Issue 217: CI efficiency implementation notes
CI efficiency implementation notes
Delivery authority and current state
Full Delivery implements SPEC.md and closed grill Q1–Q11 for issue #217. Goal identity: github:wearedevpunks/harness-intelligence/issues/217:ci-efficiency-delivery. Accepted-bounds identity: issue-217:SPEC:2026-09-22:bun-1.4. No sharding, only two-vCPU workers, no numerical performance or spending cap; preserve meaningful safety and publication authority. User explicitly requested extensive local proof. No hosted workflows, merge or product publication were dispatched.
Branch team/stefan/issue-217-ci-cost / draft PR #223 remains based on team/stefan/cli-update-quick-fixes at 4d4b7b71622ee90228143af57f995f0f6de4bff8. PR #222 is closed without merge and its branch remains. Fresh provider readback confirmed both relationships on September 22. Existing spec was retained at 3c8cfdd4d51045d23e1fc56fb87930b090f8f295; the later Bun1.4 amendment is explicit user authority.
The first implementation (T1–T10) passed its task gates and completed one retained formal review. That review found one missing consumed updater fixture in the Turbo input closure; the accepted repair passed 32 cache-policy tests and root static checks. The user then explicitly requested deeper test pruning and authorized the previously requested one-time hook bypass. W4 tasks T11a–T11h and T12 passed their gates; they implement the cited residual portfolio research. The earlier complete CLI run passed 63 files / 863 tests in 1530.919 seconds; focused checks validate subsequent changed scopes. Review lineage is preserved (review_count: 2, repair_count: 1); the final primary and challenger pass is clean. Backlog remains planning-only/unprojected.
Implementation and Task Gates
| Task | Accepted result and proof |
|---|---|
| T1 updater | Five immutable prepared seed families with private mutable copies; incidental resolvers controlled while actual installer/tool/hook/lifecycle, rollback, partial-result and receipt proof remain. 65 tests passed in scratch; final three-case workspace slice, types/lint/format passed. Three weak cases removed. |
| T2 recovery | Actual planner/validator traverses minimal real six-commit Git history with tiny artifacts. 86 release tests pass; tamper, exact binding, remote anchors and resumed/completed retry retained. Historical exact/resume replay is on demand and compile-checked only. |
| T3 portfolio | 58 direct policy/catalog/preview cases and six built executable witnesses; passing supersets cover relocated tests, with final complete suite confirming exact selection. Real planner/materialization/filesystem outcomes replace catalog declarations and repeated built permutations. |
| T4 remaining CLI | 67 original files audited; ten no-owned-invariant files removed, five refined. 27 focused tests passed. Newly selected package-staging proof found a missing local import, repaired RED→GREEN with the public re-export unchanged. Five inherited fixture failures repaired and confirmed by focused 14+3 tests. |
| T5 API | 310 tests/28 retained files and types pass. Fake service self-test and private transaction-count scan removed; actual provider-outside-transaction behavior remains. |
| T6 operator/web | 71 tests/14 backoffice files plus eight real browser journeys pass. Copy/cache-tag spellings and duplicate case removed; parked web's placeholder suite and orphan fixture removed. Three unchanged mock-style lint findings remain disclosed. |
| T7 packages | 129 tests/21 files/seven packages pass with types and focused lint/format. Four real PostgreSQL cases share one server but retain separate migrated databases. Fourteen weak/duplicate cases removed or merged. |
| T8 wiki | Four files/17 tests pass in one Vitest invocation. Small fixture feeds actual Fumadocs loader/composer and filesystem sync/prune/check-only/routes. Existing wiki lint debt remains disclosed. |
| T9a/T9 CI | Complete/disjoint CLI groups 49 source, one updater, eight release and five built files. Source/update/release avoid CLI build. Actual affected selection, precise input invalidation, separated Docker/browser identities and restored outputs pass. Final 32 policy tests/381 assertions and 119 operator tests/535 assertions pass; 12 workspace contracts, root static, focused lint/format, syntax and YAML parse checks pass. |
| T10 docs | Final153-file portfolio, local measurements, runbooks and rule routes reconciled; content/format/meta/link checks pass. |
Detailed retained outcomes, original-file dispositions and commands belong to TEST-PORTFOLIO.md and VALIDATION.md. Raw logs and task reports are under /tmp/hi-217-local-proof/; those temporary logs supplement the durable summaries rather than serving as the only acceptance evidence.
