Issue 217: test portfolio
Test portfolio
This inventory accounts for all 153 original files, including inherited parent tests, plus four added files. Counts document ownership, not a deletion quota. T1–T9 gates passed; final combined runtime validation is recorded separately in VALIDATION. No hosted speedup is claimed.
Original-file inventory
Each row identifies retained capability or an explicit cull. The scenario mapping below records material seam/setup changes. The CLI partition is source 49, update 1, release 8 and built 5 files. Other testable workspaces use test:ci; root test:operators owns seven cheap operator files, and API test:packaged owns packaged-runtime-product.test.ts. Root cache-policy and dedicated signed-cache-witness proof retain distinct owners.
| Original file | Disposition | Capability owner | Protected proof / cull rationale | Evidence |
|---|---|---|---|---|
apps/api/src/auth-lifecycle-contract.test.ts | retained | apps/api / test:ci | retain; Real resource composition; injected configuration/readiness; shared pool, missing auth, terminal disposal, race and retry outcomes | T5-result.md |
apps/api/src/backoffice-access.test.ts | retained | apps/api / test:ci | retain; Memory/DB access stores; invited/verified/revoked/default-admin actors; activation and reinvite persistence, rejected unauthorized access | T5-result.md |
apps/api/src/backoffice.test.ts | retained | apps/api / test:ci | retain; Real backoffice stores; issue/provider and DB doubles; triage mutations, canonical/legacy repository joins, adoption exclusion, trusted reporter and typed failures | T5-result.md |
apps/api/src/baseline-registry.test.ts | retained | apps/api / test:ci | retain; Registry authority resolution; persisted releases and controlled fetch; exact/stable identity, redirect credential isolation, compatibility and digest rejection | T5-result.md |
apps/api/src/baseline-release-inventory.test.ts | retained | apps/api / test:ci | retain; Inventory loader/selector/verifier; candidate histories and provider pages; immutable identity, pagination bounds, credential scope and typed availability/integrity | T5-result.md |
apps/api/src/features/baseline-delivery/baseline-delivery.test.ts | retained | apps/api / test:ci | retain; Delivery service; exact-version request and registry/artifact dependencies; authority before bytes and missing-version refusal | T5-result.md |
apps/api/src/features/baseline-promotion/baseline-promotion.test.ts | retained | apps/api / test:ci | retain; Promotion service and memory store; publisher candidates/revisions; CAS, immutable conflict, idempotent retry and audited rollback outcomes | T5-result.md |
apps/api/src/features/public-domain-root-contract.test.ts | removed | apps/api | remove; Fake submit service only; no owned product invariant (mapping above) | T5-result.md |
apps/api/src/features/report-submission/report-submission.test.ts | retained | apps/api / test:ci | retain; Real submission service; anonymous/operator reports and controlled repository/providers; durable pending/claim, duplicate, invalid-input no effects, failure release and metadata fallback | T5-result.md |
apps/api/src/features/typed-failure-contract.test.ts | retained | apps/api / test:ci | retain; Real submission service; prepare/create failures; typed operation/cause preserved across seam | T5-result.md |
apps/api/src/http-adapter-contract.test.ts | retained | apps/api / test:ci | retain; Real HTTP adapters and local server; provider results/failures, pagination and interruption; credential isolation and actual fetch cancellation | T5-result.md |
apps/api/src/index.test.ts | retained | apps/api / test:ci | retain; Composed Request-to-Response/production bootstrap; real route wiring with controlled integrations; baseline bytes, reports/telemetry, auth/admin, resource disposal | T5-result.md |
apps/api/src/integrations/baseline-artifact/baseline-artifact.test.ts | retained | apps/api / test:ci | retain; Artifact adapter; bytes/redirect/status/oversize inputs; digest, bounded retrieval, credential scope and cancellation | T5-result.md |
apps/api/src/integrations/persistence/baseline-promotion-drizzle.test.ts | retained | apps/api / test:ci | retain; Real Drizzle store with DB adapter double; durable head, locking, timestamp normalization, lost acknowledgement reconciliation and indeterminate failure | T5-result.md |
apps/api/src/integrations/persistence/report-repository.test.ts | retained | apps/api / test:ci | retain except source scan removed; Real memory/Drizzle repositories with controlled DB; stable ID, claim exclusivity/release, persisted identity on retry, unfinished-only resume, completed result | T5-result.md |
apps/api/src/integrations/reports/provider-adapters.test.ts | retained | apps/api / test:ci | retain; Owned provider adapters; controlled runner; issue labels/result mapping, anonymous/token boundary, metadata rejection and interruption | T5-result.md |
apps/api/src/platform/http/baseline-download.test.ts | retained | apps/api / test:ci | retain; HTTP download wrapper with feature substitute; verified bytes/metadata, invalid paths and fallback delegation | T5-result.md |
apps/api/src/platform/http/baseline-promotion.test.ts | retained | apps/api / test:ci | retain; HTTP promotion with real feature/store; absent/malformed/valid publisher credentials; no unauthorized persistence and typed error status | T5-result.md |
apps/api/src/platform/runtime/lifecycle.test.ts | retained | apps/api / test:ci | retain; Lifecycle owner with controlled resource effects; disposal ordering/failures and initialization race | T5-result.md |
apps/api/src/platform/runtime/resources.test.ts | retained | apps/api / test:ci | retain; Resource owner; injected config/init; sharing, retries, exactly-once release and terminal getters | T5-result.md |
apps/api/src/production-application-lifecycle-contract.test.ts | retained | apps/api / test:ci | retain; Production application composition; web/resources dispose effects; ordering, dual failure and blocked initialization | T5-result.md |
apps/api/src/production-shutdown-contract.test.ts | retained | apps/api / test:ci | retain; Built start process; real termination signals/import; awaited exactly-once shutdown and import without signal-handler side effects | T5-result.md |
