Harness Intelligence Wiki
SpecsCLIManaged Format Hook

Plan: Manifest-Backed Scaffold Format-Hook Exclusion

Plan: Manifest-Backed Scaffold Format-Hook Exclusion

Initial Situation

The distributed automatic format hook excludes a partial hard-coded set of scaffold paths. Managed files outside that set, including workspace Oxlint configuration, can be rewritten after scaffold generation and then appear as false byte drift. The accepted spec and closed grill preserve raw scaffold bytes, keep CLI lifecycle commands formatter-free, and park all consumer-repository reconciliation.

Problem Statement

The hook needs one authoritative invocation-level ownership boundary: a valid .devpunks/scaffold-manifest.json. Every candidate listed in managedFiles must bypass formatting and linting. If that evidence is unavailable or invalid, the whole invocation must make no formatter or linter mutation. Eligible unmanaged paths must retain current behavior.

Proposed Solution Shape

Load and validate the repository-root manifest once at the existing formatAndLintFiles funnel. Build a normalized repository-relative managed-path set, reject the whole receipt on unsafe or invalid entries, and filter candidates against that set before command selection. Preserve .devpunks/scaffold-manifest.json as the sole bootstrap exclusion because it cannot recursively list and hash itself. Remove the broader hard-coded fallback. Prove behavior through public hook modes, prove archive/source byte identity, update operator guidance and both baseline changelogs, then publish a compatible stable baseline after review.

Resolved Decision Ledger

DecisionStatusPlanning consequence
Raw scaffold bytes remain authoritativeLockedDo not normalize desired output or run repository format commands from CLI lifecycles.
Receipt membership governs managed candidatesLockedNo lint, Oxlint, source-guide, skill, hook, or agent path allowlist.
Manifest file is the sole bootstrap exclusionLocked by implementation evidencePreserve only the evidence file outside receipt membership; it cannot self-hash recursively.
Invalid or unavailable receipt fails closedLockedReturn an empty mutation summary before formatter/linter subprocess execution.
Unmanaged behavior stays unchangedLockedKeep current resolver, command selection, reporting, and failure behavior.
Consumer reconciliation is separateLockedDo not run or mutate Collective Intelligence.
Ship through stable baselineLockedNo npm version/schema work unless implementation disproves the current asset-only path.
Backlog projection is skippedLockedNo provider items or synchronization.

Assumptions and Constraints

  • Canonical hook source is apps/cli/src/data/hooks/format-edited-file.mjs; generated .agents and provider mirrors are not edited.
  • Manifest authority is the Git repository root, including candidates reported from nested workspaces.
  • A valid receipt requires managedFiles to be an array whose entries all contain safe, non-empty repository-relative path strings. Any invalid entry invalidates the invocation.
  • The standalone distributed .mjs remains dependency-free; it does not import package schemas.
  • No scaffold schema, desired bytes, ownership classification, source-guide replacement policy, or npm package version changes are planned.
  • Existing unrelated hi check drift and wiki metadata warnings stay out of scope.
  • Publication uses bun run baseline:publish from a clean release worktree with the existing >=3.0.0 <4 compatibility policy.

Dependency Readiness

No Stack Required.

The managed-file receipt, hook catalog, baseline archive builder, and compatible CLI 3.1.4 distribution contract already exist. bun install --frozen-lockfile completed without changing bun.lock, so the planned Vitest, Oxfmt, Oxlint, TypeScript, and Turbo validation commands are available.

Branch/Base Intent

  • Base: main at 441d87f5 (v3.1.4).
  • Delivery branch: team/stefan/investigate-generated-file-triggers.
  • Preserve the branch's existing spec commit and planning artifacts.
  • Keep Collective Intelligence reconciliation, unrelated scaffold divergence, and provider backlog projection outside this branch.

