Registry Baseline
Architecture: Registry Baseline
Context and Scope
- Capability identity:
apps/wiki/content/docs/project/specs/cli/registry-baseline. The capability is registry-based Baseline distribution for thehiCLI: publish, install, update, diff, check, and migration from the manifest-driven flow, including the issue #232 fix in the same release. - Actors and outcome: the coding agent and the human operator need the harness content in a repository to be current, to know when it is not, and to update it without manual repair. The release publisher needs one publish step. Today 47 issues trace to persisted derived state, a temporary update candidate, and generator overwrites (S4, research report, "Facts").
- In scope: Q1 to Q35 and Glossary Q32a in the grill log (S2). Non-goals:
hi report, the backoffice, implementation order, task breakdown, backlog projection (S1, "Scope and authority"). - Spec: sibling path
apps/wiki/content/docs/project/specs/cli/registry-baseline/SPEC.md, retained in the commit that follows this architecture's retention.
Canonical Terms
Exact terms from the Registry Baseline Glossary (S3). Registry, Registry Item, Baseline, Installed Record, Recorded Shape, Copied Artifact, Built Artifact, Authored Artifact, Project Skill, Harness Adapter, Drift Check. Kept from earlier glossaries: Pack, Software Scope, Commit Gate, Project settings, Managed Artifact.
Axioms used below: no content hash of a Managed Artifact is stored in the repository; each local state file has one writer; a Baseline is immutable; the Registry is the only and public Baseline source; a Project Skill is never removed or overwritten, only renamed on id collision; a Pack is the only selection unit.
Sources
| Source | Role | Exact location and anchor | Immutable revision or content hash |
|---|---|---|---|
| S1 | Grill status and closure | apps/wiki/content/docs/project/grilling/registry-baseline-grill-status.md; "Current Round", "Branch Dashboard", "Glossary" | git blob e382072e3876 |
| S2 | Durable grill log | apps/wiki/content/docs/project/grilling/registry-baseline-grill-log.md; entries ### Q1 to ### Q35, ### Glossary Q32a | git blob a3cd56697331 |
| S3 | Current glossary | apps/wiki/content/docs/project/domains/registry-baseline-glossary.mdx | git blob bf8e589f71db |
| S4 | Research evidence | apps/wiki/content/docs/project/research/scaffold-update-registry-architecture-research-report.md; "Facts", "Full harness inventory" | git blob 95b7027ba849 |
| S5 | Brainstorm evidence | apps/wiki/content/docs/project/research/registry-baseline-brainstorm-report.md; "3. Flow failure lenses", "5. Decisions recorded" | git blob 343fc543a8b9 |
| S6 | Current code behavior | Paths cited per row below, at working tree of main 4972b5d6 plus uncommitted lint changes not touched here | commit 4972b5d6 (observed behavior) |
Git blob ids are abbreviated to 12 characters and were computed with
git hash-object on 2026-09-27. Full ids resolve in this repository.
Source Disposition
| Question / entry | Disposition | Accepted detail, replacement, or unresolved point | Evidence | Parked owner / resume trigger |
|---|---|---|---|---|
| Q1 to Q10, Q12 to Q35 | accepted | As recorded in S2; details in "Accepted Detail Coverage" | S2 | |
| Q11 | superseded | "Registry requires credentials" replaced by Q19 "none; the registry stays public" | S2 ### Q19 | |
| Glossary Q32a | accepted | Project Skill term and axiom, amended by Q34 | S2, S3 | |
| Q29 selectable harness set | parked | Fixed set of four harnesses; selectable set outside scope | S1 "Parked Branches" | Owner: user. Trigger: a repository that must exclude one harness |
| Q35 single item selection | parked | Packs are the only selection unit | S1 "Parked Branches" | Owner: user. Trigger: a real request for one skill no Pack contains |
| Brainstorm K1 to K15 | accepted or rejected per S5 "5. Decisions recorded"; each surviving detail is covered by a Q above | S5 | ||
| Concurrent updates in one worktree | unknown, non-material | Not observed in the issue history | S5 lens 5 |
Whole System
Context. Today the CLI is the authority for both "what should exist" and "what does exist", and it proves the second with 654 recorded hashes (S4). In the accepted design the Registry owns "what should exist" at every version, the repository owns intent and authored files, and the installer derives everything else on demand. Nothing derived is persisted except the Installed Record.
