Scaffold Integrity Convergence Plan
Plan: Scaffold Integrity Convergence
Initial Situation
The 3.0 scaffold-state work separated desired state, observation, receipts, reconciliation, and application. It also established explicit whole-file ownership: ScaffoldManaged files belong to a verified selected baseline, while current ProjectGenerated or established project-owned exceptions belong to their repository producer.
Two edge cases remain:
- issue #104:
hi update,hi check, andhi scaffoldcan preserve or warn about divergent fixed scaffold-managed files instead of converging them to the selected baseline; successful apply can still present baseline-drift warnings; - issue #105: the portable subagent projection script writes a new projection receipt but does not refresh that receipt's exact managed-manifest entry, so the next
hi checkreports drift even though no person edited managed content.
These are authority/publication defects, not permission to refresh arbitrary hashes. The manifest is a receipt. It records bytes successfully committed by an authorized producer; it never turns observed bytes into desired truth.
Product Invariant
After any successful first-party hi scaffold, normal hi update, or generated projection sync, an immediate hi check --json must be clean unless a person or other out-of-band process actually changed fixed scaffold-managed content afterward.
Operational failures remain visible as typed errors. Legitimately project-owned or project-generated content is outside fixed-baseline overwrite and produces no warning, degraded state, or drift when its own ownership evidence is current.
Locked Decisions
- Normal
hi updateapplies the verified selected baseline without prompting.hi update --checkis the read-only preview. --writeand--yesremain compatibility aliases for normal apply; they grant no stronger overwrite policy.--checkcombined with--writeor--yesis a typed usage error before baseline resolution or filesystem mutation.- Fixed
ScaffoldManagedfiles are baseline-authoritative. If unchanged from their prior receipt, update replaces them normally. If actually edited, check reports drift; normal update archives the observed file, installs the verified baseline bytes, and receipts the committed result. - Existing project-owned/customizable exceptions remain preserved. When current they are omitted from drift, warnings, and degraded behavior.
- Current
ProjectGeneratedorRepositoryMirroroutputs retain their fingerprint-bound producer rules. Missing or stale producer evidence is not silently converted into baseline authority. - Generated subagent sync refreshes exactly its projection-receipt manifest entry after publishing truthful success or intentional failure receipt bytes. It never broadly refreshes hashes.
- Receipt then manifest publication is individually atomic, compare-and-swap guarded, and retry-safe. It is not claimed to be crash-atomic across both files; no journal is added.
- A manifest compare-and-swap failure after receipt publication exits nonzero with a retry instruction. It does not roll back a truthful receipt; retry converges.
- Issues #97, #104, and #105 and their shared root contracts are in scope. #97 requires fresh published-consumer proof rather than new production behavior. No unrelated ownership policy is redesigned.
- Stable baseline
baseline/stable/2026.08.07-scaffold-integrity-convergenceis immutable predecessor evidence and must never be overwritten. The accepted #105 rendered-output integrity follow-up changes managed scaffold bytes, so remaining delivery publishes a separate new candidate,baseline/stable/2026.08.10-projection-receipt-output-integritywith compatibility=3.1.6, then npm CLI 3.1.6 and installed-consumer proof. Issues close only after their mapped acceptance evidence passes.
Authority And Ownership Model
| State | Authority | hi check | normal hi update |
|---|---|---|---|
fixed ScaffoldManaged, observed equals desired | selected verified baseline | clean | no-op; refresh truthful receipt only if required |
fixed ScaffoldManaged, observed differs | selected verified baseline | local-edited drift | archive observed bytes, replace from baseline, receipt committed bytes |
| project-owned exception, present/current | project | clean and silent | preserve |
current ProjectGenerated / RepositoryMirror | named producer plus matching fingerprint evidence | clean and silent | preserve |
| missing/stale project-generated evidence | existing producer policy | typed drift/failure | do not invent producer output |
| projection receipt produced by sync | sync producer | clean when manifest names exact receipt bytes | publish receipt, CAS-update only its manifest entry |
| baseline authority unavailable | none | typed operational failure | typed operational failure; no mutation |
File kind is not ownership. In particular, the heterogeneous harness kind cannot decide whether a path is fixed or customizable. Effective ownership is compiled once from desired baseline metadata, explicit producer evidence, and the retained compatibility exceptions, then shared by check and apply.
Superseded And Retained Contracts
This plan narrows the earlier IP-318 rule that user-modified managed files are preserved. That preservation remains correct for project-owned/customizable and current project-generated content. It is superseded only for fixed ScaffoldManaged files: their selected verified baseline is authoritative, and normal update archives then replaces actual local edits.
The following remain distinct and unchanged:
- issue #69's existence-sensitive project-owned wiki sync behavior;
- tailored repository sync scripts and metadata already classified as project-owned;
- structured project settings and dependency-entry ownership;
- semantic skill overlap and pre-existing skill snapshot policies;
- IP-317's portable producer and durable failure receipt;
- IP-323's verified baseline authority gate;
- formatter exemption for manifest-managed byte-authoritative assets.
Design Considered Twice
Rejected: refresh all hashes from observed files
This would make false drift disappear by laundering real edits into the receipt. It reverses authority: observed bytes would become desired truth. It also hides modified skills, hooks, and other fixed assets.
Rejected: preserve conflicts unless an overwrite flag is supplied
This retains the current split behavior, leaves automation dependent on flags or prompts, and contradicts the required convergence invariant. --write cannot be a special authority grant if normal update is the repair operation.
Rejected: teach the pure three-way reconciler every path exception
The reconciler does not own effective path policy and its existing conflict classification is useful beyond this command. Passing path heuristics into it would couple a deep state machine to current CLI integration details.
Selected: typed fixed-managed recovery plan at the ownership/application seam
Keep raw three-way reconciliation strict. After effective ownership is compiled, transform only divergent file-update conflicts that are proven fixed ScaffoldManaged and whose desired bytes come from the verified selected baseline into a typed archive-and-replace action. --check presents that action as drift without executing it. Normal update executes it through one confined-filesystem primitive, then derives the receipt from the final observed target.
This seam cannot affect project-owned exceptions, generated lanes, structured entries, dependencies, deletions, or unverified baseline content.