Codebase Findings

  • All Claude/Cursor, Codex, direct-files, and OpenCode-delegated mutations converge at formatAndLintFiles in the canonical hook.
  • Existing hook tests cover only the partial helper rule. The direct files fixture provides a public executable seam; Codex requires session-start state before post.
  • apps/cli/src/data/catalog/hooks.ts registers the canonical hook and the baseline builder copies it into the archive.
  • .devpunks/scaffold-manifest.json is written after its managedFiles collection is computed, so it cannot be a member of its own hashed receipt.
  • Operator docs currently describe the obsolete partial exclusion. Main and baseline changelogs are both required for a baseline release.

External Research Used

No external dependency research was required. The behavior is owned by repository code, receipt schema, tests, and release scripts.

Dependency Graph

[T1 hook behavior, T2 archive contract, T3 docs/release notes] -> T4A hook-derived bundled fixture reconciliation -> T4B current-main skill fixture reconciliation -> T4 aggregate validation
T4 -> mandatory review -> T4C OpenCode adapter proof -> docs closeout -> T5 clean stable-baseline publication

Parallel Execution Waves

WaveTasksStart conditionWrite-scope rule
W1T1, T2, T3Plan approvedThree disjoint owners: hook behavior, archive contract, docs/release artifacts.
W2T4A, T4B, T4T1-T3 greenReconcile deterministic derived fixtures, then run aggregate validation.
W3T4C, T5T4 green plus mandatory reviewClose the review evidence gap, then publish reviewed bytes after docs closeout.

Testing Strategy

  • RED first through the public hook executable: a valid receipt-managed apps/web/oxlint.config.ts currently reaches fake formatter/linter commands, and missing/invalid receipts currently do not fail closed.
  • GREEN proves managed bytes and subprocess logs remain untouched across candidate-producing modes, while an equivalent unmanaged path still formats/lints.
  • Table-drive missing, unreadable, malformed, invalid collection, and unsafe-entry cases.
  • Strengthen the existing baseline extraction contract with byte-for-byte comparison to the canonical hook source.
  • Run focused tests before the broader CLI, docs, archive, formatting, and diff gates.

Tasks

T1: Test-drive manifest-backed hook ownership

  • depends_on: []
  • location: apps/cli/src/data/hooks/format-edited-file.mjs; apps/cli/src/data/hooks.test.ts
  • owned_paths: [apps/cli/src/data/hooks/format-edited-file.mjs, apps/cli/src/data/hooks.test.ts]
  • wave_boundary: W1
  • description: On team/stefan/investigate-generated-file-triggers based on 441d87f5, preserve the existing planning commits. Through public hook invocations, add one invocation-level manifest loader and safe normalized managed-path set at formatAndLintFiles. Skip receipt-managed candidates plus the manifest bootstrap file, remove the broader hard-coded fallback, fail the whole invocation closed for missing/unreadable/malformed/structurally invalid/unsafe receipts, and preserve unmanaged formatting/linting and reporting. Cover direct files, Claude/Cursor, Codex session-start/post, and OpenCode through its files delegation without testing unrelated path extraction.
  • validation: Managed and invalid-authority fixtures leave bytes unchanged and create no fake formatter/linter log; an equivalent unmanaged fixture mutates and retains existing lint/reporting behavior; nested workspace candidates use the Git-root receipt.
  • status: Completed
  • log: 2026-08-06 — Test-drove receipt authority through the public executable. The hook now loads and validates the Git-root receipt once at the shared mutation funnel, skips receipt members and only the manifest bootstrap file, fails closed before subprocess execution for unavailable/invalid evidence, and preserves unmanaged behavior. Permission-independent unreadable coverage uses a real EISDIR read failure.
  • files edited/created: apps/cli/src/data/hooks/format-edited-file.mjs; apps/cli/src/data/hooks.test.ts
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [autoreview, codebase-design, effect-backend-structure, effect, effect-recoverable-actions, improve-codebase-architecture, parallel-research, quality-types, simplify, swarm-planner, tdd, turborepo]
  • tdd_status: required
  • tdd_target: A valid receipt-managed formattable/lintable path is currently mutated, and invalid or missing receipt evidence currently permits mutation.
  • red_command: bun run --cwd apps/cli test -- src/data/hooks.test.ts
  • expected_red_failure: Public managed-path and fail-closed assertions observe changed bytes or fake formatter/linter subprocess entries.
  • green_command: bun run --cwd apps/cli test -- src/data/hooks.test.ts && bun run --cwd apps/cli check-types
  • reason_not_testable:
  • red_evidence: Exact focused RED exited 1 with 1 failure and 10 passes: public files mode rewrote receipt-managed apps/web/oxlint.config.ts from its original bytes to formatted\n, proving both the mutation and subprocess defect.
  • green_evidence: Exact focused GREEN passed 19/19 and CLI typecheck passed. Parent combined W1 rerun passed 42/42 across hook, archive, and release-note tests; scoped Oxfmt and git diff --check passed.
  • codebase_design_notes: Keep manifest loading local to the neutral distributed hook and inject the resulting set into candidate normalization at the single mutation funnel. Do not couple the asset to Effect or package schema resolution.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T2: Lock baseline archive bytes to the tested hook source