Anchors: Q1, Q8, Q10, Q19 (Registry, hosting, public); Q20 (two files); Q2, Q9 (Built Artifacts and Recorded Shape); Q31, Q34 (Project Skills); Q6, Q21 (hooks); Q18 (cache). Conclusion: one public source, two local files with one writer each, three artifact kinds with three rules. The installer is the only writer of anything derived. Accepted design; not yet implemented.
| Block selector / component / level | Owner | State and authority | Interface / dependency | Supported constraint and source |
|---|---|---|---|---|
| ARC-001 Registry | Release publisher | Authoritative for every Baseline; immutable per version; mutable latest pointer | Static JSON over HTTPS, shadcn registry-item schema plus meta extensions; hosted with the HI API on Vercel | Q1, Q8, Q14, Q15, Q17, Q18, Q19; S4 "What shadcn's model is" |
| ARC-002 Publisher | .github/workflows/release.yml, apps/cli/scripts | Builds the Registry from apps/cli/skills and apps/cli/src/data | BASELINE_CHANGELOG.md selects the product; skills repo stays source of truth | Q16; repo guidance on release classification |
ARC-003 Project settings .devpunks/settings.json | Human (agent on request) | Intent: registries, selected Packs, Software Scopes, providers, required tools | Read by ARC-005, managed lint runtime, backlog skills | Q20, Q22; S4 "Who actually reads that state" |
ARC-004 Installed Record .devpunks/installed.json | Installer only | Installed Baseline version, Recorded Shape, item-to-path map, failed links | Read by ARC-005, edit hook, stale detection | Q2, Q20, Q21, Q27 |
ARC-005 Installer (hi) | apps/cli | Owns the resolve-plan-apply pipeline and all derived writes | Commands init, update, diff, check; own installer, shadcn-compatible JSON | Q4, Q23, Q24, Q25, Q26, Q30 |
| ARC-006 Harness Adapters | apps/cli | Wrap one built subagent body per harness envelope; fixed set of four | Input .agents/subagents/manifest.mjs; outputs `.claude | .codex |
| ARC-007 Managed Artifact kinds | Registry / installer / repository | Copied: registry authoritative. Built: derived. Authored: repository authoritative | Rules per kind in FLOW-002 | Q9, Q24, Q31, Q34; S3 relationships |
| ARC-008 Drift Check | apps/cli | Derived, never stored | Three-way compare: local, installed Baseline, latest Baseline | Q2, Q6, Q25; classes in S3 |
| ARC-009 Hooks | Registry items | Session start: version check only. Edit hook: protected paths from ARC-004 | hi check --json structured status; missing record never blocks | Q6, Q21; S5 K2 |
| ARC-010 Managed lint runtime and Commit Gate | Registry items | Lint routes per Software Scope; anti-slop per package | Runner streams oxlint JSON to a file; file lists via stdin; explicit git diff buffer | Q5, Q7, Q28; S4 "Issue #232 mechanics" |
| ARC-011 Item cache | Installer | Disposable; verified by catalog sha256 | ~/.cache; enables offline hi diff at the installed version | Q18 |
| ARC-012 Migration branch | Installer | One-run transition inside the first registry-based hi update | Keyed on old manifest present and Installed Record absent | Q33 |
Retired: control-plane baseline API group, promotion store, bundled channel, Scaffold Manifest, projection receipt, context plan, Validation Candidate, sync-subagents.mjs, harness-projection scripts, replaced-* and pre-existing-skills archives | Q1, Q3, Q10, Q15, Q31, Q32; S6 packages/contract/src/baseline.ts:289-303, apps/cli/src/update/run.ts:6023-6396 |
Critical Flows and Boundaries
FLOW-001 Publish a Baseline
Context. Today a tarball is built, uploaded as a GitHub release artifact, then
promoted through the control plane (S6 apps/cli/scripts/publish-baseline.mjs,
packages/contract/src/baseline.ts:303). Accepted: one build, one upload, one
pointer move.