Persistent Archive Contract
The archive primitive is file-only and dedicated; it is not a loose remove-plus-write composition.
- Archive path:
.devpunks/replaced-scaffold/<observed-fingerprint>/<relative-path>. - Validate exact root, parent, and leaf identities; never follow a regular-file or symlink target.
- Reuse an existing archive only when its full canonical identity equals the observed source.
- Never overwrite a concurrently changed target or archive.
- Publish the replacement atomically after archiving.
- If replacement publication fails and the target is absent, restore the original only when identities still make restoration safe.
- If restoration cannot be proven safe, return typed recovery evidence naming the retained archive and target state.
- Receipt evidence comes from re-observing the committed target, never from planned bytes alone.
Projection Receipt Publication Contract
The canonical sync-subagents.mjs producer performs this bounded transaction:
- preflight-decode the optional manifest before projection side effects;
- require exactly one
projection-receiptentry for the configured receipt path when a manifest exists; - record the manifest's preflight canonical identity;
- publish truthful success or intentional failure receipt bytes atomically;
- reread the exact committed receipt and compute the same canonical semantic hash used by the CLI;
- compare-and-swap the manifest against its preflight identity;
- preserve every unrelated manifest field and entry while updating only the receipt entry's hash/status evidence;
- throw the original projection error after durable failure evidence has been published.
Malformed or ambiguous manifests fail before projection side effects. A post-receipt CAS conflict reports a typed retryable failure. Retrying must converge without duplicate or broad updates.
Codebase Findings
apps/cli/src/cli/update-command.tsstill describes--write/--yesas the apply switch, andapps/cli/src/update/run.tsprompts or plans by default depending on TTY/output mode.apps/cli/src/update/run.tsemits baseline-drift warnings from pre-apply state, so a successful repair can still look degraded.apps/cli/src/features/scaffold-state/reconcile.tsalready performs correct three-way comparison. The missing concept is an effective-ownership-qualified recovery action.apps/cli/src/features/scaffold-state/apply.tshas no archive-and-replace action.apps/cli/src/scaffold/confined-filesystem.tsis the containment boundary and must own persistent archive semantics and race recovery.apps/cli/src/update/run.tscurrently retains project-owned exceptions for prompts, handoffs, manifests, prompt specs, subagents, tailored sync, wiki metadata/sync, agent mirrors, and consumer-owned Claude copies. These need one audited, silent ownership result rather than warning-producing bypasses.apps/cli/src/data/scripts/sync-subagents.mjswrites the projection receipt but never its manifest entry..agents/scripts/sync-subagents.mjs, the bundled source, contract tests, and the managed-assets fixture must remain byte/identity aligned.apps/cli/src/scaffold/json.tsdefines the canonical semantic JSON hash. The standalone ESM producer needs parity, preferably through a small inline local helper rather than another shipped managed asset.- Existing manual receipt-corruption coverage remains a negative control: consumer-side manifest edits must still be reported.
Execution Assumptions And Constraints
- Implementation begins from a clean task/release worktree. This planning checkout contains accepted unrelated scaffold remediation and
.devpunks/replaced-scaffold/; workers must not reset, stage, or overwrite it. - The release candidate is
@punks/cli@3.1.6, paired exactly withbaseline/stable/2026.08.10-projection-receipt-output-integrity; T9 must verify both remain unpublished before the ordered release begins. - The selected stable baseline must be built and published through root package commands from a clean release worktree.
- Each worker owns only its listed paths, is not alone in the repository, and must accommodate prior wave changes without reverting them.
- Tests use real filesystem contracts for containment, permissions, atomic replacement, rollback, and races; orchestration tests may use scoped doubles.
- The prior parallel research report and bounded planning discovery provide current evidence, so this planning pass does not repeat parallel research.
- No retained agent-ready SPEC or provider projection relation exists for this slug. Backlog sync is therefore ineligible; the GitHub issues remain external authority and are not mutated during planning.
Dependency Graph
T0
├── T1 ──┐
├── T2 ──┼── T6 ──┬── T4 ──┐
└── T3 ──┘ └── T5 ──┼── T7 ── T8 ── T9Wave 1 runs T1-T3 concurrently because state/application, confined filesystem, and producer-script write scopes are disjoint. Wave 2 is a barrier: T6 alone records the public acceptance RED from the stable post-T1-T3 commit. Wave 3 then runs T4 and T5 concurrently and reruns T6 unchanged to GREEN. Wave 4 prepares documentation and release inputs. T8 is the Wave 5 integration/review gate; T9 is the Wave 6 clean release and installed proof gate.
Tasks
T0: Establish A Clean Execution Baseline
- depends_on: []
- location: clean task worktree based on the accepted planning/research commit
- owned_paths: []
- wave_boundary: Wave 0; parent-owned gate before implementation workers launch.
- description: Record base commit, branch, clean status, active agent settings, specialist coverage, current CLI/baseline identities, and pre-change focused failures for issues #104/#105. Confirm unrelated remediation in this planning checkout remains untouched. Assign disjoint workers from this graph.
- validation: Clean worktree proof; current focused controls run; issue reproductions fail for the expected reasons rather than setup or unavailable-authority errors.
- status: Complete
- log: 2026-08-07 — Started from clean commit
bbb6b7c9and createdteam/stefan/scaffold-integrity-convergence. Verifiedmax_depth = 1, specialist manifest coverage, and disjoint Wave 1 ownership. Existing scaffold-state and producer controls pass. Globalhi check --jsonremains separately unavailable because.devpunks/context-plan.jsonevidence drifted; no scaffold drift was inferred from that operational failure. Issue-specific RED evidence is owned by T1-T3. - files edited/created:
apps/wiki/content/docs/project/specs/cli/scaffold-integrity-convergence/IMPLEMENTATION-NOTES.md,apps/wiki/content/docs/project/specs/cli/scaffold-integrity-convergence/PLAN.md - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
implement-spec,create-plan,swarm-planner,tdd,codebase-design] - tdd_status: not_applicable
- tdd_target: Trusted execution baseline and worktree isolation.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli test src/update/run.test-cases.test.ts src/cli/public-output-contract.test.ts && bun run --cwd apps/cli test src/data/scripts/sync-subagents.test.ts - reason_not_testable: Read-only execution preflight.