Architecture Conformance Evidence
A1 passes RAC-1–4: tests still consume their original app/package public behavior. A2 passes RAC-5: existing package task interfaces feed Turbo and the existing stable aggregate; capability identity belongs to the verification adapter. No product domain, contract or release policy moved. Root operator proof has an explicit owner; one real packaged API proof retains Docker/build ownership. A3/RAC-6 passes: all153original-file dispositions, current commands, route metadata and matching runbook projections are checked; complete CLI and focused repaired-byte proof pass.
Owned tests → existing app/package seams → retained observable behavior
Verification wrapper → package capability scripts → Turbo → stable aggregate
Documentation → validated commands, evidence and ownershipCLI build artifacts retain content-addressed producer provenance when reused; fresh uncached release commands still assemble current authority. This intentionally preserves unrelated-doc cache reuse without redefining publication eligibility. Migration ledger: empty. Temporary production seams: none. Ownership/dependency drift: none. The sole product repair imports the already-exported Gitignore-pack helper at its existing script owner.
Local validation and failure continuity
Local host: Bun1.4.0+34cbb9a40, Node24.19.0, Docker29.7.2, 12 logical CPUs. Timed runs use specified two-CPU affinity; simultaneous work and warm dependency stores are disclosed. This host is not claimed equivalent to Blacksmith.
- Original updater: 68/68, 2937.77s elapsed (48.96min), CPU0,1, user2287.56s/system1216.23s, maxRSS1,384,888KiB.
- Revised updater scratch: 65/65, 994.66s (16.58min), CPU2,3 under contention. The full suite subsequently passed863tests in1530.92s, with updater65tests taking898.888s.
- Bun compatibility: isolated frozen install, 1037 packages/5.32s, lockfile unchanged.
- Final CLI build: 11.96s, CPU0,1, actual baseline and command smoke checks pass. Executable SHA256
82a1d4542e7e21783fce913b87fbef4b9266106cee145336d730a2782ddc883f. - Real backoffice browser proof: eight journeys, 26.64s total including setup/cleanup, CPU4,5.
- Final cache-policy: 32/32,34.03s; operators:119/119,3.21s, CPU8,9.
One earlier remaining-CLI run completed 55files with643passes/5failures in341.38s. It is not a passing timing claim. Existing runtime capture proved stale fixture assumptions: generated lint defaults changed, settings contracts gained explicit execution/placeholders, verifier preparation needed an executable, and unchanged repeat omitted irrelevant lint facts. Scoped workers repaired fixtures while retaining exact effects and ownership assertions; focused14+3 tests pass. A worker sandbox Git EPERM was resolved by parent execution in the supported unrestricted local runtime. No product behavior was changed to hide those failures. Final full63-file run passed863tests with rebuilt unchanged dist and frozen test/source inputs. Later type/style-only repairs receive focused validation and do not claim that the earlier full run executed changed bytes.
No product UI changed; screenshots and new app-verifier references are not applicable. Real retained browser journeys were run. Historical replay, full updater diagnostic, hosted OIDC exchange, remote provider availability and Blacksmith billing were not executed or claimed.
Skill Application Evidence
One record per forwarded task/skill guidance; parent reconciliation owns this table.
