Project-Generated Managed-File Ownership Plan
Plan: Project-Generated Managed-File Ownership
Initial Situation
hi check currently treats a changed managed-file hash as repository drift unless a narrow path/kind heuristic classifies the file as project-authored. That is correct for ordinary baseline-managed output, but it produces false drift when this repository has already regenerated a file from a separate, authoritative repository producer.
The present checkout contains such generated mirrors alongside ordinary scaffold output. The distinction is not represented in the managed-file receipt: managed entries persist only kind, path, and sha256. Desired-state output carries source/revision provenance, but observation reduces ownership to a boolean inferred from the path and kind. Check and apply then repeat related filters in different code paths.
The immediate objective is only to change this ownership/check contract and its tests. Repository regeneration and reconciliation will happen afterward. The accepted opensrc/effect.md source-guide correction is already present as unrelated side-chat work and is not part of this plan.
Problem Statement
The CLI cannot distinguish these two cases reliably:
- a baseline-managed file was edited locally and must remain
local-editeddrift; - a named repository producer generated the current file bytes and owns their parity, so the older scaffold receipt must not report those bytes as baseline drift.
Broadly skipping files because they look generated would hide real drift in skills, hooks, lint specifications, source guides, and configuration. Broadening the existing issue #69 path exception would also erase its accepted existence-sensitive semantics.
The required rule is narrower:
explicit producer claim
+ observed bytes match that producer's current output evidence
= project-generated ownership for this observation
no valid claim, stale claim, or byte mismatch
= existing scaffold-managed check behaviorLocked Decisions
- Project-owned generated files require explicit producer and ownership evidence. Path, extension, file kind, Git tracking, or a “generated” comment is not evidence.
- Ordinary baseline-managed generated files remain checked. This includes hooks, lint assets/configuration, source guides, and exact baseline skill overlaps unless a separate current producer claim proves ownership.
- A producer claim is honored only when current desired state explicitly declares that producer for the path and independently derives the same canonical output fingerprint from the producer's version-controlled authority. A receipt claim alone cannot create ownership or silence drift.
- The managed receipt persists the ownership/provenance evidence needed for a later read-only
hi check, while desired state remains authority. Ownership must not depend on an untracked cache or rerunning a mutating generator. - Legacy receipt entries without ownership metadata decode as scaffold-managed. This is a backward-compatible extension, not an implicit migration.
- A present, valid project-generated output is omitted from
changedFilesandstaleFilesand is preserved by apply. No new non-failing public drift status is added. - A missing project-generated output remains
missingdrift. Check does not run its producer, and apply does not invent producer output. Regeneration remains the named producer's responsibility. - Whole-file project-generated ownership cannot suppress managed structured keys or dependency ownership for the same path.
- Existing issue #69 behavior remains a narrow compatibility adapter: a present customized wiki sync script is preserved and omitted; an absent script remains managed and is recreated.
- Check and apply consume one ownership decision. They may not maintain separate skip lists.
- No repository regeneration,
hi scaffold,hi update,sync:skills, baseline build/publish, CLI release, manifest reconciliation, or generated wiki synchronization is authorized by this plan. - The Effect guide change, its tests, and its documentation are pre-existing work and must be preserved without modification.
Design Considered Twice
Rejected: broaden path/kind exclusions
Extend isProjectAuthoredManagedFile with more skill, hook, lint, or source-guide paths. This is small, but it makes ownership implicit, cannot prove freshness, conflicts with accepted baseline ownership policies, and lets path placement silence real drift.
Rejected: treat every repo generator as authoritative
Infer ownership from a script name, package command, Git status, or generated header. This still lacks a durable byte-level relationship between producer and output, and it cannot support read-only checks in a fresh clone.
Selected: explicit, fingerprint-bound producer ownership
Add an explicit project-producer declaration to desired state and a backward-compatible ownership-evidence field to the managed-file receipt. Desired state derives the expected fingerprint read-only from a version-controlled producer authority; it does not trust the receipt or invoke the mutating producer. Compile one pure ownership decision from desired state, prior receipt, and observation. The receipt proves prior observation but cannot grant ownership. Both compare and apply consume the result. Existing path exceptions adapt into this decision temporarily instead of bypassing it.