apps/api/src/public-api-contract.test.ts | retained | apps/api / test:ci | retain; Full HTTP contract; anonymous/authenticated/forged actors; meaningful success, authority stripping, declared error status/body and persistence/provider failure | T5-result.md |
apps/api/src/reports.test.ts | retained | apps/api / test:ci | retain; Real report stores/submission; controlled DB/provider state; dedup, canonical identity, trusted reporters, concurrency, provider-outside-transactions and recovery without duplicate issue | T5-result.md |
apps/api/src/runtime-product-contract.test.ts | retained | apps/api / test:ci | retain; Real runtime/HTTP/Postgres journey; report, login/auth, backoffice observation, invitation and email correlation | T5-result.md |
apps/api/src/runtime/baseline-ledger-cutover.test.ts | retained | apps/api / test:ci | retain; Operator validator/cutover seams; report-only/apply and provider doubles; explicit expected state, token bytes, reconciliation, readback and idempotent cleanup | T5-result.md |
apps/api/src/runtime/baseline-ledger-no-redeploy.runtime.test.ts | retained | apps/api / test:ci | retain; Real Postgres + reconstructed production runtime; verified promotion/readback durable authority across restart | T5-result.md |
apps/api/src/runtime/config-contract.test.ts | retained | apps/api / test:ci | retain; Owned configuration loaders; valid/missing/malformed environment; typed redacted failure and superseded identity ignored | T5-result.md |
apps/api/src/telemetry.test.ts | retained | apps/api / test:ci | retain; Real DB telemetry store with adapter double; idempotent events, trusted operator relation, monotonic activity, canonical/legacy repository and typed outage | T5-result.md |
apps/backoffice/e2e/public-routes.test.ts | retained | apps/backoffice / test:ci | Retain all 8 unchanged; owned output containment, anonymous redirects/login, OTP failure/retry/safe redirect, authenticated data navigation, actual loading boundary, rejected-vs-unavailable detail, invite persistence, public404 navigation | T6-result.md |
apps/backoffice/src/app/api/auth/[...path]/route.test.ts | retained | apps/backoffice / test:ci | Retain 2; GET/POST request dispatch reaches configured runtime and preserves exact response; owned route composition boundary | T6-result.md |
apps/backoffice/src/features/operator-shell/shell.test.ts | retained | apps/backoffice / test:ci | Retain 2; access summary → serializable minimal account DTO and signed-out absence; server/client boundary prevents unrelated access fields crossing | T6-result.md |
apps/backoffice/src/features/operator-workflows/actions.test.ts | retained | apps/backoffice / test:ci | Retain 12; operator forms → real actions → external API arguments, success/validation/typed failure, exact invalidation/no invalid-input side effects | T6-result.md |
apps/backoffice/src/modules/auth/login-path.test.ts | retained | apps/backoffice / test:ci | Retain 2; untrusted destination → sanitizer; internal destinations kept and external/protocol-relative/recursive-login redirects refused | T6-result.md |
apps/backoffice/src/modules/auth/server.test.ts | retained | apps/backoffice / test:ci | Retain 2; real auth-runtime composition with external constructors; explicit DB, executable Effect adapter, idempotent disposal and failed-construction cleanup | T6-result.md |
apps/backoffice/src/modules/control-plane/cache-tags.test.ts | removed | apps/backoffice | Remove; constant spelling/no owned observable invariant, above | T6-result.md |
apps/backoffice/src/modules/control-plane/client.test.ts | retained | apps/backoffice / test:ci | Retain 11; incoming cookie/configured API → real client → external fetch; protocol error mapping, plain serializable results, transient detail failure/refetch recovery | T6-result.md |
apps/backoffice/src/modules/presentation/date-time.test.ts | retained | apps/backoffice / test:ci | Retain 3; timestamps → operator-local summer/winter time and absent/invalid fallback; timezone correctness, not merely copy | T6-result.md |
apps/backoffice/src/modules/runtime/config.test.ts | retained | apps/backoffice / test:ci | Retain 4; real env loader from controlled provider; configured/default API, typed missing/invalid configuration, secret absence from diagnostics, injectable config | T6-result.md |
apps/backoffice/src/modules/runtime/shutdown.test.ts | retained | apps/backoffice / test:ci | Retain 1; real Bun child SIGTERM → disposal marker plus original signal termination; private temporary directory cleanup | T6-result.md |
apps/backoffice/src/public-routes.test.tsx | retained | apps/backoffice / test:ci | Prune 3 cases; retain 5 authorization/data failure outcomes, above | T6-result.md |
apps/backoffice/test-fixtures/browser/cleanup-order.test.ts | retained | apps/backoffice / test:ci | Retain 20; real cleanup authority with controlled process observations; identity drift, provenance, leaderless drains, EPERM/ESRCH, escalation revalidation, graph/role/dependency refusal; no signals against unowned processes | T6-result.md |
apps/backoffice/test-fixtures/browser/process-capture.test.ts | retained | apps/backoffice / test:ci | Retain 5; real process-table parser/classifier with controlled tables; exact parent/group identity and unknown-detached-child detection; bounded cwd probes | T6-result.md |
apps/backoffice/test-fixtures/browser/readiness.test.ts | retained | apps/backoffice / test:ci | Retain 1; controlled readiness barriers → real orchestrator; canonical route ready before browser spawn | T6-result.md |
apps/backoffice/test-fixtures/browser/workspace-bin.test.ts | retained | apps/backoffice / test:ci | Retain 1; private filesystem root-hoisted executable resolution when package-local directory absent | T6-result.md |
apps/cli/src/cli/behavioral-portfolio.test.ts | retained; policy scenarios moved | apps/cli / test:built | Six executable composition witnesses; policy, preview and four dependency-section inputs moved to source-owned tests. Weak eleven-command matrix and registration assertion removed. | T3-result.md; T3-semantic-fingerprints.json |
apps/cli/src/cli/commit-gate-command.test.ts | retained | apps/cli / test:source | retain; Observed health before persisted receipt, no receipt on validation failure :82–109. | T4-result.md |
apps/cli/src/cli/ensure-command.test.ts | retained | apps/cli / test:source | retain; Rejection preserves bytes; migration idempotent; disabled policy persists :59–125. | T4-result.md |
