions archive restoration is a separate transport optimization.

Use content digests and versioned canonical identities, with distinct domain tags for installation, validation and Turbo artifacts. Do not key on absolute checkout/temp paths, branch name, commit SHA alone, mtime, or package manifests alone. Normalize those only where semantics are equivalent; path-sensitive configurations must be controlled or become ineligible.

An executable configuration may read arbitrary files, environment or external state. Static imports alone do not make it cacheable. Establish a declared/controlled closed input context for supported cases; otherwise keep validation fresh. Do not strip an ambient variable if doing so changes the intended validation behavior. Credential values, .npmrc secrets and unrestricted logs never enter cache payloads or diagnostics.

The local store is under the existing XDG/home user-cache convention, in its own versioned updater namespace outside consumer repositories. .devpunks-cache remains absent/empty per existing consumer lifecycle checks. Use finite byte/entry retention bounds (implementation constants/config, not performance acceptance targets), safe eviction, integrity metadata, private staging and atomic publication. A reader obtains an immutable entry/lease; clear or eviction must not break active readers. Interrupted writers leave no visible success. Corruption causes quarantine/removal of the owned entry and rebuild. Race tests must use actual concurrent processes where filesystem atomicity matters.

Materialize a private writable installation; no mutable shared node_modules or write-through hardlinks to stored patched files. Rewrite/validate relocatable links or rebuild when relocation is unsafe. Cache operations are optional optimizations: unavailable/unwritable storage and provider outages explain a miss and use local/cold execution. Distinguish absence of cache from actual install/validation failure.

Expose --cache=auto|off (default auto), --clear-cache (clear this updater namespace before normal execution), and --progress for JSON stderr progress. These are reversible interface choices implementing Q6/Q9. --cache=off bypasses reads and writes in local/remote updater caches; --clear-cache affects local owned cache only, reports that scope, and never deletes provider artifacts. All three options must appear in command metadata/help. Remote use is optional and noninteractive; do not launch a login flow during ordinary updates.

Optional remote adapter and Turbo access

Reuse the existing signed Turbo artifact service through a provider-neutral Cache Transport port. The adapter uses versioned, domain-separated updater hashes and its own envelope/manifest; it must not impersonate a Turbo task archive or use Baseline release endpoints as mutable storage.

Use explicit trusted endpoint/team/auth/signing configuration already available to local Turbo or CI, with a documented precedence and canonical team-ID resolution. No hidden login/config mutation. A missing/expired/denied credential or missing signing authority disables remote reuse with a redacted reason and local/cold fallback. Validate authenticated origin, redirects, signature, digest, archive paths/types/links and size bounds before safe private extraction. Tokens stay at the adapter boundary and out of candidate children. Upload failures never turn successful validation into failure or successful publication evidence.

Official Remote Cache API and remote cache docs support the existing v8 service. The repository pins Turbo 2.9.14; its signature implementation differs from current main. Use pinned protocol vectors and confirm provider compatibility in T11. Ordinary command operation must not require the Turbo executable.

Latest CI verification requirements supersede historical development/protected namespace separation: equal deterministic work shares one signed trusted namespace. The later same-repository-only policy applies; fork jobs receive no cache credentials and cannot populate trusted cache. Retain pinned OIDC action exchange, separate artifact-signing authority, least privilege and publication credential separation. Do not introduce a new remote service or expand trust to fork writers.

T5 must produce runtime/capability identities before both local and CI Turbo invocations, and establish equivalent intended environment values rather than blindly removing CI, NODE_ENV or TZ from hashes. Portable tasks may cross platforms when proven equivalent; installation/native or host-dependent validation identities retain meaningful platform/capability differences. Normal root entrypoints route through one small identity-producing launcher that delegates actual work to existing package tasks. Existing repository-wide policy tests need an explicitly wired root task because they own repository workflow behavior; this is the narrow exception to package-task preference.

Current evidence: main run 35029793398 had 15/16 hits, PR run 35024149127 had 0/16; both configured remote successfully. Local credentials and artifact-specific access are unproven, and those counts do not distinguish remote from restored local cache. Required proof in T11 must not be replaced by these observations.

Architecture contract

Target ownership topology

apps/cli/src/
├─ cli/update-command.ts, update-presenter.ts        command options and output
├─ features/scaffold-update/{port,interaction,...}  public update contract
│  └─ validation-cache/                            eligibility, identities, cache use policy
├─ features/scaffold-state/                        shared desired-state/ownership rules
├─ scaffold/output.ts, stage.ts                    Scaffold Plan/materialization
├─ update/run.ts                                  update sequencing, adoption, receipts
├─ runtime/validation-candidate.ts, scripts.ts     candidate inputs and isolated execution
├─ integrations/update-cache-{filesystem,remote}.ts storage and provider mechanics
└─ platform/feature-application-operations.ts       production adapter composition

scripts/behavior-contract/                         Turbo identities and proof harnesses
.github/actions/turbo-cache/                       OIDC/signing trust transport
.github/workflows/behavior-contract.yml            trusted verification invocation
docs/runbooks/                                    operator instructions, source of wiki mirrors

The existing CLI layout is retained. Extract cohesive cache/candidate behavior behind small interfaces; this is not a wholesale migration into new folders.

Allowed dependency graph

Allowed static imports into adapters are public contract/types only; runtime adapter choice is injected at composition. Forbidden: cache adapters importing update internals/presenters; cache entries authorizing adoption or receipt completion; features importing concrete remote providers; shared scaffold packages importing CLI code; remote cache credentials reaching validation child environments; cycles concealed by dynamic import. Planner semantics stay shared across scaffold/check/update.

Public seam contract

Names below bind responsibilities and semantics; implementation may refine TypeScript signatures without widening behavior, recording compatible refinements here before dependent work starts.

SeamOwner / allowed consumersContract
planScaffoldOutput, materialization plan, scaffold-state public lifecyclescaffold-state/scaffold / scaffold, check, updaterSame desired owned artifacts for identical input; caller may reuse one resolved snapshot with explicit invalidation.
runCandidateLintPreviewruntime / updaterTakes planned candidate context and execution dependencies; returns completed findings or typed preparation/install/config/execution failure, timings/work/reuse evidence; protects live repository.
Candidate input resolverruntime candidate module / validation runtimeReturns complete contained input inventory and identity inputs, or actionable incomplete-input failure.
Validation-cache public entrypointvalidation-cache feature / runtime, compositionSeparate installation/result eligibility; lookup/publication of completed entries; reasoned misses; bypass/clear options; no adoption authority.
CacheStore / CacheTransportvalidation-cache public contract / filesystem/remote adaptersRead verified immutable entries, publish complete entries atomically, own cleanup; remote optional; typed miss/unavailable/corrupt outcomes.
ScaffoldUpdateInput, UpdateEvent, public update resultscaffold-update / CLI, production adapter, updaterBackward-compatible result fields; additive outcomes/cache/timing facts; phase events never leak secrets; JSON stdout remains one final document.
Turbo identity launcherrepository scripts / local root commands, CI wrapperControls/represents semantic environment, produces actual runtime/capability values before Turbo hashes work, delegates task work.
Cache witness harnessrepository scripts / trusted local and CI operatorsArtifact-specific origin, digest, identity, remote restore and invalidation evidence with redacted credential capability outcomes.

Responsibility acceptance criteria

criterion_idOwnerObservable assertion and evidencedue_architecture_wave
RAC-1shared plannerPublic scaffold/check plans agree for mixed JS/Python topology; authored/verifier content survives. T1 tests.A1
RAC-2candidate runtimeIrrelevant socket/FIFO/evidence never traversed; required unsupported/escaping inputs fail precisely; live tree unchanged. T2 tests.A1
RAC-3validation-cache + local adapterSeparate identities, complete-only eligibility, immutable atomic entries, concurrent safe clear/eviction/corruption recovery. T3 real-filesystem tests.A1
RAC-4command/presentationCommand emits phase before invoking expensive application, maintains final JSON, declares cache/progress options. T4 command-boundary tests.A1
RAC-5Turbo launcher + CI policyEquivalent controlled identities; meaningful capability misses; same trusted namespace with OIDC/signing and no fork credentials. T5/T6 subprocess tests plus policy inspection.A1
RAC-6remote adapterPinned signing compatibility; authenticated safe extraction; malformed/denied/offline remote yields fallback, never unverified hit. T7 HTTP tests.A2
RAC-7candidate runtimeWarm reuse skips only justified install/lint work, replays findings, performs live readiness checks, isolates writes/patches. T8 tests.A2
RAC-8updater/compositionOne consistent plan drives update; readiness and actual operations determine receipts/results; no-change avoids redundant bootstrap; operational failure does not adopt dependent state. T9 tests.A3
RAC-9complete built CLIOriginal issue cases, JSON/progress, preservation, recovery, no-op and measurements pass on runnable fixtures. T10 process evidence.A4
RAC-10trusted cache integrationArtifact-specific local/branch/worktree/PR/CI restoration and relevant-input invalidation proven for Turbo and both updater cache kinds; trust boundaries verified. T11 provider evidence.A4
RAC-11docs + final integrationSource runbooks match verified behavior, mirrors generated, graph has no forbidden edges or leftover migration seams. T12 docs checks + cumulative review.A5

Architecture waves and checkpoints

A1 Boundaries and component behavior (W1; RAC-1…5)
  → A2 Cached candidate execution and remote adapter (W2; RAC-6…7)
  → A3 Production command integration (W3; RAC-8)
  → A4 End-to-end and cross-context proof (W4; RAC-9…10)
  → A5 Documented closure (W5; RAC-11)

Each checkpoint requires all task validations and all criteria due through that wave. Parent inspects cumulative import direction, public seam changes, ownership and migration ledger, and reruns earlier affected assertions. Missing, failing or regressed evidence blocks dependent waves. Workers in one wave may finish independently; the next architecture wave starts after its entry checkpoint.

