Plan: Manifest-Backed Scaffold Format-Hook Exclusion
Plan: Manifest-Backed Scaffold Format-Hook Exclusion
Initial Situation
The distributed automatic format hook excludes a partial hard-coded set of scaffold paths. Managed files outside that set, including workspace Oxlint configuration, can be rewritten after scaffold generation and then appear as false byte drift. The accepted spec and closed grill preserve raw scaffold bytes, keep CLI lifecycle commands formatter-free, and park all consumer-repository reconciliation.
Problem Statement
The hook needs one authoritative invocation-level ownership boundary: a valid .devpunks/scaffold-manifest.json. Every candidate listed in managedFiles must bypass formatting and linting. If that evidence is unavailable or invalid, the whole invocation must make no formatter or linter mutation. Eligible unmanaged paths must retain current behavior.
Proposed Solution Shape
Load and validate the repository-root manifest once at the existing formatAndLintFiles funnel. Build a normalized repository-relative managed-path set, reject the whole receipt on unsafe or invalid entries, and filter candidates against that set before command selection. Preserve .devpunks/scaffold-manifest.json as the sole bootstrap exclusion because it cannot recursively list and hash itself. Remove the broader hard-coded fallback. Prove behavior through public hook modes, prove archive/source byte identity, update operator guidance and both baseline changelogs, then publish a compatible stable baseline after review.
Resolved Decision Ledger
| Decision | Status | Planning consequence |
|---|---|---|
| Raw scaffold bytes remain authoritative | Locked | Do not normalize desired output or run repository format commands from CLI lifecycles. |
| Receipt membership governs managed candidates | Locked | No lint, Oxlint, source-guide, skill, hook, or agent path allowlist. |
| Manifest file is the sole bootstrap exclusion | Locked by implementation evidence | Preserve only the evidence file outside receipt membership; it cannot self-hash recursively. |
| Invalid or unavailable receipt fails closed | Locked | Return an empty mutation summary before formatter/linter subprocess execution. |
| Unmanaged behavior stays unchanged | Locked | Keep current resolver, command selection, reporting, and failure behavior. |
| Consumer reconciliation is separate | Locked | Do not run or mutate Collective Intelligence. |
| Ship through stable baseline | Locked | No npm version/schema work unless implementation disproves the current asset-only path. |
| Backlog projection is skipped | Locked | No provider items or synchronization. |
Assumptions and Constraints
- Canonical hook source is
apps/cli/src/data/hooks/format-edited-file.mjs; generated.agentsand provider mirrors are not edited. - Manifest authority is the Git repository root, including candidates reported from nested workspaces.
- A valid receipt requires
managedFilesto be an array whose entries all contain safe, non-empty repository-relativepathstrings. Any invalid entry invalidates the invocation. - The standalone distributed
.mjsremains dependency-free; it does not import package schemas. - No scaffold schema, desired bytes, ownership classification, source-guide replacement policy, or npm package version changes are planned.
- Existing unrelated
hi checkdrift and wiki metadata warnings stay out of scope. - Publication uses
bun run baseline:publishfrom a clean release worktree with the existing>=3.0.0 <4compatibility policy.
Dependency Readiness
No Stack Required.
The managed-file receipt, hook catalog, baseline archive builder, and compatible CLI 3.1.4 distribution contract already exist. bun install --frozen-lockfile completed without changing bun.lock, so the planned Vitest, Oxfmt, Oxlint, TypeScript, and Turbo validation commands are available.
Branch/Base Intent
- Base:
mainat441d87f5(v3.1.4). - Delivery branch:
team/stefan/investigate-generated-file-triggers. - Preserve the branch's existing spec commit and planning artifacts.
- Keep Collective Intelligence reconciliation, unrelated scaffold divergence, and provider backlog projection outside this branch.