apps/cli/src/cli/safety-invariants.test.ts | retained | apps/cli / test:built | retain; Confinement, no partial state, stream behavior, secret redaction :83–154. | T4-result.md |
apps/cli/src/cli/scaffold-subagent-alignment.test.ts | retained | apps/cli / test:built | retain; Generated roles preserve custom roles and planned specialist skills :138–178. | T4-result.md |
apps/cli/src/cli/update-command.test.ts | retained | apps/cli / test:source | merge/prune; Keep JSON/progress/cache-clear; cull option existence :163–165 when behavior retained. See semantic map above. | T4-result.md |
apps/cli/src/cli/update-presenter.test.ts | retained | apps/cli / test:source | retain; Preserve completedFiles/legacy changedFiles meaning in command-output proof :23–42. | T4-result.md |
apps/cli/src/content/finder-entrypoints-catalog-prompts.test.ts | retained | apps/cli / test:source | merge/prune; Cull registration :23; preserve explicit-human-invocation guidance boundary :39. See semantic map above. | T4-result.md |
apps/cli/src/content/improve-mobile-frontend.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/content/scaffold-copy.project-verifier.test.ts | retained | apps/cli / test:source | retain; Preserve authored verifier and legacy handoff semantics :31–40 with generated-output proof. | T4-result.md |
apps/cli/src/content/scaffold-guidance.test.ts | retained | apps/cli / test:source | merge/prune; Bounded authoring action and empty action behavior, rendered scope targets, physical shared-prompt mirror; historical handback.test.ts is now this file. See semantic map above. | T4-result.md |
apps/cli/src/content/verification-recovery-skills.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/content/wiki.test.ts | merged into retained proof | apps/cli (removed; see mapping) | merge; Removed file; retained real owned decision/consumer proof identified in semantic map above. | T4-result.md |
apps/cli/src/data/catalog/architect-pipeline-registration.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/data/catalog/make-tsuite-registration.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/data/catalog/verification-registration.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/data/hooks/format-edited-file.test.ts | retained | apps/cli / test:source | retain; Real shipped hook fixes, previews, diagnostics, failure and isolation :124, :402. | T4-result.md |
apps/cli/src/data/scripts/commit-gate-runner.test.ts | retained | apps/cli / test:source | retain; Real staged Git paths, worktrees, deleted files, owner cwd and aggregate failures. | T4-result.md |
apps/cli/src/data/scripts/harness-projection/authoring.test.ts | retained | apps/cli / test:source | retain; Allowed authoring scope depends on current proof, custom roles preserved :36–79. | T4-result.md |
apps/cli/src/data/scripts/harness-projection/core.test.ts | retained | apps/cli / test:source | retain; Gate contributions must produce no harness writes; prefer result over adapter-call check :15–60. | T4-result.md |
apps/cli/src/data/scripts/harness-projection/lint-feedback.test.ts | retained | apps/cli / test:source | retain; Owned finding/failure projection, clean silence, exhausted repair requests. | T4-result.md |
apps/cli/src/data/scripts/sync-subagents-validator.test.ts | retained | apps/cli / test:source | retain; Carry rejected input through delivered script to prove no projection. | T4-result.md |
apps/cli/src/features/commit-gate/index.test.ts | retained | apps/cli / test:source | retain; Unresolved until observed proof; preserve foreign hooks; invalidate changed config :49–148. | T4-result.md |
apps/cli/src/features/commit-gate/quality.test.ts | retained | apps/cli / test:source | retain; Command ownership and mutating formatter refusal across spellings :13–181. | T4-result.md |
apps/cli/src/features/commit-gate/setup.test.ts | retained | apps/cli / test:source | retain; Rootless/independent setup, live executables and hook integrity :154, :208, :461. | T4-result.md |
apps/cli/src/features/context-planning/compiler.test.ts | retained | apps/cli / test:source | retain; Portable identity, ownership, partial outcomes and typed incomplete contracts :77, :574. | T4-result.md |
apps/cli/src/features/operator-skill/lifecycle-target-delegation.test.ts | retained | apps/cli / test:source | retain; Stale authority cannot retry/install; preserve uncovered bindings and cancellation :446. | T4-result.md |
apps/cli/src/features/project-settings/service.test.ts | retained | apps/cli / test:source | retain; Inherited parent: persist explicit repository authority while preserving unresolved/absent command policy. | T4-result.md |
apps/cli/src/features/repository-check/application.test.ts | retained | apps/cli / test:source | retain; Independent health/drift survives dependency failure; dependent mutation blocked :91, :478. | T4-result.md |
apps/cli/src/features/scaffold-state/generation-inputs.test.ts | retained | apps/cli / test:source | retain; Filesystem input closure, hashes, unsupported files and symlink escape :100. | T4-result.md |
apps/cli/src/features/scaffold-state/portability.test.ts | retained | apps/cli / test:source | retain; Relocation preserves bytes but rechecks live hooks :196–199. | T4-result.md |
apps/cli/src/features/scaffold-state/reconcile.test.ts | retained | apps/cli / test:source | retain; Keep edit/deletion invalidation; replace reference identity/intermediate shapes :94, :262. | T4-result.md |
apps/cli/src/features/scaffold-update/validation-cache/cache.test.ts | retained | apps/cli / test:source | retain; Promotion, invalidation, bypass/failure no publication, optional storage :39, :162. | T4-result.md |
apps/cli/src/features/scaffold-update/validation-plan.test.ts | retained | apps/cli / test:source | retain; Inherited parent: exact owning workspace/catalog/config consumers select validation; unknown packages fail closed and guidance-only changes do not select installation. | T4-result.md |
apps/cli/src/integrations/repository-detector.test.ts | retained | apps/cli / test:source | retain; Real manifests map to owned package-manager authority :63, :175. | T4-result.md |
apps/cli/src/integrations/skills-cli-target-delegation.test.ts | retained | apps/cli / test:source | retain; Fresh source authority, refusal before install, prompt preservation :422. | T4-result.md |