This is the minimum design that preserves strict baseline checking while recognizing a repository producer's current output.
Contract Shape
The implementation may adjust exact Effect Schema syntax, but the public concepts are fixed:
type ProjectGeneratedOwnership = {
readonly producer: string;
readonly revision?: string;
readonly authority: {
readonly _tag: "RepositoryMirror";
readonly sourcePath: string;
};
readonly outputFingerprint: ManagedFileFingerprint;
};
type ManagedFileOwnership =
| { readonly _tag: "ScaffoldManaged" }
| {
readonly _tag: "ProjectGenerated";
readonly evidence: ProjectGeneratedOwnership;
};ScaffoldManagedis the default for legacy entries and ordinary desired output.ProjectGeneratedis explicit and fingerprint-bound. Desired state derives it from a version-controlled producer authority; the receipt records the evidence observed at the last successful write/reconciliation boundary.produceris a stable machine identifier, not a display label or shell command.revisionis optional provenance.outputFingerprintreuses the repository's canonical content, file-type, mode, and symlink-target identity; byte hash alone is insufficient.- The first supported authority is a contained, version-controlled repository mirror. Desired state observes
sourcePathread-only and derives the expected output fingerprint itself. Transformed or external generators remain scaffold-managed until a separately tested authority adapter exists. - Ownership metadata is receipt evidence, not desired-state authority. It cannot cause arbitrary paths to be created or deleted.
The pure classifier returns one of:
scaffold-managed
project-generated-current
project-generated-stale
project-generated-missingOnly project-generated-current suppresses whole-file changed/stale reporting and apply writes/deletions. It requires matching independently derived desired declaration, receipt evidence, and observed canonical fingerprint; receipt evidence by itself resolves as strict scaffold-managed drift.
Scope
In scope
- Shared and CLI managed-file schema/model changes.
- Backward-compatible receipt decoding and encoding.
- A pure ownership classifier at the scaffold-state boundary.
- Propagation through desired state, observation, comparison, stale detection, apply staging, and receipt writing.
- A narrow adapter retaining issue #69 behavior.
- Focused unit and
runUpdateintegration tests, including strict baseline controls. - Operator documentation for the ownership rule.
Out of scope
- Declaring or regenerating this checkout's final producer receipts.
- Reconciling the currently reported files or proving a clean repository check.
- Changing which skills, hooks, lint files, or source guides are emitted by the baseline.
- Updating the canonical shared skills repository or any generated skill mirror.
- The completed IP-318 or issue #69 delivery plans.
opensrc/effect.mdgeneration, content, tests, or release follow-through.- Baseline/CLI publishing and downstream consumer migration.
Codebase Findings
packages/scaffold/src/baseline/managed-file.ts,apps/cli/src/scaffold/models.ts, and the manifest schema inapps/cli/src/update/run.tscurrently expose only path, kind, and digest.apps/cli/src/features/scaffold-state/model.tsanddesired-output.tsalready carry desired-output source/revision provenance, but it does not express project ownership.apps/cli/src/features/scaffold-state/observe.tsandapps/cli/src/update/run.tscollapse observation to path/kind-drivenprojectAuthoredstate.apps/cli/src/update/run.tsindependently filters check comparison, stale detection, staged writes, and stale deletion. A single classifier must replace those ownership decisions.- Existing tests in
apps/cli/src/update/run.test-cases.test.tscover ordinary managed conflicts, project-authored prompts, local skills, manifest-only receipt updates, and issue #69's wiki sync script. - Issue #69 intentionally protects one existing project-authored script but treats the missing file as scaffold-managed. This remains a compatibility case, not the general producer contract.
- IP-318 requires desired state, observation, reconciliation, and application to remain separate; receipts are evidence rather than authority; whole-file ownership cannot overlap structured-key/dependency ownership.
- Current docs explicitly state that static skills, hooks, lint specifications, source guides, settings, and wiki scaffold structure are checked. That remains true unless an individual output has current explicit producer evidence.
Assumptions And Execution Safety
- The planning checkout is dirty with accepted update artifacts, untracked snapshots, and the Effect guide correction. Implementation must begin in a clean task worktree based on the commit that contains the Effect fix, or wait until those changes are committed and then branch from that commit.