FLOW-001-STEP-001 sync skills repo main into apps/cli/skills (existing, Q16)
FLOW-001-STEP-002 release workflow classifies product by changed changelog paths;
BASELINE_CHANGELOG.md selects the Registry (Q16)
FLOW-001-STEP-003 build registry.json and /<YYYY.MM.DD-sha>/<item>.json (Q14)
each item: files with ~/ targets, meta.symlinks, meta.merge,
meta.workspaceDependencies, templates with inputs; per-item
sha256 and CLI compatibility range in the catalog (Q4, Q17, Q18)
FLOW-001-STEP-004 upload to the Vercel deployment with the HI API; move `latest`
to the new version (Q8, Q15)Anchors: Q8, Q14 to Q18. Conclusion: a version is immutable once uploaded; the
only mutable state is the latest pointer. No promotion step exists, so the
authority failures of issues 49, 91, and 94 have no place to occur (S4).
FLOW-002 Update, including init
Context. Today hi update stages a full temporary copy of the repository,
installs dependencies, runs a lint preview, then applies with a pending
publication marker (S6 apps/cli/src/update/run.ts:6023-6456). Six of the 47
issues come from that candidate (S4). Accepted: plan, validate, apply in a
fixed order, record last, no marker.
Anchors: Q22 (STEP-002), Q23 (order, STEP-004, STEP-012), Q24 (STEP-005), Q2 and Q9 (STEP-006), Q31 and Q34 (STEP-007), Q27 (STEP-009), Q13 and Q26 (STEP-010), Q17 (STEP-001), Q5 (STEP-013). Conclusion: every step before STEP-012 is idempotent by content compare, so a crash at any point is repaired by running again. The Installed Record is the only proof of completion and it is written after every other effect (S5 lens 4, lens 7).
hi init is FLOW-002 with two extra steps before STEP-001: detect the
repository once to propose Packs and Software Scopes, and write Project
settings from the confirmed selection (Q22, Q30). init needs network access
and no credential (Q10, Q19).
Non-interactive rule: with --yes, STEP-005 overwrites a Copied Artifact that
has both a local edit and an upstream change, and reports the path; git keeps
the local version (Q24). Authored Artifacts are never overwritten (Q9, Q31).
FLOW-003 Diff and check
Context. Today hi check is the update pipeline in check mode, forces a stable
refetch, and hashes 654 files on every session start (S6
apps/cli/src/features/repository-check/application.ts:592-597). Accepted:
version compare for check, three-way compare for diff.
FLOW-003-STEP-001 fetch registry.json (Q6)
FLOW-003-STEP-002 compare installed version with latest
hi check stops here: status current | update-available | unavailable
offline: status unavailable plus the cached installed version (Q6, S5 K2)
FLOW-003-STEP-003 hi diff: fetch installed and latest items, cache by sha256 (Q18)
FLOW-003-STEP-004 per managed path, classify:
Copied local vs installed vs latest bytes, normalized line
endings and trailing whitespace (Q25)
Built re-render at installed version with Recorded Shape;
re-render with current shape -> shape-drift (Q2)
Authored never byte-compared; report template changed since
authoring (Q9)
link missing symlink -> link-failed (Q27)
classes: update-available, local-edit, conflict, shape-drift,
missing, stale, link-failed (S3)
FLOW-003-STEP-005 report one row per path; hi diff writes nothingAnchors: Q2, Q6, Q18, Q25, Q27. Conclusion: because both the installed and the latest bytes come from the Registry, no hash is needed in the repository, and the four drift-fix waves in the issue history (S4) have no recurrence path.
FLOW-004 Agent session and edits
session start hook runs hi check --json -> reads status field only
current: one line; update-available: suggest hi update;
unavailable: say so with the cached installed version (Q6, S5 K2)
file edit hook reads managed paths from the Installed Record;
protected paths are not formatted;
record missing -> nothing is managed, never block (Q21)
manifest edit .agents/subagents/manifest.mjs changed -> no hook action;
hi diff reports harness agents stale; hi update re-renders (Q12)Anchors: Q6, Q12, Q21. Conclusion: the session hook never claims "no drift" after a failed fetch, and a fresh worktree never blocks edits (issue 231).