apps/cli/src/integrations/tool-management.test.ts | retained | apps/cli / test:source | retain; Nonmutating readiness, actual version evidence, redacted failures :75–83. | T4-result.md |
apps/cli/src/integrations/update-cache-filesystem.test.ts | retained | apps/cli / test:source | retain; Atomic process publication, corruption/recovery, private restore, confinement :63, :209. | T4-result.md |
apps/cli/src/integrations/update-cache-remote.test.ts | retained | apps/cli / test:source | retain; Owned signing/redirect/archive/outage policy and refusal before request :88, :603. | T4-result.md |
apps/cli/src/platform/commit-gate-capabilities.test.ts | retained | apps/cli / test:source | retain; Live hook/dependency/lock authority, foreign hook ownership, no false receipt :465. | T4-result.md |
apps/cli/src/platform/feature-application-operations.test.ts | retained | apps/cli / test:source | retain; Missing live tools reject cached validation, local unauthenticated cache :41–85. | T4-result.md |
apps/cli/src/platform/scoped-scaffold-operation.test.ts | retained | apps/cli / test:source | retain; Tool install suppresses lifecycle scripts; partial failure, opt-out, confinement :88–156. | T4-result.md |
apps/cli/src/runtime/config.test.ts | retained | apps/cli / test:source | retain; Secret/environment allowlist excludes unrelated variables :47. | T4-result.md |
apps/cli/src/runtime/scripts.test.ts | retained | apps/cli / test:source | retain; Changed-input refusal, candidate isolation, cleanup/cache/env/process failures :143, :2905. | T4-result.md |
apps/cli/src/runtime/validation-candidate.test.ts | retained | apps/cli / test:source | retain; Special/escaping files refused, contained aliases allowed :233. | T4-result.md |
apps/cli/src/scaffold/confined-root-alias.test.ts | retained | apps/cli / test:source | retain; Retarget/escape refusal leaves external bytes untouched :151–160. | T4-result.md |
apps/cli/src/scaffold/generated-gate-scoping.test.ts | retained | apps/cli / test:source | retain; Actual generated linter rejects staged invalid, ignores unstaged invalid :134–148. | T4-result.md |
apps/cli/src/scaffold/output-receipt-validation.test.ts | retained | apps/cli / test:source | retain; Malformed/failure receipt rejected before adoption :151; owned output :36. | T4-result.md |
apps/cli/src/scaffold/output-root-dependencies.test.ts | retained | apps/cli / test:source | retain; Planned/applied package agreement and conflicting ownership refusal :76–186. | T4-result.md |
apps/cli/src/scaffold/output-root-materialization.test.ts | retained | apps/cli / test:source | retain; Rootless placement and conflicts preserve inventory :263–272. | T4-result.md |
apps/cli/src/scaffold/output-wiki-plugin-alias.test.ts | retained | apps/cli / test:source | strengthen/prepare; Actual generated linter accepts owned alias and emits rule diagnostics :129. See semantic map above. | T4-result.md |
apps/cli/src/scaffold/output.test.ts | retained | apps/cli / test:source | retain; Keep hook/role/adoption safety :928; replace object-identity memoization :57. | T4-result.md |
apps/cli/src/scaffold/project-verifier-preservation.test.ts | retained | apps/cli / test:built | retain; Arbitrary authored verifier bytes/absence survive generated updates :236–270. | T4-result.md |
apps/cli/src/scaffold/settings-selection.test.ts | retained | apps/cli / test:source | retain; Supported authority, read-only planning, independent output when quality unresolved :404. | T4-result.md |
apps/cli/src/scripts/promote-baseline-authority.test.ts | retained | apps/cli / test:release | retain; Redirect refusal and exact historical readback after stable advances :70, :188. | T4-result.md |
apps/cli/src/scripts/release-authority.test.ts | retained | apps/cli / test:release | merge/prune; Wrong tree/squash source, duplicate and expired evidence refused :189, :486. See semantic map above. | T4-result.md |
apps/cli/src/scripts/release-candidate.test.ts | merged into retained proof | apps/cli (removed; see mapping) | merge; Removed file; retained real owned decision/consumer proof identified in semantic map above. | T4-result.md |
apps/cli/src/scripts/release-changelog-selection.test.ts | retained | apps/cli / test:release | retain; Changed changelogs alone select baseline/npm/mixed/none :62–133. | T4-result.md |
apps/cli/src/scripts/release-convergence.test.ts | retained | apps/cli / test:release | retain; Stable product order, no-product no calls, immutable mismatch refusal :98–186. | T4-result.md |
apps/cli/src/scripts/release-dispatcher.test.ts | retained | apps/cli / test:release | retain; Preflight conflict/ambiguity refusal, prerelease metadata and archive cleanup :44–185. | T4-result.md |
apps/cli/src/scripts/release-guidance-contract.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/scripts/release-impact-freshness.test.ts | retained | apps/cli / test:release | retain; Old unchanged notes cannot authorize later changed payload :35. | T4-result.md |
apps/cli/src/scripts/release-publication.test.ts | retained | apps/cli / test:built | retain; Tamper/exact identity, credentials, safe extraction, idempotency and readback :1650–1683. | T4-result.md |
apps/cli/src/scripts/release-recovery-publication.test.ts | retained / historical scenarios moved | apps/cli / test:release | Actual planner/validator; six-commit real Git history, tiny valid artifacts, exact binding/tamper/partial/completed retry. Historical replay diagnostic only. | T2-result.md |
apps/cli/src/scripts/release-recovery.test.ts | retained | apps/cli / test:release | retain; First-parent history, notes/tree/version authority and strict recovery declaration :78–233. | T4-result.md |
apps/cli/src/scripts/release-verification-evidence.test.ts | merged into retained proof | apps/cli (removed; see mapping) | merge; Removed file; retained real owned decision/consumer proof identified in semantic map above. | T4-result.md |
apps/cli/src/scripts/sync-skills-repo.test.ts | removed | apps/cli (removed; see mapping) | remove; No observable capability invariant: registration/prose/source SHA snapshot (semantic map above). | T4-result.md |
apps/cli/src/update/planned-wiki.test.ts | retained | apps/cli / test:source | retain; Read-only authored/managed/missing wiki states and authority :195–283. | T4-result.md |