  • depends_on: []
  • location: apps/cli/src/baseline/baseline-release-scripts.test.ts
  • owned_paths: [apps/cli/src/baseline/baseline-release-scripts.test.ts]
  • wave_boundary: W1
  • description: Extend the existing baseline build-and-extract contract to compare the archived data/hooks/format-edited-file.mjs bytes with the canonical source while retaining compatibility and digest assertions.
  • validation: The focused release-script test proves the built archive contains the exact canonical hook bytes.
  • status: Completed
  • log: 2026-08-06 — Added raw buffer equality between the extracted baseline hook and canonical source inside the existing reproducibility/build contract. No builder, catalog, or production path changed.
  • files edited/created: apps/cli/src/baseline/baseline-release-scripts.test.ts
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [autoreview, codebase-design, effect-backend-structure, effect, effect-recoverable-actions, improve-codebase-architecture, parallel-research, quality-types, simplify, swarm-planner, tdd, turborepo]
  • tdd_status: not_applicable
  • tdd_target: Verification-only strengthening of an existing copy contract; the builder already copies canonical bytes, so a truthful pre-change RED is unavailable.
  • red_command: not_applicable
  • expected_red_failure: not_applicable
  • green_command: bun run --cwd apps/cli test -- src/baseline/baseline-release-scripts.test.ts
  • reason_not_testable: The new assertion verifies an already-existing distribution mechanism rather than changing its behavior.
  • red_evidence: not_applicable; the existing builder already copied canonical bytes.
  • green_evidence: Focused suite passed 19/19. Direct archive/source cmp, scoped Oxfmt, and diff checks passed; parent combined W1 rerun also passed.
  • codebase_design_notes: Test the catalog-to-archive distribution seam; do not modify the builder or create a second hook ledger.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T3: Update operator guidance and baseline release notes