Codebase Findings
- All Claude/Cursor, Codex, direct-files, and OpenCode-delegated mutations converge at
formatAndLintFilesin the canonical hook. - Existing hook tests cover only the partial helper rule. The direct
filesfixture provides a public executable seam; Codex requires session-start state before post. apps/cli/src/data/catalog/hooks.tsregisters the canonical hook and the baseline builder copies it into the archive..devpunks/scaffold-manifest.jsonis written after itsmanagedFilescollection is computed, so it cannot be a member of its own hashed receipt.- Operator docs currently describe the obsolete partial exclusion. Main and baseline changelogs are both required for a baseline release.
External Research Used
No external dependency research was required. The behavior is owned by repository code, receipt schema, tests, and release scripts.
Dependency Graph
[T1 hook behavior, T2 archive contract, T3 docs/release notes] -> T4A hook-derived bundled fixture reconciliation -> T4B current-main skill fixture reconciliation -> T4 aggregate validation
T4 -> mandatory review -> T4C OpenCode adapter proof -> docs closeout -> T5 clean stable-baseline publicationParallel Execution Waves
| Wave | Tasks | Start condition | Write-scope rule |
|---|---|---|---|
| W1 | T1, T2, T3 | Plan approved | Three disjoint owners: hook behavior, archive contract, docs/release artifacts. |
| W2 | T4A, T4B, T4 | T1-T3 green | Reconcile deterministic derived fixtures, then run aggregate validation. |
| W3 | T4C, T5 | T4 green plus mandatory review | Close the review evidence gap, then publish reviewed bytes after docs closeout. |
Testing Strategy
- RED first through the public hook executable: a valid receipt-managed
apps/web/oxlint.config.tscurrently reaches fake formatter/linter commands, and missing/invalid receipts currently do not fail closed. - GREEN proves managed bytes and subprocess logs remain untouched across candidate-producing modes, while an equivalent unmanaged path still formats/lints.
- Table-drive missing, unreadable, malformed, invalid collection, and unsafe-entry cases.
- Strengthen the existing baseline extraction contract with byte-for-byte comparison to the canonical hook source.
- Run focused tests before the broader CLI, docs, archive, formatting, and diff gates.
Tasks
T1: Test-drive manifest-backed hook ownership
- depends_on: []
- location:
apps/cli/src/data/hooks/format-edited-file.mjs;apps/cli/src/data/hooks.test.ts - owned_paths: [
apps/cli/src/data/hooks/format-edited-file.mjs,apps/cli/src/data/hooks.test.ts] - wave_boundary: W1
- description: On
team/stefan/investigate-generated-file-triggersbased on441d87f5, preserve the existing planning commits. Through public hook invocations, add one invocation-level manifest loader and safe normalized managed-path set atformatAndLintFiles. Skip receipt-managed candidates plus the manifest bootstrap file, remove the broader hard-coded fallback, fail the whole invocation closed for missing/unreadable/malformed/structurally invalid/unsafe receipts, and preserve unmanaged formatting/linting and reporting. Cover direct files, Claude/Cursor, Codex session-start/post, and OpenCode through its files delegation without testing unrelated path extraction. - validation: Managed and invalid-authority fixtures leave bytes unchanged and create no fake formatter/linter log; an equivalent unmanaged fixture mutates and retains existing lint/reporting behavior; nested workspace candidates use the Git-root receipt.
- status: Completed
- log: 2026-08-06 — Test-drove receipt authority through the public executable. The hook now loads and validates the Git-root receipt once at the shared mutation funnel, skips receipt members and only the manifest bootstrap file, fails closed before subprocess execution for unavailable/invalid evidence, and preserves unmanaged behavior. Permission-independent unreadable coverage uses a real
EISDIRread failure. - files edited/created:
apps/cli/src/data/hooks/format-edited-file.mjs;apps/cli/src/data/hooks.test.ts - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: required
- tdd_target: A valid receipt-managed formattable/lintable path is currently mutated, and invalid or missing receipt evidence currently permits mutation.
