Locate every malformed manifest.
Scan the selected DSH closure.
Scan the exact execution cache path.
Scan the selected profile dependencies.
Separate tracked files from generated installs.
{}.Name, version, exports, dependencies, module type, and native-install contracts are executable package metadata.
Replace the owning closure.
Prove the artifact before touching production.
Use the channel that owns the bad path.
Repair the external mutation boundary first.
Twelve acceptance gates.
All bad paths and hashes retained.
Repaired scan reports zero failures.
Boot, config, turn, and tool pass.
Cold restart stays clean.
Primary evidence.
Keep the complete recovery runbook.
The canonical guide includes a read-only recursive scanner, install-owner matrix, exact-version probe, npm/npx/profile/source recovery, unsafe shortcuts, twelve gates, and an upstream diagnostic contract.
Read the complete runbook