A1 checkpoint — passed 2026-09-16

  • Expected / observed ownership: shared desired-state policy remains in features/scaffold-state and scaffold; candidate resolution/execution remains in runtime; cache identity/policy remains in features/scaffold-update/validation-cache; filesystem mechanics remain in integrations; command/presentation and repository Turbo/trust boundaries retain their declared owners.
  • Dependency direction: production imports follow the declared graph. No production feature imports a concrete cache adapter; the one feature-to-filesystem-adapter import is test composition. Provider/cache adapters do not own update/adoption policy.
  • Due criteria: RAC-1 through RAC-5 are met by T1–T6 focused tests and runtime/process evidence. Parent cumulative verification passed 12 CLI files / 119 tests and 3 root policy files / 27 tests under pinned Bun 1.3.5; after the T2 repair, its exact 3-file suite passed 81 tests. Pinned CLI typecheck and git diff --check passed.
  • Public seams: additive declared seams only: resolved Scaffold Output planning, candidate inventory/typed failures, validation-cache ports, progress/result facts, Turbo identity launcher, and trust readiness output. No undeclared deep import or compatibility alias was observed.
  • Migration ledger: empty. No temporary seam, dual cache authority, obsolete call path, or expired migration exists through A1.
  • Verdict: passed; A2 / W2 is unblocked. The persisted $show-me ownership/dependency view and detailed evidence are in IMPLEMENTATION-NOTES.md.

A2 checkpoint — passed 2026-09-16

  • Expected / observed ownership: candidate cache orchestration stays in runtime/scripts.ts; eligibility and truthful local/remote origin stay in the validation-cache feature; filesystem and signed HTTP provider mechanics stay in separate integrations. Production runtime imports ports/types only.
  • Dependency direction: runtime → candidate resolver + cache feature ports; cache feature → no concrete adapter; integrations → public cache contract. The only feature→filesystem adapter edge is a co-located integration test. No provider credential enters child validation processes.
  • Due criteria: RAC-1 through RAC-7 are met. Parent cumulative verification passed 13 CLI files / 147 tests and 3 root behavior-contract files / 27 tests under pinned Bun 1.3.5. CLI typecheck and git diff --check passed.
  • Public seams: compatible declared refinements only: CacheRead adds truthful hit origin; LintPreviewFacts adds cache/timing/execution evidence; runCandidateLintPreview accepts injected cache codecs/policy and a pre-lookup live-readiness check. T9 remains the production composition owner.
  • Migration ledger: empty. No concrete-provider import in runtime, dual cache path, path-keyed compatibility identity, or temporary seam remains.
  • Verdict: passed; A3 / W3 is unblocked. Detailed runtime evidence and the cumulative ownership view are in IMPLEMENTATION-NOTES.md.

Migration ledger

Planned temporary seams: none
Each checkpoint: inventory introduced adapters/aliases/old call paths → remove or record owner + expiry
Final closure: zero temporary seams and obsolete compatibility paths

No dual cache authority or compatibility API is planned. If implementation needs a temporary seam, amend this ledger with introducing task, reason, allowed consumers, removal task, expiry architecture wave and removal proof before consumers depend on it. Changes to approved behavior/trust require handback; routine compatible internal signatures do not.

Task graph and worker waves

Worker waveTasks launched togetherEntry checkpointWhy this grouping
W1T1, T2, T3, T4, T5, T6G0Six disjoint scopes, contracts specified above.
W2T7, T8A1Both consume T3; remote adapter and runtime orchestration are disjoint.
W3T9A2One writer owns shared update orchestration and production composition.
W4T10, T11A3Built-command verification and provider proof own separate harnesses/evidence.
W5T12A4Final documentation describes proven integrated behavior.

Before dispatch, verify global/project agent configuration and .agents/subagents/manifest.mjs. Prefer apps-cli-src for CLI source tasks, a bounded general worker for root/CI tasks and docs for runbooks. Tell every worker that other workers are active and their edits must be preserved. Parent owns this PLAN and execution bookkeeping; workers report evidence for parent updates. A broad path in a task is exclusive only within its declared scope; no same-wave task may edit it.

G0: execution readiness

Before behavioral RED or benchmark capture:

  1. Verify branch/base, working tree, scoped instructions and current accepted authority. Preserve uncommitted artifacts.
  2. Use repository-pinned dependencies/runtime (Bun 1.3.5; inspected Node 24.19.0; Effect 4.0.0-beta.101). Resolve exact APIs from opensrc/effect.md and opensrc path Effect-TS/effect; do not rely on incompatible global fallback modules.
  3. Prepare dependencies and build fresh CLI assets using normal repository scripts. Confirm the bundled NestJS .gitignore packaging issue is resolved for the tested build. If not, report the exact readiness blocker; do not silently expand into unrelated packaging changes or label infrastructure failure RED.
  4. Establish one runnable existing focused test, the built CLI --help, and disposable fixture paths. Use the package-owned bun run --cwd apps/cli check-types and bun run --cwd apps/cli check; their scripts resolve the repository-pinned compiler and formatter. Run root bun run check-types later for workspace checks.
  5. Before any implementation, retain a runnable pre-change build in a separate execution-owned baseline worktree at the verified base revision, outside this checkout, with its complete apps/cli/dist assets and required pinned dependencies. Verify its --help and fixture invocation, then record the absolute entrypoint as HI_ISSUE215_BASELINE_ENTRYPOINT in local execution bookkeeping (no committed machine path). Keep that worktree immutable until T10 completes; record its revision and distribution digest and clean it only afterward. Capture pre-change first-output/total/phase/work evidence on a runnable fixture using that retained CLI. Large-checkout data is diagnostic; do not mutate the user's actual consumer repository to obtain it. Record runtime versions and cache state. If a case cannot run, retain the failure separately and use comparable runnable fixtures.
  6. Use normal test subprocess/temporary-root facilities. Tests run from root via bun run --cwd apps/cli test <src paths>; root workflow-contract tests run via bun test scripts/behavior-contract/<file>.test.ts. New tests named below are created by their task before recording RED. Missing test files, unresolved modules, or stale builds are not expected RED.
  7. Provider access is not required to start local implementation; it is required to complete T11/A4. Never print secret values, alter provider trust, or claim unobserved access.

Tasks

Each task is a vertical behavioral slice, not a separate all-tests-first phase. Exact ownership below includes its tests. Evidence commands are run from repository root. New planned files at discovery include validation-candidate.ts and its test, validation-cache/**, update-cache-filesystem/remote adapters and tests, update-command/update-presenter tests, feature-application-operations.test.ts, cache-identity/run-turbo modules, shared-cache-witness modules/workflow, issue-215-update-benchmark.mjs and the evidence trees. Workers create these within their owned paths; other listed files already exist.

T1: Unify manifest-driven selection and shared planning

id: "T1"
depends_on: []
location: "apps/cli/src/features/scaffold-state/**"
owned_paths: ["apps/cli/src/features/scaffold-state/**","apps/cli/src/scaffold/output.ts","apps/cli/src/scaffold/output.test.ts","apps/cli/src/scaffold/output-root-materialization.test.ts","apps/cli/src/scaffold/output-root-dependencies.test.ts","apps/cli/src/scaffold/stage.ts"]
wave_boundary: "W1"
description: "Implement R1/R2 through the existing shared planner: inventory/settings/topology plus actual managed-path hashes; fix mixed Python/JS workspace classification; expose a reusable resolved Scaffold Plan with explicit invalidation. Preserve authored content, verifier references and receipt-owned removals. Keep generation and plan-only decisions identical; do not add a second update-only ownership scanner."
validation: "Scaffold→check parity; mixed Python/JS including independent non-JS manifests; unchanged plan repeat; edited/missing managed files; settings/topology invalidation; authored ignored/untracked verifier preservation. Run existing scaffold-state and output suites, then CLI typecheck."
status: "Complete"
log: "W1/A1 parent gate passed after repair: shared mixed-topology planning and invocation-local resolved-output reuse now invalidate independently on settings, topology, managed state, relevant inputs and generation options."
"files edited/created": ["apps/cli/src/features/scaffold-state/snapshot.ts","apps/cli/src/features/scaffold-state/reconcile.ts","apps/cli/src/features/scaffold-state/reconcile.test.ts","apps/cli/src/features/scaffold-state/index.ts","apps/cli/src/scaffold/output.ts","apps/cli/src/scaffold/output.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
tdd_status: "required"
tdd_target: "A mixed Python/JS repository produces the same lint artifacts in scaffold materialization and check, preserving project-authored verifier files."
red_command: "bun run --cwd apps/cli test src/scaffold/output.test.ts -t 'mixed workspace desired state'"
expected_red_failure: "New public plan/materialization assertion observes different lint-config paths or a missing required managed artifact before the fix."
green_command: "bun run --cwd apps/cli test src/scaffold/output.test.ts src/scaffold/output-root-materialization.test.ts src/scaffold/output-root-dependencies.test.ts src/features/scaffold-state/reconcile.test.ts src/features/scaffold-state/portability.test.ts"
reason_not_testable: ""
red_evidence: "Pinned Bun 1.3.5 public-seam test expected the resolved desired artifact plan to be reused but received a newly planned object; 1 failed and 20 were skipped."
green_evidence: "Pinned Bun 1.3.5 exact five-file T1 command passed 34 tests; CLI typecheck passed."
codebase_design_notes: "Deepen existing shared lifecycle decisions; expose immutable planning results, not private traversal helpers. Keep caller migration in T9."
review_mode: "cli"
runtime_validation: "not_required"
runtime_target: "not_applicable"
runtime_evidence: "not_applicable"
runtime_cleanup: "not_applicable"
architecture_wave: "A1"
behavior_owner: "Shared scaffold-state and scaffold planner"
integration_surface: "scaffold, repository-check and runUpdate"
public_seam: "planScaffoldOutput / materialization / scaffold-state lifecycle"
topology_delta: "One desired-state classifier and managed selection authority."
forbidden_ownership: "No cache/provider concerns in planner; no separate check/update classifiers."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-1"]