FLOW-005 Migration of a manifest-based repository
trigger hi update finds .devpunks/scaffold-manifest.json and no installed.json (Q33)
STEP-001 read old settings.json: Packs, Software Scopes, providers, required tools
STEP-002 detect once -> Recorded Shape
STEP-003 move skills from .devpunks/pre-existing-skills into .agents/skills as
Project Skills; apply Q34 on id collision
STEP-004 delete scaffold-manifest.json, harness-projection-receipt.json,
context-plan.json, specs/lint/assets.json, replaced-scaffold,
replaced-skills, emptied pre-existing-skills
STEP-005 keep every Authored Artifact in place
STEP-006 continue as FLOW-002 from STEP-001; report each deletionAnchors: Q31, Q33, Q34. Conclusion: migration is one branch of update, not a
command, and it converges on re-run like the rest of FLOW-002.
Accepted Detail Coverage
| Question + anchor | Exact accepted choice and supplied detail | Provided rationale / alternatives | Architecture selector + visual | System constraint served |
|---|---|---|---|---|
Q1 (S2 ### Q1) | Registry in shadcn format is the only Baseline distributor and drift source; GitHub release artifacts and promotion stop | Nine authority issues (S4) | ARC-001; system map | One source of truth |
Q2 (S2 ### Q2) | Installer records install-time repository shape (workspace paths, Pack ids, technologies) | Separate local edit from shape change | ARC-004; FLOW-003-STEP-004 | Drift without stored hashes |
Q3 (S2 ### Q3) | CLI builds each subagent body once and wraps per harness; sync-subagents.mjs and harness-projection/* removed | Body byte-identical across four outputs; second writer (#105) | ARC-006; FLOW-002-STEP-006 | One writer |
Q4 (S2 ### Q4) | Own small installer; item JSON byte-compatible with shadcn; extensions under meta | shadcn prompts ignore --yes, no merges or symlinks | ARC-005, ARC-001; FLOW-001-STEP-003 | Fallback compatibility |
Q5 (S2 ### Q5) | Issue #232 fixed inside the registry release | Runner and gate are registry items | ARC-010; FLOW-002-STEP-013 | Large Software Scopes lint and commit |
Q6 (S2 ### Q6) | Session-start hook stays; Baseline version check only | Dead drift-detected branch; network-bound check | ARC-009; FLOW-003-STEP-002, FLOW-004 | Fast, honest session start |
Q7 (S2 ### Q7) | Anti-slop stays default for TypeScript Software Scopes; files scoped per app and package | Like per-package lint rules | ARC-010, ARC-007 | Lint policy per Software Scope |
Q8 (S2 ### Q8) | Registry hosted with the existing HI API on Vercel; exact mount is delivery detail | "Whatever is easiest" | ARC-001; FLOW-001-STEP-004 | Single deployment |
Q9 (S2 ### Q9) | Prompt specs, AGENT-HANDOFF.md, AGENT-SYSTEM-PROMPT.md stay tracked Built Artifacts | Tied to the Baseline | ARC-007; FLOW-002-STEP-006 | Baseline coverage of handoff |
Q10 (S2 ### Q10) | Bundled fallback dropped | Issue 43; one fewer source | Retired row; FLOW-002 init note | One source of truth |
Q11 (S2 ### Q11) | superseded by Q19 | |||
Q12 (S2 ### Q12) | Per-harness subagent files rebuilt only by hi update and hi diff | No build inside the edit hook | ARC-006; FLOW-004 | One writer, predictable cost |
Q13 (S2 ### Q13) | hi update removes devDependencies no lint asset requires | Risk accepted; guard in Q26 | FLOW-002-STEP-010 | No dead dependencies |
Q14 (S2 ### Q14) | Version format YYYY.MM.DD-<short sha> | Existing format | ARC-001; FLOW-001-STEP-003 | Stable identity |
Q15 (S2 ### Q15) | One latest pointer, no promotion step; promote endpoint and store retired | Issues 49, 91, 94 | ARC-001; FLOW-001-STEP-004 | No server-side authority state |
Q16 (S2 ### Q16) | Existing release workflow builds and publishes; BASELINE_CHANGELOG.md selects; skills repo remains source of truth | Unchanged release classification | ARC-002; FLOW-001-STEP-001 to 002 | Release rules preserved |