| Task | Skill | Forwarded behavior | Status | Evidence |
|---|---|---|---|---|
| T1 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T1 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T1 | quality-types | Keep typed meaningful fixtures and results; no casts masking invalid test state. | applied | Owning CLI typecheck passed; typed fixtures use public results without masking invalid state. |
| T1 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T2 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T2 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T2 | quality-types | Keep typed meaningful fixtures and results; no casts masking invalid test state. | applied | Owning CLI typecheck passed; typed fixtures use public results without masking invalid state. |
| T2 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T3 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T3 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T3 | quality-types | Keep typed meaningful fixtures and results; no casts masking invalid test state. | applied | Owning CLI typecheck passed; typed fixtures use public results without masking invalid state. |
| T3 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T4 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T4 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed. T4 also repaired an observed package-staging RED with one missing import. |
| T4 | quality-types | Keep typed meaningful fixtures and results; no casts masking invalid test state. | applied | Owning CLI typecheck passed; typed fixtures use public results without masking invalid state. |
| T4 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T5 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T5 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T5 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T6 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T6 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T6 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T7 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T7 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed without inventing production RED. |
| T7 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T8 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T8 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Test-only transformation exception used; retained real outcome proof passed. Wiki runner consolidation additionally has RED/GREEN. |
| T8 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T9a | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Actual selection, identity, input, restoration and trust RED/GREEN recorded in VALIDATION.md. |
| T9a | turborepo | Use explicit actual input closure, package scripts and strict environment/trust identities; validate real keys/outputs. | applied | Real Turbo discovery, affected plan, input hashes and output restoration validate declared consumers. |
| T9a | architect-pipeline | Preserve aggregate/trigger/release authority; remove redundant work without sharding or oversized workers. | applied | Two-vCPU topology, signed cache, PR/main aggregate and protected Linux npm publication boundaries retained. |
| T9a | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T9a | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T9 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | Actual selection, identity, input, restoration and trust RED/GREEN recorded in VALIDATION.md. |
| T9 | turborepo | Use explicit actual input closure, package scripts and strict environment/trust identities; validate real keys/outputs. | applied | Real Turbo discovery, affected plan, input hashes and output restoration validate declared consumers. |
| T9 | architect-pipeline | Preserve aggregate/trigger/release authority; remove redundant work without sharding or oversized workers. | applied | Two-vCPU topology, signed cache, PR/main aggregate and protected Linux npm publication boundaries retained. |
| T9 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | Original-file dispositions and retained observable outcomes mapped in TEST-PORTFOLIO.md; no test-title quota. |
| T9 | codebase-design | Use existing owned public seams; preserve locality and avoid private shape assertions. | applied | Existing owned public seams retained; no ownership migration, private export or temporary production seam. |
| T10 | docs-ingest-phase | Document implemented behavior and evidence only; keep docs source/projection aligned. | applied | TEST-PORTFOLIO/VALIDATION and source/projected runbooks agree; content, routing and formatting checks pass. No runtime behavior changed by documentation. |
| T10 | make-tsuite | Record semantic fingerprints; cull only no-owned-invariant or mapped redundancy; test-only scope. | applied | TEST-PORTFOLIO/VALIDATION and source/projected runbooks agree; content, routing and formatting checks pass. No runtime behavior changed by documentation. |
| T10 | tdd | Capture real RED before any observable production/config selection behavior change; use explicit test-only exception otherwise. | applied | TEST-PORTFOLIO/VALIDATION and source/projected runbooks agree; content, routing and formatting checks pass. No runtime behavior changed by documentation. |
Codebase Rule Evidence
Root/scoped AGENTS, active agent settings and manifest ownership were inspected before scoped dispatch. No machine configuration or reusable skills were edited.