- red_command:
bun run --cwd apps/cli test -- src/data/hooks.test.ts - expected_red_failure: Public managed-path and fail-closed assertions observe changed bytes or fake formatter/linter subprocess entries.
- green_command:
bun run --cwd apps/cli test -- src/data/hooks.test.ts && bun run --cwd apps/cli check-types - reason_not_testable:
- red_evidence: Exact focused RED exited 1 with 1 failure and 10 passes: public
filesmode rewrote receipt-managedapps/web/oxlint.config.tsfrom its original bytes toformatted\n, proving both the mutation and subprocess defect. - green_evidence: Exact focused GREEN passed 19/19 and CLI typecheck passed. Parent combined W1 rerun passed 42/42 across hook, archive, and release-note tests; scoped Oxfmt and
git diff --checkpassed. - codebase_design_notes: Keep manifest loading local to the neutral distributed hook and inject the resulting set into candidate normalization at the single mutation funnel. Do not couple the asset to Effect or package schema resolution.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T2: Lock baseline archive bytes to the tested hook source
- depends_on: []
- location:
apps/cli/src/baseline/baseline-release-scripts.test.ts - owned_paths: [
apps/cli/src/baseline/baseline-release-scripts.test.ts] - wave_boundary: W1
- description: Extend the existing baseline build-and-extract contract to compare the archived
data/hooks/format-edited-file.mjsbytes with the canonical source while retaining compatibility and digest assertions. - validation: The focused release-script test proves the built archive contains the exact canonical hook bytes.
- status: Completed
- log: 2026-08-06 — Added raw buffer equality between the extracted baseline hook and canonical source inside the existing reproducibility/build contract. No builder, catalog, or production path changed.
- files edited/created:
apps/cli/src/baseline/baseline-release-scripts.test.ts - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: not_applicable
- tdd_target: Verification-only strengthening of an existing copy contract; the builder already copies canonical bytes, so a truthful pre-change RED is unavailable.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command:
bun run --cwd apps/cli test -- src/baseline/baseline-release-scripts.test.ts - reason_not_testable: The new assertion verifies an already-existing distribution mechanism rather than changing its behavior.
- red_evidence: not_applicable; the existing builder already copied canonical bytes.
- green_evidence: Focused suite passed 19/19. Direct archive/source
cmp, scoped Oxfmt, and diff checks passed; parent combined W1 rerun also passed. - codebase_design_notes: Test the catalog-to-archive distribution seam; do not modify the builder or create a second hook ledger.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T3: Update operator guidance and baseline release notes
- depends_on: []
- location: operator docs, hook concept, and release changelogs
- owned_paths: [
docs/README.md,docs/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md,apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx,CHANGELOG.md,BASELINE_CHANGELOG.md] - wave_boundary: W1
- description: Replace partial-exclusion wording with receipt-backed exclusion, the manifest bootstrap exception, fail-closed invalid-authority behavior, unchanged unmanaged behavior, and the manual-format boundary. Add matching
baseline/stable/2026.08.06-managed-format-hookentries to both changelogs without an npm semver bump. Keep the root/wiki runbook projections aligned without broad content synchronization that would absorb unrelated metadata drift. - validation: Both changelogs contain the exact baseline tag; root and wiki runbooks carry equivalent guidance; scoped Markdown/JSON formatting and diff checks pass. The global wiki content check is observed separately because it has two pre-existing out-of-scope metadata findings.
- status: Completed
- log: 2026-08-06 — Updated operator, runbook, and hook-concept guidance for receipt-backed exclusion, the sole manifest bootstrap exception, fail-closed authority, unchanged unmanaged behavior, and the manual-format boundary. Added matching baseline-only release entries with no npm semver bump.