T2: Build a bounded, contained candidate and retain failures

id: "T2"
depends_on: []
location: "apps/cli/src/runtime/scripts.ts"
owned_paths: ["apps/cli/src/runtime/scripts.ts","apps/cli/src/runtime/scripts.test.ts","apps/cli/src/runtime/validation-candidate.ts","apps/cli/src/runtime/validation-candidate.test.ts","apps/cli/src/integrations/tool-management.ts","apps/cli/src/integrations/tool-management.test.ts"]
wave_boundary: "W1"
description: "Replace broad candidate copying with the required input inventory and bounded affected-workspace/local-dependency expansion. Prune irrelevant trees before traversal, preserve required ignored/untracked inputs, canonicalize roots/children consistently and classify unsupported required entries. Separate preparation/install/config/lint operational failures; retain bounded redacted stdout/stderr, exit/signal and cause, including plain-text Oxlint and tool-bootstrap failures. Preserve mutation protection, lifecycle-script disabling, independent package roots and cleanup."
validation: "Real filesystem socket/FIFO under irrelevant delivery tree is not visited; required special input fails with path/type; alias root passes and actual escape fails; incomplete candidate blocks; plain-text stdout survives parse error; subprocess failure reports phase/code/stderr. Real private Bun fixture runs with no live tree mutation. CLI typecheck."
status: "Complete"
log: "W1/A1 parent gate passed after repair: bounded complete-or-fail candidate inventory prunes runtime evidence before traversal, preserves required inputs, blocks unproven executable config and directory links precisely, retains redacted process facts, and cleans private candidates."
"files edited/created": ["apps/cli/src/runtime/scripts.ts","apps/cli/src/runtime/scripts.test.ts","apps/cli/src/runtime/validation-candidate.ts","apps/cli/src/runtime/validation-candidate.test.ts","apps/cli/src/integrations/tool-management.ts","apps/cli/src/integrations/tool-management.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","backend-recoverable-actions"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "backend-recoverable-actions"
    applicable_behavior: "Classify preparation, publication and cleanup separately; atomically expose complete cache state and test interruption/partial failure without pretending external writes roll back."
tdd_status: "required"
tdd_target: "runCandidateLintPreview succeeds on required inputs when an unrelated delivery subtree contains a socket/FIFO, with no live changes."
red_command: "bun run --cwd apps/cli test src/runtime/scripts.test.ts -t 'ignores unrelated runtime entries'"
expected_red_failure: "Old recursive copy raises ERR_INTERNAL_ASSERTION or reports candidate/config failure because it traverses unrelated special files."
green_command: "bun run --cwd apps/cli test src/runtime/scripts.test.ts src/runtime/validation-candidate.test.ts src/integrations/tool-management.test.ts"
reason_not_testable: ""
red_evidence: "The required unrelated-runtime-tree test failed under the old broad copier; repair REDs also showed arbitrary executable-config I/O executing successfully and directory symlink contents failing only as generic ENOENT."
green_evidence: "Pinned Bun 1.3.5 exact three-file T2 command passed 81 tests; runtime correlation hi-215-alias-lloY2U preserved the live hash and removed all fixtures/candidates; CLI typecheck passed."
codebase_design_notes: "Candidate resolution returns a complete inventory or typed incomplete-input error. Keep the existing runtime public seam; T8 is the only later cache integrator for scripts.ts."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "runCandidateLintPreview using real isolated Bun/Node fixtures"
runtime_evidence: "Record candidate paths/work counters, process output, untouched live hashes and cleanup after success/failure; repeat canonical alias case on actual macOS in T10."
runtime_cleanup: "Unique test-owned temp root per run; close socket/FIFO processes and remove only those roots in finalizers."
architecture_wave: "A1"
behavior_owner: "Candidate runtime; tool-management adapter owns its subprocess facts"
integration_surface: "runUpdate lint-preview boundary"
public_seam: "runCandidateLintPreview / Candidate input resolver"
topology_delta: "Input selection becomes bounded and explicit; errors retain originating phase."
forbidden_ownership: "No ownership inference from ignore rules; no whole-repository fallback or candidate writes into live root."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-2"]

T3: Implement separate durable cache identities and local storage

id: "T3"
depends_on: []
location: "apps/cli/src/features/scaffold-update/validation-cache/**"
owned_paths: ["apps/cli/src/features/scaffold-update/validation-cache/**","apps/cli/src/integrations/update-cache-filesystem.ts","apps/cli/src/integrations/update-cache-filesystem.test.ts"]
wave_boundary: "W1"
description: "Add the public validation-cache contract, pure installation/result identities and eligibility, local store, immutable envelope and optional CacheTransport port. Implement bounded retention, atomic complete publication, integrity checks, private materialization, active-reader protection, crash recovery, bypass/clear and miss reasons. Store outside consumer repositories. Test values/results through the public cache seam; remote implementation is T7 and production execution is T8/T9."
validation: "Cross-root equivalent-input hits; source change misses result but preserves installation; lock/config/tool/runtime/patch/topology/env changes invalidate correctly; dynamic/uncontrolled inputs ineligible. Real filesystem corruption/interrupted writer/concurrent processes/eviction versus leased readers/private writable materialization; no operational failure stored as success; unavailable store gives cold fallback. CLI typecheck."
status: "Complete"
log: "W1/A1 parent gate passed: separate installation/result identities, cache policy ports and bounded atomic filesystem storage support immutable reads, corruption/interruption recovery and private installation materialization."
"files edited/created": ["apps/cli/src/features/scaffold-update/validation-cache/index.ts","apps/cli/src/features/scaffold-update/validation-cache/cache.test.ts","apps/cli/src/integrations/update-cache-filesystem.ts","apps/cli/src/integrations/update-cache-filesystem.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","backend-domain-structure","backend-recoverable-actions"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "backend-domain-structure"
    applicable_behavior: "Keep feature policy, process composition and provider/filesystem mechanics in their declared owners; expose deliberate public ports and keep dependencies acyclic."
  - skill: "backend-recoverable-actions"
    applicable_behavior: "Classify preparation, publication and cleanup separately; atomically expose complete cache state and test interruption/partial failure without pretending external writes roll back."
tdd_status: "required"
tdd_target: "After publishing a completed entry through the public cache API, an equivalent input from another root restores private state without mutating the stored entry."
red_command: "bun run --cwd apps/cli test src/features/scaffold-update/validation-cache/cache.test.ts -t 'reuses equivalent inputs across roots'"
expected_red_failure: "A runnable public-seam test records a miss/reexecution on equivalent cross-root inputs until durable reuse exists. Establish the smallest callable skeleton first; missing import/collection failure is not behavioral RED."
green_command: "bun run --cwd apps/cli test src/features/scaffold-update/validation-cache/cache.test.ts src/integrations/update-cache-filesystem.test.ts"
reason_not_testable: ""
red_evidence: "Pinned Bun 1.3.5 equivalent cross-root inputs returned miss/absent before the cache implementation."
green_evidence: "Pinned Bun 1.3.5 exact T3 suite passed 9 tests; real concurrent producers and interrupted-writer recovery passed under correlation hi-t3-runtime-wGjusm; CLI typecheck passed."
codebase_design_notes: "Pure identities are values, not services. CacheStore represents real filesystem authority; policy never imports its concrete adapter. In-process Effect Cache is insufficient for persistent cross-process storage."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Filesystem cache adapter with independent Node processes"
runtime_evidence: "Readers never see incomplete entries; concurrent producers yield a valid entry; interrupted/cleared entries rebuild; writes to restored files do not change cache bytes."
runtime_cleanup: "Dedicated XDG cache root and process/run IDs for fixtures; never clear the user's shared cache during tests."
architecture_wave: "A1"
behavior_owner: "Validation-cache feature policy and filesystem adapter"
integration_surface: "candidate runtime, platform composition"
public_seam: "Validation-cache entrypoint / CacheStore / CacheTransport"
topology_delta: "Separate cache identity and artifact-lifecycle authority from updater adoption."
forbidden_ownership: "No live adoption decisions, remote SDK calls, shared writable node_modules or consumer .devpunks-cache."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-3"]

T4: Define early progress and compatible command results

id: "T4"
depends_on: []
location: "apps/cli/src/cli/update-command.ts"
owned_paths: ["apps/cli/src/cli/update-command.ts","apps/cli/src/cli/update-command.test.ts","apps/cli/src/cli/update-presenter.ts","apps/cli/src/cli/update-presenter.test.ts","apps/cli/src/features/scaffold-update/port.ts","apps/cli/src/features/scaffold-update/interaction.ts","apps/cli/src/features/scaffold-update/application.ts","apps/cli/src/features/scaffold-update/index.ts","apps/cli/src/presentation/operation-result/lint-preview-facts.ts"]
wave_boundary: "W1"
description: "Add typed phase/reuse/timing facts and planned/completed operation facts without changing old JSON meanings. Emit initial human progress at the command boundary before invoking the application. Add --cache, --clear-cache and opt-in JSON --progress to metadata/parser/input; route progress to stderr in JSON mode and retain one final stdout document. Keep command parsing/presentation thin. T9 supplies production facts and forwards runtime events."
validation: "Command-boundary tests hold the expensive operation behind a deterministic barrier and observe initial output first. JSON stdout parses as one document; default JSON is quiet until final result; --progress only writes stderr. Existing fields/changedFiles meanings retained on partial failure; options reject invalid modes and appear in help. CLI typecheck."
status: "Complete"
log: "W1/A1 parent gate passed: command-boundary progress precedes expensive application work, JSON stdout remains one final document, opt-in JSON progress uses stderr, and cache/progress controls are declared."
"files edited/created": ["apps/cli/src/cli/update-command.ts","apps/cli/src/cli/update-command.test.ts","apps/cli/src/cli/update-presenter.ts","apps/cli/src/cli/update-presenter.test.ts","apps/cli/src/features/scaffold-update/application.ts","apps/cli/src/features/scaffold-update/index.ts","apps/cli/src/features/scaffold-update/interaction.ts","apps/cli/src/presentation/operation-result/lint-preview-facts.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","effect","effect-backend-structure"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "effect"
    applicable_behavior: "Follow repository-compatible Effect v4 APIs and typed failures; use deterministic synchronization and scoped cleanup; consult current/pinned source before unfamiliar APIs."
  - skill: "effect-backend-structure"
    applicable_behavior: "Keep update policy in the feature/action and adapter selection in platform composition; propagate requirements until the owning composition provides them."
tdd_status: "required"
tdd_target: "The public update command emits its initial human progress before a deliberately suspended application completes or begins expensive work."
red_command: "bun run --cwd apps/cli test src/cli/update-command.test.ts -t 'progress precedes application work'"
expected_red_failure: "Before the change no progress is observable until the application returns."
green_command: "bun run --cwd apps/cli test src/cli/update-command.test.ts src/cli/update-presenter.test.ts"
reason_not_testable: ""
red_evidence: "A deterministic application barrier proved the old command emitted no initial human output before entering expensive work."
green_evidence: "Pinned Bun 1.3.5 exact command/presenter suite passed 4 tests, including real subprocess stream ordering; CLI typecheck passed."
codebase_design_notes: "Command entry owns first output; UpdateEvent transports phase facts; presenter owns formatting. Do not hide the initial event inside runUpdate after baseline resolution."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Effect CLI command boundary with captured real streams"
runtime_evidence: "Ordered stream observations show initial progress before the work barrier; machine mode has exactly one parseable final stdout document."
runtime_cleanup: "Scope captured streams and release test barriers in finalizers; no arbitrary timing assertion."
architecture_wave: "A1"
behavior_owner: "CLI transport/presentation and scaffold-update public contract"
integration_surface: "makeUpdateCommand / production adapter / runUpdate"
public_seam: "ScaffoldUpdateInput / UpdateEvent / public update result"
topology_delta: "Add progress and explicit execution facts without changing legacy field semantics."
forbidden_ownership: "No file ownership, cache I/O or baseline work in presenter; no secret-bearing diagnostics."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-4"]

