Delivery started from accepted PLAN.md on branch team/stefan/scaffold-integrity-convergence.
The plan is the explicit execution authority; no sibling SPEC.md exists by design.
Implementation and protected-cache follow-ups merged through PRs #112, #114, and #115, ending at c4dcca3134eace76750fa899f3b581411af094d0.
The surviving order is PR #109, then #113, then #116, then docs PR #117. #109/#113 inherit the merged scaffold implementation; #116 fixes a newly found obsolete remediation copy. No #108-derived scaffold implementation remains to port.
T8 local integration is complete. T9 remains In Progress. The 2026.08.07 stable baseline remains immutable predecessor evidence. The #105 rendered-output integrity and strict projection-health follow-up has fixed bundled digest 1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98 and requires new candidate baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6, followed by npm 3.1.6, the exact published installed-consumer matrix, and issue-closure proof.
implement-spec normally requires SPEC.md. The user explicitly ordered delivery from the accepted implementation plan onward, so the plan's locked decisions and acceptance matrix replace that redundant artifact.
The original receipt encoded projection actions but could not change when a valid project-authored subagent description changed rendered provider bytes. The accepted #105 follow-up adds renderedOutputSha256, derived canonically from effective hooks and rendered provider-output maps. This changes managed baseline bytes, so the published 2026.08.07 baseline remains predecessor evidence rather than the final T9 authority.
Historical IP-317 projection health treated expected capability gaps and preserved project prompts as degraded/partial. The current contract retains them as neutral durable receipt provenance with success and empty manifest scaffoldDegradations. Actual projection/application faults and missing managed canonical sources fail; partial remains only for a genuine actionable nonfatal anomaly.
The original session-start hi check --json was unavailable because recorded context evidence for .devpunks/context-plan.json drifted. Focused issue tests supplied the implementation RED surface; later merged lifecycle proof resolved the delivery question without classifying that unavailable result as scaffold drift.
A Wave 1 worker role committed and pushed the concurrent shared snapshot prematurely. No scope was lost; parent orchestration stopped further worker commits and retained later review fixes for a controlled integration commit.
Filesystem review exposed multiple race windows beyond the initial tests. T2 was recovered through additional RED/GREEN cycles until source acquisition used a private pinned-CWD hold and retirement completed before replacement publication.
Findings-first review found a High archive-worker deadlock and a Low obsolete prompt surface, plus CAS, containment, and public-root integration findings. All were fixed; final rereview reported no findings.
Full-repository validation exposed that generic regenerated Oxlint configs dropped required CLI shipped-asset exclusions and backoffice rule exceptions. Those policies now live in canonical lint assets selected only by the exact package names @punks/cli and @punks/backoffice; workspace oxlint.config.ts files remain strict baseline-managed content rather than project-owned exceptions.
Canonical lint output now converges at all three publication seams: the emitter produces formatter-stable TypeScript, preset rules are injected only when declared, and root lint evidence derives from the applied plan plus explicit project-owned legacy .oxlintrc files instead of current managed output.
Protected attestation now runs its Turbo release-test graph with --concurrency=1 after the prior aggregate run exposed host oversubscription.
Local protected release verification is intentionally unavailable without the protected cache environment. The exact-head GitHub protected gate remains authoritative.
The repaired installed-consumer validator now has six evidence rows and two authority modes. Its bundled/local-tarball run is a rehearsal. The deterministic packaged-bundled fixture/cache authority serves a matching /manifest, but hi check refreshes metadata and archive bytes and verifies the archive's embedded baseline manifest instead of requesting that separate artifact, so its manifestRequests: 0 is intentional. The final strict gate passed 30/30 focused tests with 121 assertions and all six full scenarios; fresh init and every scaffold reported success through complete canonical operation objects with empty issues, warnings, and degradations, both remote checks were clean, and cleanup retained no paths. Managed hashes covered 230/230 init entries and 229/229 scaffold entries, including legacy and ScaffoldManaged content while skipping only ProjectGenerated; internal symlinks were validated without following them. Partial or truncated operation payloads fail. Only exact @punks/cli@3.1.6 plus the new published stable baseline qualifies for T9 closure.
The checked-in root receipt reports status success, zero warnings or failures, and renderedOutputSha25625962b79154a851d925d900ec2027dc1c4975a2c141fedb0d9a9bbf4bba9b9a8. Its scaffold manifest reports projectionStatussuccess, empty scaffoldDegradations, and matching receipt semantic SHA 5e8c2a00c7380ec92bf45450944b1cc2f63ef53ee4d10643d0b49b6a1b228bfd. This checked-in root/local observation is not published baseline proof.
The CI candidate at 3844fab was canceled and is superseded. It is not exact-head proof; a fresh final producer/replay remains pending.
Public update/check/scaffold and shipped producer lifecycle
Vitest-created isolated roots
Full convergence matrix
4/4 lifecycle rows passed; fixed edit archived/replaced, final checks clean, flags made zero downstream calls, typed negative controls remained visible.
Test cleanup removed owned roots.
PASS
T8
Integrated local CLI lifecycle
Public scaffold/update/check and producer lifecycle
PRs #112/#114/#115; exact head c4dcca3134
Clean first-party lifecycle with typed negative controls
Protected run 31245179530 passed; attestation producer and consumer each completed the exact two-task graph.
Test-owned roots removed
PASS
T9
Published CLI and stable baseline in fresh consumers
Local six-row bundled rehearsal passed; published pair absent
2026.08.07 predecessor targets c4dcca3134; new candidate pending
Installed lifecycle clean and issues closable
Predecessor authority and local rehearsal are proven separately. New stable candidate and npm 3.1.6 remain unpublished, so published-consumer proof is absent.
Preserve the corrected open order: PR #109, then #113, then #116, then #117. Merge only with fresh authorization.
After #117 merges, publish baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6. Preserve the 2026.08.07 release unchanged.
Publish @punks/cli@3.1.6 through the approved clean release path.
Run HI_IP346_PACKAGE_SPEC=@punks/cli@3.1.6 HI_IP346_BASELINE=stable HI_IP346_EXPECTED_BASELINE_VERSION=2026.08.10-projection-receipt-output-integrity bun run validate:consumer-repositories against the exact published CLI and new stable baseline.
Attach issue-specific evidence to #97, #104, and #105, then close only an issue whose complete acceptance evidence passes.
Registry readback for @punks/cli@3.1.6 returned E404 on 2026-08-09. This leaves npm publication and installed-consumer convergence unproven.
New stable candidate baseline/stable/2026.08.10-projection-receipt-output-integrity with compatibility =3.1.6 is release input only; publication and public readback remain pending.