- The Effect side-chat owner must first commit or otherwise provide an immutable integration commit for that accepted fix. This is an external prerequisite, not an action authorized by this plan. T0 stops if that commit does not exist.
- Workers are not alone in the codebase. They must preserve unrelated edits and never reset or overwrite the planning checkout.
- The routed plan is the sole artifact created now. Backlog sync is intentionally skipped because the user requested a direct plan and deferred repository reconciliation.
- No external dependency changes are required. Existing Effect Schema and
@effect/vitestconventions are sufficient. - Public behavior is tested through shared schema decoding and
runUpdateresults, not private helper snapshots.
Dependency Graph
T0 -> T1 -> T2 -> T3 -> T4 -> T5The graph is sequential because T1-T3 share the managed-file contract and central run.ts integration seam. Documentation can only state the final behavior after those tests pass. The parent coordinates workers, reviews each handoff, and runs final validation.
Tasks
T0: Establish a Clean Execution Baseline
- depends_on: []
- location: task-specific clean worktree for
/Users/stefan/Desktop/repos/harness-intelligence - description: Create or select a clean task worktree from a commit containing the accepted Effect guide fix. Record the base commit, branch, dirty-state proof, active agent settings, and specialist coverage. Confirm that no current update artifacts or pre-existing snapshots will be copied, reset, or reconciled. Run the narrow pre-change suites unchanged.
- validation: Clean worktree; Effect fix present; existing shared managed-file and CLI update tests pass before behavior edits; current planning checkout remains untouched.
- status: Complete
- owned_paths: []
- wave_boundary: Wave 0; parent-owned preflight. No implementation worker starts until this gate passes.
- log: 2026-08-06 — Created clean worktree
team/stefan/project-generated-ownershipat immutable preparation commitae933168, containing only the accepted Effect/plan paths overorigin/main. Excluded the dirty checkout's manifest, settings, and snapshot artifacts. Installed the frozen workspace and recorded passing shared/scaffold-state baselines plus the focused issue #69 update case. The four-shard aggregate was stopped after exceeding two minutes without output; the exact focused public case passed independently. - files edited/created: isolated worktree and
IMPLEMENTATION-NOTES.md; no production source edits - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
implement-spec,tdd,codebase-design] - tdd_status: not_applicable
- tdd_target: Trusted pre-change baseline and worktree isolation.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd packages/scaffold test && bun run --cwd apps/cli test src/features/scaffold-state src/update/run.test-cases.test.ts - reason_not_testable: Read-only execution preflight.
- red_evidence:
- green_evidence:
packages/scaffold51/51; scaffold-state 49/49; focusedignores project-owned wiki sync scripts during update checks and writes1/1 (91 skipped). - codebase_design_notes: Do not build the implementation on top of uncommitted generated reconciliation state.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T1: Add the Backward-Compatible Ownership Contract
- depends_on: [T0]
- location:
packages/scaffold/src/baseline/managed-file.ts,packages/scaffold/src/public-scaffold-contract.test.ts,apps/cli/src/scaffold/models.ts,apps/cli/src/features/scaffold-state/model.ts,apps/cli/src/features/scaffold-state/reconcile.ts,apps/cli/src/features/scaffold-state/reconcile.test.ts, and the managed-file schema declarations inapps/cli/src/update/run.ts - description: First add a failing public schema test proving that a legacy
{kind,path,sha256}receipt decodes as scaffold-managed and that explicit project-generated desired/receipt entries round-trip producer, optional revision, and canonical output fingerprint. Then add the minimum shared/CLI model and schema changes. Reuse full file identity, including content, type, mode, and symlink target. Reject unknown ownership tags and malformed fingerprints. Keep desired declaration distinct from receipt evidence. Do not add path inference, persistence, or producer-specific behavior in this slice. - validation: Legacy fixtures remain valid; explicit ownership round-trips; malformed claims fail decoding; type checks pass.
- status: Complete
- owned_paths: [
packages/scaffold/src/baseline/managed-file.ts,packages/scaffold/src/public-scaffold-contract.test.ts,apps/cli/src/scaffold/models.ts,apps/cli/src/features/scaffold-state/model.ts,apps/cli/src/features/scaffold-state/reconcile.ts,apps/cli/src/features/scaffold-state/reconcile.test.ts,apps/cli/src/update/run.ts] - wave_boundary: Wave 1; one contract worker. T2 waits for shared and internal schema GREEN.