T5: Make Turbo identities consistent across eligible contexts

id: "T5"
depends_on: []
location: "package.json"
owned_paths: ["package.json","turbo.json","scripts/behavior-contract/run-ci-verification.mjs","scripts/behavior-contract/run-turbo.mjs","scripts/behavior-contract/cache-identity.mjs","scripts/behavior-contract/cache-identity.test.ts","scripts/behavior-contract/affected-verification.test.ts","scripts/behavior-contract/cli-verification-cache-fixture.d.mts","scripts/behavior-contract/cli-host-capability-cache-fixture.d.mts"]
wave_boundary: "W1"
description: "Produce actual runtime/capability identities before local and CI Turbo entrypoints and align semantic execution environments. Audit declared inputs/outputs and passthrough variables; remove only irrelevant partitions with evidence. Preserve portable task reuse and host-sensitive misses; leave external mutations uncached. Wire repository cache-policy Bun tests into normal verification. Remove or replace stale fixture declarations whose implementations no longer exist; do not restore obsolete development/protected policy."
validation: "Real subprocess fixtures/dry-run hashes demonstrate equivalent branch/worktree/local-CI contexts share intended identities and source/runtime/config/capability differences miss. Show actual restored outputs on repeated fixture task, not just hash equality. Affected selection and existing build task dependencies remain correct; check workflow-contract tests are selected by normal verification."
status: "Complete"
log: "W1/A1 parent gate passed: one runtime/capability identity launcher feeds package-owned Turbo tasks, equivalent controlled contexts hash together, meaningful host differences miss, and restored bytes are proven."
"files edited/created": ["package.json","turbo.json","scripts/behavior-contract/run-turbo.mjs","scripts/behavior-contract/cache-identity.mjs","scripts/behavior-contract/cache-identity.test.ts","scripts/behavior-contract/run-ci-verification.mjs","scripts/behavior-contract/affected-verification.test.ts","scripts/behavior-contract/cli-host-capability-cache-fixture.d.mts","scripts/behavior-contract/cli-verification-cache-fixture.d.mts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","turborepo"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "turborepo"
    applicable_behavior: "Delegate work to owning package tasks, define complete inputs/outputs and semantic env identities, preserve signed optional remote reuse, and validate actual task restoration."
tdd_status: "required"
tdd_target: "One repository verification task with identical semantic inputs obtains the same task identity across two checkout locations with local and CI labels."
red_command: "bun test scripts/behavior-contract/cache-identity.test.ts -t 'equivalent contexts share task identity'"
expected_red_failure: "Current ambient CI/environment partitioning or missing identity producers changes the task hash for otherwise equivalent controlled contexts."
green_command: "bun test scripts/behavior-contract/cache-identity.test.ts scripts/behavior-contract/affected-verification.test.ts"
reason_not_testable: ""
red_evidence: "Pinned Bun 1.3.5 required RED produced different local and CI hashes (249080a51b4a2bcd versus a64cbd8427f9bab3); later slices exposed missing capability, config and seed inputs."
green_evidence: "Pinned Bun 1.3.5 T5 suites passed 19 tests / 61 assertions; equivalent local/CI hash was 8f0172567b4afc20 and restored bytes matched fresh output SHA-256 375c027715824d8c68c9faa50228dbcc03d8b23a0921965c7eddbb5c67f66377."
codebase_design_notes: "One thin launcher computes context then delegates to Turbo; package tasks retain work ownership. Root repository-policy testing is explicitly justified, not a generic root task bucket."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Pinned Turbo 2.9.14 subprocesses in disposable fixture worktrees"
runtime_evidence: "Retain dry-run task hashes/inputs and restored output digests; prove host-sensitive changes miss. T11 provides authenticated remote proof."
runtime_cleanup: "Own temporary worktrees and task caches by run ID; remove only fixture refs/worktrees after processes exit."
architecture_wave: "A1"
behavior_owner: "Repository verification identity and task graph"
integration_surface: "root scripts / affected CI wrapper"
public_seam: "Turbo identity launcher"
topology_delta: "Introduce real semantic identity producers before hashing and wire missing policy test execution."
forbidden_ownership: "No blind env/hash deletion, forced local-CI partition, provider secret access or caching publication commands."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-5"]

T6: Preserve one trusted signed cache namespace and access policy

id: "T6"
depends_on: []
location: ".github/actions/turbo-cache/action.yml"
owned_paths: [".github/actions/turbo-cache/action.yml",".github/actions/turbo-cache/cache-trust-policy.mjs",".github/workflows/behavior-contract.yml","scripts/behavior-contract/cache-trust.test.ts"]
wave_boundary: "W1"
description: "Reconcile cache transport configuration with latest accepted trust policy. Preserve pinned short-lived OIDC exchange and independent signing authority; expose nonsecret canonical team/access diagnostics needed by both cache clients. Same-repo trusted PR/main verification uses one signed namespace. Keep forks credential-free, publication credentials isolated and outer Actions archive keys distinct from inner task identities. Inspect runner isolation and provider-policy requirements; unresolved provider facts remain T11 obligations."
validation: "Subprocess policy tests prove the same trusted authority yields one namespace, empty/expired/denied signing/auth conditions are handled without printing values, fork/untrusted contexts cannot obtain trusted write access, and publication secrets are absent from cache/validation child env. Inspect workflow permissions, action pins, environment exports and outer archive restore keys; parse YAML."
status: "Complete"
log: "W1/A1 parent gate passed: trusted same-repository contexts share one configured signed authority, fork/untrusted contexts export no credentials, and readiness distinguishes configured inputs from unverified provider capability."
"files edited/created": [".github/actions/turbo-cache/action.yml",".github/actions/turbo-cache/cache-trust-policy.mjs",".github/workflows/behavior-contract.yml","scripts/behavior-contract/cache-trust.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","turborepo"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "turborepo"
    applicable_behavior: "Delegate work to owning package tasks, define complete inputs/outputs and semantic env identities, preserve signed optional remote reuse, and validate actual task restoration."
tdd_status: "required"
tdd_target: "Cache policy reports actionable redacted readiness for shared signed reuse and refuses incomplete signing authority without exposing a key or granting untrusted writer access."
red_command: "bun test scripts/behavior-contract/cache-trust.test.ts -t 'reports signed cache readiness without secrets'"
expected_red_failure: "Current policy lacks the structured readiness/canonical authority evidence expected by the new behavioral assertion; use actual subprocess outputs, not source-string tests."
green_command: "bun test scripts/behavior-contract/cache-trust.test.ts"
reason_not_testable: ""
red_evidence: "Pinned Bun 1.3.5 readiness subprocess test failed because no readiness document was emitted."
green_evidence: "Pinned Bun 1.3.5 exact T6 suite passed 8 tests / 158 assertions; runtime proof reported configured signing/authentication without secrets and retained providerAccess=unverified."
codebase_design_notes: "The action owns authentication transport; task identity stays in T5; CLI remote client consumes an explicit credential context through its adapter. audit-cicd-security informed readonly discovery; it is not a request for new provider trust."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Cache policy subprocess and existing trusted workflow definition"
runtime_evidence: "Retain redacted policy execution and parsed permissions/credential flow. Real token capabilities and persistent runner isolation must be proven in T11, not inferred from env names."
runtime_cleanup: "Temporary GitHub env/output files contain only fixture secrets, are isolated per test and removed after inspection."
architecture_wave: "A1"
behavior_owner: "Trusted CI cache transport policy"
integration_surface: "trusted PR/main workflow and remote adapter configuration"
public_seam: "OIDC/signing/team environment boundary"
topology_delta: "Make shared trusted access and readiness explicit while preserving publication isolation."
forbidden_ownership: "No fork credentials, secret values in logs/artifacts, new provider/team or silent access-policy weakening."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-5"]

