# Release Integrity Regression

Audience: AI coding agents first.

## Outcome

Validate recovered 0.9.36 artifact as untrusted input. Apply only minimal current-master fixes for release integrity, version consistency, and activation. Verify all applicable gates. Commit locally. NEVER push, merge, rebase, deploy, or contact dev1.

## Status

DONE — artifact validated and selectively ported; deterministic regression tests and all applicable gates pass; local commit created by this transaction is the terminal integration boundary. No push, merge, rebase, deployment, dev1 request, staging request, or production request occurred.

## Tasks

- `RIR-1` Verify archive checksums, embedded/separate patch identity, artifact instructions, changed-file inventory.
- `RIR-2` Reproduce root cause from current `origin/master` plus original good/bad snapshots.
- `RIR-3` Accept, modify, or reject each candidate file. Keep only current necessary changes. Preserve untracked `admin/dist/` release generation.
- `RIR-4` Run targeted artifact tests plus complete applicable PHPUnit, PHPStan, PHPCS, admin build, and release-tool gates.
- `RIR-5` Verify activation only against local Podman WordPress at `localhost:8080` when required.
- `RIR-6` Commit locally with one terse imperative sentence. Record receipt.

## Source Request

Review, reproduce, safely apply, verify, and locally commit recovered ChatGPT artifact for international-press-zone 0.9.36 release-integrity regression. Integration remains sequential; do not push or land.

## Acceptance Criteria

- Archive checksum manifest verifies.
- Embedded `PATCH.diff` byte-matches separate downloaded patch.
- Deterministic evidence identifies actual regression root cause.
- Every artifact file receives accepted, modified, or rejected disposition.
- No stale README/source rewrite, unrelated change, needless version churn, tracked `admin/dist/`, dev1 dependency, or weakened localhost-only safety remains.
- Targeted tests and complete applicable release gates pass without ignored warnings.
- Local commit exists; no push, merge, rebase, deployment, or non-local smoke test occurs.

## Preserved WIP / Ref / Path

- Base: `origin/master` = `3fb0f1bd7a316f9df73d40fac3203423b6d9164d`.
- Worktree: `/home/user/Projects/Press.zone/wordpress/wp-content/.worktrees/ask-gpt-regression`.
- Artifact ZIP: `/home/user/.cache/agent-tmp/claude-1000/-home-user-Projects-Press-zone-wordpress-wp-content-plugins-international-press-zone/7b24368f-13dc-46e9-8d3f-5d1b6ab05f39/scratchpad/downloads/regression-retry/international-press-zone-0.9.36-release-integrity-fix(1).zip`.
- Patch copy: `/home/user/.cache/agent-tmp/claude-1000/-home-user-Projects-Press-zone-wordpress-wp-content-plugins-international-press-zone/7b24368f-13dc-46e9-8d3f-5d1b6ab05f39/scratchpad/downloads/regression-retry/IPZ-0.9.36-release-integrity-fix(1).patch`.
- Original context: `/home/user/.cache/agent-tmp/claude-1000/-home-user-Projects-Press-zone-wordpress-wp-content-plugins-international-press-zone/7b24368f-13dc-46e9-8d3f-5d1b6ab05f39/scratchpad/regression-diag/`.

## Constraints

- Work only inside named worktree.
- Treat generated artifact as proposal; NEVER blind-overwrite.
- NEVER contact `dev1.danzigeronline.com` or `dev1`.
- Use only local Podman WordPress at `localhost:8080` for runtime checks.
- Review `tools/deploy-dev1.mjs` statically only; NEVER execute it.
- Browser plus dev-server E2E MUST use `~/.claude/bin/e2e-remote`.
- Preserve release-generated, untracked `admin/dist/`.

## Execution

1. Read rules, local skills, release tooling, manifests, artifact metadata, and snapshots.
2. Verify artifact provenance checks deterministically.
3. Reproduce failure before source mutation.
4. Compare each proposal against current master and snapshots.
5. Apply minimal fix with regression tests.
6. Run focused then complete applicable gates; resolve every signal.
7. Commit locally and update receipt.

## Current Receipt

2026-08-11: ZIP structure and all eight manifest hashes passed. Embedded and separate patches byte-match at SHA-256 `e9e2ec8051b415c428acf89b26f1e26509607994543311ade7def7f41674c928`; ZIP SHA-256 is `c8b9539dc48b86d4cbdb1d1201ff2b411e3e09a9a54c5adf0baa6d0c52230492`. Deterministic RED proved current archive verification accepted missing, unexpected, and byte-altered runtime files; activation test proved activation skipped normal bootstrap. Root evidence also confirms two distinct 0.9.36 archives (`6db594e1…` and `fa4859f…`) and active-file replacement skipped activation. Exact deployed fatal member remains unknowable without the retained incident ZIP bytes or PHP fatal log.

Accepted with current-master modifications: `international-press-zone.php`, `tests/unit/ActivationBootstrapStandaloneTest.php`. Accepted: `tools/build-distribution.mjs`, `tools/build-distribution.test.mjs`, `tools/version-bump.test.mjs`. Rejected: stale `README.md`; dev1-coupled `tools/deploy-dev1.mjs` and `tools/deploy-dev1.test.mjs`. Gate repairs required by current master: deterministic process-lifecycle marker handshake; admin build-before-test ordering for ignored `admin/dist/`; canonical soft/hard TTL fixture sync; two PHPCS-only array-syntax repairs.

Passed: standalone activation regression; artifact static deployment tests without network; release Node tests serially; dirty-source release-builder refusal; version declaration check; full admin locked install/lint/production build/Vitest gate; PHPUnit; PHPStan; full PHPCS baseline scope; Bash syntax; PHP syntax across 209 files; `git diff --check`. Expected negative-path admin logger output was asserted by passing tests. No unresolved warning remains. No runtime activation was needed beyond the deterministic activation seam; no remote host was contacted.

## Next Executable Action

None. Integration is intentionally deferred to the coordinator's sequential landing step.