  • depends_on: []
  • location: operator docs, hook concept, and release changelogs
  • owned_paths: [docs/README.md, docs/runbooks/hi-cli-scaffolding.md, apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md, apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx, CHANGELOG.md, BASELINE_CHANGELOG.md]
  • wave_boundary: W1
  • description: Replace partial-exclusion wording with receipt-backed exclusion, the manifest bootstrap exception, fail-closed invalid-authority behavior, unchanged unmanaged behavior, and the manual-format boundary. Add matching baseline/stable/2026.08.06-managed-format-hook entries to both changelogs without an npm semver bump. Keep the root/wiki runbook projections aligned without broad content synchronization that would absorb unrelated metadata drift.
  • validation: Both changelogs contain the exact baseline tag; root and wiki runbooks carry equivalent guidance; scoped Markdown/JSON formatting and diff checks pass. The global wiki content check is observed separately because it has two pre-existing out-of-scope metadata findings.
  • status: Completed
  • log: 2026-08-06 — Updated operator, runbook, and hook-concept guidance for receipt-backed exclusion, the sole manifest bootstrap exception, fail-closed authority, unchanged unmanaged behavior, and the manual-format boundary. Added matching baseline-only release entries with no npm semver bump.
  • files edited/created: docs/README.md; docs/runbooks/hi-cli-scaffolding.md; apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md; apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx; CHANGELOG.md; BASELINE_CHANGELOG.md
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [autoreview, codebase-design, docs-onboarding, improve-codebase-architecture, parallel-research, simplify, tdd, writing-beats, writing-for-agents, writing-fragments, writing-shape, create-spec, create-plan, implement-spec]
  • tdd_status: not_applicable
  • tdd_target: Documentation and release bookkeeping only.
  • red_command: not_applicable
  • expected_red_failure: not_applicable
  • green_command: bun run --cwd apps/cli test -- src/scripts/release-notes.test.ts && test "$(rg -l '^## baseline/stable/2026\.08\.06-managed-format-hook - 2026-08-06$' CHANGELOG.md BASELINE_CHANGELOG.md | wc -l | tr -d ' ')" = 2 && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx CHANGELOG.md BASELINE_CHANGELOG.md && git diff --check
  • reason_not_testable: No production behavior changes in this task; release-note and content validators are the executable contract.
  • red_evidence: not_applicable; documentation and release bookkeeping only.
  • green_evidence: Release-note suite passed 4/4; the exact baseline heading occurs once in each changelog; all six owned files pass Oxfmt and diff checks. Root/wiki runbook guidance is byte-identical.
  • codebase_design_notes: Document the hook boundary at operator and concept surfaces; do not broaden CLI lifecycle ownership.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T4A: Reconcile generated bundled identity and derived public-context fixture

  • depends_on: [T1]
  • location: generated bundled identity and public context outcome fixture
  • owned_paths: [apps/cli/src/data/bundled-baseline-identity.generated.ts, apps/cli/test-fixtures/public-output/context-outcome.json]
  • wave_boundary: W2 recovery before T4 rerun
  • description: Preserve the digest generated by build-dist.mjs from the changed canonical hook asset and update only the derived context-outcome.json provenance digest/sha256. Do not change managed-assets.json: its manifest-derived file hashes already match and the hook is not part of that fixture inventory. This is build/fixture reconciliation, not an npm version bump or new behavior.
  • validation: A fresh CLI build reproduces the checked-in generated digest; the public context contract passes with the fixture aligned; no other fixture changes.
  • status: Completed
  • log: 2026-08-06 — The first supported release-suite run exposed two public-context failures because the hook changed the generated bundled digest while the derived outcome fixture retained the previous digest. The manifest-derived managed-assets fixture still passed and remains untouched.
  • files edited/created: apps/cli/src/data/bundled-baseline-identity.generated.ts; apps/cli/test-fixtures/public-output/context-outcome.json
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [autoreview, codebase-design, effect-backend-structure, effect, effect-recoverable-actions, improve-codebase-architecture, parallel-research, quality-types, simplify, swarm-planner, tdd, turborepo]
  • tdd_status: not_applicable
  • tdd_target: Generated identity and derived fixture bookkeeping caused by the accepted asset change.
  • red_command: bun run --cwd apps/cli build && bun run --cwd apps/cli test:release
  • expected_red_failure: Public context fixture still reports the prior bundled digest in exactly two assertions.
  • green_command: bun run --cwd apps/cli build && bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts
  • reason_not_testable: The behavior RED belongs to T1; this task reconciles deterministic generated and derived evidence.
  • red_evidence: Supported release runner passed all 96 update-shard tests, then passed 81/82 files and 1105/1107 tests; only the public context contract's bundled digest and derived outcome equality failed.
  • green_evidence: Fresh build deterministically generated 24e037717f33eb1c7f33d35e7daf5651882d5191322916a23d2144920c44a5bc; only fixture provenance digest and sha256 changed. Public context contract passed 20/20, scoped Oxfmt and diff checks passed, and managed-assets.json remained untouched. The supported release runner then passed 96/96 update-shard tests plus 82/82 files and 1107/1107 tests.
  • codebase_design_notes: Keep the existing build generator and public-context fixture seam. Do not add a ledger or broaden the managed-assets fixture.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T4B: Reconcile current-main bundled skill fixture hashes

