Harness Intelligence Wiki
SpecsCLIIssue 215 — Manifest-Driven UpdateEvidenceCache

Issue 215 Cache Witness Evidence

Cache witness evidence

Trusted PR run 35169090936 closed the first-run provider/context matrix: the producer performed authenticated signed PUT/GET operations for portable Turbo, host Turbo, prepared-installation, and validation artifacts; fresh isolated Linux restored all four kinds; fresh macOS arm64 restored the portable Turbo artifact. Later trusted PR run 35169496396 selected that producer, restored the exact artifacts using only remote GETs, and made no PUT requests.

local-capability.json records the current local blocker: authentication-missing, zero artifacts, and completed cleanup. The existing Vercel account and canonical team discovery do not supply the shared artifact signer. No secrets were fetched, printed, rotated, or changed to produce this report.

provider-authority.json retains allowlisted fields from authenticated Vercel CLI GETs: account dev-6868, canonical team/slug correspondence, confirmed OWNER membership, and enabled remote caching both for the team and current principal. These reads prove local membership/configuration; they do not prove artifact read/write scope or the GitHub OIDC principal's authority.

Witness boundary

The harness runs pinned Turbo 2.9.14, Bun 1.3.5, and Node 24.19.0. A loopback observer forwards bounded requests only to the fixed Vercel API origin, verifies each artifact's HMAC against its exact hash and canonical team, and records only method, status, digest, size, identity, origin, and scenario. Tokens, signature values, provider response text, task logs, and temporary paths are excluded.

Turbo runs with --cache=remote:w for production and --cache=remote:r for restoration. Every task output and execution marker is removed before a consumer executes. Restoration requires a remote GET, matching signed archive and output digests, a task cache HIT, and absence of fresh execution. Independent Git worktrees provide equivalent roots.

Updater evidence uses the production identity, cache-policy, filesystem, and remote adapters. Prepared installations use the candidate runtime's array-of-archive-strings envelope and restore into private directories. Validation findings must decode with the production finding schema. Each consumer has a fresh local store; successful reads must report origin: remote. Wrong signers, denied tokens, corrupt responses, absent credentials, relevant input changes, local fallback, and cold misses are exercised separately.

Loopback HTTP tests exercise the harness itself and are labelled loopback-test-only. They are never provider evidence. The production installation envelope initially exposed archive-invalid in the remote adapter. The owning T7 repair added bounded array-envelope validation; the same witness now passes with the actual runtime format.

Trusted CI execution

.github/workflows/cache-reuse-witness.yml accepts trusted same-repository PRs and manual main-branch execution through the existing OIDC/signature action. Forks receive no witness credentials. The canonical team is team_0QvyOroTH1I7k8hWMqSRCOqH (dev-punks). Provider policy and secret configuration are unchanged.

The producer retains cache-witness-producer/producer.json. Fresh Linux and macOS jobs download only that report and retain cache-witness-consumer-linux/consumer.json and cache-witness-consumer-macos/consumer.json. The macOS consumer must restore the portable Turbo artifact; incompatible host tasks and updater installations must instead prove changed identity and a provider miss. The existing action may restore its checkout-local Actions archive, but witness fixtures never consume that directory.

A later PR run selects the earlier successful witness run from the same repository and branch. Manual main execution accepts producer_run_id. Both use read-only restoration and bind the producer report by digest, revision, runtime, team, and exact artifact identities. Restore runs must make no PUT requests. No release or publication task runs.

The separate macos-candidate job has no cache/signing credentials and retains cli-macos-proof/cli-macos.json plus cli-macos-safety.json from T10's built-command platform and safety scenarios.

Trusted PR run 35169090936

EvidenceResultSHA-256
provider-run-35169090936-producer.jsonFour provider PUTs returned 202; signed GET/restoration and negative authority/signature/corruption cases passed.41bf463407601efd80b9eeb03fb33e60cc44f1a209e4c99d0443a361cf3d7621
provider-run-35169090936-consumer-linux.jsonFresh Linux runner restored all four artifact kinds from remote with empty local caches and matching output digests.59a0c13e39e1387f0ba02be1c015e248c562ae21b0b3f808f25cb3a449a33411
provider-run-35169090936-consumer-macos.jsonFresh macOS arm64 runner restored the portable Turbo artifact from remote with an empty local cache; host-sensitive identities missed as required.372884829e53690eefa15c5454d00f4a5e875ede80212f4568159bc6a3af97f6

All three reports bind provider vercel, canonical team team_0QvyOroTH1I7k8hWMqSRCOqH / dev-punks, run 35169090936, producer evidence digest 41bf4634…7621, exact artifact/output digests, isolated roots, and completed cleanup. No secret value or provider response body is retained.

Later trusted PR run 35169496396

provider-run-35169496396-producer.json is the read-only restore report retained as cache-witness-producer/producer.json by the later run. It selects producer run 35169090936, binds its exact producer SHA-256 (41bf463407601efd80b9eeb03fb33e60cc44f1a209e4c99d0443a361cf3d7621), restores all four artifact kinds remotely with localEmpty: true, and records 44 GETs with zero PUTs. The isolated Linux and macOS consumers bind this later report by its exact SHA-256 (b2e294148027d659867872ca55f85b6d85f170431040c0becab9fea64c1cd56b); they retain their own fresh local stores and record only remote GETs.

EvidenceResultSHA-256
provider-run-35169496396-producer.jsonRead-only later-run producer report selected run 35169090936; all four exact artifact/output digest pairs restored remotely with localEmpty: true; 44 GETs, zero PUTs.b2e294148027d659867872ca55f85b6d85f170431040c0becab9fea64c1cd56b
provider-run-35169496396-consumer-linux.jsonIsolated Linux consumer restored all four exact artifact/output digest pairs remotely with localEmpty: true; 44 GETs, zero PUTs.b1a6b3dab941ff3dcfa67cc47b1929b6cc67e103594f60eefafe675d4b023b4c
provider-run-35169496396-consumer-macos.jsonIsolated macOS arm64 consumer restored the portable Turbo artifact with its exact artifact/output digests remotely with localEmpty: true; 13 GETs, zero PUTs.a5cdf3cd549342c4a3af330856be1d327b8914d00354204725cb38141b779851

Actual main/release-verification context remains an explicit obligation until its corresponding report exists. Exact successful PUT/GET results establish exercised write/read capability; they do not invent a provider membership list or token-expiry observation.

All local witness roots, worktrees, and refs live inside one execution-owned temporary root and are removed in the finalizer. Provider artifacts have content-derived identities and remain under provider retention; there is no team-cache flush or assumed deletion API.

Commands

Run these with the pinned toolchain and existing authorized environment configuration:

bun test scripts/behavior-contract/shared-cache-witness.test.ts
bun scripts/behavior-contract/shared-cache-witness.mjs --output producer.json
bun scripts/behavior-contract/shared-cache-witness.mjs --mode restore --producer producer.json --output consumer.json
bun scripts/behavior-contract/shared-cache-witness.mjs validate consumer.json

The required environment is TURBO_TOKEN, TURBO_REMOTE_CACHE_SIGNATURE_KEY, and canonical TURBO_TEAM_ID; TURBO_TEAM records the nonsecret slug. The harness does not launch login, discover secret values, or weaken signing requirements when these are unavailable.

On this page