apps/cli/src/update/run.test.ts | retained; three no-invariant cases removed | apps/cli / test:update | Actual runUpdate filesystem/receipt outcomes; immutable seeds/private copies; controlled incidental resolver. Real installer/hooks/lifecycle suppression retained. | T1-result.md; T1-final-hashes.json |
apps/cli/src/update/wiki-alignment-owner.test.ts | retained | apps/cli / test:source | retain; Full update preserves authored/root rules and records truthful owner receipt :131–151. | T4-result.md |
apps/web/src/public-routes.test.tsx | removed | apps/web | Remove sole placeholder/copy/source test; no owned invariant | T6-result.md |
apps/wiki/scripts/public-wiki-contract.test.ts | retained | apps/wiki / test:ci | Single Vitest owner; real sync/prune/check-only, Fumadocs navigation or route outcomes retained. See complete semantic mapping below. | T8-result.md |
apps/wiki/scripts/source-page-tree.test.mjs | retained | apps/wiki / test:ci | Single Vitest owner; real sync/prune/check-only, Fumadocs navigation or route outcomes retained. See complete semantic mapping below. | T8-result.md |
apps/wiki/scripts/sync-content.test.mjs | retained | apps/wiki / test:ci | Single Vitest owner; real sync/prune/check-only, Fumadocs navigation or route outcomes retained. See complete semantic mapping below. | T8-result.md |
apps/wiki/src/public-routes.test.tsx | retained | apps/wiki / test:ci | Single Vitest owner; real sync/prune/check-only, Fumadocs navigation or route outcomes retained. See complete semantic mapping below. | T8-result.md |
packages/auth/src/auth-email-contract.test.ts | retained | packages/auth / test:ci | merge/remove; Real createAuth HTTP lifecycle, cookie/session revocation, OTP/email, startup/disposal; test harness parity and cleanup | T7-result.md |
packages/auth/src/composition-contract.test.ts | retained | packages/auth / test:ci | retain; Auth layer composition and exactly-once pool disposal on success/construction failure | T7-result.md |
packages/auth/src/config-contract.test.ts | retained | packages/auth / test:ci | retain; Injected config validation/redaction, typed failures, layer-fed builder and no ambient env architecture boundary | T7-result.md |
packages/auth/src/index.test.ts | retained | packages/auth / test:ci | retain; createAuthOptions/config provider email policy, optional cross-domain cookies, preview URL and fail-closed missing Resend | T7-result.md |
packages/auth/src/public-domain-root-contract.test.ts | retained | packages/auth / test:ci | retain; Four owned verification-code policy variants and complete production Resend forwarding | T7-result.md |
packages/auth/src/typed-failure-contract.test.ts | retained | packages/auth / test:ci | retain; Own adapter normalization of persistence/auth/Resend rejection and provider error response; original causes retained | T7-result.md |
packages/config/public-config-contract.test.ts | retained | packages/config / test:ci | remove snapshot; Real consuming TypeScript compile and root-only patch lifecycle | T7-result.md |
packages/contract/src/api.test.ts | retained | packages/contract / test:ci | remove redundant/shape; Input validation, baseline identity/digest/authority constraints, report/telemetry policy | T7-result.md |
packages/contract/src/public-protocol-contract.test.ts | retained | packages/contract / test:ci | retain; Complete normalized public protocol compatibility; oracle sensitivity/normalizer support and package boundary | T7-result.md |
packages/db/src/baseline-authority-postgres.test.ts | retained | packages/db / test:ci | merge preparation; Four isolated real SQL authority cases described above | T7-result.md |
packages/db/src/composition-contract.test.ts | retained | packages/db / test:ci | retain; Scoped pool release, connection failure normalization and exactly-once disposal | T7-result.md |
packages/db/src/config-contract.test.ts | retained | packages/db / test:ci | retain; Injected redacted connection config, missing/invalid typed startup rejection | T7-result.md |
packages/db/src/index.test.ts | retained | packages/db / test:ci | retain; Explicit URL required even when ambient DATABASE_URL exists | T7-result.md |
packages/db/src/postgres-contract.test.ts | retained | packages/db / test:ci | remove simulated duplicate; Real migrations, transactions, uniqueness/SQL constraints and cleanup witness | T7-result.md |
packages/db/src/typed-failure-contract.test.ts | retained | packages/db / test:ci | retain; Public persistence failure wrappers preserve owned operation/cause semantics | T7-result.md |
packages/env/src/public-env-contract.test.ts | retained | packages/env / test:ci | retain; Isolated process public/server environment decoding, exposure boundary/defaults, invalid values and secret redaction | T7-result.md |
packages/scaffold/src/context-plan.test.ts | retained | packages/scaffold / test:ci | retain; Shared plan roundtrip, forbidden runtime payload fields, malformed contribution and explicit/legacy quality command execution | T7-result.md |
packages/scaffold/src/harness-capability.test.ts | retained | packages/scaffold / test:ci | retain; Complete/unique families and support variants, projection/action/trace/failure outcome compatibility and invalid combinations | T7-result.md |
packages/scaffold/src/index.test.ts | retained | packages/scaffold / test:ci | merge/remove; Legacy/published/embedded compatibility classes and required tool acceptance/rejection | T7-result.md |
packages/scaffold/src/public-scaffold-contract.test.ts | retained | packages/scaffold / test:ci | retain; Public schema/wire compatibility, malformed inputs, full capability families, receipt ownership/legacy and unknown-field behavior | T7-result.md |
packages/ui/src/public-ui-contract.test.tsx | retained | packages/ui / test:ci | merge/remove; Public primitive accessible names, invalid and disabled/checked state | T7-result.md |
scripts/behavior-contract/affected-verification.test.ts | retained; selected | test:cache-policy | Existing root verification or signed-cache witness proof; Cache-policy files run under test:cache-policy; shared-cache-witness remains in the dedicated witness workflow. | T9-result.md |
scripts/behavior-contract/cache-identity.test.ts | retained; selected | test:cache-policy | Existing root verification or signed-cache witness proof; Cache-policy files run under test:cache-policy; shared-cache-witness remains in the dedicated witness workflow. | T9-result.md |
