Parent and order
Parent delivery slice: #604.
Implementation order: 1 of 3. All three sibling tasks are executable together; this order is recorded for commits and does not create a native dependency.
Outcome
The root quality CLI freshly collects and later re-checks one revision-bound bundle containing five separate V8 coverage profiles and the inputs required to accept them.
Acceptance criteria
- Expose
npm run quality:verify -- --base <exact-sha>, npm run quality:check -- --base <exact-sha> --head <exact-sha> [--bundle <path>], and npm run quality:test through one entry script.
- Define five explicit profiles: root happy-dom, Chromium, shared selection, server Node unit, and telemetry happy-dom unit with generated Worker types and root
INIT_CWD. Keep their maps separate and do not claim combined coverage or workerd execution.
- Keep
src/main.ts excluded only from root happy-dom; Chromium includes it. Every declared source file must appear in its map, including zero-hit files. Type-only files and barrels may have empty counters. No source omission classifier is permitted.
- Record exact commands, environment, source/test scopes and exclusions, producer root, producer OS, Node/npm/Vitest/V8 versions, effective config and lock identities, base/head, clean state, tracked plus nonignored-untracked path/content inventory, raw logs, artifact digests, results, and durations.
- Invalidate the prior run's certification before collection. Preserve failure logs. Certify only after all producers succeed and post-run inputs and HEAD still match.
- Validate the complete bundle against requirements from the expected checkout: required profiles, scope, schema, original-root mapping, file completeness, artifact paths and digests, commands/results, and cross-record agreement. Artifact paths must remain inside the bundle;
producerRoot may translate coverage paths but must not authorize arbitrary reads.
quality:check is read-only, works on a relocated bundle from another OS, and does not reject valid evidence merely because the reader OS differs from the producer OS.
- Real-CLI tests in isolated temporary Git repositories cover success and absent, malformed, empty, incomplete, foreign-root, wrong-base/head/tool/config/source/test, changed tracked or nonignored-untracked input, failed producer, and stale-certification failures without rerunning all five suites for each equivalent corruption.
Non-goals
- No combined coverage percentage, threshold, mutation score, dependency, product-source edit, provider framework, or second test harness.
- No malicious-bundle signature or certification-history ledger.
Write boundary
package.json
scripts/quality-evidence.mjs
- focused
scripts/quality/{config,bundle,coverage,fallow}.mjs modules only when the named responsibility justifies the file
tests/scripts/quality-evidence.test.ts
- existing Vitest runner configuration only where verified CLI flags cannot preserve the frozen profile
Generated evidence belongs under ignored .fallow/quality/**. package-lock.json and product source are out of bounds.
Verification
Run npm run quality:test and a clean npm run quality:verify -- --base <exact-starting-origin-develop-sha>, then re-check its bundle with exact base/head.
Observability
None. These are engineering verification artifacts.
Parent and order
Parent delivery slice: #604.
Implementation order: 1 of 3. All three sibling tasks are executable together; this order is recorded for commits and does not create a native dependency.
Outcome
The root quality CLI freshly collects and later re-checks one revision-bound bundle containing five separate V8 coverage profiles and the inputs required to accept them.
Acceptance criteria
npm run quality:verify -- --base <exact-sha>,npm run quality:check -- --base <exact-sha> --head <exact-sha> [--bundle <path>], andnpm run quality:testthrough one entry script.INIT_CWD. Keep their maps separate and do not claim combined coverage or workerd execution.src/main.tsexcluded only from root happy-dom; Chromium includes it. Every declared source file must appear in its map, including zero-hit files. Type-only files and barrels may have empty counters. No source omission classifier is permitted.producerRootmay translate coverage paths but must not authorize arbitrary reads.quality:checkis read-only, works on a relocated bundle from another OS, and does not reject valid evidence merely because the reader OS differs from the producer OS.Non-goals
Write boundary
package.jsonscripts/quality-evidence.mjsscripts/quality/{config,bundle,coverage,fallow}.mjsmodules only when the named responsibility justifies the filetests/scripts/quality-evidence.test.tsGenerated evidence belongs under ignored
.fallow/quality/**.package-lock.jsonand product source are out of bounds.Verification
Run
npm run quality:testand a cleannpm run quality:verify -- --base <exact-starting-origin-develop-sha>, then re-check its bundle with exact base/head.Observability
None. These are engineering verification artifacts.