- log: 2026-08-06 — RED proved legacy receipts lacked a safe ownership default and reconciliation dropped explicit desired ownership. GREEN added one shared tagged ownership/fingerprint contract, backward-compatible decode/encode, desired/receipt separation, and typed receipt decoding. Scope expanded only to the baseline public export root and its exact export-contract test.
- files edited/created:
packages/scaffold/src/baseline/managed-file.ts,packages/scaffold/src/baseline.ts,packages/scaffold/src/public-scaffold-contract.test.ts,packages/scaffold/src/public-domain-root-contract.test.ts,apps/cli/src/scaffold/models.ts,apps/cli/src/features/scaffold-state/model.ts,apps/cli/src/features/scaffold-state/reconcile.ts,apps/cli/src/features/scaffold-state/reconcile.test.ts, managed-file schema/decoding inapps/cli/src/update/run.ts - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: Legacy managed entries default safely while explicit fingerprint-bound desired declaration and receipt evidence survive public decoding/encoding without conflating authority and evidence.
- red_command:
bun run --cwd packages/scaffold test -- -t "managed file ownership" - expected_red_failure: The shared schema has no ownership field/default and cannot round-trip a project-generated claim.
- green_command:
bun run --cwd packages/scaffold test && bun run --cwd packages/scaffold check-types && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Public contract decoded legacy
ownershipasundefinedinstead ofScaffoldManaged; reconcile omitted desired project-generated evidence from the receipt. - green_evidence: Parent revalidation: scaffold 52/52 and typecheck pass; reconcile 29/29 and CLI typecheck pass;
git diff --checkpass. - codebase_design_notes: Keep one shared ownership type. Do not duplicate structurally similar unions in update logic.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T2: Centralize Ownership Resolution
- depends_on: [T1]
- location:
apps/cli/src/features/scaffold-state/project-producer.ts,project-producer.test.ts,ownership.ts,ownership.test.ts,model.ts,desired-output.ts, andobserve.ts - description: First add a failing authority test using a temporary contained source file and output declaration. Implement a read-only
RepositoryMirroradapter that derives the canonical expected fingerprint from the source path; tests may not inject a precomputed “authoritative” fingerprint. Reject escaping/missing source paths and unsupported producer kinds. Then add one failing test at a time for the four classifier outcomes. Implement a pure resolver that combines the derived desired producer declaration, prior receipt evidence, and observation. It recognizes project ownership only when producer identity/revision agree, the file exists, and the complete observed fingerprint equals the independently derived expected fingerprint. Add byte, executable-mode, file-type, and symlink-target mismatch tests. A receipt-only claim, unknown producer, missing output, or mismatched evidence falls back to strict drift semantics. Encode the structured-key/dependency exclusion at this boundary. Existing compatibility categories remain unchanged until T3 routes them through this result. - validation: Focused tests prove contained read-only authority derivation, path-escape/missing/unsupported rejection, current, stale, missing, legacy, receipt-only, unknown-producer, content/mode/type/symlink mismatch, and semantic-path behavior without invoking a mutating producer.
- status: Complete
- owned_paths: [
apps/cli/src/features/scaffold-state/project-producer.ts,apps/cli/src/features/scaffold-state/project-producer.test.ts,apps/cli/src/features/scaffold-state/ownership.ts,apps/cli/src/features/scaffold-state/ownership.test.ts,apps/cli/src/features/scaffold-state/model.ts,apps/cli/src/features/scaffold-state/desired-output.ts,apps/cli/src/features/scaffold-state/observe.ts] - wave_boundary: Wave 2; one classifier worker after T1. T3 waits for all compatibility and fingerprint cases to be GREEN.