T7: Add the optional signed updater cache transport

id: "T7"
depends_on: ["T3"]
location: "apps/cli/src/integrations/update-cache-remote.ts"
owned_paths: ["apps/cli/src/integrations/update-cache-remote.ts","apps/cli/src/integrations/update-cache-remote.test.ts","apps/cli/src/integrations/update-cache-remote-fixtures/**"]
wave_boundary: "W2"
description: "Implement CacheTransport against the existing artifact provider with the pinned v8/signature contract and updater-specific envelope/hash domain. Resolve configured team identity/auth securely; verify signatures and digests before safe extraction. Add bounded transfer, redirects/auth-origin rules, retry only for safe transient operations, and redacted miss/fallback outcomes. Never require Turbo executable or interactive login. Keep credential values and private registry config outside cached payloads."
validation: "Loopback HTTP boundary tests cover valid pinned signature vectors, wrong team/key/digest, denied/expired auth, redirects to another origin, traversal/symlink/hardlink/special-file archives, oversized/truncated transfer, timeout/offline, interrupted upload and cold/local fallback. Use actual archive bytes/files; real provider compatibility remains T11. CLI typecheck."
status: "Complete"
log: "W2/A2 task gate passed: signed v8 transport uses pinned Turbo 2.9.14 HMAC semantics with an updater-specific envelope, canonical team resolution, bounded same-origin transfer, verified inventory, and reasoned local/cold fallback. Live provider compatibility remains T11."
"files edited/created": ["apps/cli/src/integrations/update-cache-remote.ts","apps/cli/src/integrations/update-cache-remote.test.ts","apps/cli/src/integrations/update-cache-remote-fixtures/pinned-vector.ts","apps/cli/src/features/scaffold-update/validation-cache/index.ts","apps/cli/src/features/scaffold-update/validation-cache/cache.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","backend-domain-structure","backend-recoverable-actions"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "backend-domain-structure"
    applicable_behavior: "Keep feature policy, process composition and provider/filesystem mechanics in their declared owners; expose deliberate public ports and keep dependencies acyclic."
  - skill: "backend-recoverable-actions"
    applicable_behavior: "Classify preparation, publication and cleanup separately; atomically expose complete cache state and test interruption/partial failure without pretending external writes roll back."
tdd_status: "required"
tdd_target: "A correctly signed completed updater entry from the transport restores verified bytes, while a tampered artifact becomes a reasoned miss and is never materialized."
red_command: "bun run --cwd apps/cli test src/integrations/update-cache-remote.test.ts -t 'restores only verified signed artifacts'"
expected_red_failure: "The T3 absent-remote adapter cannot restore the valid artifact; the test also proves tampered bytes never reach a caller. A missing module is not RED."
green_command: "bun run --cwd apps/cli test src/integrations/update-cache-remote.test.ts"
reason_not_testable: ""
red_evidence: "The required signed-restoration case expected a verified hit but received remote-unavailable before the adapter implementation."
green_evidence: "Pinned Bun 1.3.5 T7 suite passed 8 tests and combined cache suites passed 18 tests; runtime correlation hi-t7-runtime-9AVw2H verified PUT/GET/restoration and rejected tampering as signature-invalid."
codebase_design_notes: "Provider mechanics implement public cache contracts only. Pin Turbo 2.9.14 signing vectors, including canonical team ID; avoid current-main protocol drift. Do not reuse Baseline publication storage."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Real HTTP/archival transport fixture; existing provider in T11"
runtime_evidence: "Record request origin, redacted auth outcome, envelope/hash/digest verification and cleanup on transfer failure; no secret-bearing request dump."
runtime_cleanup: "Bind an ephemeral test listener, own transfer/extraction temp roots, abort outstanding requests and close listener in finalizers."
architecture_wave: "A2"
behavior_owner: "Updater remote cache integration adapter"
integration_surface: "CacheTransport selected by platform composition"
public_seam: "CacheTransport"
topology_delta: "Add a second real cache adapter without coupling policy to provider details."
forbidden_ownership: "No baseline endpoint mutation, feature-internal imports, unverified extraction or automatic login."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-6"]

T8: Reuse installations and completed validation safely

Compatible A2 seam refinement (recorded before implementation): T8 also owns the narrow additive schema change in apps/cli/src/presentation/operation-result/lint-preview-facts.ts needed for typed cache origin, miss reason, timing, and execution-count evidence returned by runCandidateLintPreview. Presenter behavior remains unchanged; T9 alone maps these facts into the update result. CacheRead may add a typed local/remote origin because cache policy is the only layer that can truthfully identify it. Candidate execution may accept an optional injected live-readiness check that runs before every cache lookup; T9 binds the production ownership/tool policy, so cache evidence never authorizes readiness. This does not change an owner, dependency edge, adoption authority, or migration ledger entry.

A3 integration repair: the built T9 composition proved that generated .claude/skills directory links are required contained Validation Candidate inputs. T8 must represent a contained directory link by recursively inventorying its canonical target within the existing entry/byte bounds and preserving the link in the private candidate; missing, escaping, special, or incomplete targets still fail typed before execution. T8 also emits PhaseStarted/PhaseCompleted evidence at actual candidate preparation/install/config/lint/cleanup boundaries so T9 can forward truthful live progress; accumulated timings remain result facts and are not replayed as progress.

A3 generated-config repair: the same built fixture proved the bounded declarative parser rejected Harness's generated wiki config at a grouped trusted-preset expression ((core.ignorePatterns ?? [])). T8 must accept only grouped data-composition syntax on already-approved local/Ultracite/Effect preset bindings, with focused positive and negative tests. It must not widen acceptance to arbitrary calls, optional calls, unknown packages, computed ambient reads, filesystem/network/process access, or dynamic loading.

id: "T8"
depends_on: ["T2","T3"]
location: "apps/cli/src/runtime/scripts.ts"
owned_paths: ["apps/cli/src/runtime/scripts.ts","apps/cli/src/runtime/scripts.test.ts"]
wave_boundary: "W2"
description: "Integrate the public cache policy into candidate validation using injected adapters. Resolve final manifest/lock state before installation identity; privately materialize Prepared Installations and preserve explicit approved patches. Independently evaluate Validation Result eligibility, replay complete warnings/findings on hit, and validate fresh on unknown inputs. Recheck live tool readiness/ownership-related inputs and compare identities before publishing completed entries. Record hit/miss origins, work and durations. No remote concrete imports; T9 wires T7."
validation: "Public runCandidateLintPreview cases: cold, installation-only hit, result hit, source-only edit, settings/lock/config/tool/patch/runtime/topology/env changes, dynamic input miss, required live tool missing, remote-port fallback, warnings replay, operational failure not cached, private patch isolation, concurrent invocation and cleanup. Existing candidate safety remains green."
status: "Complete"
log: "W2/A2 parent gate passed after semantic-identity repair: separate installation/result reuse uses content/runtime inputs rather than paths, readiness runs before lookup, children preserve registry/Git auth while excluding cache/signing/publication credentials, and publication follows cleanup plus live mutation witnesses."
"files edited/created": ["apps/cli/src/runtime/scripts.ts","apps/cli/src/runtime/scripts.test.ts","apps/cli/src/presentation/operation-result/lint-preview-facts.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","backend-domain-structure","backend-recoverable-actions"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "backend-domain-structure"
    applicable_behavior: "Keep feature policy, process composition and provider/filesystem mechanics in their declared owners; expose deliberate public ports and keep dependencies acyclic."
  - skill: "backend-recoverable-actions"
    applicable_behavior: "Classify preparation, publication and cleanup separately; atomically expose complete cache state and test interruption/partial failure without pretending external writes roll back."
tdd_status: "required"
tdd_target: "Two equivalent public validation calls reuse completed validation findings, including warnings; a source-only edit reruns lint while preserving eligible installation reuse."
red_command: "bun run --cwd apps/cli test src/runtime/scripts.test.ts -t 'reuses completed validation and replays warnings'"
expected_red_failure: "Current validator installs/lints again or cannot report distinct installation/result reuse for the second equivalent invocation."
green_command: "bun run --cwd apps/cli test src/runtime/scripts.test.ts src/runtime/validation-candidate.test.ts src/features/scaffold-update/validation-cache/cache.test.ts"
reason_not_testable: ""
red_evidence: "Warning replay initially repeated 2 installs and 2 lints instead of 1/1. Parent review later held the gate when raw PATH and executable locations partitioned equivalent contexts; credential-filter RED also showed required registry/Git auth was stripped."
green_evidence: "Pinned Bun 1.3.5 exact T8 suite passed 94 tests; relocation reuses by executable-content identity, changed runtime content misses, timezone reruns validation only, registry/SSH auth remains available, cache/signing credentials are absent, and CLI typecheck passes."
codebase_design_notes: "One runtime orchestration boundary selects fresh versus reused work. The cache is evidence, not live readiness or adoption authority. Keep independent non-workspace install roots supported."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Real isolated candidate installation/patch/lint using injected local cache"
runtime_evidence: "Per-phase invocation counts, returned findings, miss reasons, current tool readiness and unchanged live hashes; inspect relocated installed executable containment."
runtime_cleanup: "Per-run private candidate roots; release cache leases and clean only owned materializations after completion/interruption."
architecture_wave: "A2"
behavior_owner: "Candidate validation runtime"
integration_surface: "runUpdate lintPreview port"
public_seam: "runCandidateLintPreview / Validation-cache entrypoint"
topology_delta: "Consume durable cache through ports while preserving fresh fallback and isolated execution."
forbidden_ownership: "No cache hit as adoption proof, caching operational failure as success, inherited cache credentials in children, or writable shared install."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-7"]

