Harness Intelligence Wiki
SpecsCLIIssue 217 CI Efficiency

Issue 217: local validation

Local validation

Implementation and capability-graph gates passed. The combined CLI run passed 63 files / 863 tests in 1530.919 seconds (25.515 minutes), before the subsequent scoped type/style repairs described below. Focused post-repair checks passed for every repaired scope; the first formal review is retained and its cache-input finding has been repaired; subsequent residual pruning passed the focused checks below and the second retained formal review is clean. No hosted workflow was dispatched for this work.

Environment and comparison limits

Local runtime: Bun 1.4.0+34cbb9a40, Node 24.19.0, Docker 29.7.2. Runs used two logical CPU affinities on a Linux x86_64 AMD Ryzen 5 3600 host with six physical cores and 12 logical CPUs; other workers shared the host. This bounds each selected process to two CPUs but does not reproduce Blacksmith hardware, scheduling, storage or network. Python measured wall/user/system time because /usr/bin/time was unavailable.

The original updater passed 68/68 in 2937.77 seconds (48.96 minutes), user 2287.56s/system 1216.23s, maximum RSS 1,384,888 KiB, CPUs 0,1 with existing warm dependency stores. Evidence: /tmp/hi-217-local-proof/updater-before.log. The candidate updater partition passed 65/65 in 898.888 seconds (14.98 minutes), within the passing complete CLI run on CPUs 0,1. The reduced proof includes the documented three low-signal removals and fixture changes; this is a local observation, not a hosted percentage guarantee. Failed/interrupted trials and cache-hit execution are not fresh-proof speedups. Whole hosted job duration, summed Blacksmith runner work, monthly billing, remote provider availability and hit rate remain unmeasured; there is no percentage or minute ceiling acceptance gate.

Passing local evidence

All evidence filenames below are under /tmp/hi-217-local-proof/ unless a repository path is given. Task reports include exact commands and relevant input hashes. Counts are scoped and overlap; do not sum them as a unique suite count.

ScopeResultEvidence
Bun compatibilityFrozen install 1037 packages, 5.32s, lockfile unchanged; full CLI build passed 15.70sbun-compat-install.json; cli-build.json
Final CLI rebuildPassed 11.96s; executable digest unchanged: 82a1d4542e7e21783fce913b87fbef4b9266106cee145336d730a2782ddc883fParent build custody; T9-result.md
Updater65/65 in compatible isolated checkout; final workspace 3/3 after lint cleanupT1-scratch-final.log; T1-workspace-final-slice.log; T1-final-hashes.json
RecoveryRoutine 7/7; surrounding release 86/86T2-green.log; T2-release-suite-final.log
CLI policy/compositionFinal 58 source cases passed within 59-case superset before duplicate deletion; six built witnesses passed within 8-case superset before preview relocationportfolio-source-complete.log; portfolio-built-final.log; T3-result.md
Remaining changed CLI tests27/27; inherited fixture/expected metadata repairs 14/14 and Project Verifier 3/3 passed focused validationT4-focused.json; owning repair handoffs
API310 tests/28 files; types passed; actual DB/auth/runtime and shutdown retainedT5-api-tests.log; T5-api-types.log
Backoffice71 tests/14 files; eight real browser journeys passed 26.64sT6-vitest.log; backoffice-browser.json
Packages129 tests/21 files across seven packages; applicable types and changed-file lint/format passedT7-result.md; T7-relevant-inputs.json
Wiki17 tests/four files in one Vitest runner; real loader fixture-sensitivity failure observed and restoredT8-final.log; T8-sensitivity.log
Independent root/operator work155 tests/821 assertions passed 32.65s, including one private real API build/Postgres/auth packaged proofT9a-final-suite.json; T9a-final-suite.log
Final cache policy32 tests/381 assertions passed 34.03sT9-policy-final.log
Final cheap operators119 tests/535 assertions passed 3.21sT9-operators-final.log
Root static/configurationcheck:repo, changed-file lint/format and syntax passed ; 12 workspace contracts valid; three workflows parse as YAMLT9-static-check-final.log; T9-contracts-final.json; T9-result.md

Historical recovery was compiled only; its full old-builder replay was deliberately not run. The full diagnostic updater lifecycle was not rerun as routine CI proof.

Selection, cache and trust

Final CLI discovery is 49 source + 1 updater + 8 release + 5 built files, disjoint and complete. Other testable workspace selectors retain API 28, backoffice 14, wiki 4, auth 6, contract 2, DB 6, env 1, scaffold 4, UI 1 and config 1 file; parked web has zero tests and retains build/types. Seven root operator files and the API-owned packaged proof reconcile the eight previously unselected files. See TEST-PORTFOLIO.

Real Turbo graph perturbations proved unrelated README/lint edits preserve product keys while consumed prompts, shipped skills and scaffold dependency source invalidate consumers. Source-test-only edits preserve unrelated build/update keys. Docker/browser identity changes and failed capability observations affect their own consumers. Selected files appear in real task inputs. A populated cache restored deleted output into a byte-identical worktree without producing another execution marker. These prove local reuse and output restoration, not signed-provider availability.

Static and affected jobs both configure existing signed-cache trust; tests retain fork/untrusted/missing-signature/auth-failure refusal. Root cache-policy executes once. Actual affected planning selects Chromium only for browser work. PR/main conditions, cancellation, Stable Aggregate and protected GitHub-hosted npm OIDC identity remain. No live token exchange, publication or provider mutation was used for this validation. Selection/cache RED/GREEN and input identities: T9-result.md, T9-owned-input-hashes.json and T9-cli-selector-freeze.json.