  • depends_on: [T4A]
  • location: manifest-derived managed-assets fixture
  • owned_paths: [apps/cli/test-fixtures/public-output/managed-assets.json]
  • wave_boundary: W2 integration recovery before T4 rerun
  • description: After integrating current origin/main, update exactly the three existing hashes for the already-released parallel-research and requirements-grill bundled skill bytes. Do not add inventory entries, change hook-related hashes, or alter fixture structure. This preserves current-main baseline contents instead of publishing an older baseline that would drop them.
  • validation: The three fixture hashes equal the current canonical skill bytes; public context contract passes 20/20; no other managed-assets entry changes.
  • status: Completed
  • log: 2026-08-06 — Current-main integration added the two latest stable-baseline skill changes. Their existing manifest-derived fixture entries retained the prior hashes and caused one focused public-context failure after the bundled provenance digest was reconciled.
  • files edited/created: apps/cli/test-fixtures/public-output/managed-assets.json
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [autoreview, codebase-design, effect-backend-structure, effect, effect-recoverable-actions, improve-codebase-architecture, parallel-research, quality-types, simplify, swarm-planner, tdd, turborepo]
  • tdd_status: not_applicable
  • tdd_target: Derived fixture bookkeeping for current-main baseline assets.
  • red_command: bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts
  • expected_red_failure: The managed byte contract reports exactly three stale skill hashes.
  • green_command: bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts
  • reason_not_testable: This task reconciles manifest-derived fixture evidence for already-accepted mainline skill bytes.
  • red_evidence: Focused contract passed provenance and 19/20 tests, then failed the managed-byte assertion for exactly the two parallel-research files and one requirements-grill file.
  • green_evidence: Exactly three existing hashes changed to match canonical current-main skill bytes. Public context contract passed 20/20; scoped Oxfmt and diff checks passed; inventory shape and every other hash remained unchanged.
  • codebase_design_notes: Keep the current manifest-derived fixture seam and update only existing entries; do not create a second fixture authority.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T4: Run aggregate CLI, documentation, and archive validation

  • depends_on: [T1, T2, T3, T4A, T4B]
  • location: repository validation surfaces; plan evidence
  • owned_paths: [apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md]
  • wave_boundary: W2
  • description: Independently rerun the focused suites, full CLI suite, CLI checks, scoped wiki/docs checks, explicit compatible baseline build, archive/source byte comparison, formatting/diff checks, and scope audit. Record exact evidence in this plan. Observe the global wiki content check and record its two known out-of-scope metadata findings separately. Do not run hi update --write or modify generated scaffold mirrors.
  • validation: All owned behavior and distribution gates pass; the global wiki check reports only content/docs/project/specs/cli/meta.json and content/docs/project/specs/cli/project-generated-managed-file-ownership/meta.json as pre-existing debt.
  • status: Completed
  • log: 2026-08-06 — Final current-main merged validation passed the supported release topology, CLI static/type gates, deterministic fixture checks, exact stable-baseline build, archive/source hook comparison, scoped docs formatting, release headings, and diff checks. Global wiki content validation reports only the two recorded pre-existing CLI metadata findings. The root Turbo command requires --env-mode=loose to propagate explicit release identity; the verified release command records it.
  • files edited/created: apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [create-spec, create-plan, implement-spec, simplify, turborepo]
  • tdd_status: not_applicable
  • tdd_target: Aggregate verification after behavior TDD.
  • red_command: not_applicable
  • expected_red_failure: not_applicable
  • green_command: bun run --cwd apps/cli build && bun run --cwd apps/cli test:release && bun run --cwd apps/cli check && bun run --cwd apps/cli check-types && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx CHANGELOG.md BASELINE_CHANGELOG.md && BASELINE_VERSION=2026.08.06-managed-format-hook BASELINE_CLI_VERSION_RANGE='>=3.0.0 <4' bun run baseline:build -- --env-mode=loose && tar -xOf apps/cli/dist/baseline/scaffold-baseline.tgz ./data/hooks/format-edited-file.mjs | cmp - apps/cli/src/data/hooks/format-edited-file.mjs && git diff --check
  • reason_not_testable: Validation-only task; T1 owns the behavior RED/GREEN cycle.
  • red_evidence:
  • green_evidence: Final merged commit build plus test:release passed 96/96 update-shard tests, then 82/82 files and 1107/1107 tests. CLI Oxlint/Oxfmt checked 346 files; typecheck passed. Root baseline build with loose env produced exact tag baseline/stable/2026.08.06-managed-format-hook, compatibility >=3.0.0 <4, archive SHA-256 8955f4b1b02080683cb145a5fafd9a5f0299cef3971c9a289a5cede0fdc1d4b7, and archived hook bytes equal canonical source. Exact release headings, scoped docs Oxfmt, and git diff --check passed. Global wiki check reports only the two pre-existing metadata findings named in validation.
  • codebase_design_notes: Verify the public hook, catalog/archive boundary, docs, and release artifacts without adding implementation.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T4C: Prove the OpenCode adapter reaches the managed-file boundary