T9: Connect selection, cached validation and truthful update outcomes

compatible_a3_seam_refinement: "T9 may add/test a narrow readonly readiness function in integrations/tool-management.ts and .test.ts applying existing minimum-version and ensureCommands policy without installation or mutation. Platform composition binds it to checkLiveReadiness before cache lookup; the mutating ensure path remains authoritative on failure. The planned run.test-cases.test.ts path is absent; its cases remain exercised through run.test.ts. This changes no owner, dependency direction, provider decision, or adoption authority."
id: "T9"
depends_on: ["T1","T4","T7","T8"]
location: "apps/cli/src/update/run.ts"
owned_paths: ["apps/cli/src/update/run.ts","apps/cli/src/update/run.test.ts","apps/cli/src/update/run.test-cases.test.ts","apps/cli/src/platform/feature-application-operations.ts","apps/cli/src/platform/feature-application-operations.test.ts","apps/cli/src/integrations/tool-management.ts","apps/cli/src/integrations/tool-management.test.ts"]
wave_boundary: "W3"
description: "Wire the shared resolved plan, cache options/adapters, candidate validator and events into the production update path. Remove redundant plan/materialization/staging work where the same valid plan can be reused. Recheck required live tools cheaply and avoid bootstrap when already ready; otherwise capture bootstrap outcomes. Preserve recovery/adoption/receipt ordering. Populate additive planned/completed facts, keep changedFiles as its existing planned meaning and record successful independent work when dependent work fails. Emit phases through actual command interaction even with legacy emitOutput false."
validation: "runUpdate and platform tests exercise no-change no-bootstrap, managed drift, settings/topology invalidation, cache hits with missing live tools, failure after independent completion, output facts/receipts, candidate incompleteness, local-only no-login, bypass/clear and remote outage. Shared scaffold/check consistency and verifier tests remain green. Typecheck and fresh CLI build after integration."
status: "Complete"
log: "Integrated the shared resolved-output plan, fresh generation witnesses, local and optional signed-remote cache composition, readonly live-tool readiness, truthful progress/result facts, local updater-cache clear behavior, and recovery/adoption/receipt ordering. Production-fixture adoption, no-change, managed-drift, cache-clear, and receipt evidence passed. Parent validation covered 16 CLI files / 243 unique tests plus 3 root files / 27 tests; run.test.ts was accounted by 59 exact-name one-test reports after the monolithic run exceeded practical duration. A3 / RAC-8 passed and W4 was unblocked."
"files edited/created": ["apps/cli/src/update/run.ts","apps/cli/src/update/run.test.ts","apps/cli/src/platform/feature-application-operations.ts","apps/cli/src/platform/feature-application-operations.test.ts","apps/cli/src/integrations/tool-management.ts","apps/cli/src/integrations/tool-management.test.ts"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","backend-domain-structure","effect","effect-backend-structure","effect-service-design","backend-recoverable-actions"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "backend-domain-structure"
    applicable_behavior: "Keep feature policy, process composition and provider/filesystem mechanics in their declared owners; expose deliberate public ports and keep dependencies acyclic."
  - skill: "effect"
    applicable_behavior: "Follow repository-compatible Effect v4 APIs and typed failures; use deterministic synchronization and scoped cleanup; consult current/pinned source before unfamiliar APIs."
  - skill: "effect-backend-structure"
    applicable_behavior: "Keep update policy in the feature/action and adapter selection in platform composition; propagate requirements until the owning composition provides them."
  - skill: "effect-service-design"
    applicable_behavior: "Introduce a service only for real resource/authority ownership; keep deterministic values pure; preserve dependency-requiring Layers and public caller seams."
  - skill: "backend-recoverable-actions"
    applicable_behavior: "Classify preparation, publication and cleanup separately; atomically expose complete cache state and test interruption/partial failure without pretending external writes roll back."
tdd_status: "required"
tdd_target: "An unchanged update with ready local tools returns truthful no-change/completed facts without reinstalling/bootstrap, while progress still precedes baseline work at the command boundary."
red_command: "bun run --cwd apps/cli test src/update/run.test.ts -t 'unchanged ready update avoids bootstrap'"
expected_red_failure: "The old updater invokes tool/bootstrap work even though managed content and required local tools are unchanged and ready."
green_command: "bun run --cwd apps/cli test src/update/run.test.ts src/platform/feature-application-operations.test.ts src/features/repository-check/application.test.ts"
reason_not_testable: ""
red_evidence: "The public no-change test initially observed unnecessary bootstrap/tool work before the shared plan and readonly readiness composition were connected."
green_evidence: "Pinned Bun 1.3.5 exact-name accounting passed all 59 unique run.test.ts cases; the broader A3 surface passed 184 non-updater CLI cases and 27 root cache/trust cases, with typecheck, fresh build, scoped lint/format, import-direction inspection, and diff checks green."
codebase_design_notes: "runUpdate owns sequencing/adoption; platform owns adapter construction; feature public types carry result/events. Extend existing operations rather than creating a second orchestration service. The excluded run.test-cases file is exercised through run.test.ts, not claimed as a standalone suite."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Production composition and built hi update on disposable consumers"
runtime_evidence: "Record phase ordering, actual write/setup outcomes, receipts and no-change behavior; production remote adapter is optional and local-only works with no Turbo/login."
runtime_cleanup: "Fixture consumer roots and XDG cache roots tagged by run ID; never run mutating update on the user's live checkout."
architecture_wave: "A3"
behavior_owner: "Update orchestration and platform composition"
integration_surface: "real CLI application port"
public_seam: "runUpdate / ScaffoldUpdateInput / UpdateEvent / public result"
topology_delta: "Join shared planning and cached candidate execution under existing adoption authority."
forbidden_ownership: "No concrete provider decisions in update feature, no successful receipts for planned-only work, no weakened operational failure gates."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-8"]

T10: Prove built-command regressions and measure performance

id: "T10"
depends_on: ["T9","T5","T6"]
location: "apps/cli/src/cli/behavioral-portfolio.test.ts"
owned_paths: ["apps/cli/src/cli/behavioral-portfolio.test.ts","apps/cli/src/cli/safety-invariants.test.ts","apps/cli/src/scaffold/project-verifier-preservation.test.ts","scripts/behavior-contract/issue-215-update-benchmark.mjs","apps/wiki/content/docs/project/specs/cli/issue-215-manifest-driven-update/evidence/cli/**"]
wave_boundary: "W4"
description: "Extend real built-CLI scenarios for issue cases and approved lifecycle/cache/output behavior; run cold/warm/no-op/source-only/managed-drift fixtures and ignored/untracked verifier preservation. Add a test-only HI_ISSUE215_CLI_ENTRYPOINT override to behavioral-portfolio.test.ts, defaulting to its existing built dist/index.js; use only an absolute verified executable path. Select the retained G0 baseline explicitly for RED and leave the override unset for current-build GREEN. Add a diagnostic benchmark harness recording first output, final output, phase durations, visited/copied/hashed counts/bytes and install/lint executions, with runtime/cache/fixture metadata. Compare the G0 before sample to the same after fixture. Execute actual macOS alias/special-file proof as well as Linux; unsupported platform cases are explicit outstanding evidence, not silent passes."
validation: "Build CLI once after integration; run listed public process suites, full CLI suite and direct CLI typecheck. Assert output/event ordering and skipped work structurally, never elapsed-time thresholds. Confirm JSON has one final document, actual outcomes match filesystem/receipts, cache failure falls back, interruption cleans up. Report before/after measurements and all non-comparable/blocked cases honestly."
status: "Focused lifecycle and merge-tree-equivalent Behavior Contract proof complete"
final_local_log: "The historical full local suite (67/68 files, 722/723 tests, 75/76 portfolio tests; SHA-256 8710300cc46295cb7263e8cbc88d99ee1066a91f2228206fc699585e5d80fe40) is diagnostic only. Exact repair commit 3928e1de91c7ec4539a5e0fed04d1f83f764b512 produced final built CLI SHA-256 e1c9bdf97ce2e502492794e1a91c98e074799c2dbe913185077b50ddb60f931a."
followup_log: "The repair fails executable-config inputs closed as uncontrolled-validation-inputs and runs fresh lint without cache reuse; it strips cache/signing/publication credentials from candidate children while preserving required package-manager registry/Git authentication, and derives package-manager/executable identity from content and runtime capability rather than raw PATH."
log: "Focused repaired 10-sample lifecycle proof /tmp/issue215-lifecycle-cacheoff-repair.json has SHA-256 a2f793ef714bf23536680caefd44230144aede428ab46cf310726c5019dcd215, failures [], and cleanup true. Cache Witness 35185839278 succeeded on a PR merge tree identical to head 3928e1de91c7ec4539a5e0fed04d1f83f764b512 in all four jobs, with final CLI e1c9…f931a and macOS platform/safety evidence. Behavior Contract 35185839490 also succeeded on that a PR merge tree identical to head: root static, trusted affected verification, and stable aggregate all passed."
"files edited/created": ["apps/cli/src/cli/behavioral-portfolio.test.ts","apps/cli/src/cli/safety-invariants.test.ts","apps/cli/src/scaffold/project-verifier-preservation.test.ts","scripts/behavior-contract/issue-215-update-benchmark.mjs","apps/wiki/content/docs/project/specs/cli/issue-215-manifest-driven-update/evidence/cli/**"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types"]
implementation_skill_guidance:
  - skill: "tdd"
    applicable_behavior: "Write one failing public-behavior test before changing that behavior; record genuine RED/GREEN and iterate in vertical slices."
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
tdd_status: "required"
tdd_target: "The complete built hi update process preserves ignored/untracked project verifier content and reports exact completed outcomes after an injected preparation failure."
red_command: "HI_ISSUE215_CLI_ENTRYPOINT=\"${HI_ISSUE215_BASELINE_ENTRYPOINT:?G0 baseline entrypoint required}\" bun run --cwd apps/cli test src/cli/behavioral-portfolio.test.ts -t 'issue 215 update outcomes'"
expected_red_failure: "Run the first new scenario against the retained runnable pre-change G0 build: expected special-file/preparation/preservation/progress outcome fails. Then rebuild current HEAD for GREEN. Do not invent RED if it already passed historically; retain it as a characterization assertion instead."
green_command: "bun run --cwd apps/cli build && bun run --cwd apps/cli test src/cli/behavioral-portfolio.test.ts src/cli/safety-invariants.test.ts src/scaffold/project-verifier-preservation.test.ts"
reason_not_testable: ""
red_evidence: "The retained baseline and intermediate production builds failed the new exact planned/completed, warm-warning, source-only, special-file, canonical-alias, and configured-remote recovery assertions. The final recovery audit also proved runtime configuration dropped all supplied TURBO_* keys before transport construction."
green_evidence: "Pinned Bun 1.3.5 local proof passed 2 Issue 215 portfolio tests, 7 preservation/safety tests, 16 before/current samples, 10 lifecycle samples, 3 platform samples, and 8 final recovery samples. Identical warm inputs execute zero install/lockfile/patch/lint work while preserving findingCount=903, all 20 published diagnostics, truncation and warnings; configured remote failure is transport-unavailable followed by safe fresh validation."
codebase_design_notes: "Observe exit code, streams, files and receipts from built CLI. Counters verify less unnecessary work without wall-time acceptance. This task does not repair production files outside its scope; route genuine failures back to their owner before proceeding."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Built Node CLI on Linux and actual macOS fixtures"
runtime_evidence: "Store redacted command/transcript, exact build revision, fixture identities, before/after diagnostic timings/work counts, outcomes and cleanup. No numeric speedup/latency gate."
runtime_cleanup: "Own temp consumers, socket servers, FIFOs, worktrees and measurement output by run ID; release handles before deleting only those resources. After recording baseline/current evidence, remove the retained G0 baseline worktree and its owned dependencies/artifacts."
architecture_wave: "A4"
behavior_owner: "Built-command behavioral verification"
integration_surface: "hi update / scaffold / check"
public_seam: "CLI subprocess contract"
topology_delta: "Prove integrated externally visible behavior without adding product policy."
forbidden_ownership: "No timing threshold, fabricated baseline, stale-build GREEN, or silent platform skip."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-9"]