- red_evidence:
- green_evidence:
reconcile.test.ts,apply.test.ts, andsync-subagents.test.ts: 104/104 tests passed in 41.95s. Git worktree was clean before branch/notes creation. Globalhi check --jsonreproduced only the typed context-evidence validation failure. - codebase_design_notes: Do not implement over uncommitted generated remediation or conflate authority-unavailable with drift.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T1: Model Fixed-Managed Recovery After Ownership Resolution
- depends_on: [T0]
- location:
apps/cli/src/features/scaffold-state/reconcile.ts,reconcile.test.ts,apply.ts,apply.test.ts, and a narrow recovery-planning module underapps/cli/src/features/scaffold-update/ - owned_paths: [
apps/cli/src/features/scaffold-state/reconcile.ts,apps/cli/src/features/scaffold-state/reconcile.test.ts,apps/cli/src/features/scaffold-state/apply.ts,apps/cli/src/features/scaffold-state/apply.test.ts,apps/cli/src/features/scaffold-update/fixed-managed-recovery.ts,apps/cli/src/features/scaffold-update/fixed-managed-recovery.test.ts] - wave_boundary: Wave 1; runs with T2 and T3. Stop if the design requires path heuristics inside raw reconciliation.
- description: Add a typed file-only archive-and-replace application action. Keep raw three-way conflicts unchanged, then add a pure transformation that accepts the compiled set of fixed scaffold-managed paths and verified desired baseline provenance. Transform only divergent file-update conflicts eligible under that input. Prove project-owned, current project-generated, structured-entry, dependency, removal, and unverified-baseline cases cannot enter the action. Teach the applicator to delegate the typed action and persist the post-commit observed fingerprint.
- validation: Pure tests cover eligible conversion and every exclusion; applicator tests prove it consumes committed observation, propagates typed recovery failure, and never converts receipt-only evidence into authority.
- status: Complete
- log: 2026-08-07 — Added a typed post-ownership fixed-managed recovery transformation while keeping raw three-way reconciliation strict. Review hardened the adapter boundary so it returns only committed observation fields; the applicator derives path, kind, and
ScaffoldManagedownership from the verified action. Actual project-owned/current-generated classification remains an explicit T4 integration assertion. - files edited/created:
apps/cli/src/features/scaffold-state/reconcile.ts,apps/cli/src/features/scaffold-state/reconcile.test.ts,apps/cli/src/features/scaffold-state/apply.ts,apps/cli/src/features/scaffold-state/apply.test.ts,apps/cli/src/features/scaffold-update/fixed-managed-recovery.ts,apps/cli/src/features/scaffold-update/fixed-managed-recovery.test.ts - backlog_item_id: GH-104
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/104
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: Only a verified fixed
ScaffoldManageddivergent file update becomes an archive-and-replace action. - red_command:
bun run --cwd apps/cli test src/features/scaffold-state/reconcile.test.ts src/features/scaffold-state/apply.test.ts src/features/scaffold-update/fixed-managed-recovery.test.ts -t "plans recoverable replacement only for fixed scaffold-managed conflicts" - expected_red_failure: Divergent fixed files remain generic preserved conflicts and no typed recovery action exists.
- green_command:
bun run --cwd apps/cli test src/features/scaffold-state/reconcile.test.ts src/features/scaffold-state/apply.test.ts src/features/scaffold-update/fixed-managed-recovery.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Missing recovery module; recovery action initially routed through ordinary
applyFile; adversarial adapter could forge receipt path/kind/ownership. - green_evidence: 45/45 focused reconcile/apply/recovery tests passed; CLI typecheck, scoped Oxlint/Oxfmt, and diff check passed. Read-only review findings were fixed.
- codebase_design_notes: Keep ownership policy at the update seam; preserve the reusable strict reconciler. The new action is explicit data, not an apply-side path exception.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T2: Add A Confined Persistent Archive-And-Replace Primitive
- depends_on: [T0]
- location:
apps/cli/src/scaffold/confined-filesystem.tsand its real-filesystem contract tests - owned_paths: [
apps/cli/src/scaffold/confined-filesystem.ts,apps/cli/src/scaffold/confined-filesystem.test.ts] - wave_boundary: Wave 1; runs with T1 and T3. T4 waits for the primitive's rollback and race suite.
- description: Implement the persistent archive contract as one confined-filesystem operation. Use canonical full identity for archive naming/reuse, exact no-follow containment checks, atomic target publication, safe restoration, and typed retained-archive recovery evidence. Cover regular files and symlinks without dereferencing. Do not assemble this from public remove/write calls.
- validation: Real-filesystem tests cover success, retry reuse, archive mismatch, concurrent target/archive replacement, symlink swaps, publication failure with safe restore, and unsafe restore with retained recovery evidence.
- status: Complete
- log: 2026-08-07 — Added a dedicated confined archive-and-replace state machine for regular files and symlinks. Recovered review REDs drove atomic source acquisition into a private pinned-CWD hold, canonical identity verification, retirement before replacement publication, deterministic no-overwrite archive reuse, no-overwrite restore, late containment rollback, and typed retained recovery evidence. No known in-goal destructive race remains.
- files edited/created:
apps/cli/src/scaffold/confined-filesystem.ts,apps/cli/src/scaffold/confined-filesystem.test.ts - backlog_item_id: GH-104
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/104
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: Archive-and-replace is contained, no-follow, atomic per publication, retry-safe, and recoverable under races.
- red_command:
bun run --cwd apps/cli test src/scaffold/confined-filesystem.test.ts -t "archives and replaces a managed file without following identities" - expected_red_failure: The confined filesystem has no persistent archive-and-replace operation or recovery result.
- green_command:
bun run --cwd apps/cli test src/scaffold/confined-filesystem.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Primitive missing; in-place source edits incorrectly succeeded; late root swaps retained archive/replacement artifacts; pre-acquisition edits could be erased; hold-path substitution could redirect claim acquisition; hold-retirement failure could leave the target absent.
- green_evidence: 45/45 real-filesystem tests passed, including every recovered race and the archive-worker deadlock regression; CLI typecheck, scoped Oxlint/Oxfmt, and diff check passed. Final bounded rereview found no actionable issue.