- log: 2026-08-06 — Implemented two deep seams: a read-only contained
RepositoryMirrorfingerprint adapter and a pure ownership resolver with a minimal typed observation union. The first worker completed the producer tracer then stalled; a replacement worker preserved that slice, finished the classifier RED/GREEN cycles, and removed coupling to the broad observed-file model. Actualrun.tsobservation adaptation remains correctly owned by T3. - files edited/created:
apps/cli/src/features/scaffold-state/project-producer.ts,project-producer.test.ts,ownership.ts,ownership.test.ts - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: A present repository mirror with an independently derived, fingerprint-bound producer claim resolves
project-generated-current; every unproven case remains strict. - red_command:
bun run --cwd apps/cli test src/features/scaffold-state -- -t "resolves managed file ownership" - expected_red_failure: No central resolver exists and observation cannot distinguish current from stale producer evidence.
- green_command:
bun run --cwd apps/cli test src/features/scaffold-state - reason_not_testable:
- red_evidence: Producer tracer initially failed because the module did not exist. Classifier cycles failed for the missing module, scaffold desired classification, missing output, stale fallback, unsupported authority, and missing nested source normalization before their owning implementation.
- green_evidence: Parent revalidation: producer 10/10 and ownership 19/19; full scaffold-state 79/79; CLI typecheck; scoped Oxlint/Oxfmt;
git diff --check. - codebase_design_notes: The filesystem adapter derives one canonical ownership value from a contained source. The pure classifier accepts only
Missing | Unsupported | Present{fingerprint}and returns policy data; it has no filesystem,ObservedManagedFile, Effect-service, or CLI-presentation coupling. T3 adapts the existing observation model into this seam. - review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T3: Make Check, Apply, and Receipt Writing Consume One Decision
- depends_on: [T2]
- location:
apps/cli/src/update/run.ts,apps/cli/src/update/run.test-cases.test.ts - description: Add vertical
runUpdatetests before each behavior change. Prove that a present/current project-generated repository mirror is absent from changed/stale results, produces a clean check when no other drift exists, is preserved by apply, and persists the ownership evidence defined by T1. Prove that a tampered/unknown producer claim, stale evidence, content/mode/type/symlink divergence, and missing output remain drift. Add ordinary baseline-managed controls for an exact-overlap skill, hook, lint specification, lint selection, workspaceoxlint.config.ts, source guide underopensrc/, and configuration; each must still reportlocal-edited. Prove semantic structured ownership is unaffected. Route every current exception through the classifier: wiki metadata, tailored sync scripts, agent prompts, handoffs, manifests, prompt specs, subagents, Harness mirrors, and issue #69's existence-sensitive wiki sync script. Preserve each behavior without broadening its paths. Refactor check comparison, stale filtering, staged writes, stale deletion, and receipt persistence to consume this one decision, then remove only the ownership branches made redundant by the change. - validation: All focused ownership cases pass; the existing project-authored, issue #69, local-skill, receipt-only, and managed-conflict tests remain green; check remains read-only.
- status: Complete
- owned_paths: [
apps/cli/src/update/run.ts,apps/cli/src/update/run.test-cases.test.ts] - wave_boundary: Wave 3; one integration worker after T2. Documentation waits for public behavior GREEN.
- log: 2026-08-06 — Completed the vertical integration through one path-indexed ownership decision. Production derives desired ownership from the declared repository authority; comparison, reconciliation, staging, stale deletion, compatibility lanes, and receipt persistence consume that decision. Normal files, handoff/system prompts, and typed Claude copies adopt ownership only through the normal applicator's post-write full-fingerprint proof. Explicit current ownership survives orphan cleanup. Missing output remains planned drift: matching, mismatched, and absent historical receipts do not create output, mutate repository state, or report
applied: true; mismatched evidence remains strict. The adjacent inventory correction records the already-emitted rootoxlint.config.ts. The Effect guide fixture hash remains support for the accepted pre-existing Effect fix only. - files edited/created:
apps/cli/src/update/run.ts,apps/cli/src/update/run.test-cases.test.ts,apps/cli/src/update/run.shards.test.ts,apps/cli/src/scaffold/output.ts,apps/cli/src/scaffold/output.test.ts - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target:
runUpdatesuppresses drift and writes only for currently proven project output while retaining strict baseline controls. - red_command:
bun run --cwd apps/cli test src/update/run.test-cases.test.ts -- -t "honors current project-generated ownership" - expected_red_failure: The current hash comparison reports the project-produced bytes as