Q17 (S2 ### Q17) | Registry version declares a CLI range; CLI refuses outside it and says upgrade | Today's behavior | ARC-001; FLOW-002-STEP-001 | Format compatibility |
Q18 (S2 ### Q18) | Catalog carries per-item sha256, used only for cache integrity | Never for repository drift | ARC-011; FLOW-003-STEP-003 | Trustworthy offline compare |
Q19 (S2 ### Q19) | No credentials; registry public; no hi login, headers, or token storage. Supersedes Q11 | No CLI login exists in code | ARC-001; system map | No new mechanism |
Q20 (S2 ### Q20) | settings.json intent, human writer; installed.json installer writer with version, Recorded Shape, item-to-path map | One-writer axiom; edit hook needs paths | ARC-003, ARC-004 | One writer per file |
Q21 (S2 ### Q21) | Missing Installed Record: hook does not block; hi check reports "not installed" | Issue 231 | ARC-009; FLOW-004 | Fresh worktrees work |
Q22 (S2 ### Q22) | Selected Packs explicit in settings; detection at init and on request proposes only; unselected detected Pack is information | Issues 50, 62 | ARC-003; FLOW-002-STEP-002 | No pack drift class |
Q23 (S2 ### Q23) | Order: plan, validate merge targets, files, merges, symlinks, dependencies, Installed Record last; no pending marker | Marker produced publication-stale | FLOW-002-STEP-003 to 012 | Re-run converges |
Q24 (S2 ### Q24) | --yes overwrites a conflicting Copied Artifact and reports; Authored never overwritten | Git keeps local version | FLOW-002-STEP-005, STEP-007 | Baseline authority for Copied |
Q25 (S2 ### Q25) | Compare after normalizing line endings and trailing whitespace only | Issue 65 becomes visible, harmless | ARC-008; FLOW-003-STEP-004 | No formatter coupling |
Q26 (S2 ### Q26) | Remove stale devDependency only if no first-party source in that workspace imports it; else report and keep | Direct use by the project | FLOW-002-STEP-010 | Safe removal |
Q27 (S2 ### Q27) | No copy fallback; report failed symlink and target; Drift Check link-failed; retried each update | Issue 58 | FLOW-002-STEP-009; FLOW-003-STEP-004 | Visible, repairable state |
Q28 (S2 ### Q28) | Commit Gate keeps full-owner expansion on config change; file list via stdin | Config change must prove the whole scope | ARC-010 | E2BIG fix without weaker gate |
Q29 (S2 ### Q29) | Harness set fixed: Claude, Codex, Cursor, OpenCode; selectable set parked | Today's behavior | ARC-006 | Predictable outputs |
Q30 (S2 ### Q30) | Commands: init, update, diff, check; scaffold retired into init; no add | User rejected add | ARC-005 | Small surface |
Q31 (S2 ### Q31) | replaced-scaffold, replaced-skills retired; pre-existing skills moved into .agents/skills as Project Skills; archive dropped | Archive existed only for removed skills | ARC-007, ARC-012; FLOW-005-STEP-003 | Project Skills preserved in place |
Q32 (S2 ### Q32) | Terms added, kept, retired as listed in S3 | Canonical Terms | Shared language | |
Q32a (S2 ### Glossary Q32a) | Project Skill term and axiom | ARC-007 | Ownership clarity | |
Q33 (S2 ### Q33) | One-run migration inside the first registry-based hi update; exact read, move, delete, keep list; no migrate command | ARC-012; FLOW-005 | Consumers converge | |
Q34 (S2 ### Q34) | On id collision the Baseline skill wins; Project Skill renamed [DEPRECATED] <name>; reported; renamed directory visible in every harness | User decision, reversing recommendation | FLOW-002-STEP-007 | Baseline authority for skills |
Q35 (S2 ### Q35) | No single-item selection; Packs only; parked | ARC-003; parked | Small selection model |
Spec Traceability
- State: complete. Spec codes OUT-001 to OUT-015 and AC-001 to AC-037 from the
sibling
SPEC.md(section "Requirements Outcomes" and "Acceptance Criteria") map below. Completed bycreate-specon 2026-09-28 without changing accepted design.