- codebase_design_notes: This is a deep persistence boundary. Keep orchestration/path policy out; return typed evidence instead of logging or throwing generic filesystem strings.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T3: Publish Projection Receipts With Exact Manifest Evidence
- depends_on: [T0]
- location: canonical bundled
sync-subagents.mjsand direct script tests - owned_paths: [
apps/cli/src/data/scripts/sync-subagents.mjs,apps/cli/src/data/scripts/sync-subagents.test.ts] - wave_boundary: Wave 1; runs with T1 and T2. T5 waits for success, failure, malformed-manifest, and CAS tests.
- description: Add manifest preflight and the bounded receipt-publication transaction to the canonical standalone ESM script. Match the CLI's semantic JSON hashing exactly with the smallest local helper. On success and intentional failure, publish the truthful receipt, reread it, and CAS-update only its unique projection-receipt manifest entry while preserving unrelated bytes semantically. Fail before projection side effects on malformed/ambiguous manifests. After a post-receipt CAS conflict, retain truthful receipt evidence and return an explicit retryable error.
- validation: Direct tests cover success, intentional projection failure, no-manifest compatibility, malformed manifest preflight, missing/duplicate/wrong-path receipt entry, unrelated-field preservation, receipt reread, hash parity, post-receipt CAS conflict, and retry convergence.
- status: Complete
- log: 2026-08-07 — Added optional manifest preflight and exact projection-receipt evidence publication for success and intentional failure. Review REDs bound the reread receipt semantics/status to the authored committed object and made ownership decoding fail closed. CAS conflicts retain truthful receipt evidence and retry converges without broad hash refresh.
- files edited/created:
apps/cli/src/data/scripts/sync-subagents.mjs,apps/cli/src/data/scripts/sync-subagents.test.ts - backlog_item_id: GH-105
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/105
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: The producer receipts its exact committed receipt bytes and updates no other managed hash.
- red_command:
bun run --cwd apps/cli test src/data/scripts/sync-subagents.test.ts -t "refreshes only the committed projection receipt manifest entry" - expected_red_failure: The script publishes a receipt while leaving the matching manifest hash stale.
- green_command:
bun run --cwd apps/cli test src/data/scripts/sync-subagents.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Receipt hash/status remained stale; ambiguous duplicate paths reached projection effects; out-of-band receipt substitution was authorized; unknown ownership reached projection effects.
- green_evidence: 89/89 direct producer tests passed; CLI typecheck, scoped Oxlint/Oxfmt, and diff check passed. Review findings covering exact CAS evidence, containment, and public-root routing were fixed.
- codebase_design_notes: The producer may update its own exact receipt evidence, not desired baseline hashes. Avoid a journal and avoid adding another shipped managed helper asset.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4: Make Normal Update Converge Fixed Managed Content
- depends_on: [T1, T2, T6]
- location: update command boundary, application/presentation operations, and
runUpdateintegration tests - owned_paths: [
apps/cli/src/cli/update-command.ts,apps/cli/src/cli/update-presenter.ts,apps/cli/src/cli/public-output-contract.test.ts,apps/cli/src/features/command-boundary-contract.test.ts,apps/cli/src/features/scaffold-update/application.ts,apps/cli/src/features/scaffold-update/interaction.ts,apps/cli/src/platform/feature-application-operations.ts,apps/cli/src/update/run.ts,apps/cli/src/update/run.test-cases.test.ts] - wave_boundary: Wave 3; one central integration worker after T1/T2 and the T6 RED barrier. Runs with T5.
- description: Validate contradictory flags at the command boundary before effects. Make no-flag update apply in TTY, redirected, and JSON modes; retain
--write/--yesas aliases and--checkas readonly. Compile effective ownership once, preserving all established project-owned and current project-generated exceptions silently. Route only verified fixed-managed divergent updates through archive-and-replace. Recompute result/warnings after application so successful convergence is clean. Preserve typed unavailable-authority, local-edit check, archive recovery, and true producer-stale outcomes. - validation: Public and integration tests cover default apply across output modes, alias equivalence, read-only check, every contradictory flag pair, actual fixed-file edit archive/replacement, false hash mismatch with equal canonical content, silent retained exceptions, structured settings preservation, post-apply warning removal, and manual receipt corruption remaining drift.
- status: Complete
- log: 2026-08-07 — Normal update now applies across interactive, redirected plain, and JSON modes;
--write/--yesare aliases and--checkremains read-only. Contradictory flags fail before effects. One compiled ownership decision feeds comparison, fixed-managed recovery, staging, and reporting. Equal-content stale evidence refreshes without archive; actual fixed edits archive/replace from verified baseline; project-owned/current-generated content remains silent; successful repair reports clean post-apply state. - files edited/created:
apps/cli/src/cli/update-command.ts,apps/cli/src/cli/public-output-contract.test.ts,apps/cli/src/features/command-boundary-contract.test.ts,apps/cli/src/update/run.ts,apps/cli/src/update/run.test-cases.test.ts - backlog_item_id: GH-104
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/104
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: Normal update repairs only fixed managed content and returns clean; check remains read-only; project-owned exceptions remain silent.
- red_command:
bun run --cwd apps/cli test src/update/run.test-cases.test.ts src/cli/public-output-contract.test.ts src/features/command-boundary-contract.test.ts -t "rejects contradictory update flags before effects|applies fixed scaffold-managed drift by default" - expected_red_failure: No-flag update plans/prompts or preserves the conflict; contradictory
--check --writeand--check --yescases reach operation/baseline/filesystem seams instead of returning the typed pre-effect usage error. - green_command:
bun run --cwd apps/cli test src/update/run.test-cases.test.ts src/cli/public-output-contract.test.ts src/features/command-boundary-contract.test.ts && bun run --cwd apps/cli check-types && bun run --cwd apps/cli check - reason_not_testable:
- red_evidence: Both contradictory flag pairs invoked update effects; redirected no-flag update previewed/degraded without applying; T6 fixed-edit/default update preserved conflict and emitted no archive.
- green_evidence: Command boundary 3/3, ownership integration 2/2, interactive/redirected witnesses 2/2, JSON default witness 1/1, T6 4/4, bounded review 51/51, CLI typecheck, scoped Oxlint/Oxfmt, and diff check passed. T4 review found no actionable issue.