scripts/behavior-contract/cache-trust.test.ts | retained; selected | test:cache-policy | Existing root verification or signed-cache witness proof; Cache-policy files run under test:cache-policy; shared-cache-witness remains in the dedicated witness workflow. | T9-result.md |
scripts/behavior-contract/consumer-repositories.test.ts | retained; selected | test:operators | Retain installed-consumer authority, provenance, quarantine, cleanup, archive and prompt-flow proofs. One fixed transition-name inventory case removed (no observable capability). Actual isolated CLI-source build test now uses a tiny real source + installed fixture dependency + stale dist, preserving actual preparation and equivalent Bun artifact bytes without compiling this entire CLI twice. Material input intentionally narrows from current app to minimal consumer; full built CLI witnesses remain T3. No production source changes here. | T9a-result.md |
scripts/behavior-contract/cutover-repeat.test.ts | retained; selected | test:operators | Retain all 12 public orchestration/cleanup/evidence/concurrency scenarios; no full real repository gate is executed by these injected operation-adapter tests. Real owned subprocess termination remains. | T9a-result.md |
scripts/behavior-contract/isolation.test.ts | retained; selected | test:operators | Retain all 45 real/controlled filesystem ownership, symlink/race/process-group cleanup/provenance scenarios. Removed 109 lines of implementation-source spelling/order assertions attached to these cases (signal-handler formatting, source function names, wrapper argument spelling, config implementation). Genuine refusal, untouched adjacent state, full-preflight and process graph tests remain, including backoffice cleanup-order suite as an independent consumer witness. No claim removed source-string checks were runtime proof. | T9a-result.md |
scripts/behavior-contract/packaged-runtime-product.test.ts | retained; selected | @punks/api#test:packaged | Retain one real stale-artifact rebuild -> real API/DB/auth runtime -> genuine evidence validation. Private API checkout owns dist/evidence; dependencies shared read-only; shared API dist is never overwritten. Capture genuine evidence, then independently reject run-id and source-target corruption through actual validator with no-op rebuild/evidence-runner process stand-ins and exact single-error assertions. Cheap negative seam is evidence consumption, not repeated auth proof. Unknown option and missing explicit packaged entrypoint remain. Five tests; one actual API build/runtime loop, no cleanup rebuild. | T9a-result.md |
scripts/behavior-contract/process-identity.test.ts | retained; selected | test:operators | Retain all 3 strict GNU/BSD parsing/layout/locale cases; called by cleanup/browser/runtime owners. | T9a-result.md |
scripts/behavior-contract/shared-cache-witness.test.ts | retained; selected | dedicated cache-witness workflow | Existing root verification or signed-cache witness proof; Cache-policy files run under test:cache-policy; shared-cache-witness remains in the dedicated witness workflow. | T9-result.md |
scripts/behavior-contract/validate.test.ts | retained; selected | test:operators | Retain authority/path/ownership/refusal tests, add explicit parked-web waiver boundary. Only packages/config and deliberately parked apps/web may waive runtime tests; active CLI refusal remains. | T9a-result.md |
scripts/external-drift/npm-trusted-publisher-oidc-exchange.test.ts | retained; selected | test:operators | Retain 6 package/event/environment/token masking/child failure/workflow-boundary proofs. Existing injected external OIDC transport; no live token exchange. | T9a-result.md |
scripts/install-git-hooks.test.ts | retained; selected | test:operators | Retain 2 idempotent local hook installation/worktree-context cases. Existing intercepted pre-push forwarding does NOT prove obsolete --base/--head release CLI succeeds; parent owns acknowledged hook defect resolution, no bypass introduced. | T9a-result.md |
Added test files
| File | Owner / meaningful proof | Selection status |
|---|---|---|
apps/cli/src/cli/portfolio-catalog.test.ts | CLI materialization: dependencies/devDependencies/peerDependencies/optionalDependencies retain consumer declaration and root catalog ownership | Selected by final T9 graph |
apps/cli/src/cli/portfolio-policy.test.ts | CLI application: prepare/catalog/ownership policies through runScaffold/runUpdate and real filesystem receipts | Selected by final T9 graph |
apps/cli/src/cli/portfolio-preview.test.ts | CLI direct preview: findings/cleanup and escaping-symlink refusal; no executable build prerequisite | Selected by final T9 graph |
scripts/behavior-contract/ci-topology.test.ts | Root CI topology: disjoint complete CLI capability discovery, exact-once root graph and real docs/consumed-input hash perturbation; T9 graph tests passed | Selected by final T9 graph |
Meaningful transformations
| Group | Actor, authority and material input | Before → retained seam | Observable result, effects and isolation |
|---|---|---|---|
| T1 updater | Local updater; authored/managed files, live receipt, conflicting/missing/corrupt state | Full incidental dependency resolution → actual runUpdate with existing dependencyProcess control | Real confined mutations, truthful partial/failed results, rollback and withheld proof. Resolver rejection includes dependency rollback absence. Real resolver/hooks/executable tools/lifecycle suppression remain a focused bundled-assets journey. No npm peer-resolution compatibility claim. |
| T1 prepared fixtures | Same updater authority; completed authoring, ready validation, ordinary multi-workspace and managed publication states | Repeated convergence → five immutable prepared seed families, copied privately | Each scenario mutates an independent root. Receipt recovery, live-input tampering and no-install/no-lint outcomes remain actual update operations. Tiny valid skill bodies retain catalog identity; the installer journey consumes full bundled skills. |
| T2 recovery | Release planner; exact first-parent commits, notes hashes, trees, versions, remote tags and reviewed recovery declaration | Historical monorepo builds → production planner/validator over six real Git commits and tiny valid artifacts | Exact binding and archive tamper refusal; partial anchor excludes spent work; completed retry is empty. Bun/npm pack/tar remain real. Private history owns deliberate tag mutations. Historical builders/version-specific replay moves on demand. |