  • depends_on: [T4]
  • location: apps/cli/src/data/hooks.test.ts
  • owned_paths: [apps/cli/src/data/hooks.test.ts]
  • wave_boundary: W3 review recovery
  • description: Close the mandatory spec-review evidence gap with the smallest direct public-contract test of FormatAndLintPlugin. Invoke its tool.execute.after adapter for a manifest-managed edited file and prove the delegated hook leaves bytes unchanged without formatter/linter subprocess evidence. Do not change production behavior or add unrelated OpenCode path-extraction coverage.
  • validation: Focused hook tests and scoped CLI static checks pass with the OpenCode adapter exercised directly.
  • status: Completed
  • log: 2026-08-06 — Mandatory spec review found that shared files-mode coverage proved the delegated behavior but did not directly exercise the OpenCode adapter. Added the direct public-contract test without production changes.
  • files edited/created: apps/cli/src/data/hooks.test.ts; apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [review-phase, tdd, simplify]
  • tdd_status: not_applicable
  • tdd_target: Verification-only coverage of an adapter that already delegates to the tested public files mode.
  • red_command: not_applicable
  • expected_red_failure: not_applicable
  • green_command: bun run --cwd apps/cli test -- src/data/hooks.test.ts && bun run --cwd apps/cli check && bun run --cwd apps/cli check-types
  • reason_not_testable: The adapter already delegates to the implemented ownership funnel, so a truthful behavior RED is unavailable; the review gap is missing direct evidence.
  • red_evidence: not_applicable
  • green_evidence: Direct OpenCode adapter coverage passed in the focused hook suite, 20/20. The managed file retained its original bytes, the fake formatter/linter log was absent, and scoped Oxlint, Oxfmt, and diff checks passed.
  • codebase_design_notes: Test the public adapter boundary without introducing another ownership rule or production seam.
  • review_mode: cli
  • runtime_validation: not_required
  • runtime_target: not_applicable
  • runtime_evidence: not_applicable
  • runtime_cleanup: not_applicable