| Spec code / section selector | Architecture selectors | Accepted grill Q / evidence anchors | Coverage explanation |
|---|---|---|---|
| OUT-001; AC-001, AC-002, AC-003 | ARC-001; system map; Retired row | Q1 ### Q1, Q8 ### Q8, Q10 ### Q10, Q19 ### Q19; S4 "Facts" | Registry as the only public source; retired control-plane group, artifacts, bundle |
| OUT-002; AC-004, AC-005, AC-006, AC-007 | ARC-001, ARC-011; FLOW-001-STEP-003, STEP-004; FLOW-002-STEP-001 | Q14 to Q18 ### Q14..### Q18 | Immutable versions, latest pointer, CLI range, cache sha256 |
| OUT-003; AC-008, AC-009 | ARC-002; FLOW-001-STEP-001 to STEP-003 | Q4 ### Q4, Q16 ### Q16; S4 "What shadcn's model is" | Publisher and shadcn-compatible item JSON with meta extensions |
| OUT-004; AC-010 | ARC-007, ARC-010; FLOW-002-STEP-005 to STEP-007 | Q7 ### Q7, Q9 ### Q9; S4 "Full harness inventory"; S5 "1. Boundary" | Every inventory kind is a Registry Item; anti-slop per package; tracked Built handoff files |
| OUT-005; AC-011, AC-012, AC-013 | ARC-003, ARC-004; FLOW-002-STEP-002, STEP-012 | Q2 ### Q2, Q20 ### Q20, Q22 ### Q22; S3 axioms | Two files, one writer each, explicit Packs, no hashes |
| OUT-006; AC-014, AC-015, AC-016 | ARC-007; FLOW-002-STEP-005, STEP-006, STEP-007 | Q9 ### Q9, Q24 ### Q24, Q31 ### Q31, Q32a ### Glossary Q32a | Copied overwrite, Built re-render, Authored write once |
| OUT-007; AC-017, AC-018, AC-019, AC-020, AC-021 | FLOW-002-STEP-001 to STEP-014; ARC-012 not involved | Q13 ### Q13, Q23 ### Q23, Q26 ### Q26, Q27 ### Q27; S5 lenses 4, 6, 7 | Fixed order, validate before write, import guard, reported links, record last, convergence |
| OUT-008; AC-022, AC-023, AC-024 | ARC-008; FLOW-003-STEP-003 to STEP-005 | Q2 ### Q2, Q25 ### Q25, Q27 ### Q27; S3 Drift Check classes | Three-way compare, normalization, shape drift, classes |
| OUT-009; AC-025, AC-026, AC-027 | ARC-009; FLOW-003-STEP-001, STEP-002; FLOW-004 | Q6 ### Q6, Q21 ### Q21; S5 K2; S4 "The session-start check" | Version-only check, closed status set, missing record never blocks |
| OUT-010; AC-028, AC-029 | ARC-006; FLOW-002-STEP-006; FLOW-004 manifest edit | Q3 ### Q3, Q12 ### Q12, Q29 ### Q29 | Adapters in the CLI, four harnesses, rebuilt by update and diff only |
| OUT-011; AC-030 | ARC-005; FLOW-002 init note | Q30 ### Q30 | Four commands; scaffold folded into init; no add |
| OUT-012; AC-031, AC-032, AC-033 | ARC-007; FLOW-002-STEP-007; FLOW-005-STEP-003; Retired row | Q31 ### Q31, Q34 ### Q34, Q32a | Project Skills preserved; collision rename; archives retired |
| OUT-013; AC-034 | ARC-012; FLOW-005-STEP-001 to STEP-006 | Q33 ### Q33 | One-run migration inside update |
| OUT-014; AC-035, AC-036 | ARC-010; FLOW-002-STEP-013 | Q5 ### Q5, Q28 ### Q28; S4 "Issue #232 mechanics"; S5 K14 | Runner output size, gate argument passing, full-owner rule kept |
| OUT-015; AC-037 | Canonical Terms; ARC-009 (hook messages) | Q32 ### Q32; S3 retired terms; repository guidance on docs updates | Terms in output, docs, and operator skill; retired terms removed |
Retired or Superseded Selectors
| Selector | Disposition | Replacement / reason | Source |
|---|---|---|---|
| none | First compilation |
Flow Failure Coverage
| Lens | Evidence / unknown / justified not applicable | Guarantee at stake | Material unresolved gap |
|---|---|---|---|
| Entry points and path convergence | init, update, diff, check, session hook share FLOW-002/003 (Q30). shadcn fallback writes files only; hi diff reports its gaps as missing (S5 K6) | Every entry reaches the same rules | None |
| Critical execution paths | FLOW-002 fixed order; dependency install is the only subprocess (Q23) | Lint runs on the real repository | None |
| State ownership and authority | ARC-001 owns Copied and templates; human owns ARC-003 and Authored; installer owns ARC-004 and Built (Q20, Q31, Q34) | One writer per file | None |