- files edited/created:
docs/README.md;docs/runbooks/hi-cli-scaffolding.md;apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md;apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx;CHANGELOG.md;BASELINE_CHANGELOG.md - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
autoreview,codebase-design,docs-onboarding,improve-codebase-architecture,parallel-research,simplify,tdd,writing-beats,writing-for-agents,writing-fragments,writing-shape,create-spec,create-plan,implement-spec] - tdd_status: not_applicable
- tdd_target: Documentation and release bookkeeping only.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command:
bun run --cwd apps/cli test -- src/scripts/release-notes.test.ts && test "$(rg -l '^## baseline/stable/2026\.08\.06-managed-format-hook - 2026-08-06$' CHANGELOG.md BASELINE_CHANGELOG.md | wc -l | tr -d ' ')" = 2 && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx CHANGELOG.md BASELINE_CHANGELOG.md && git diff --check - reason_not_testable: No production behavior changes in this task; release-note and content validators are the executable contract.
- red_evidence: not_applicable; documentation and release bookkeeping only.
- green_evidence: Release-note suite passed 4/4; the exact baseline heading occurs once in each changelog; all six owned files pass Oxfmt and diff checks. Root/wiki runbook guidance is byte-identical.
- codebase_design_notes: Document the hook boundary at operator and concept surfaces; do not broaden CLI lifecycle ownership.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4A: Reconcile generated bundled identity and derived public-context fixture
- depends_on: [T1]
- location: generated bundled identity and public context outcome fixture
- owned_paths: [
apps/cli/src/data/bundled-baseline-identity.generated.ts,apps/cli/test-fixtures/public-output/context-outcome.json] - wave_boundary: W2 recovery before T4 rerun
- description: Preserve the digest generated by
build-dist.mjsfrom the changed canonical hook asset and update only the derivedcontext-outcome.jsonprovenance digest/sha256. Do not changemanaged-assets.json: its manifest-derived file hashes already match and the hook is not part of that fixture inventory. This is build/fixture reconciliation, not an npm version bump or new behavior. - validation: A fresh CLI build reproduces the checked-in generated digest; the public context contract passes with the fixture aligned; no other fixture changes.
- status: Completed
- log: 2026-08-06 — The first supported release-suite run exposed two public-context failures because the hook changed the generated bundled digest while the derived outcome fixture retained the previous digest. The manifest-derived managed-assets fixture still passed and remains untouched.
- files edited/created:
apps/cli/src/data/bundled-baseline-identity.generated.ts;apps/cli/test-fixtures/public-output/context-outcome.json - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: not_applicable
- tdd_target: Generated identity and derived fixture bookkeeping caused by the accepted asset change.
- red_command:
bun run --cwd apps/cli build && bun run --cwd apps/cli test:release - expected_red_failure: Public context fixture still reports the prior bundled digest in exactly two assertions.
- green_command:
bun run --cwd apps/cli build && bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts - reason_not_testable: The behavior RED belongs to T1; this task reconciles deterministic generated and derived evidence.
- red_evidence: Supported release runner passed all 96 update-shard tests, then passed 81/82 files and 1105/1107 tests; only the public context contract's bundled digest and derived outcome equality failed.
- green_evidence: Fresh build deterministically generated
24e037717f33eb1c7f33d35e7daf5651882d5191322916a23d2144920c44a5bc; only fixture provenancedigestandsha256changed. Public context contract passed 20/20, scoped Oxfmt and diff checks passed, andmanaged-assets.jsonremained untouched. The supported release runner then passed 96/96 update-shard tests plus 82/82 files and 1107/1107 tests. - codebase_design_notes: Keep the existing build generator and public-context fixture seam. Do not add a ledger or broaden the managed-assets fixture.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4B: Reconcile current-main bundled skill fixture hashes
- depends_on: [T4A]
- location: manifest-derived managed-assets fixture
- owned_paths: [
apps/cli/test-fixtures/public-output/managed-assets.json] - wave_boundary: W2 integration recovery before T4 rerun
- description: After integrating current
origin/main, update exactly the three existing hashes for the already-releasedparallel-researchandrequirements-grillbundled skill bytes. Do not add inventory entries, change hook-related hashes, or alter fixture structure. This preserves current-main baseline contents instead of publishing an older baseline that would drop them. - validation: The three fixture hashes equal the current canonical skill bytes; public context contract passes 20/20; no other managed-assets entry changes.