T5: Publish and verify the reviewed stable baseline

  • depends_on: [T4C]
  • location: clean release worktree and stable baseline authority
  • owned_paths: []
  • wave_boundary: W3 after mandatory review and docs-ingest phases
  • description: After the delivery router records a clean mandatory review and documentation closeout, commit and push every reviewed source artifact. Create a clean release worktree at that exact commit and run the root supported baseline publisher for baseline/stable/2026.08.06-managed-format-hook with compatibility >=3.0.0 <4. Verify the promoted stable revision, manifest record, archive record, and exact hook bytes. Do not publish npm and do not mutate any consumer repository.
  • validation: The supported publisher completes from a clean worktree; stable authority resolves the exact new tag/revision; published manifest/archive digests and archived hook bytes match the reviewed build.
  • status: Completed
  • log: 2026-08-06 — Published from clean detached worktree commit b8a8b694a5143f681dd770ffc3c8ea7f99310e07 with the supported root command and --env-mode=loose. GitHub release baseline/stable/2026.08.06-managed-format-hook is non-draft and non-prerelease. The control plane committed revision 9 after revision 8 with compatibility >=3.0.0 <4. Independent readback proved exact manifest identity and archive/source hook byte equality. Publication from detached HEAD initially created the Git tag at default-branch 2c6a35eb; verification caught the mismatch and the exact new tag was corrected to manifest commit b8a8b694 before closeout.
  • files edited/created:
  • backlog_item_id: not_applicable
  • backlog_item_url: not_applicable
  • relation_mode: not_applicable
  • assigned_skills: [implement-spec, turborepo, simplify]
  • tdd_status: not_applicable
  • tdd_target: Credential-backed external publication of already tested bytes.
  • red_command: not_applicable
  • expected_red_failure: not_applicable
  • green_command: BASELINE_VERSION=2026.08.06-managed-format-hook BASELINE_CLI_VERSION_RANGE='>=3.0.0 <4' bun run baseline:publish -- --env-mode=loose
  • reason_not_testable: Publication is an external release operation; T1-T4 own code and artifact test coverage.
  • red_evidence:
  • green_evidence: Supported publication completed from clean detached commit b8a8b694a5143f681dd770ffc3c8ea7f99310e07. Independent GitHub readback found release baseline/stable/2026.08.06-managed-format-hook non-draft and non-prerelease. Control-plane outcome was committed revision 9, previous revision 8, with compatibility >=3.0.0 <4. Manifest asset 504004763 has SHA-256 d3d038b090e0fdd49a5ece6816c9beb75bd1957de081895c7f4f02be07fbd16d; its commit, tag, version, and range are exact. Archive asset 504004778 has SHA-256 081680c429cbfa81879097222a3c32816c86ff5ef46fa4d0b8fd927ff00f3fff; its archived hook bytes match canonical source by cmp. Final git ls-remote resolves the release tag to b8a8b694a5143f681dd770ffc3c8ea7f99310e07 after correcting the detached-HEAD default-target mismatch.
  • codebase_design_notes: Use the supported root release command; do not call the implementation script directly or add a second promotion path.
  • review_mode: cli
  • runtime_validation: required
  • runtime_target: Stable baseline authority and immutable GitHub release assets.
  • runtime_evidence: Exact stable tag/revision plus manifest/archive digest readback and byte identity for data/hooks/format-edited-file.mjs.
  • runtime_cleanup: Removed /tmp/hi-managed-format-release-EcUwBl through git worktree remove after verification. Stable release facts and assets remain as intentional durable outputs.

Review, Documentation, and Release Gates

  • Spec rereview and automated branch review are clean after T4C closed the OpenCode adapter evidence gap; Standards review remained clean. The focused hook suite passed 20/20 with unchanged managed bytes and no formatter/linter subprocess evidence.
  • Private/internal documentation ingestion completed on 2026-08-06. Existing runbook and hook projections already capture the proven behavior, so no new flow, concept, route, or metadata write was needed.
  • T5 completed from clean detached commit b8a8b694a5143f681dd770ffc3c8ea7f99310e07 using the supported publisher with Turbo loose environment mode.
  • Stable revision 9 and the GitHub manifest/archive records passed independent readback. No npm release or Collective Intelligence reconciliation occurred.

Risks and Mitigations

  • Unsafe receipt path bypass: reject the entire receipt on absolute, empty, root, or escaping paths; compare normalized repository-relative values only.
  • Partial fallback reappears: delete the broader hard-coded list and assert representative formerly missed managed paths through the public executable.
  • Nested workspace reads wrong authority: resolve Git root first and load its manifest once.
  • Mode-specific mutation bypass: test every candidate-producing mode at the shared funnel; treat OpenCode delegation as the files seam.
  • Generated-mirror churn: edit only canonical hook source and explicitly owned docs; never run write reconciliation.
  • Release mismatch: permanent archive byte test plus clean-worktree publication and exact tag release notes.

Unresolved Questions

None. Consumer reconciliation, existing consumer drift, and backlog projection are explicitly parked rather than unresolved.

On this page