| Rule | Result | Evidence |
|---|---|---|
| HI-REPO-001, HI-API-001, HI-CONTRACT-001 | pass | API/schema ownership unchanged; real protocol tests and12 behavior contracts pass. |
| HI-CLI-001, HI-CLI-003 | pass | Tests retain CLI-owned effects; only product change is the script-local missing import; types and relevant runtime proof pass. |
| HI-CLI-002 | pass | Version/changelog publication selectors and protected npm authority unchanged; no selected changelog path. Release classification consultation is recorded below. |
| HI-CLI-004 | pass | Managed assets/receipts remain behaviorally tested; no catalog/generated asset source changed. |
| HI-BACKOFFICE-001 | pass | Private auth/operator boundaries preserved in71tests/eight browser journeys. |
| HI-WEB-001 | pass | Parked placeholder removal is accepted; revised rule names build/types and requires behavioral proof when owned routes are added. |
| HI-AUTH-001, HI-DB-001 | pass | Real session/provider and migrated database boundaries retained; isolated DB lifetimes pass. |
| HI-CONFIG-001, HI-ENV-001, HI-SCAFFOLD-001, HI-UI-001 | pass | Package ownership unchanged; owning proof/types passed and actual transitive inputs tested. |
| HI-REPO-003 | pass | Stable portless API URL retained; no endpoint/origin configuration change. |
| HI-WIKI-001, HI-WIKI-003, HI-DOCS-001 | pass | T10 routes/frontmatter/projection/content and formatting checks pass. Inherited broad lint debt remains disclosed under the explicit one-time delivery bypass. |
| HI-REPO-002, HI-REPO-004 | not-applicable | No baseline publication or reusable skill edit. |
Release and closeout boundaries
Consulted actual release classifier apps/cli/scripts/release-impact-classifier.mjs: changed CHANGELOG.md and BASELINE_CHANGELOG.md paths alone select products; artifact differences are diagnostic. git diff --name-only origin/team/stefan/cli-update-quick-fixes -- CHANGELOG.md BASELINE_CHANGELOG.md returns no paths at current parent4d4b7b7 and working tree, so release selector is none. Recheck exact final commit before closeout. No artifact comparison or hosted publication is claimed.
Inherited broad lint/format debt and the obsolete pre-push Candidate Evidence invocation remain disclosed failures. The latest broad run counted 4,118 lint errors before focused repairs; that is not a current exact recount. All introduced diagnostics identified by baseline comparison were repaired. The user explicitly authorized this delivery’s one-time commit/pre-push bypass: use a per-command core.hooksPath=/dev/null and [skip ci], leave hooks unchanged, and do not claim inherited gates passed.
Manual Review Checklist
- Inspect original-file dispositions and every removed meaningful scenario's retained owner.
- Confirm prepared seeds are immutable and each mutating scenario copies to a private root.
- Inspect actual Git recovery/tamper/resume and real installer/lifecycle witnesses.
- Inspect actual Turbo selected inputs and relevant/irrelevant mutation plus restoration proof.
- Confirm only2vCPU/noMac/noShards and both signed-cache consumers' trust boundaries.
- Read back PR223 base and closed/unmerged PR222.
- Record final whole CLI result and T10 docs checks.
- First frozen primary review plus independent cache/safety challenger retained and adjudicated; ci-cache-001 repaired with real input-perturbation proof. The second frozen primary/challenger review is retained and clean.
- User explicitly authorized the one-time delivery hook bypass; inherited gates remain disclosed, hook files unchanged.
Acceptance reconciliation
| Criterion | Result | Evidence |
|---|---|---|
| AC-001 | pass | TEST-PORTFOLIO maps all153 original files plus four added files; parent-added tests included. |
| AC-002 | pass | Semantic mappings distinguish retained observable safety outcomes from no-owned-invariant culls. |
| AC-003 | pass | Seven cheap operator files and separate API packaged proof reconcile all eight previously unselected files. |
| AC-004 | pass | Actual runUpdate effects retain filesystem/receipts while incidental dependencyProcess work is controlled. |
| AC-005 | pass | Five immutable seed families provide private copies; separate PostgreSQL databases retain isolation. |
| AC-006 | pass | Real executable installation/lifecycle suppression and rollback/partial/withheld-proof cases pass. |
| AC-007 | pass | Minimal real history invokes actual planner/validator; exact binding, tamper and resumed anchors pass. |
| AC-008 | pass | Historical recovery and full lifecycle diagnostic scripts exist outside routine selectors; historical code compile-checked. |
| AC-009 | pass | Direct planner/materialization/receipt checks and six built witnesses retain boundary coverage. |