Focused checks after the full CLI run

All six scoped repair gates passed. These edits changed test/type/style expressions without changing production behavior, fixture authority or assertions. Evidence: /tmp/hi-217-local-proof/final-scoped-repair-summary.md and its owning task reports/logs.

ScopeAccepted repair and proof
T1 updaterThree equivalent expressions: regex exec, explicit undefined and return-await. Owner typed lint, types and format passed; focused custom-root updater case passed in 43.18s.
T2 recoveryStandalone Node/ES2023 types, JSDoc and validated unknown package version; unused diagnostic helper removed. Typed lint, project types and explicit strict fixture compilation passed; seven recovery tests passed in 4.64s. Historical replay was not executed.
T3 portfolioTyped fixture library identity and async/void/regex/matcher cleanup; no casts, suppression or assertion changes. Typed lint, types and format passed; six catalog/receipt/seed cases passed in 25.23s.
T7 packagesEleven auth promise callbacks and one DB port condition. Types/format and focused auth success/provider/rollback plus real DB constraints passed. All 12 introduced errors cleared; auth retains eight verified preexisting typed lint errors. DB scoped lint passed.
T8 wikiPath style only. Three focused tests, types and format passed; the new diagnostic was resolved. Inherited wiki lint debt remains.
T9 capability configsFour property-ordering fixes; base Vitest config unchanged. Owner lint/format and 75 selector-discovery assertions passed.

Repairs and outstanding limits

The first remaining 55-file CLI run failed five cases in three unchanged files. Three inherited fixture/contract expectations and two built Project Verifier fixture outcomes were repaired by their owners; focused 14/14 and 3/3 passed. The combined rerun passed all 63 files / 863 tests; its updater partition passed 65/65 in 898.888 seconds. This full result precedes subsequent scoped cosmetic/type repairs; their focused proof is recorded below, rather than attributing the earlier full run to later bytes. A separate real packaging test exposed a missing local import in package-bundled-gitignore.mjs; its original ReferenceError was reproduced before the one-import repair, and the same staging test passed afterward (T4-repair-red.json and T4-repair-green.json).

The final broad owner static/type check exited 1: 11 checks failed across multiple lint/format scopes, while 12 tasks reported success (final-owner-static.log/json). Baseline comparison identified inherited debt plus 60 introduced or moved changed-line errors. All introduced findings were repaired and their scoped gates accepted. Broad static validation remains failing from verified inherited lint/format debt; no waiver or overall static pass is inferred. Focused checks cover the later changed bytes, without repeating the full expensive CLI suite for these equivalent expression/type/style edits. Changed backoffice tests retain three preexisting prefer-import-in-mock findings, and wiki has existing broad lint debt. A web typegen attempt emitted an environment error despite success exit; rerunning with NEXT_PUBLIC_SERVER_URL=https://harness-api.localhost passed cleanly in 0.607 seconds (web-types-final.log/json). actionlint was unavailable; YAML parsing and owned behavior checks are narrower validation. The existing pre-push hook invokes obsolete release:candidate --base/--head arguments; hook installation tests do not prove that command succeeds. The user subsequently explicitly authorized the previously requested one-time commit/pre-push bypass. Per-command hook overrides leave repository hooks unchanged; inherited gates remain failing. Final review, release classification and commit/push remain parent-owned.

Final residual-pruning checks

The additional pruning removes 25 cases and repeated expensive operations, while eight policy input classes move to real public planning. These local checks validate the final changed scopes; the earlier full 863-case CLI run is preserved as earlier evidence, not relabelled as a complete run of final bytes.

GatePassing local proof
T11a updater/scaffold12 selected retained witnesses across three files; five updater cases rechecked after final assertion grouping. Owner typed lint/types/format pass. Both real Project Verifier journeys remain.
T11b runtime/cache125 cases across three files; owner lint/types/format pass. Six invalidation classes, one recovery sequence and production-runtime reuse all execute.
T11c release84 cases across five files, including real classification and recovery; owner lint/types/format pass.
T11d cache topology31 tests / 384 assertions; root static and formatting pass. Final formatted topology case passes. Removing a selected command in an isolated scratch tree makes the retained membership assertion fail.
T11e authSix policy/configured-callback cases; owner lint/types/format pass.
T11f backofficeFour route cases plus types/format pass; three unchanged mock-style lint findings remain. Existing eight browser journeys are unchanged and their prior passing evidence is retained.
T11g wikiNine real sync/public-contract cases; format/diff pass. Existing retained wiki lint findings remain; no new lint pass is claimed.
T11h policy60 cases across changed policy and retained reconciliation/catalog/root-materialization files pass in 199.05 s total. Final eight planning rows pass in 229 ms test time (2.31 s wall); typed lint/types/format pass.
T12 docsOwning content/projection checks, formatting and diff checks pass. Only canonical docs and owned projection changed.

All runs used two logical CPU affinities on the same Linux AMD host, with concurrent work during scoped runs. The 229 ms planning time is a changed-scope observation, not a same-condition before/after benchmark. No final hosted improvement percentage or monthly cost projection is claimed. No full historical replay, hosted workflow, merge or publication was dispatched.

First review finding ci-cache-001 is repaired: updater now includes consumed monorepo fixture inputs. Applied proof passed 32 cache-policy cases before T11d removed the redundant dry-run. The retained first report is immutable in 4f52937ed5e48bcb568dc068594fdf8df721a4e7; validation returned valid with no errors. The user-authorized one-time hook bypass applies only to this delivery's commits/push, using per-command configuration and [skip ci]; hook files remain unchanged.

Final review: second retained report in 6ce4a4f5be7b2bac0583f4d114e790c8153d406e; all five primary lenses and the independent retained-safety challenger are clean. Report bytes, report-only retention commit and branch containment validate. Subsequent closeout updates are administrative evidence prose only; no code or test input changed.

On this page