- codebase_design_notes: Delete prompting machinery only if these semantics make it genuinely unused. Do not leave duplicate default/apply policy in parser, runner, and presenter.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T5: Prove Scaffold To Sync To Check Convergence
- depends_on: [T3, T6]
- location: active-script parity, managed-assets fixture, and public lifecycle integration tests
- owned_paths: [
.agents/scripts/sync-subagents.mjs,apps/cli/src/data/scripts/harness-projection/contract.test.ts,apps/cli/src/data/scripts/sync-subagents.lifecycle.test.ts,apps/cli/test-fixtures/public-output/managed-assets.json] - wave_boundary: Wave 3; runs with T4 after the T6 RED barrier. Update the whole managed-assets fixture through its generator, never individual hashes.
- description: Copy the proven canonical producer to the active scaffold source and keep byte-parity contract coverage. Add a public temp-repository lifecycle: scaffold, run the generated producer for success and intentional failure, then run check. Success must be clean. Intentional producer failure must retain truthful failure evidence without unrelated managed drift. Keep a separate consumer-side manifest corruption control that still fails. Regenerate the complete managed-assets fixture with the repository command.
- validation: Active/bundled byte parity, producer lifecycle, corruption negative control, canonical hash parity, and full fixture integrity pass.
- status: Complete
- log: 2026-08-07 — Synchronized the reviewed canonical producer to the active scaffold source, added shipped lifecycle coverage, regenerated the complete managed-assets fixture, and aligned generated bundled/context provenance to digest
335ac26a…. Review strengthened failure isolation to require empty changed/stale arrays and changed the corruption control to semantic receipt mutation with unchanged manifest evidence. - files edited/created:
.agents/scripts/sync-subagents.mjs,apps/cli/src/data/scripts/sync-subagents.lifecycle.test.ts,apps/cli/test-fixtures/public-output/managed-assets.json,apps/cli/src/data/bundled-baseline-identity.generated.ts,apps/cli/test-fixtures/public-output/context-outcome.json - backlog_item_id: GH-105
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/105
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: A freshly scaffolded repository remains clean after its generated projection producer publishes exact receipt evidence.
- red_command:
bun run --cwd apps/cli test src/data/scripts/sync-subagents.lifecycle.test.ts -t "scaffold sync check converges" - expected_red_failure: The post-sync check reports the projection receipt as managed drift.
- green_command:
bun run --cwd apps/cli test src/data/scripts/sync-subagents.lifecycle.test.ts src/data/scripts/harness-projection/contract.test.ts && bun run --cwd apps/cli fixtures:check:managed-assets - reason_not_testable:
- red_evidence: Active/canonical bytes differed; shipped lifecycle returned degraded; managed-assets parity expected stale active hash
a864ce…instead ofb35800…. - green_evidence: Active/canonical parity exact; shipped lifecycle 3/3; lifecycle plus projection contract 33/33; complete managed-assets regeneration and check passed; CLI typecheck, scoped Oxlint/Oxfmt, and diff check passed. Review findings were fixed.
- codebase_design_notes: The lifecycle test must execute the shipped producer, not a rewritten test helper. Preserve the receipt-corruption negative control.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T6: Author The Cross-Issue Acceptance Matrix RED
- depends_on: [T1, T2, T3]
- location: a new CLI lifecycle contract test isolated from central
run.tstest ownership - owned_paths: [
apps/cli/src/update/scaffold-integrity-lifecycle.test.ts] - wave_boundary: Wave 2 barrier; runs alone from the stable post-T1-T3 commit, records RED before any T4/T5 production edit, and owns only a new test file. T4/T5 may launch only after its RED evidence is logged.
- description: Add one table-driven temp-repository acceptance suite covering clean scaffold/check, no-op update/check, equal-content stale receipt recovery, actual fixed-file edit check/update/archive/check, project-owned exception silence, generated sync/check, generated failure evidence, contradictory flags with zero operation/baseline/filesystem calls, unavailable baseline authority, and repeat-run idempotence. Assert JSON status, exit code, warnings, changed paths, archive contents, manifest hash, final bytes, and pre-effect call counts rather than snapshots alone. Record RED before consuming T4/T5 GREEN changes; then rerun unchanged after both integrations land.
- validation: Before T4/T5 integration, the fixed-edit/default-update and contradictory-flag rows fail for their stated behavior; the producer-receipt row may already be GREEN from T3 and its result is recorded without forcing failure. After integration, every row proves the product invariant or its typed failure exception through public boundaries and real filesystem behavior.
- status: Complete
- log: 2026-08-07 — Authored the public lifecycle matrix from stable Wave 1 commit
97004b72. Genuine RED covered stale equal-content receipt recovery, no-flag fixed-file repair/archive/clean-check, and both contradictory flag combinations reaching downstream seams. After T4/T5, the same matrix is GREEN for convergence, silent ownership exceptions, producer success/failure, corruption, idempotence, unavailable authority, and pre-effect flag rejection. The only assertion adjustment matched the established nested JSON error envelope. - files edited/created:
apps/cli/src/update/scaffold-integrity-lifecycle.test.ts - backlog_item_id: GH-104
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/104
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: All first-party producers converge and only actual fixed-content edits or typed operational failures remain observable.
- red_command:
bun run --cwd apps/cli test src/update/scaffold-integrity-lifecycle.test.ts - expected_red_failure: Fixed-edit/default-update reports preservation or false drift, while contradictory flags invoke at least one forbidden downstream seam. The suite is RED overall; #105 rows may already pass after T3.
- green_command:
bun run --cwd apps/cli test src/update/scaffold-integrity-lifecycle.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Initial focused matrix: 3 failed/1 passed. Equal-content update left a zero manifest hash; fixed edit returned exit 1/degraded/preserved with no archive; contradictory pairs called operation/baseline/filesystem once each. Unavailable authority passed.
- green_evidence: T6 4/4 passed through public boundaries and disposable repositories; integrated T4/T5/T6 public/contract selection 162/162 passed. CLI typecheck and managed-assets check passed.
- codebase_design_notes: Prefer a small public-behavior matrix over duplicating internal branches already proved by T1-T5.