| AC-010 | pass | Weak registrations/status checks removed; retained tests assert concrete state/output or authoritative accept/refuse. |
| AC-011 | pass | Actual Turbo graph shows no CLI build prerequisite for source/update/release tasks. |
| AC-012 | pass | Real mutation tests: unrelated README/lint preserve product keys; prompt/skill/transitive source miss correctly. |
| AC-013 | pass | Separate Docker/browser identities and failed-capability nonce prevent stale consumer reuse; signed trust refusals pass. |
| AC-014 | pass | Actual deleted-output/cross-worktree restoration avoids execution; complete selections preserve aggregate and live-readiness policy. |
| AC-015 | pass | Workflow labels use2vCPU, macOS jobs removed, no shard matrix; GitHub-hosted Linux npm OIDC boundary retained. |
| AC-016 | pass | Actual affected plan controls Chromium setup; root policy selected only in Static Verification. |
| AC-017 | pass | Four real PostgreSQL cases use isolated migrated DBs; one wiki runner retains loader/sync/routes. |
| AC-018 | pass | Full CLI863tests/1530.92s, user1241.176s/system715.612s,RSS1492376KiB. VALIDATION distinguishes local fresh execution, cache restoration, setup/retry costs and unmeasured hosted runner totals. |
| AC-019 | pass | Parsed trust/aggregate checks and provider readback preserve PR/main/cancellation/release/parent-child authority. |
| AC-020 | pass | Current selectors, diagnostics, cache boundary and parked-web verification route appear in source runbooks and matching wiki projection. |
Final local integration and bounded static repair
bun run --cwd apps/cli test completed63files/863tests with exit0:1530.919s elapsed,1241.176s user,715.612s system,1492376KiB maxRSS,CPU0,1. Updater65cases took898.888s in that run. This complete CLI result is distinct from the original updater-only2937.77s baseline; no whole-CI percentage comparison is implied.
Final broad owner command bunx turbo run check check-types --concurrency=2 --continue=always ran in22.84s:12successful/23tasks,11owner checks failed. All selected type commands exited0, but web typegen initially logged a missing NEXT_PUBLIC_SERVER_URL despite exit0; its supported rerun with https://harness-api.localhost generated route types cleanly and passed. Baseline comparison used exact HEAD archive and same installed toolchain without builds/installs/tests: API/backoffice/web/contract/env/config/UI had no unmatched diagnostics; typed errors introduced in CLI fixtures/configs, auth callbacks, DB port condition and wiki import were corrected in their original ownership scopes. Whole-workspace static remains a failing gate, never reported as green. Comparison details: static-baseline-result.md and static-baseline/comparison.json under local-proof.
T9 config repair passes owner-cwd lint/format and75selector assertions; only property ordering changed, base config unchanged. T8 import-only repair passes three focused tests, types and formatting, with the introduced import diagnostic resolved and inherited lint debt disclosed. All scoped repairs passed: T1 one focused updater case43.18s with owner typed lint/types/format; T2 seven real recovery cases4.64s with typed lint and explicit strict standalone fixture compilation; T3 six catalog/receipt/seed cases25.23s with owner typed lint/types/format; T7 auth success/provider/rollback and one real DB constraint case plus types/format passed, with all12introduced diagnostics cleared. Auth retains eight verified pre-existing typed errors. No assertions were weakened, rules suppressed or production/config policy changed. Prior root-cwd narrow lint results did not establish all owner-cwd typed rules; current evidence uses actual owner invocation.
Retained review and accepted repair
The first immutable report is review-af60c94612b40a418623-20260922T110444Z-45b6e1f9c1a0, retained in 4f52937ed5e48bcb568dc068594fdf8df721a4e7 after implementation commit e41938f0. Report SHA-256: 82f7982aaedbf197a9810c62fef6db3fb257887123d1700f5c53a9bd16eb9ea1. Retention validation returned valid with no errors. Its authority is historical to the frozen reviewed bytes; subsequent changes do not rewrite that report.
Accepted finding ci-cache-001 added test-fixtures/monorepo-root/** to the updater input closure and extended an existing real Turbo perturbation case. Isolated RED reused the old updater hash; GREEN invalidated updater and preserved unrelated build. Applied workspace proof passed 32 tests / 384 assertions, root static and formatting. T11d subsequently consolidated a duplicate dry-run, leaving 31 tests / 384 assertions and an isolated missing-selection mutation failure. The repair is complete; one fewer process does not remove the corrected fixture check.