- status: Completed
- log: 2026-08-06 — Current-main integration added the two latest stable-baseline skill changes. Their existing manifest-derived fixture entries retained the prior hashes and caused one focused public-context failure after the bundled provenance digest was reconciled.
- files edited/created:
apps/cli/test-fixtures/public-output/managed-assets.json - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
autoreview,codebase-design,effect-backend-structure,effect,effect-recoverable-actions,improve-codebase-architecture,parallel-research,quality-types,simplify,swarm-planner,tdd,turborepo] - tdd_status: not_applicable
- tdd_target: Derived fixture bookkeeping for current-main baseline assets.
- red_command:
bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts - expected_red_failure: The managed byte contract reports exactly three stale skill hashes.
- green_command:
bun run --cwd apps/cli test -- src/features/context-planning/public-context-contract.test.ts - reason_not_testable: This task reconciles manifest-derived fixture evidence for already-accepted mainline skill bytes.
- red_evidence: Focused contract passed provenance and 19/20 tests, then failed the managed-byte assertion for exactly the two
parallel-researchfiles and onerequirements-grillfile. - green_evidence: Exactly three existing hashes changed to match canonical current-main skill bytes. Public context contract passed 20/20; scoped Oxfmt and diff checks passed; inventory shape and every other hash remained unchanged.
- codebase_design_notes: Keep the current manifest-derived fixture seam and update only existing entries; do not create a second fixture authority.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4: Run aggregate CLI, documentation, and archive validation
- depends_on: [T1, T2, T3, T4A, T4B]
- location: repository validation surfaces; plan evidence
- owned_paths: [
apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md] - wave_boundary: W2
- description: Independently rerun the focused suites, full CLI suite, CLI checks, scoped wiki/docs checks, explicit compatible baseline build, archive/source byte comparison, formatting/diff checks, and scope audit. Record exact evidence in this plan. Observe the global wiki content check and record its two known out-of-scope metadata findings separately. Do not run
hi update --writeor modify generated scaffold mirrors. - validation: All owned behavior and distribution gates pass; the global wiki check reports only
content/docs/project/specs/cli/meta.jsonandcontent/docs/project/specs/cli/project-generated-managed-file-ownership/meta.jsonas pre-existing debt. - status: Completed
- log: 2026-08-06 — Final current-main merged validation passed the supported release topology, CLI static/type gates, deterministic fixture checks, exact stable-baseline build, archive/source hook comparison, scoped docs formatting, release headings, and diff checks. Global wiki content validation reports only the two recorded pre-existing CLI metadata findings. The root Turbo command requires
--env-mode=looseto propagate explicit release identity; the verified release command records it. - files edited/created:
apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
create-spec,create-plan,implement-spec,simplify,turborepo] - tdd_status: not_applicable
- tdd_target: Aggregate verification after behavior TDD.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command:
bun run --cwd apps/cli build && bun run --cwd apps/cli test:release && bun run --cwd apps/cli check && bun run --cwd apps/cli check-types && bunx oxfmt --check docs/README.md docs/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/project/runbooks/hi-cli-scaffolding.md apps/wiki/content/docs/harness/validation-and-tools/hooks.mdx CHANGELOG.md BASELINE_CHANGELOG.md && BASELINE_VERSION=2026.08.06-managed-format-hook BASELINE_CLI_VERSION_RANGE='>=3.0.0 <4' bun run baseline:build -- --env-mode=loose && tar -xOf apps/cli/dist/baseline/scaffold-baseline.tgz ./data/hooks/format-edited-file.mjs | cmp - apps/cli/src/data/hooks/format-edited-file.mjs && git diff --check - reason_not_testable: Validation-only task; T1 owns the behavior RED/GREEN cycle.