local-edited, and check/apply do not share one ownership decision. - green_command:
bun run --cwd apps/cli test src/update/run.test-cases.test.ts - reason_not_testable:
- red_evidence: The initial current-output case reported the producer-owned skill as changed. Subsequent vertical cycles caught compatibility-current agent mirrors reintroduced by staging, issue #69 clean-check failure, controller-manifest overwrite, explicit
ScaffoldManagedmigration, unconditional legacy prompt rewriting, weak false-positive tests, missing shard inventory, semantic overlap, and an unreceipted emitted Oxlint config. - green_evidence: Final focused and aggregate evidence: the release-style CLI run passed all four update shards, 96/96, and the remaining 82 files, 1098/1098, for 86 files and 1194 tests total. Strengthened runtime cases prove a real unrelated applied write retains orphaned explicit
ProjectGeneratedownership and yields a clean follow-up check; a settled missing-only write leaves the repository fingerprint unchanged and reportsapplied: false. CLI typecheck, lint/format, andgit diff --check ae933168pass. Independent final Spec and Standards reviews rejected or cleared the remaining static findings and reported no P1/P2 findings. - codebase_design_notes: Receipt evidence cannot create desired files. Compile one immutable ownership decision per path, including compatibility inputs, before comparison or apply consumes it. Keep prompt/Claude persistence explicit, missing apply reporting truthful, and decoded ownership normalized through the shared type.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4: Document the Exact Ownership Boundary
- depends_on: [T3]
- location:
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md - description: Document that repository-generated output is ignored only with explicit current producer evidence; list stale, mismatched, missing, legacy, and ordinary baseline behavior; state that
hi checknever runs producers. Integrate surgically with the already accepted Effect-guide edits in these dirty paths. Do not run the wiki sync or regenerate any repository files. - validation: Documentation matches tested behavior and retains the Effect guide section unchanged; markdown/format checks pass; no other generated file changes.
- status: Complete
- owned_paths: [
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md] - wave_boundary: Wave 4; one documentation worker after T3. Must start from the immutable Effect integration commit and preserve that text.
- log: 2026-08-06 — Added a concise linked summary and identical detailed runbook sections describing the exact tested
RepositoryMirrorboundary, current-only suppression, strict negative cases, semantic ownership, and issue #69. The three diffs are insertion-only and preserve the accepted Effect and publisher text. Targeted formatting and mirror checks pass.apps/wiki check:contentstill requests the accepted plan folder's generatedmeta.jsonrouting; that regeneration is explicitly deferred and was not run. - files edited/created: CLI docs, runbook, routed wiki runbook
- backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,create-spec,create-plan,docs-onboarding,implement-spec,improve-codebase-architecture,parallel-research,simplify,tdd,writing-beats,writing-for-agents,writing-fragments,writing-shape] - tdd_status: not_applicable
- tdd_target: Operator contract documentation.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli check && bun run --cwd apps/wiki check:content && bun run --cwd apps/wiki check && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md - reason_not_testable: Documentation-only slice after behavior is proven.
- red_evidence: Existing operator docs described static managed drift and compatibility skips but had no explicit producer-evidence boundary.
- green_evidence: Oxfmt passed all three docs; detailed runbook bodies are byte-identical; insertion-only numstat is 1/0, 10/0, 10/0; diff check passes. Wiki content check reports only the deferred specs/cli metadata regeneration.
- codebase_design_notes: Describe the producer-evidence rule once and link to it; do not add a second policy source.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T5: Validate and Review Without Repository Reconciliation
- depends_on: [T4]
- location: all T1-T4 owned paths
- description: Run focused suites first, then CLI/shared type, lint, and format checks. Run the broader CLI suite only after focused GREEN. Inspect the diff for duplicate ownership policy, accidental path exemptions, manifest migration, Effect-guide changes, generated artifacts, or reconciliation output. Use a plan/review specialist for a final read-only contract review. Do not use the current checkout's
hi checkresult as acceptance because producer receipts and repository regeneration are explicitly deferred. - validation: Focused and broad tests pass; review finds no blanket generated-file exemption; only planned logic/tests/docs changed; regeneration remains a separately authorized follow-up.
- status: Complete
- owned_paths: []
- wave_boundary: Wave 5; parent-owned aggregate gate after T4. Review findings reopen the owning wave.