- review_mode: cli
- runtime_validation: required
- runtime_target: built local CLI executed in disposable temp repositories across the acceptance matrix
- runtime_evidence:
bun run --cwd apps/cli test src/update/scaffold-integrity-lifecycle.test.ts: 4/4. Disposable repositories exercised clean scaffold/check, receipt recovery, fixed edit/check/default update/archive/clean check, silent project-owned/generated paths, shipped producer success/failure/corruption, idempotence, unavailable authority, and contradictory flag zero-effect counts. Test cleanup removed owned roots. - runtime_cleanup: Remove only task-created temp repositories after retaining assertion output; never clean the planning checkout.
T7: Align Operator Docs, Changelogs, And Release Inputs
- depends_on: [T4, T5, T6]
- location: root docs index, CLI scaffold runbook, routed wiki behavior docs, changelogs, and CLI version metadata
- owned_paths: [
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/research/scaffold-integrity-root-cause-plan-research-report.md,apps/wiki/content/docs/project/specs/cli/scaffold-integrity-convergence/PLAN.md,CHANGELOG.md,BASELINE_CHANGELOG.md,apps/cli/package.json] - wave_boundary: Wave 4; starts only after T4/T5 are GREEN and T6 has recorded RED then GREEN. Do not publish in this task.
- description: Document the normal-update default, check-only flag, contradictory-flag error, ownership table, archive recovery location, silent project-owned exceptions, and exact producer receipt update. Update root and baseline changelogs. At release preflight, select and record the next available CLI patch version; do not overwrite a newer concurrent release. Update plan task evidence only through the parent implement-spec workflow.
- validation: Docs describe proven behavior and recovery without implying manifest authority or two-file crash atomicity; content checks, JSON checks, changelog checks, and package metadata tests pass.
- status: Complete
- log: 2026-08-07 — Prepared
@punks/cli@3.1.6and baseline inputbaseline/stable/2026.08.07-scaffold-integrity-convergenceafter live registry/tag preflight. Updated operator docs, root/baseline changelogs, research conclusion, and generated wiki runbook projection. Docs state default apply, read-only check, compatibility aliases, typed contradictory flags, archive/replacement, silent exceptions, exact producer receipt CAS, and the honest non-crash-atomic two-file boundary. Nothing was published in this task. - files edited/created:
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/research/scaffold-integrity-root-cause-plan-research-report.md,CHANGELOG.md,BASELINE_CHANGELOG.md,apps/cli/package.json - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,create-plan,create-spec,docs-onboarding,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,implement-spec,improve-codebase-architecture,parallel-research,quality-types,review,simplify,swarm-planner,tdd,turborepo,writing-beats,writing-for-agents,writing-fragments,writing-shape] - tdd_status: not_applicable
- tdd_target: Durable documentation and release metadata reflect already-proven behavior.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/wiki check:content && bun run --cwd apps/cli check-types && bun run test:release && git diff --check - reason_not_testable: Documentation and release metadata task; behavioral tests are owned by T1-T6.
- red_evidence:
- green_evidence: Release metadata tests 31/31, assigned-file formatting, package/changelog assertions, wiki content projection check, JSON parsing, and diff check passed. CLI/baseline remain explicitly unpublished.
- codebase_design_notes: Say “receipt evidence,” not “manifest authority.” Keep operator recovery concrete and bounded.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T8: Integrate, Review, And Run Full Validation
- depends_on: [T4, T5, T6, T7]
- location: all paths changed by T1-T7; no speculative scope
- owned_paths: [
apps/cli/**,apps/wiki/content/docs/project/specs/cli/scaffold-integrity-convergence/**,apps/wiki/content/docs/project/research/scaffold-integrity-root-cause-plan-research-report.md,docs/**,packages/scaffold/**,CHANGELOG.md,BASELINE_CHANGELOG.md] - wave_boundary: Wave 5; one integration owner after all implementation/docs handoffs.
- description: Review the combined diff findings-first. Resolve write-scope integration, remove obsolete prompting/duplicate policy created by the change, confirm no broad hash refresh or new path heuristic exists, and run narrow-to-wide validation. Inspect generated fixture diffs and archive security tests manually. Record any validation limitation instead of weakening gates.
- validation: Focused suites, CLI/scaffold checks, managed-assets integrity, root release verification, root tests, content routing, and diff hygiene all pass from a clean task worktree.
- status: Complete
- log: 2026-08-09 — Implementation integration, findings-first review, and validation merged through PR #112 as
7a88d0856831cba0bf9d38f0ccce3d6711d9c8e8. Protected-cache follow-ups merged through PR #114 as3f5f9622188ec96529b1efea3cd759b6a283d92dand PR #115 asc4dcca3134eace76750fa899f3b581411af094d0. Protected run 31245179530 passed at that exact head and restored both attestation tasks. The corrected open stack, #109 then #113, already inherits this complete scaffold implementation. 2026-08-10 — Strict projection health now keeps expected provider limitations and preserved project-owned prompts as neutral provenance with successful receipt/manifest status and empty scaffold degradations. Final focused consumer proof passed 30/30 with 121 assertions; the full six-scenario local gate exited 0 with clean remote checks and complete cleanup. The canceled3844fabCI candidate is superseded; fresh exact-head producer/replay remains pending. T8 local integration is complete. - files edited/created: Combined T1-T8 implementation, test, generated fixture, package scaffold, changelog, operator documentation, and project wiki paths recorded by the preceding task entries; final status artifacts are
PLAN.md,IMPLEMENTATION-NOTES.md, andPHASE-HANDOFF.mdin this folder. - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,create-plan,create-spec,docs-onboarding,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,implement-spec,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo,writing-beats,writing-for-agents,writing-fragments,writing-shape] - tdd_status: not_applicable
- tdd_target: Independent review and integrated validation of completed RED/GREEN slices.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd packages/scaffold test && bun run --cwd packages/scaffold check-types && bun run --cwd packages/scaffold check && bun run --cwd apps/cli test && bun run --cwd apps/cli check-types && bun run --cwd apps/cli check && bun run --cwd apps/cli fixtures:check:managed-assets && bun run --cwd apps/wiki check:content && bun run test:release && bun run release:verify && bun run test && git diff --check - reason_not_testable: Review/integration gate; underlying behavior has explicit RED/GREEN tasks.