- red_evidence:
- green_evidence: Final merged commit build plus
test:releasepassed 96/96 update-shard tests, then 82/82 files and 1107/1107 tests. CLI Oxlint/Oxfmt checked 346 files; typecheck passed. Root baseline build with loose env produced exact tagbaseline/stable/2026.08.06-managed-format-hook, compatibility>=3.0.0 <4, archive SHA-2568955f4b1b02080683cb145a5fafd9a5f0299cef3971c9a289a5cede0fdc1d4b7, and archived hook bytes equal canonical source. Exact release headings, scoped docs Oxfmt, andgit diff --checkpassed. Global wiki check reports only the two pre-existing metadata findings named in validation. - codebase_design_notes: Verify the public hook, catalog/archive boundary, docs, and release artifacts without adding implementation.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T4C: Prove the OpenCode adapter reaches the managed-file boundary
- depends_on: [T4]
- location:
apps/cli/src/data/hooks.test.ts - owned_paths: [
apps/cli/src/data/hooks.test.ts] - wave_boundary: W3 review recovery
- description: Close the mandatory spec-review evidence gap with the smallest direct public-contract test of
FormatAndLintPlugin. Invoke itstool.execute.afteradapter for a manifest-managed edited file and prove the delegated hook leaves bytes unchanged without formatter/linter subprocess evidence. Do not change production behavior or add unrelated OpenCode path-extraction coverage. - validation: Focused hook tests and scoped CLI static checks pass with the OpenCode adapter exercised directly.
- status: Completed
- log: 2026-08-06 — Mandatory spec review found that shared
files-mode coverage proved the delegated behavior but did not directly exercise the OpenCode adapter. Added the direct public-contract test without production changes. - files edited/created:
apps/cli/src/data/hooks.test.ts;apps/wiki/content/docs/project/specs/cli/scaffold-managed-format-hook/PLAN.md - backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
review-phase,tdd,simplify] - tdd_status: not_applicable
- tdd_target: Verification-only coverage of an adapter that already delegates to the tested public
filesmode. - red_command: not_applicable
- expected_red_failure: not_applicable
- green_command:
bun run --cwd apps/cli test -- src/data/hooks.test.ts && bun run --cwd apps/cli check && bun run --cwd apps/cli check-types - reason_not_testable: The adapter already delegates to the implemented ownership funnel, so a truthful behavior RED is unavailable; the review gap is missing direct evidence.
- red_evidence: not_applicable
- green_evidence: Direct OpenCode adapter coverage passed in the focused hook suite, 20/20. The managed file retained its original bytes, the fake formatter/linter log was absent, and scoped Oxlint, Oxfmt, and diff checks passed.
- codebase_design_notes: Test the public adapter boundary without introducing another ownership rule or production seam.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
T5: Publish and verify the reviewed stable baseline
- depends_on: [T4C]
- location: clean release worktree and stable baseline authority
- owned_paths: []
- wave_boundary: W3 after mandatory review and docs-ingest phases
- description: After the delivery router records a clean mandatory review and documentation closeout, commit and push every reviewed source artifact. Create a clean release worktree at that exact commit and run the root supported baseline publisher for
baseline/stable/2026.08.06-managed-format-hookwith compatibility>=3.0.0 <4. Verify the promoted stable revision, manifest record, archive record, and exact hook bytes. Do not publish npm and do not mutate any consumer repository. - validation: The supported publisher completes from a clean worktree; stable authority resolves the exact new tag/revision; published manifest/archive digests and archived hook bytes match the reviewed build.