T11: Prove remote cache reuse and access across trusted contexts

id: "T11"
depends_on: ["T9","T5","T6"]
location: "scripts/behavior-contract/shared-cache-witness.mjs"
owned_paths: ["scripts/behavior-contract/shared-cache-witness.mjs","scripts/behavior-contract/shared-cache-witness.test.ts",".github/workflows/cache-reuse-witness.yml","apps/wiki/content/docs/project/specs/cli/issue-215-manifest-driven-update/evidence/cache/**"]
wave_boundary: "W4"
description: "Build a bounded witness harness and same-repo trusted manual workflow using the existing cache action. Prove Turbo artifacts plus Prepared Installation and Validation Result remote reuse, with distinct format identities. Run the matrix below with local/Actions restored caches disabled or isolated so remote retrieval is attributable. Verify canonical team, token read/write capabilities, signing compatibility, provider OIDC context policy, writer membership and runner isolation using metadata and authenticated outcomes only. Do not edit provider access or fetch raw secret values to force a pass."
validation: "Harness subprocess tests validate evidence completeness and error paths; real provider reads/writes prove restored output digests and identities, not generic hit totals. Include negative auth/signature/invalidation cases and credential-free ordinary update fallback. If local auth or required trusted CI execution is unavailable, retain an explicit blocker; T11/A4 remains incomplete."
status: "PR producer/consumer/later-run witness complete; main/release and authenticated local↔CI matrix pending"
trusted_ci_log: "Cache Witness 35185839278 is a terminal merge-tree-equivalent success on 3928e1de91c7ec4539a5e0fed04d1f83f764b512: all four jobs succeeded, downloaded artifacts confirm final CLI SHA-256 e1c9bdf97ce2e502492794e1a91c98e074799c2dbe913185077b50ddb60f931a, both final macOS reports have failures [], cleanup true, and the later consumer recorded 44 Linux GETs and 13 macOS GETs."
log: "The same-repository PR producer/consumer/later-run witness is complete without exposing credentials. Actual post-merge main/release verification and the authenticated local↔CI matrix remain the only T11/A4 proof gap; local capability remains honestly authentication-missing and is not substituted for that matrix."
"files edited/created": ["scripts/behavior-contract/shared-cache-witness.mjs","scripts/behavior-contract/shared-cache-witness.test.ts",".github/workflows/cache-reuse-witness.yml","apps/wiki/content/docs/project/specs/cli/issue-215-manifest-driven-update/evidence/cache/**"]
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["tdd","codebase-design","quality-types","turborepo"]
implementation_skill_guidance:
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "quality-types"
    applicable_behavior: "Use discriminated outcomes and validated boundary data; derive shared types rather than duplicating them; exercise real filesystem/process behavior."
  - skill: "turborepo"
    applicable_behavior: "Delegate work to owning package tasks, define complete inputs/outputs and semantic env identities, preserve signed optional remote reuse, and validate actual task restoration."
tdd_status: "not_applicable"
tdd_target: "Proof harness and evidence collection for already implemented cache behavior; verify incomplete evidence is rejected and positive evidence is attributable."
red_command: "not_applicable"
expected_red_failure: "not_applicable"
green_command: "bun test scripts/behavior-contract/shared-cache-witness.test.ts"
reason_not_testable: "Test/evidence harness and trusted workflow invocation only; product cache behavior is test-driven in T3/T5/T6/T7/T8/T9. Exercise harness failure handling, but do not manufacture RED by introducing incorrect production behavior."
red_evidence: "Harness completeness tests reject missing provider transfer attribution, restoration digests, authority, signing, and isolated-cache evidence; local capability reports authentication-missing rather than claiming provider proof."
green_evidence: "Pinned local witness, cache-identity, and cache-trust validation passed 19 tests / 212 assertions. Trusted run 35169090936 provided producer/fresh-consumer evidence; later trusted run 35169496396 selected it, made zero PUTs, performed 44 isolated-Linux GETs and 13 isolated-macOS GETs, and matched exact artifact/output digests retained in normalized evidence."
codebase_design_notes: "Witness code owns observation, not task/cache policy. The manual workflow uses existing trusted action and only nonsecret fixture inputs; never execute arbitrary refs from fork input with credentials."
review_mode: "cli"
runtime_validation: "required"
runtime_target: "Existing signed artifact provider, authenticated local client and trusted same-repo PR/main/CI contexts"
runtime_evidence: "Persist producer/consumer revision/context, task or cache-kind identity, artifact digest, actual remote read/write outcome, restored-output digest, local-cache isolation proof and redacted access checks for every matrix row."
runtime_cleanup: "Use fixture cache roots and content-derived disposable witness artifacts; remove local roots/temporary branches/worktrees created by the run. Provider has no assumed delete API: record artifact IDs and rely on provider retention, never flush shared team cache."
architecture_wave: "A4"
behavior_owner: "Cross-context access and artifact proof"
integration_surface: "Turbo remote tasks and hi update remote cache"
public_seam: "Cache witness harness / trusted workflow"
topology_delta: "Add attributable evidence for shared remote transport without expanding trust."
forbidden_ownership: "No credentials in artifacts, provider-policy mutation, generic-hit proof substitution, or live publication execution."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-10"]

T12: Document proven behavior and close the architecture checks

id: "T12"
depends_on: ["T10","T11"]
location: "docs/README.md"
owned_paths: ["docs/README.md","docs/runbooks/hi-cli-scaffolding.md","docs/runbooks/ci-verification-and-publication.md","apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md","apps/wiki/content/docs/project/runbooks/ci-verification-and-publication.md","apps/wiki/log.md"]
wave_boundary: "W5"
description: "Document measured behavior, managed selection, bounded candidate failures, cache modes/clear/storage/eligibility, warnings/outcomes/progress, optional local auth and signed cross-context reuse. Edit source runbooks then generate exact wiki mirrors; clarify credential names/roles without values and distinguish publication from cached verification. Parent performs cumulative architecture, Standards/requirements review and updates PLAN evidence/status. Classify actual delivery changes before release preparation, without publishing as part of this plan."
validation: "Generate/check wiki content through owning scripts, validate links/navigation and git diff --check. Parent inspects all RAC evidence, task graph, changed imports, removed duplicate paths, migration ledger (must be empty), full relevant tests and release classification. A failed access/platform proof remains visible and prevents completed status."
status: "Documentation and migration-ledger scope complete; A5 follows A4"
log: "2026-09-17: Source runbooks and generated wiki mirrors document the implemented manifest-driven update, isolated candidate, local/optional remote cache modes, cache-clear scope, progress/output contract, and the completed PR producer/consumer/later-run witness. Docs-ingest is a verified no-op because this direct-plan folder intentionally has no SPEC.md: do not change its ingestion fields or wiki log/routes/meta. A5 remains dependent on the sole A4 post-merge/local↔CI matrix blocker; no release or publication is claimed."
"files edited/created": []
task_identity_mode: "planning-only"
backlog_item_id: "not_applicable"
backlog_item_url: "not_applicable"
relation_mode: "unprojected"
backlog_sync_skip_reason: "User requested direct planning from the approved grill without a SPEC.md or provider Task projection."
assigned_skills: ["codebase-design","writing-for-agents"]
implementation_skill_guidance:
  - skill: "codebase-design"
    applicable_behavior: "Keep a deep module behind its declared small interface; test the same public seam used by callers and keep policy local."
  - skill: "writing-for-agents"
    applicable_behavior: "Make commands, ownership, completion gates and blockers explicit; distinguish accepted contracts from observed implementation and avoid stale duplicated authority."
tdd_status: "not_applicable"
tdd_target: "Runbooks and generated mirrors accurately describe verified operator behavior and evidence limits."
red_command: "not_applicable"
expected_red_failure: "not_applicable"
green_command: "node apps/wiki/scripts/sync-content.mjs && bun run --cwd apps/wiki check:content && git diff --check"
reason_not_testable: "Documentation and readonly architecture closeout; no product behavior is changed by this task."
red_evidence: ""
green_evidence: "Source runbooks were updated first; `node apps/wiki/scripts/sync-content.mjs` regenerated exact runbook mirrors, and wiki content/check plus focused source/mirror and whitespace validation passed. The migration ledger is empty. Docs-ingest was verified as a no-op because there is no SPEC.md; A5 follows the remaining A4 post-merge/local↔CI matrix proof."
codebase_design_notes: "docs/runbooks is the editable operational source; wiki mirrors are generated. Keep this direct plan as requirements/execution authority and avoid a retroactive spec."
review_mode: "cli"
runtime_validation: "not_required"
runtime_target: "not_applicable"
runtime_evidence: "not_applicable"
runtime_cleanup: "not_applicable"
architecture_wave: "A5"
behavior_owner: "Operator documentation; parent owns cumulative closeout"
integration_surface: "source runbooks and generated wiki"
public_seam: "Documented CLI/cache operator contract"
topology_delta: "Bring operational guidance into line with proven behavior and verify convergence."
forbidden_ownership: "No hand-edited generated mirror content or claims of unrun access/platform verification."
temporary_seams: []
responsibility_acceptance_criteria: ["RAC-11"]

Closeout readback

CI provenance correction: workflows 35185839278 and 35185839490 checked out PR merge commit a223bdb4602ad70d7aa15f158d872b60ec86d339, whose tree 0eb4a6d09f989fa0278cb4b968977f1e6bfe9a5a is identical to head commit 3928e1de91c7ec4539a5e0fed04d1f83f764b512. They are retained as merge-tree-equivalent evidence rather than exact-head execution. Provider-retained artifacts are Cache Witness IDs 10482585836, 10482252258, 10482242221, and 10482197428, plus Behavior Contract tree artifact 10483835411.

