← back to Ticket System
data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ/vienna-e2e-proof.json
137 lines
{
"intent": "Harden actual Vienna inventory CLI and prove the local executor contract with hermetic persisted adapters",
"risk_tier": "R3 local integration rehearsal only",
"environment": "macOS; detached isolated worktree; no real secrets or network",
"baseline_commit": "7fb358ca8948290915678dd2c34f83a02d5a0532",
"build_identity": "Content hashes below; local commit reported in handoff",
"timestamp": "2026-09-08T12:59:32.920387+00:00",
"ticket": "TK-11300-vienna-inventory-executor-freeze-exact-m",
"parent_ticket": "TK-11299-zero-price-bin-zsh-orderable-regression",
"task_id": "cycle-20260908T1221Z.HzXvuQ/vienna-executor",
"worktree": "/private/tmp/vienna-executor.qdoRbR",
"commands": [
"VIENNA_EVIDENCE_DIR=/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ node --test test/cli-preflight.test.mjs test/vienna-executor.test.mjs",
"node --check apply-fix.mjs",
"node --check cli-args.mjs",
"node --check vienna-executor.mjs",
"node --check vienna-offline-adapter.mjs",
"git diff --check"
],
"results": {
"tests": 91,
"pass_count": 91,
"failed": 0,
"skipped": 0
},
"checks": [
{
"check": "CLI preflight and help",
"verdict": "PASS",
"evidence": "42 legacy CLI and calibrated boundary checks preserved with stricter frozen-input rejection"
},
{
"check": "Manifest and store preflight",
"verdict": "PASS",
"evidence": "Strict schema, external SHA256, store GID/domain, age, exact GIDs, vendor/line, sample/price/tracking/policy, duplicate/collision, canary/full-location checks before denied adapter reads"
},
{
"check": "Plan",
"verdict": "PASS",
"evidence": "Actual --plan and --enumerate under denied writes/adapter-state read; no journal or fixture changes"
},
{
"check": "Offline execution",
"verdict": "PASS",
"evidence": "Exact frozen canary and all-record multi-location compare/set/postread with persisted fixture and journal assertions"
},
{
"check": "Retry and rollback",
"verdict": "PASS",
"evidence": "No duplicate successful writes; confirmed rejection separated; partial multi-location rollback uses only journal successes; idempotent restore"
},
{
"check": "Ambiguous result and receipt gaps",
"verdict": "PASS",
"evidence": "Throw before/after persisted write and confirmed response before success append; durable intent blocks apply/rollback before denied adapter boundary in both directions"
},
{
"check": "Postread interruptions",
"verdict": "PASS",
"evidence": "Forward and rollback success retained, drift blocks further writes, restored matching state permits verification-only recovery"
},
{
"check": "Journal integrity and concurrency",
"verdict": "PASS",
"evidence": "External checkpoint plus chain/schema/state/membership/quantity checks; malformed/forged/truncated history rejection; existing exclusive lock rejected"
},
{
"check": "File protection",
"verdict": "PASS",
"evidence": "Symlink and hardlink targets refused; exact input aliases rejected; atomic fixture replacement; retained temp/state"
},
{
"check": "Real denied boundaries",
"verdict": "PASS",
"evidence": "Canonical secret-file read, fetch, HTTPS and child spawn calibration under process preload; no live transport exists"
},
{
"check": "Syntax and diff",
"verdict": "PASS",
"evidence": "node --check for four shipped modules and git diff --check"
},
{
"check": "Production execution",
"verdict": "OUT_OF_SCOPE",
"evidence": "No live adapter, authoritative manifest acquisition, actual shop identity, credential scope or approval; separate parent TK11299 gate"
},
{
"check": "After-open and after-intent drift",
"verdict": "PASS",
"evidence": "Independent library regression read preserves quantity9 without writes; actual CLI preload injects external quantity9 after intent fsync, rejects compare/write, persists9 and records no successful mutation"
