SpecsCLIManaged Format Hook
Implementation Notes: Manifest-Backed Scaffold Format-Hook Exclusion
Implementation Notes: Manifest-Backed Scaffold Format-Hook Exclusion
Summary
- Implementation, aggregate validation, mandatory review recovery, private/internal docs ingestion, and stable-baseline publication are complete.
Deviations From the Plan
- Aggregate validation exposed the expected generated bundled-digest change from editing a baseline asset. Added T4A to reconcile the generated identity and only the derived public-context provenance fixture;
managed-assets.jsonremained authoritative and unchanged.
Surprises and Decisions
- Follow-up review found three shipped-state gaps. Path checks were lexical, so a repository symlink could send formatter writes outside the repository. Codex trusted every path parsed from a successful patch command even when that path was unchanged, and it did not recheck the observed digest before invoking the formatter. OpenCode's tracked config and projection receipt still retained the removed native formatter alongside the plugin. The repair adds realpath confinement, changed-path intersection, a last-moment digest gate, and canonical projection regeneration. Codex itself invokes
PostToolUseonly after a successful tool result, so no duplicate local success parser was added. - Planning confirmed that
.devpunks/scaffold-manifest.jsoncannot recursively list and hash itself. It is the sole bootstrap exclusion; all other managed exclusions come from a valid receipt. - The generic one-process Vitest runner is not the release gate: its baseline artifact mutation can invalidate later bundled-identity reads. The repository-supported
test:releasetopology passed after the generated identity/fixture reconciliation. - Mandatory spec review found one evidence gap: OpenCode delegated through tested
filesbehavior but its adapter was not invoked directly. T4C added that public-contract proof without changing production behavior. - Autoreview suggested marking managed or fail-closed Codex candidates as processed. That was rejected: retrying after manifest authority is restored or ownership changes is intentional, and repeat posts still invoke no formatter or linter for skipped candidates.
- The publisher ran from detached HEAD and initially let GitHub create the release tag at the default branch instead of the manifest commit. Independent tag readback caught it; the exact new tag was corrected from
2c6a35ebto reviewed commitb8a8b694before closeout.
Sanity Checks
| Check | Result | Notes |
|---|---|---|
bun install --frozen-lockfile | Pass | Dependencies restored; bun.lock unchanged. |
| Focused W1 suites | Pass | 3 files and 42 tests passed. |
| OpenCode review recovery | Pass | Direct adapter coverage raised the focused hook suite to 20/20 with no subprocess evidence. |
| Mandatory review | Pass | Spec rereview and automated branch review are clean after T4C; Standards review remained clean. |
| CLI typecheck | Pass | tsc --noEmit exited 0. |
| Scoped Oxfmt and diff checks | Pass | All W1-owned paths matched formatting; git diff --check exited 0. |
| Public context fixture | Pass | Fresh build plus focused contract passed 20/20; generated digest and fixture provenance agree. |
| Supported CLI release suite | Pass | Update shards 96/96; remaining suite 82 files and 1107 tests. |
| Final merged CLI static gates | Pass | Oxlint/Oxfmt checked 346 files; TypeScript check passed. |
| Exact baseline build | Pass | Exact tag/range and archived-hook byte identity passed; archive SHA-256 8955f4b1…d1d4b7. |
| Stable baseline publication | Pass | Revision 9 committed after revision 8; independent GitHub and asset readback passed. |
| Wiki content check | Known pre-existing failure | Only the two recorded out-of-scope CLI metadata findings remain. |
Acceptance Criteria Status
| Criterion | Status | Notes |
|---|---|---|
| AC-001 through AC-006 | Met in focused validation | Public managed/unmanaged/fail-closed behavior and every adapter surface passed 20/20 tests. |
| AC-007 | Met | Published manifest/archive identity, compatibility, digests, and canonical hook bytes pass. |
| AC-008 | Met in focused validation | No desired-state, ownership, source-guide, schema, npm, or consumer changes. |
Pre-existing Issues
bun run --cwd apps/wiki check:contentreports stalecontent/docs/project/specs/cli/meta.jsonand missingcontent/docs/project/specs/cli/project-generated-managed-file-ownership/meta.json; neither belongs to this implementation.
Out of Scope Observations
- Collective Intelligence reconciliation and its existing drift remain parked for Stefan as a separate follow-up.
- Provider backlog projection was explicitly skipped.
Remaining Work
- None within this scope. Consumer reconciliation remains out of scope.
Steering
| Date | Feedback | Changes |
|---|---|---|
| 2026-08-06 | Skip backlog; execute delivery fully in parallel; preserve all grill decisions. | Planned three disjoint W1 tasks, no consumer mutation, and a baseline-only release. |