- red_evidence:
- green_evidence: Local gates included producer, confined filesystem, lifecycle, update shards, public output, package scaffold, Effect, exact-package lint policy, formatter-stable generation, optional preset injection, root evidence, wiki content,
check:repo, CLI typecheck, formatting, and diff hygiene. The final strict consumer contract passed 30/30 with 121 assertions; the full local six-scenario gate exited 0, both remote checks returned success with empty issues/warnings/degradations, and cleanup retained no paths. Findings-first rereview reported no findings. PRs #112, #114, and #115 merged throughc4dcca3134; protected run 31245179530 restored exact remote hits for bothbuildandrelease:attest. This is local bundled/fixture evidence, not published or fresh exact-head proof. - codebase_design_notes: Reject fixes that silence warnings without converging bytes, that update receipts from untrusted observation, or that widen fixed ownership accidentally.
- review_mode: cli
- runtime_validation: required
- runtime_target: built local CLI lifecycle in disposable consumer repositories plus full repository verification
- runtime_evidence: Local disposable-consumer lifecycle passed 4/4 and the full update shard inventory passed 96/96 before the lint-policy integration follow-up. The strict installed-consumer rehearsal later passed 30/30 focused tests with 121 assertions and all six full scenarios; fresh init and every scaffold reported success, both remote checks were clean, and cleanup reported no retained paths. Package-scoped lint, formatter/injection, root-evidence, and serialized-attestation contracts pass locally. Protected run 31245179530 passed at
c4dcca3134; its attestation producer executed 2/2 tasks and its consumer restored the same 2/2 tasks remotely. Final exact-head CI remains pending because the3844fabcandidate was canceled. - runtime_cleanup: Remove only integration-created temp consumers after evidence capture; preserve release artifacts needed by T9.
T9: Publish And Prove Installed Consumer Convergence
- depends_on: [T8]
- location: clean release worktree and disposable downstream consumer repositories
- owned_paths: [
apps/cli/package.json,CHANGELOG.md,BASELINE_CHANGELOG.md,apps/cli/src/data/bundled-baseline-identity.generated.ts,apps/cli/test-fixtures/public-output/managed-assets.json,apps/wiki/content/docs/project/specs/cli/scaffold-integrity-convergence/PLAN.md] - wave_boundary: Wave 6; release owner only. No issue closes before all runtime proof is attached.
- description: Preserve
baseline/stable/2026.08.07-scaffold-integrity-convergenceatc4dcca3134as immutable predecessor evidence. After #117 merges, publish new candidatebaseline/stable/2026.08.10-projection-receipt-output-integritywith compatibility=3.1.6, then publish npm CLI 3.1.6, install both published authorities in fresh disposable consumers, and retain exact JSON plus artifact evidence for every row. The six-row installed-consumer matrix is the closure gate: fresh init, repeated scaffold, semantic context-plan formatting, packaged-bundled fixture/cache freshness, managed archive/replacement, and projection-receipt refresh. The deterministic fixture/cache authority serves a matching/manifest, buthi checkrefreshes metadata and archive bytes and verifies the archive's embedded baseline manifest instead of requesting that separate artifact, somanifestRequests: 0is intentional; the row is not published-stable evidence. Expected provider limitations and preserved project-owned prompts must remain neutral provenance withsuccess, empty issues/warnings/degradations, and emptyscaffoldDegradations; actual projection/application or missing managed canonical faults must fail. Attach issue evidence only after every row passes; otherwise retain typed failure evidence and leave all three issues open. - acceptance_mapping: #97 = fresh scaffold, semantically reserialize/format
.devpunks/context-plan.jsonwithout changing its JSON value, thenhi check --jsonstays clean and accepts the recorded semantic hash/evidence. #104 = deliberately edit one fixed managed file, observehi check --jsondrift, run unflaggedhi update, prove its archive and verified-baseline replacement, then prove the nexthi check --jsonis clean while existing project-owned exceptions remain silent. #105 = change one project-authored subagent description, run generatedsync-subagents, prove all four provider outputs and receiptrenderedOutputSha256change and later restore together, prove receipt bytes and semantic hash change, prove exactly the projection-receipt managed-manifest entry refreshes while unrelated entries and the manifest envelope remain identical, provehi check --jsonis clean, prove deliberate receipt-fingerprint corruption fails closed, and prove repeated restored sync is byte-stable. Primary backlog mapping remains GH-104, but closure evidence covers #97, #104, and #105. - validation: New stable tag ancestry and compatibility, registry/package identity, bundled identity and digest
1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98, installed CLI version, exact downstream--jsonoutputs, #97 raw-versus-semantic hash evidence, #104 archive hash/path and quiet-exception output, #105 provider-output hashes plus receipt fingerprint and single-entry manifest diff, strict projection-health status, final clean checks, restored idempotence, and the receipt-corruption negative control all agree. A local bundled run is rehearsal only. A failed publication or any incomplete published lifecycle row leaves issues open with typed evidence. - release_sequence: From a clean post-merge #117 release worktree, first run
BASELINE_VERSION=2026.08.10-projection-receipt-output-integrity BASELINE_CLI_VERSION_RANGE='=3.1.6' DP_CONTROL_PLANE_URL='<api-origin>' DP_BASELINE_PUBLISH_TOKEN='<redacted>' bun run baseline:publish. Verify the new stable tag, compatibility, manifest, archive, and control-plane readback while leaving the 2026.08.07 predecessor untouched. Next publish npm 3.1.6 through the protected entrypointgh workflow run behavior-contract.yml --ref main -f release_channel=latestand verify registry, tag, and GitHub release identity. Then runHI_IP346_PACKAGE_SPEC=@punks/cli@3.1.6 HI_IP346_BASELINE=stable HI_IP346_EXPECTED_BASELINE_VERSION=2026.08.10-projection-receipt-output-integrity bun run validate:consumer-repositories. Only after all six rows in that published-package run pass with empty issues, warnings, and degradations—five using published-stable authority plus the packaged-bundled fixture/cache row—may the operator attach issue-specific evidence and close #97, #104, and #105. - status: In Progress
- log: 2026-08-09 — Stable release
baseline/stable/2026.08.07-scaffold-integrity-convergencetargetsc4dcca3134. Control-plane promotion revision 12 and public stable readback agree on version, compatibility>=3.0.0 <4, manifest SHA-256e64d13f63db52870afa7b8fc6bc727e0ee6115dbe95df19116d2c1a9a09b9d77, and archive SHA-256d4f6788d01d36004111913b8c39825b173538e406fe0c6b9d7e254056880ae1e. Registry readback for@punks/cli@3.1.6returnsE404. 2026-08-10 — The strict local bundled rehearsal passed 30/30 focused tests with 121 assertions and all six full scenarios. Fresh init and every scaffold returned success, remote checks had empty issues/warnings/degradations, and cleanup retained no paths. Expected provider limitations and preserved prompts remain neutral provenance; legacy degradations refresh silently; actual faults fail. The fixed bundled digest is1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98. This local package and bundled/fixture authority are not release proof. The canceled3844fabCI candidate is superseded, so fresh exact-head CI is also pending. Candidatebaseline/stable/2026.08.10-projection-receipt-output-integritywith compatibility=3.1.6must be published after #117 merges and before npm 3.1.6. The exact published stable-plus-registry matrix and issue closure remain pending; T9 is not complete. - files edited/created:
- backlog_item_id: GH-104
- backlog_item_url: https://github.com/wearedevpunks/harness-intelligence/issues/104
- relation_mode: none
- assigned_skills: [
autoreview,codebase-design,create-plan,create-spec,effect,effect-backend-structure,effect-recoverable-actions,effect-service-design,implement-spec,improve-codebase-architecture,parallel-research,prototype,quality-types,review,simplify,swarm-planner,tdd,turborepo] - tdd_status: not_applicable
- tdd_target: Release and downstream proof of behavior already covered by T1-T8.