},
{
"check": "Refreshed store identity",
"verdict": "PASS",
"evidence": "Actual CLI injected store drift after intent fails renewed adapter pin; unresolved intent blocks further replay before adapter"
},
{
"check": "Competing CLI writers",
"verdict": "PASS",
"evidence": "Two real child CLI processes use different journals against one fixture; first pauses after journal header while state lock held, contender rejects EEXIST with no second journal, first completes4 writes; both owned locks released"
}
],
"evidence_directory": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ",
"final_test_log": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ/vienna-test-fix3.txt",
"retained_failed_run": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ/vienna-test-first.txt",
"failed_run_cause": "Test factory aliased shared store object; negative mutation contaminated subsequent fixtures. Fixed cloning, then replaced generated baseline with versioned fixture+SHA256.",
"historical_proof": "verification/cli-preflight-e2e-proof-7fb358c.json and source commit7fb358c; provisional87-test proof preserved in git7645583 and cycle/vienna-e2e-proof-provisional-7645583.json",
"correlations": [
"dm-mtsnoxgl-42285-kfum1h",
"action-mtsnr96r-13925-y5u8k8",
"action-mtso4bm9-13925-fmifo2",
"action-mtso70ap-13925-lhw161"
],
"cleanup": "All fixture directories, failing logs and interrupted journals retained. Only own completed-process lock is released by runtime code. No live cleanup.",
"trust_boundary": "External manifest and journal hashes are independent operator trust anchors, not catalog completeness or arbitrary journal provenance. Operator cannot derive approval by recomputing an unreviewed hash.",
"limitations": [
"Production adapter intentionally absent; actual transport semantics and permissions unverified; only supported CLI writers share fixture-state locking",
"Synthetic shop and IDs only; authoritative manifest completeness and actual identity remain external preflight",
"No automatic resolution of ambiguous intent or crashed lock; independent reconciliation required",
"Local process fault injection proves conservative gaps; no physical power-loss experiment"
],
"verdict": "PASS for scoped local consumer/executor and offline adapter proof; production recovery remains gated",
"file_sha256": {
"apply-fix.mjs": "73a910ebf571fae0e5ff69f894af172ce82e2e58c0f576d995b08739d8f192ba",
"cli-args.mjs": "716158c0530c7f06937e439dc26d64118a38d081c6bafc9e2d3ae1b3ac5d72fb",
"vienna-executor.mjs": "78203b13d56676a735f586baca0bce49bf521e5740024bf815a5f5e59ab2b03c",
"vienna-offline-adapter.mjs": "eba5810037757cdfb106a3b7d1cd93b9283c14b382ce72949b596031bd526698",
"test/vienna-executor.test.mjs": "c9fc5f45a0f3a2f17f0d5e9ce6be52ae8d622772edb12d1b776064036db3a197",
"test/vienna-boundaries.cjs": "5f16fb3d167d77fd340ff5d0933e5a12cb09be9cf98d3b305cac1930ac98de1d",
"test/fixtures/vienna-manifest.json": "1b21ab81983284920c22f857a1480741335b5513d003a23b38f9d1c2378bc1c7",
"test/fixtures/vienna-manifest.sha256": "061b8fe166b4744e4cef87c02d642f85561a404ffc8158873835af5a77c9a6f2",
"VIENNA-EXECUTOR.md": "4aed87b9797df54408cde1103a70a1080bd84cb11ad2c7e9dc8f60b94c6fb37e"
},
"superseded_claim": "Provisional87-test proof did not cover persisted state changed after adapter open. Independent parent/Cody reproductions showed cached read logging could overwrite current quantities. FIX3 reload/nonmutating read and shared-state locking closes this scoped local defect; prior claim superseded.",
"decision": "Final DTD FIX-THEN-SHIP2/2, judge KEEP /private/tmp/dtd-cycle1221-final.l8xVdk; conditional parent/Cody independent verification still required"
}