- log: 2026-08-06 — Completed aggregate validation and final read-only review at fixed point
ae933168, including untracked implementation files. The release-style CLI split passed 96/96 shard tests plus 1098/1098 tests across the remaining 82 files. Shared scaffold tests, both typechecks, CLI/scaffold/wiki lint and format checks, and diff check passed. Structured autoreview's final static findings were rejected by stronger runtime witnesses: an actual unrelated applied write retained orphaned explicit ownership and produced a clean follow-up check, while a settled missing-only write kept the repository fingerprint unchanged andapplied: false. Independent final Spec and Standards reviewers retracted or cleared those findings and reported no P1/P2 findings. A final evidence-aware structured autoreview rerun remained active for more than ten minutes without returning and was interrupted; this is residual tool unavailability, not a remaining code finding. Repository producer declaration/regeneration/reconciliation and wiki routing metadata remain deferred. - files edited/created: none unless review findings require an owning task to be reopened
- backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
review-phase,autoreview,simplify] - tdd_status: not_applicable
- tdd_target: Aggregate verification of completed vertical slices.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd packages/scaffold test && bun run --cwd packages/scaffold check-types && bun run --cwd packages/scaffold check && bun run --cwd apps/cli test && bun run --cwd apps/cli check-types && bun run --cwd apps/cli check && git diff --check - reason_not_testable: Aggregate validation only; RED/GREEN belongs to T1-T3.
- red_evidence:
- green_evidence:
apps/cli: four update shards 96/96 plus remaining 82 files 1098/1098, totaling 86 files and 1194 tests.packages/scaffold: 5 files and 52/52 tests. CLI and scaffold typechecks passed. CLI, scaffold, and wiki lint/format checks passed.git diff --check ae933168passed. Final Spec and Standards reviews reported no P1/P2 findings. The final evidence-aware structured autoreview rerun was interrupted after more than ten minutes without a result; this residual tool unavailability does not reopen a code finding. Wikicheck:contentreports only the explicitly deferred update toapps/wiki/content/docs/project/specs/cli/meta.jsonand creation ofapps/wiki/content/docs/project/specs/cli/project-generated-managed-file-ownership/meta.json. - codebase_design_notes: If review finds a second ownership policy seam, reopen its owning task instead of patching during review.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
Acceptance Criteria
- AC-01: Legacy managed-file receipts remain valid and default to scaffold-managed behavior.
- AC-02: Current desired state independently derives the producer's canonical expected fingerprint; the receipt records evidence but cannot grant ownership by itself.
- AC-03: A present file whose desired declaration, receipt evidence, and complete observed fingerprint agree is absent from changed/stale results and is preserved by apply.
- AC-04: Unknown, receipt-only, stale, malformed, missing, content-mismatched, mode-mismatched, type-mismatched, or symlink-mismatched producer evidence does not silence drift.
- AC-05: Ordinary baseline-managed skill, hook, lint, source-guide, and configuration outputs retain existing strict check behavior.
- AC-06: Whole-file ownership does not suppress structured-key or dependency reconciliation.
- AC-07: Issue #69's existing-path behavior remains unchanged and is not generalized by path.
- AC-08: Check, stale detection, apply staging, and stale deletion consume one ownership classifier.
- AC-09:
hi checkremains read-only and never invokes a repository producer. - AC-10: The Effect guide fix and unrelated dirty checkout artifacts are unchanged.
- AC-11: No repository regeneration/reconciliation, skill sync, baseline build/publish, CLI release, or manifest migration occurs during this implementation.
- AC-12: Shared and CLI focused/broad validation passes, and documentation states the same boundary proven by tests.
Deferred Follow-Up
After this plan is implemented and reviewed, create a separate authorized task to:
- declare the actual Harness repository producer claims;
- run the named generators;
- reconcile the managed receipt;
- rerun
hi check --json; - classify any remaining drift, which should still include ordinary baseline-managed divergence.
That follow-up must decide and prove the exact producer-to-output mappings. It must not be folded into this logic change.
Open Questions
None. The two scope decisions were confirmed by the user on 2026-08-06. Implementation details may vary only within the locked digest-bound ownership contract and exclusions above.