| T3 CLI policy | Scaffold/update operator; catalog ownership and prepare/dependency declarations | Built command permutations → runScaffold/runUpdate plus actual detector/planner/materialization | Real manifest/receipt mutations and no-write/refusal outcomes remain. Four dependency sections run materialization plus one representative updater lifecycle. Each fixture privately copies immutable successful prerequisites; installation is controlled when incidental. |
| T3 ownership delta | Managed incompatible Effect tuple versus an already-existing exact catalog | Incidental resolver failure previously rolled back to catalog reference → controlled successful installation reaches0.39.0 | Explicit semantic boundary change, not identical old side effect. Existing exact tuple no-write preview remains; prior-owned receipt lifecycle is covered by dedicated catalog-consumer cases. One duplicate converged-catalog row removed after passing superset. |
| T3 preview/composition | Preview caller and actual CLI process; hostile symlink, preparation failure, cache and transport inputs | Two preview scenarios move to direct source file; six focused executable witnesses remain | Cleanup/findings and escaping-symlink refusal need no build. Built artifact still proves startup/aliases, JSON/exit/stream semantics, scaffold/update cold/warm composition, refusal without consumer mutation and delegation. Full benchmark permutations become on-demand. |
| T4 release evidence | Release authority selector; structurally valid/invalid evidence, exact source tree/run/PR binding | Standalone decoder copies → actual release-authority acceptance/refusal | Wrong/squash tree, extra source release state, duplicate/expired or invalid evidence cannot confer authority. Pure typed-error constructor identity is not retained as product proof. |
| T4 generated lint | Local scaffold operator; root/wiki emitted configuration and deliberately valid/invalid import inputs | Source substring expectations and incidental npm install → actual generated Oxlint execution using read-only installed dependency link | Positive alias acceptance, rule diagnostics, root recursion and wiki exclusion remain observable. Private mutable root owns emitted files; deleting its symlink never removes shared dependencies. |
| T4 command stream | CLI user; ordinary JSON, quiet clear-cache, cleared/skipped progress and invalid cache mode | Repeated normal invocation merged into existing real command case | Exact exit/status/stderr/progress semantics retained; invalid mode refuses before application. Help option presence alone removed. |
| T5 API | Anonymous/operator submission and persistence actors; concurrent claim/provider activity | Fake submit self-test and source/transaction-count scans removed; existing real services/repository/HTTP seams retained | Actual idempotence, durable pending/claim/retry, provider work outside transactions, typed failures and authority remain. Real DB/auth/runtime and built shutdown proof retained. |
| T6 operator/web | Anonymous/authenticated operator; route failures and invalid/valid form data | Static copy/cache-tag spellings culled; real actions/client/route/browser seams retained | Invite/revoke/map/update invalidate actual owned state; invalid form produces no effects. Eight real browser journeys remain. Parked web copy has no owned behavioral invariant and intentionally has no tests. |
| T7 SQL | Real DB caller; empty migrated database, conflicting ledger/release identities and append-only constraints | Four PostgreSQL server lifetimes → one server with independent migrated DB per case | Atomic rejection, migration idempotence, immutable ledger and publication/rollback uniqueness remain real SQL. No mutable DB state crosses cases. Simulated in-memory SQL replay removed. |
| T7 package contracts | Untrusted protocol/schema/environment input, auth/session callers and primitive consumers | Duplicate shapes/constructors/source/CSS snapshots removed; public decoder, real auth/DB, compiler and accessible renderer seams retained | Runtime malformed-input refusal/legacy compatibility, authority validation, exact env exposure/redaction, real session/email persistence and primitive disabled/checked/invalid accessible state remain. UI proof is SSR, not browser. |
| T8 wiki | Sync operator and route reader; mixed source-owned/canonical content, redirects and missing pages | Multiple runners and complete authored content preparation → one Vitest runner and tiny test collections feeding real Fumadocs loader | Real create/update/prune/check-only/nonmutation and navigation/route behavior retained. Redirect destination existence remains consumed. Static historical route inventory, exact prose and one redundant projection equality check removed. |
| T9a package staging | CLI packaging operator; immutable consumer source with stale build output | Two full CLI compiles → tiny real source plus installed fixture dependency and actual staging/build operation | Artifact freshness, authority/provenance/quarantine and source nonmutation retained; complete CLI executable composition remains T3. This deliberately narrows input, not the packaging boundary. |
| T9a packaged API | Packaged runtime validator; stale artifact, genuine API/Postgres/auth evidence, independently corrupted runId and target | Shared dist mutation and repeated complete runtime journeys → one private API copy/build/runtime seed and separate evidence refusal probes | Actual fresh bundle and real API runtime evidence retained. Each corruption reaches production validator independently; no-op child stand-ins are used only after capturing genuine evidence. Never included in cheap operators. |
No-owned-invariant culls
- T1: one no-issue/no-applied case that never observed claimed repository-check preservation; two resolved-output object-identity cases.
- T3: registration accounting and eleven generic command rows accepting any typed status/error; one redundant converged catalog row.
- T4: mobile/recovery skill prose, catalog registration, release guidance and fixed skill SHA snapshots; duplicate help-option presence and rendered static wording. Complete original-file rows identify each deleted file. Rendered explicit invocation boundaries and physical prompt-mirror behavior remain where actually consumed.