- status: Completed
- log: 2026-08-06 — Published from clean detached worktree commit
b8a8b694a5143f681dd770ffc3c8ea7f99310e07with the supported root command and--env-mode=loose. GitHub releasebaseline/stable/2026.08.06-managed-format-hookis non-draft and non-prerelease. The control plane committed revision 9 after revision 8 with compatibility>=3.0.0 <4. Independent readback proved exact manifest identity and archive/source hook byte equality. Publication from detached HEAD initially created the Git tag at default-branch2c6a35eb; verification caught the mismatch and the exact new tag was corrected to manifest commitb8a8b694before closeout. - files edited/created:
- backlog_item_id: not_applicable
- backlog_item_url: not_applicable
- relation_mode: not_applicable
- assigned_skills: [
implement-spec,turborepo,simplify] - tdd_status: not_applicable
- tdd_target: Credential-backed external publication of already tested bytes.
- red_command: not_applicable
- expected_red_failure: not_applicable
- green_command:
BASELINE_VERSION=2026.08.06-managed-format-hook BASELINE_CLI_VERSION_RANGE='>=3.0.0 <4' bun run baseline:publish -- --env-mode=loose - reason_not_testable: Publication is an external release operation; T1-T4 own code and artifact test coverage.
- red_evidence:
- green_evidence: Supported publication completed from clean detached commit
b8a8b694a5143f681dd770ffc3c8ea7f99310e07. Independent GitHub readback found releasebaseline/stable/2026.08.06-managed-format-hooknon-draft and non-prerelease. Control-plane outcome was committed revision 9, previous revision 8, with compatibility>=3.0.0 <4. Manifest asset504004763has SHA-256d3d038b090e0fdd49a5ece6816c9beb75bd1957de081895c7f4f02be07fbd16d; its commit, tag, version, and range are exact. Archive asset504004778has SHA-256081680c429cbfa81879097222a3c32816c86ff5ef46fa4d0b8fd927ff00f3fff; its archived hook bytes match canonical source bycmp. Finalgit ls-remoteresolves the release tag tob8a8b694a5143f681dd770ffc3c8ea7f99310e07after correcting the detached-HEAD default-target mismatch. - codebase_design_notes: Use the supported root release command; do not call the implementation script directly or add a second promotion path.
- review_mode: cli
- runtime_validation: required
- runtime_target: Stable baseline authority and immutable GitHub release assets.
- runtime_evidence: Exact stable tag/revision plus manifest/archive digest readback and byte identity for
data/hooks/format-edited-file.mjs. - runtime_cleanup: Removed
/tmp/hi-managed-format-release-EcUwBlthroughgit worktree removeafter verification. Stable release facts and assets remain as intentional durable outputs.
Review, Documentation, and Release Gates
- Spec rereview and automated branch review are clean after T4C closed the OpenCode adapter evidence gap; Standards review remained clean. The focused hook suite passed 20/20 with unchanged managed bytes and no formatter/linter subprocess evidence.
- Private/internal documentation ingestion completed on 2026-08-06. Existing runbook and hook projections already capture the proven behavior, so no new flow, concept, route, or metadata write was needed.
- T5 completed from clean detached commit
b8a8b694a5143f681dd770ffc3c8ea7f99310e07using the supported publisher with Turbo loose environment mode. - Stable revision 9 and the GitHub manifest/archive records passed independent readback. No npm release or Collective Intelligence reconciliation occurred.
Risks and Mitigations
- Unsafe receipt path bypass: reject the entire receipt on absolute, empty, root, or escaping paths; compare normalized repository-relative values only.
- Partial fallback reappears: delete the broader hard-coded list and assert representative formerly missed managed paths through the public executable.
- Nested workspace reads wrong authority: resolve Git root first and load its manifest once.
- Mode-specific mutation bypass: test every candidate-producing mode at the shared funnel; treat OpenCode delegation as the files seam.
- Generated-mirror churn: edit only canonical hook source and explicitly owned docs; never run write reconciliation.
- Release mismatch: permanent archive byte test plus clean-worktree publication and exact tag release notes.
Unresolved Questions
None. Consumer reconciliation, existing consumer drift, and backlog projection are explicitly parked rather than unresolved.