The four-lane residual research is Remaining test repetition. It explicitly separates redundant work from unique safety coverage and local AMD host measurements from unmeasured hosted performance. The user’s additional pruning request expands implementation after review; a second bounded pass is eligible for this accepted scope change, especially migration of application assertions to cheaper public planning interfaces. No additional review is opened merely to obtain a clean label for the ordinary cache repair.
Residual-pruning completion
T11a–T11h and T12 are complete. The final portfolio records 25 additional case removals, 21 fewer candidate executions, seven fewer updater calls, three fewer previews, four fewer scaffold writes, two fewer plans, two fewer context preparations, one fewer Turbo process chain, and 12 fewer policy application requests. These are operation counts rather than a hosted savings estimate. Eight policy scenarios now use the existing public planning seam. Three prepare-receipt mutation cases and the empty-route traversal remain under the explicit keep-and-explain fallback.
All affected retained witnesses and appropriate owner checks passed; unchanged inherited lint failures remain disclosed in VALIDATION. RAC-1–6 remain satisfied: test ownership, actual safety boundaries, complete selectors and correct signed-cache inputs are unchanged. No public API, production export or new scheduler was introduced. UI runtime behavior did not change; the existing browser evidence remains applicable. The added research is private knowledge, and canonical operator docs plus their projection were updated in T12.
| Task | Skill | Application evidence |
|---|---|---|
| T11a | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11a-result.md; production immutable. |
| T11a | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11a | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11b | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11b-result.md; production immutable. |
| T11b | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11b | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11c | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11c-result.md; production immutable. |
| T11c | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11c | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11d | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11d-result.md; production immutable. |
| T11d | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11d | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11e | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11e-result.md; production immutable. |
| T11e | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11e | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11f | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11f-result.md; production immutable. |
| T11f | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11f | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11g | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11g-result.md; production immutable. |
| T11g | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11g | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T11h | make-tsuite | Explicit removal-to-retained-proof mapping and real focused GREEN in T11h-result.md; production immutable. |
| T11h | tdd | Test-only equivalence exception; no fabricated RED or changed product behavior; meaningful public outcomes retained. |
| T11h | simplify | Duplicate setup/assertions removed at existing owning seams; no new production export or policy implementation. |
| T12 | docs-ingest-phase | Canonical operational docs and owned wiki projection reconciled; content checks pass. |
| T12 | simplify | Concise operational guidance links the single research/portfolio authority instead of duplicating its scenario ledger. |
Rule evidence: T11a/b/c/h pass HI-CLI-001/003; T11e passes HI-AUTH-001; T11f passes HI-BACKOFFICE-001; T11g preserves wiki source ownership; T12 and parent research/notes pass HI-DOCS-001 and HI-WIKI-001/003 with route/content checks. Other registry triggers are not-applicable to these test-only/doc changes. T11d has no new registry trigger; original CI task rule evidence remains applicable. No reusable skill, contract, asset, production release or deployment change occurs in this wave.
Final retained review and closeout
The second bounded primary/challenger review is retained in 6ce4a4f5be7b2bac0583f4d114e790c8153d406e, SHA-256 adc1f19a2f6bdd8f3dca244b78da60415327f2bc2d2ed69769f22cc11bdfdbd0. Standards/security, skill adherence, architecture, simplify, Spec and independent retained-safety coverage are all clean. Retained-pass validation returned valid with no errors; frozen target and source hashes were unchanged. No findings remain. The two-completed-pass policy is satisfied; no further review is opened.
This closeout update changes only evidence/status prose in PLAN, VALIDATION and these notes. It does not alter reviewed implementation or runtime test inputs. Owning content/format/diff checks cover the administrative update. Release selection remains none when compared with actual parent; final provider readback must confirm the pushed head, draft state and unchanged base. Delivery uses the user-approved per-command hook bypass and [skip ci]. No hosted workflow dispatch, merge, issue closure or product publication is authorized. Runtime failure diagnosis from the first implementation is recorded above; residual pruning required no new production repair. Documentation ingest is complete in T12, and no user-facing runtime UI changed.