- T5: fake submit service testing itself, implementation source scanning and transaction-count bookkeeping.
- T6: cache-tag spelling, static terminal/skeleton copy and parked-web placeholder/source layout assertions.
- T7: hand-written provider/SQL imitation, error constructors, endpoint inventory already covered by complete protocol proof, fixture/example duplication, lint history strings and Tailwind spelling.
- T8: review/onboarding prose, fixed historical route counts and one chosen projection equality check. General synchronization/drift verification remains.
- T9a: fixed transition-name inventory and source spelling/order checks. Actual ownership, cleanup, process lifecycle and refusal outcomes remain.
Eight previously unselected operator files
| File | Supported owner and retained proof | Execution selection |
|---|---|---|
| consumer-repositories.test.ts | Package-consumer tooling; provenance, staging freshness, quarantine and cleanup | Cheap root operator task; test:operators |
| cutover-repeat.test.ts | Repeat operator; orchestration, concurrency, evidence and termination | Cheap root operator task |
| isolation.test.ts | Cleanup/repeat/browser support; filesystem/process ownership, symlink/race refusal and untouched adjacent state | Cheap root operator task |
| packaged-runtime-product.test.ts | API packaged-runtime validator; private fresh build, real DB/auth runtime and bound evidence refusal | Separate API capability requiring Docker/build |
| process-identity.test.ts | Cleanup/browser/runtime process identity; GNU/BSD/locale parsing | Cheap root operator task |
| validate.test.ts | Repository behavior-contract authority; ownership/path/refusal and explicit parked-web boundary | Cheap root operator task |
| npm-trusted-publisher-oidc-exchange.test.ts | Protected publisher; package/event/environment/token masking/child failure/workflow boundaries | Cheap root operator task; no live token exchange |
| install-git-hooks.test.ts | Local hook operator; idempotence/worktree installation | Cheap root operator task; does not prove obsolete pre-push CLI invocation succeeds |
Existing signed-cache-witness tests keep their witness execution owner; no additional routine duplication is inferred.
Evidence
See VALIDATION for local results, runtime identities, repair evidence and unresolved checks. Source task handoffs and fingerprints were consolidated from /tmp/hi-217-local-proof/T1-result.md through T9-result.md, T3-semantic-fingerprints.json, and the original 153-file inventory. The complete semantic decisions are retained above; temporary logs are supporting local evidence, not hosted authority.
Residual pruning after the first retained review
The user explicitly requested deeper pruning. Four readonly lanes and a focused policy follow-up produced Remaining test repetition. T11a–T11h remove 25 additional cases, with no skipped/quarantined rows and no selector/file-count change. CLI cases derive from 863 to 843; this arithmetic is not a claim that the complete final suite was rerun. Current changed scopes have focused passing proof. The original inventory still accounts for all 153 files; 10 are removed and three merged into retained proof, with four replacement files listed above.
| Task | Case reduction | Surviving proof and actual work removed |
|---|---|---|
| T11a updater/scaffold | 93 → 86 | One cold missing-proof publication; missing/corrupt/stale converged repair with actual receipt hash and byte-stable repeat; tampered/missing handoff repair plus healthy repeat; valid accepted authoring carried into existing recovery; stale scaffold handoff publication; both real verifier journeys. Removes seven update calls, three previews, four scaffold writes, two plans and two context preparations. Cold/damage and entrypoint/damage cross-products are intentionally reduced. |
| T11b runtime/cache | 128 → 125 | Every one of six invalidation classes retains cold/change execution; one row owns the failure/retry/unknown-runtime/corrupt-envelope tail. Actual preparation mutation replaces call-order-only proof. Full cache matrix retains closed-input refusal; production-runtime reuse retains exact installation payload. Removes 21 candidate executions and one temporary cache fixture. |
| T11c release | 87 → 79 | Real planner/validator subsumes duplicate no-release, baseline entry, npm readback and compatibility proof. Real classifier owns four product selections; one publication witness proves inspect-before-publish. Newest selection combines older valid/expired receipts, with duplicate refusal retained. All unique authority dimensions remain. |
| T11d root | 32 → 31 | Three selected-command assertions move into existing real topology dry-run; one Turbo process chain removed. Actual consumed-fixture perturbation and unrelated-build stability remain. |
| T11e auth | 5 → 3 | Configured OTP composition owns exact sign-in payload, sender and real policy/adapter forwarding. Three other email types and provider failures remain. |
| T11f backoffice | 5 → 4 | Required real browser journey proves exact /access redirect and usable login; forbidden and unavailable route cases remain. |
| T11g wiki | 7 → 6 | Public sync contract fingerprints the complete tree during check-only and proves actual apply; source-owned/canonical pruning distinctions remain. |
| T11h policy | 52 → 50 | Remove duplicate exact catalog materialization and missing-object repair; missing-array repair retains preservation, narrow ownership and repeat stability. Eight declared-value/refusal inputs now use actual inspection/public planning and exact typed errors or desired bytes, with unchanged manifest checks. Expanded application requests fall from 58 to 46 (nine scaffold, three write-update requests avoided). |
All cases retain their original capability owners. T11h's eight planning rows are still eight separately reported inputs, not hidden behind one label. Three proposed prepare-receipt migrations were rejected: exported reconciliation consumes normalized segment observations and cannot independently prove private prior-receipt-aware composition and published receipt. The full update cases remain. The empty/whitespace route traversal also remains because an exact selected lower-level empty-input witness was not established.
No unique auth/session/cookie, SQL constraint, filesystem confinement, rollback, receipt publication, installer/hook, browser or release-authority guarantee is removed. Reduced Cartesian combinations are explicitly recorded above. Source hashes, commands and actor/input/authority/outcome mappings are retained in task handoffs under /tmp/hi-217-local-proof/pruning-research/; this durable table and the research report retain their conclusions.