| Transaction and side-effect boundaries | No multi-file transaction; record last; no marker (Q23). Transient window where hi diff shows just-written files as local edits (S5 lens 4) | Re-run converges | None |
| Concurrency and stale state | Update records the exact version applied (Q23). Immutable versions remove cache staleness (Q14, Q18). Two updates in one worktree: unknown, not observed (S5 lens 5) | Applied equals recorded | None, non-material |
| Idempotency and retries | Skip identical by content compare (FLOW-002-STEP-005/006); re-run after lost result | Repeating is safe | None |
| Partial failure and recovery | Crash mid-write: re-run. Dependency failure: partial with failing step. Invalid merge target: caught at STEP-004, nothing written (Q23) | No manual archiving | None |
| Execution lifetime and durability | No long-running process; atomic rename in ARC-011 only (S5 lens 8) | Nothing unfinished needs an owner | None |
| Lifecycle and dependency transitions | Stale Copied removed, stale Authored reported (STEP-011); devDependency removal with import guard (Q26); Project Skill collision (Q34); shape drift re-renders Built (Q2); migration FLOW-005 (Q33) | Old state has no hidden dependents | None |
| Completion and observability | Installed Record plus per-path rows; planned and applied separate; status from a closed set (S5 K2, lens 10) | Applied vs planned vs failed distinguishable | None |
Parked Work and Non-material Unknowns
| Question / source | Disposition and scope consequence | Owner / resume trigger | Why current guarantees remain closed |
|---|---|---|---|
| Q29 selectable harness set | Parked; all four harnesses always | User; a repository that must exclude one harness | Fixed set is today's behavior |
| Q35 single Registry Item selection | Parked; Packs only | User; a real request for one skill no Pack contains | Packs cover every current item |
| Concurrent updates in one worktree | Unknown, non-material | Not owned; a reproduced report | Not observed in 47 issues; re-run converges |
| Exact Vercel mount for the Registry | Delivery detail under Q8 | Delivery | Either static files or an apps/api route satisfies Q1 and Q19 |
Renamed Project Skill visible as [DEPRECATED] <name> in harness skill lists | Consequence noted in Q34 | User, if the visibility is unwanted | Reported by the command; user chose visibility |
Validation
- Decision/source/glossary reconciliation: S1 shows confirmation
confirmed, frontier empty, all branches 100%; S2 contains Q1 to Q35 and Q32a; Q11 is superseded by Q19; S3 matches the S1 glossary snapshot. Result: consistent. - Exact-detail and cross-level coverage: every Q has a row in "Accepted Detail Coverage" with a selector; every selector appears in a table, flow, or diagram label. Result: complete.
- Relative links, selector targets, and visual source/order checks: all links are routed wiki paths that exist in the working tree; diagram order follows the accepted step order in Q23 and Q33. Result: pass.
- Spec-code -> architecture -> grill coverage: complete. OUT-001 to OUT-015 and AC-001 to AC-037 each map to at least one ARC or FLOW selector and to accepted Q entries; no code lacks a structural counterpart.
- Mermaid parsing/rendering: both diagrams parsed as
flowchart-v2withmermaid11.15.0 (the wiki's pinned version) under Bun, usinghappy-domas the DOM shim in an isolated temporary environment outside the repository, because the repository installs no DOM shim andmermaid.parseneeds one for label sanitization. Rendering to an image was not run; the wiki renders Mermaid at build time. Labels use plain text without HTML line breaks. - Existing spec agreement: absent; architecture precedes spec.
- Remaining limits: git blob ids are abbreviated to 12 characters; the sources are uncommitted at compile time and are retained in the same dedicated commit as this artifact.