- red_command:
- expected_red_failure:
- green_command:
HI_IP346_PACKAGE_SPEC=@punks/cli@3.1.6 HI_IP346_BASELINE=stable HI_IP346_EXPECTED_BASELINE_VERSION=2026.08.10-projection-receipt-output-integrity bun run validate:consumer-repositories - reason_not_testable: External release operation gated by completed automated behavior tests.
- red_evidence:
- green_evidence: The 2026.08.07 predecessor tag ancestry, release assets, downloaded manifest, control-plane revision 12, and public readback agree exactly on commit/version/range and both artifact digests. The strict local bundled six-row rehearsal is green at digest
1c6d1157a133461a04bf281372ce824c8e2cc9b58e7c3c44ae7b2a2fbcf65b98. Both are incomplete T9 evidence only; neither proves the new candidate baseline or published npm package. - codebase_design_notes: Preserve the 2026.08.07 predecessor release exactly. Publish the new 2026.08.10 candidate from clean post-merge state, then publish npm from clean state. Never hand-edit bundled identity or a single managed-assets hash. Close no issue from rehearsal or predecessor proof.
- review_mode: cli
- runtime_validation: required
- runtime_target: published CLI 3.1.6 and
baseline/stable/2026.08.10-projection-receipt-output-integrityinstalled in fresh disposable consumer repositories - runtime_evidence: Predecessor stable authority and the strict local bundled six-row rehearsal are proven separately. The rehearsal passed 30/30 focused tests with 121 assertions and all six full scenarios, but used a local
@punks/cli@3.1.6package plus bundled/fixture authority. Its complete operation envelopes reported success with empty issues, warnings, and degradations; managed-hash proof covered 230/230 init entries and 229/229 scaffold entries, including legacy andScaffoldManagedcontent while skipping onlyProjectGenerated, with no-follow validation of safe internal symlinks. New candidate publication is pending, registry readback for@punks/cli@3.1.6returnsE404, and the canceled3844fabcandidate supplies no fresh exact-head evidence. After both authorities publish, capture their identities, install command, consumer commit/status, each command JSON payload, #97 raw/semantic hash evidence, #104 archive path/hash and project-owned quiet output, #105 provider-output hashes plus receiptrenderedOutputSha256, receipt bytes/hash, the single changed manifest entry and unchanged envelope, strict health status, restored idempotence, corruption failure, and issue comment URLs. - runtime_cleanup: Retain immutable registry/tag/issue evidence; remove only disposable local consumers after proof.
Test Strategy
Testing proceeds outside-in only after each narrow RED/GREEN cycle:
- pure recovery eligibility and exclusions;
- real confined-filesystem archive/race/rollback contracts;
- standalone producer success/failure/CAS/hash contracts;
- command/update integration and public output;
- scaffold-to-sync-to-check lifecycle;
- cross-issue installed-style matrix;
- full CLI, scaffold, wiki, release, and monorepo gates.
Required negative controls remain explicit: manual receipt/manifest corruption, actual fixed managed edits, stale producer evidence, unavailable baseline authority, concurrent archive/target changes, malformed manifest, and contradictory flags. Tests must distinguish clean, drift, operational failure, and recovery-required outcomes.
Risks And Shields
- Authority laundering: no receipt may be refreshed from arbitrary observed bytes; only verified baseline application or the exact named producer may publish its evidence.
- Ownership regression: eligibility is explicit effective ownership, not file kind or a new path list. Existing exception cases get dedicated silent tests.
- Data loss during replacement: persistent archive plus real race/rollback tests precede update integration.
- False success after apply: result and health are derived from post-commit observation; expected limitations/preservation remain neutral, actual faults fail, and acceptance asserts immediate clean check.
- Two-file crash window: documented honestly; CAS failure is retryable and truthful receipt is retained.
- Hash algorithm skew: producer/CLI parity vectors include reordered keys, formatting differences, Unicode, arrays, null, and malformed JSON.
- Fixture drift: regenerate the complete managed-assets fixture with
fixtures:update:managed-assets; validate with its check command. - Release skew: verify the immutable predecessor's identity and ancestry, never overwrite it, then publish the new baseline candidate before npm 3.1.6 from clean post-merge state and run the exact published-authority matrix.
Backlog Sync
Skipped. There is no retained agent-ready SPEC or stable provider projection relation for scaffold-integrity-convergence. GitHub issues #104 and #105 remain referenced delivery authority, but planning does not rewrite, relate, or close them.
Unresolved Questions
None.
The implementation may refine private type names and file splits during TDD, but it may not change the locked authority, silence, default-update, contradiction-error, archive, receipt-publication, or release contracts without returning to requirements.