SurfaceRun / evidenceStatusExact remaining condition
T10 focused lifecycle/tmp/issue215-lifecycle-cacheoff-repair.json; SHA-256 a2f793ef714bf23536680caefd44230144aede428ab46cf310726c5019dcd21510 samples, failures: [], cleanup: true; final built CLI SHA-256 e1c9bdf97ce2e502492794e1a91c98e074799c2dbe913185077b50ddb60f931a from repair commit 3928e1de91c7ec4539a5e0fed04d1f83f764b512Behavior Contract 35185839490 succeeded on the a PR merge tree identical to head in all three jobs.
T11 PR witnessCache Witness 35185839278Terminal merge-tree-equivalent success in all four jobs; downloaded artifacts confirm final CLI evidence, macOS platform/safety failures: [] with cleanup true, and 44 Linux / 13 macOS GETs.Actual post-merge main/release and authenticated local↔CI matrix only.
A4RAC-9/RAC-10PR producer/consumer/later-run proof complete.Blocked only on the post-merge main/release and authenticated local↔CI matrix after the PR proof.
A5RAC-11Documentation and migration ledger are complete; ledger is empty. Docs-ingest is a verified no-op because this direct-plan folder has no SPEC.md; ingested: false and last_ingested: null remain unchanged, with no wiki log/routes/meta changes.Follows A4 only; no release or publication claim.

Required verification matrix

T10: command correctness and diagnostic performance

CaseRequired observation
Cold updateCorrect writes/receipts, complete contained candidate, disabled install scripts, useful progress and timings.
Warm unchanged updateSame correctness and warning output; eligible expensive phases skipped; live readiness still checked.
Source-only editRelevant validation reruns; eligible Prepared Installation can remain reusable.
Managed file edit/deletionActual hashes detect drift; preserve user-owned content and apply only established ownership rules.
Settings/workspace/lock/config/patch changeRelevant selection and cache identity invalidate; scaffold/check/update still agree.
Dynamic unrepresented inputExplicit ineligibility reason and fresh validation, not stale success.
Large irrelevant evidence tree with socket/FIFOTree pruned before traversal; no unsupported-file crash or broad copying.
Required special input or incomplete dependency closureActionable failure blocks dependent adoption without falsifying completed independent work.
Alias root and real escapeCanonical aliases succeed; actual escapes fail; include real macOS evidence.
Ignored/untracked project verifier and authored filesIncluded when required for validation; preserved by ownership rules.
Plain-text Oxlint/bootstrap errorOriginating phase, command context, code/signal and bounded redacted output survive.
JSON/default human/JSON progressOne final JSON stdout document; early human output; opt-in JSON progress on stderr.
Corrupt cache, bypass, clear, remote unavailableCorrect local/cold fallback and miss reason, isolated cleanup and no false success.
Interrupted validation/write/cache publicationNo partial success entry or receipt; owned resources cleaned; recovery remains verified.

Capture command-start, first stdout/stderr observation, final result, phase elapsed time, files/bytes visited/copied/hashed, install/lint invocation counts and cache-kind/origin/reason. Include cache state, fixture size, runtime versions, input identity and exact CLI revision. Run comparable before/after cases on the same fixture, state limitations and retain individual samples; do not use a maximum duration or required speedup. Structural assertions about omitted work are correctness checks, not time thresholds.

T11: attributable reuse and access

Each eligible positive row is exercised for Turbo artifacts and separately for both updater cache kinds where that artifact's runtime/platform contract allows it. For an ineligible combination, record the meaningful input difference and demonstrate the expected miss/fresh execution; a branch/path label alone cannot justify a miss.

Producer → consumerRequired proof
Local checkout → equivalent branch/worktreeSame semantic identity, actual restore, correct output digest; no absolute-root dependency.
Local repository → another compatible repository fixtureUpdater entries reuse across repository roots when complete inputs match; repository identity is not an accidental key.
Local authenticated context ↔ trusted CIUpload and authenticated remote restore in both directions with local cache absent.
Trusted same-repo PR → main/release-verification contextOne signed namespace and compatible deterministic identities; no publication side effects or publication credentials.
CI run → fresh later CI runRestore attributable to remote service with Actions/local cache restoration disabled for the witness.
Portable task across compatible hostsEquivalent portable task restores; native/host-dependent task misses when capability/ABI differs.
Source/config/lock/tool/runtime/environment changeRelevant entries miss; source-only edit can retain installation reuse.
Wrong signer/corrupt artifact/expired or denied tokenNo trusted restore; redacted diagnostics and local/cold fallback.
Fork/untrusted contextNo trusted cache write/signing credentials; policy rejects transfer into trusted namespace.
Ordinary local update without Turbo/loginNo interactive auth or remote dependency; local/cold command completes correctly.

For each row retain producer/consumer context and revision, exact artifact/cache kind, semantic identity, canonical team/namespace (nonsecret), signed artifact/output digest, request/read outcome, cache-isolation method, evidence path and cleanup. Verify OIDC subject/context policy, token read/write scope, team writer membership and runner workspace isolation using provider metadata or authenticated capability outcomes. Merely finding secret names or seeing remote enabled is insufficient.

A real provider restriction that prevents the approved reuse is a blocker with a concrete proposed fix. A new remote service, broader fork trust, or unapproved credential/policy mutation requires handback; do not silently remove a matrix row. Routine authorized implementation of the configured client and fixture code proceeds without another requirements interview.

Validation commands and completion

Commands are run from root after G0. Each task owns RED/GREEN evidence, and the parent records the aggregate checkpoint result. Validation commands containing multiple steps run sequentially.

  • Focused CLI tests: commands in T1–T10; build before any built-process suite.
  • CLI type check: bun run --cwd apps/cli check-types.
  • Full relevant CLI suite after integration: bun run --cwd apps/cli test. The source-case support file excluded by Vitest is not a standalone suite.
  • Root cache/CI tests: bun test scripts/behavior-contract/cache-identity.test.ts scripts/behavior-contract/cache-trust.test.ts scripts/behavior-contract/affected-verification.test.ts scripts/behavior-contract/shared-cache-witness.test.ts.
  • Existing repository workspace validation: bun run check-types, bun run check, then affected CI verification with the real base/head bounds expected by scripts/behavior-contract/run-ci-verification.mjs. Do not invent missing package scripts or silently skip the direct CLI check.
  • Docs: node apps/wiki/scripts/sync-content.mjs, bun run --cwd apps/wiki check:content, git diff --check.
  • Before release-bearing delivery closeout, consult the actual root/CLI release classification entrypoint and run with the verified base/head. Changed BASELINE_CHANGELOG.md/CHANGELOG.md select release product; this plan creates neither release notes nor publication authority. Any later selected release must meet its existing notes/version/compatibility gates.

Architecture checkpoints are cumulative and independent of elapsed performance. Review changed imports/public entrypoints and each RAC's actual behavioral evidence. Apply source guidance to implementation; do not write string-spelling tests as substitutes for public outcomes. Purely illustrative test vectors do not replace real filesystem/process/provider proof.

Risks and handling

  • Unknown executable-config inputs: keep result cache ineligible and validate fresh. This may reduce hits; it preserves R12 while installation reuse still helps.
  • Candidate incompleteness: expand within affected dependency scope; block dependent adoption if still incomplete. Never disguise this as a harmless cache miss.
  • Installation relocation/patching: private writable copies, validated links and exact runtime compatibility; rebuild unsafe entries.
  • Protocol drift: bind signing tests to pinned Turbo 2.9.14 and verified provider behavior; changing versions requires explicit compatibility evidence.
  • Post-merge provider matrix: the PR producer/consumer/later-run witness is complete. A4 remains blocked only until actual main/release and authenticated local↔CI observations are read back; record precise capability facts without printing values.
  • Missing bundled assets/dependencies: resolve environment readiness before claiming RED/benchmark; out-of-scope packaging repair is surfaced separately.
  • Task ownership collision: parent serializes/amends exact ownership before writes. T2 and T8 intentionally share runtime files in different waves; T9 alone owns production composition.
  • Stale generated docs or release assumptions: regenerate mirrors and use current accepted CI/release requirements; legacy declarations are not authority.

Unresolved questions

No product/design decision is open or parked. The sole remaining uncertainty is the post-merge actual main/release and authenticated local↔CI provider matrix; it cannot be converted into an A4 acceptance claim without exact readback.

Planning review record

The readonly plan-reviewer checked this file against the approved grill, paths/scripts, wave safety, architecture criteria, RED targets and runtime cleanup. All actionable findings were resolved before handoff. Planning completion does not mark any implementation task complete.

  • Review state: complete. One P2 about baseline selection was corrected by explicit G0 retention and T10 entrypoint selection; readonly follow-up confirmed resolution and no new actionable findings.
  • Plain-language pass: completed using canonical terms; no requirement was changed.
  • Document validation: all 12 task records parsed; required fields, dependency ordering, disjoint same-wave ownership, TDD classification/guidance, relative links, navigation JSON and wiki log bounds passed. node apps/wiki/scripts/sync-content.mjs --check and git diff --check passed. No product tests were run in this planning-only task.
  • Task states: T1–T10 are implemented/evidenced, merge-tree-equivalent Behavior Contract 35185839490 passed, T11's PR producer/consumer/later-run witness is complete, and T12 documentation/migration-ledger scope is complete. A4 remains blocked only on the post-merge main/release and authenticated local↔CI matrix; A5 follows A4. No publication is claimed.

On this page

Issue 215 — Safe and Fast Manifest-Driven UpdatesIssue 224 managed lint amendmentExecution contractProblem and evidenceRequirements and acceptance ledgerCanonical languageSolution and constraintsSelection and candidate constructionCache contractOptional remote adapter and Turbo accessArchitecture contractTarget ownership topologyAllowed dependency graphPublic seam contractResponsibility acceptance criteriaArchitecture waves and checkpointsA1 checkpoint — passed 2026-09-16A2 checkpoint — passed 2026-09-16Migration ledgerTask graph and worker wavesG0: execution readinessTasksT1: Unify manifest-driven selection and shared planningT2: Build a bounded, contained candidate and retain failuresT3: Implement separate durable cache identities and local storageT4: Define early progress and compatible command resultsT5: Make Turbo identities consistent across eligible contextsT6: Preserve one trusted signed cache namespace and access policyT7: Add the optional signed updater cache transportT8: Reuse installations and completed validation safelyT9: Connect selection, cached validation and truthful update outcomesT10: Prove built-command regressions and measure performanceT11: Prove remote cache reuse and access across trusted contextsT12: Document proven behavior and close the architecture checksCloseout readbackRequired verification matrixT10: command correctness and diagnostic performanceT11: attributable reuse and accessValidation commands and completionRisks and handlingUnresolved questionsPlanning review record