← back to Tk 10965 Zero Price Analysis

verification/e2e-proof.json

137 lines

{
  "intent": "Harden actual Vienna inventory CLI and prove the local executor contract with hermetic persisted adapters",
  "risk_tier": "R3 local integration rehearsal only",
  "environment": "macOS; detached isolated worktree; no real secrets or network",
  "baseline_commit": "7fb358ca8948290915678dd2c34f83a02d5a0532",
  "build_identity": "Content hashes below; local commit reported in handoff",
  "timestamp": "2026-09-08T12:59:32.920387+00:00",
  "ticket": "TK-11300-vienna-inventory-executor-freeze-exact-m",
  "parent_ticket": "TK-11299-zero-price-bin-zsh-orderable-regression",
  "task_id": "cycle-20260908T1221Z.HzXvuQ/vienna-executor",
  "worktree": "/private/tmp/vienna-executor.qdoRbR",
  "commands": [
    "VIENNA_EVIDENCE_DIR=/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ node --test test/cli-preflight.test.mjs test/vienna-executor.test.mjs",
    "node --check apply-fix.mjs",
    "node --check cli-args.mjs",
    "node --check vienna-executor.mjs",
    "node --check vienna-offline-adapter.mjs",
    "git diff --check"
  ],
  "results": {
    "tests": 91,
    "pass_count": 91,
    "failed": 0,
    "skipped": 0
  },
  "checks": [
    {
      "check": "CLI preflight and help",
      "verdict": "PASS",
      "evidence": "42 legacy CLI and calibrated boundary checks preserved with stricter frozen-input rejection"
    },
    {
      "check": "Manifest and store preflight",
      "verdict": "PASS",
      "evidence": "Strict schema, external SHA256, store GID/domain, age, exact GIDs, vendor/line, sample/price/tracking/policy, duplicate/collision, canary/full-location checks before denied adapter reads"
    },
    {
      "check": "Plan",
      "verdict": "PASS",
      "evidence": "Actual --plan and --enumerate under denied writes/adapter-state read; no journal or fixture changes"
    },
    {
      "check": "Offline execution",
      "verdict": "PASS",
      "evidence": "Exact frozen canary and all-record multi-location compare/set/postread with persisted fixture and journal assertions"
    },
    {
      "check": "Retry and rollback",
      "verdict": "PASS",
      "evidence": "No duplicate successful writes; confirmed rejection separated; partial multi-location rollback uses only journal successes; idempotent restore"
    },
    {
      "check": "Ambiguous result and receipt gaps",
      "verdict": "PASS",
      "evidence": "Throw before/after persisted write and confirmed response before success append; durable intent blocks apply/rollback before denied adapter boundary in both directions"
    },
    {
      "check": "Postread interruptions",
      "verdict": "PASS",
      "evidence": "Forward and rollback success retained, drift blocks further writes, restored matching state permits verification-only recovery"
    },
    {
      "check": "Journal integrity and concurrency",
      "verdict": "PASS",
      "evidence": "External checkpoint plus chain/schema/state/membership/quantity checks; malformed/forged/truncated history rejection; existing exclusive lock rejected"
    },
    {
      "check": "File protection",
      "verdict": "PASS",
      "evidence": "Symlink and hardlink targets refused; exact input aliases rejected; atomic fixture replacement; retained temp/state"
    },
    {
      "check": "Real denied boundaries",
      "verdict": "PASS",
      "evidence": "Canonical secret-file read, fetch, HTTPS and child spawn calibration under process preload; no live transport exists"
    },
    {
      "check": "Syntax and diff",
      "verdict": "PASS",
      "evidence": "node --check for four shipped modules and git diff --check"
    },
    {
      "check": "Production execution",
      "verdict": "OUT_OF_SCOPE",
      "evidence": "No live adapter, authoritative manifest acquisition, actual shop identity, credential scope or approval; separate parent TK11299 gate"
    },
    {
      "check": "After-open and after-intent drift",
      "verdict": "PASS",
      "evidence": "Independent library regression read preserves quantity9 without writes; actual CLI preload injects external quantity9 after intent fsync, rejects compare/write, persists9 and records no successful mutation"
    },
    {
      "check": "Refreshed store identity",
      "verdict": "PASS",
      "evidence": "Actual CLI injected store drift after intent fails renewed adapter pin; unresolved intent blocks further replay before adapter"
    },
    {
      "check": "Competing CLI writers",
      "verdict": "PASS",
      "evidence": "Two real child CLI processes use different journals against one fixture; first pauses after journal header while state lock held, contender rejects EEXIST with no second journal, first completes4 writes; both owned locks released"
    }
  ],
  "evidence_directory": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ",
  "final_test_log": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ/vienna-test-fix3.txt",
  "retained_failed_run": "/Users/macstudio3/Projects/ticket-system/data/codex-yoloforever/cycle-20260908T1221Z.HzXvuQ/vienna-test-first.txt",
  "failed_run_cause": "Test factory aliased shared store object; negative mutation contaminated subsequent fixtures. Fixed cloning, then replaced generated baseline with versioned fixture+SHA256.",
  "historical_proof": "verification/cli-preflight-e2e-proof-7fb358c.json and source commit7fb358c; provisional87-test proof preserved in git7645583 and cycle/vienna-e2e-proof-provisional-7645583.json",
  "correlations": [
    "dm-mtsnoxgl-42285-kfum1h",
    "action-mtsnr96r-13925-y5u8k8",
    "action-mtso4bm9-13925-fmifo2",
    "action-mtso70ap-13925-lhw161"
  ],
  "cleanup": "All fixture directories, failing logs and interrupted journals retained. Only own completed-process lock is released by runtime code. No live cleanup.",
  "trust_boundary": "External manifest and journal hashes are independent operator trust anchors, not catalog completeness or arbitrary journal provenance. Operator cannot derive approval by recomputing an unreviewed hash.",
  "limitations": [
    "Production adapter intentionally absent; actual transport semantics and permissions unverified; only supported CLI writers share fixture-state locking",
    "Synthetic shop and IDs only; authoritative manifest completeness and actual identity remain external preflight",
    "No automatic resolution of ambiguous intent or crashed lock; independent reconciliation required",
    "Local process fault injection proves conservative gaps; no physical power-loss experiment"
  ],
  "verdict": "PASS for scoped local consumer/executor and offline adapter proof; production recovery remains gated",
  "file_sha256": {
    "apply-fix.mjs": "73a910ebf571fae0e5ff69f894af172ce82e2e58c0f576d995b08739d8f192ba",
    "cli-args.mjs": "716158c0530c7f06937e439dc26d64118a38d081c6bafc9e2d3ae1b3ac5d72fb",
    "vienna-executor.mjs": "78203b13d56676a735f586baca0bce49bf521e5740024bf815a5f5e59ab2b03c",
    "vienna-offline-adapter.mjs": "eba5810037757cdfb106a3b7d1cd93b9283c14b382ce72949b596031bd526698",
    "test/vienna-executor.test.mjs": "c9fc5f45a0f3a2f17f0d5e9ce6be52ae8d622772edb12d1b776064036db3a197",
    "test/vienna-boundaries.cjs": "5f16fb3d167d77fd340ff5d0933e5a12cb09be9cf98d3b305cac1930ac98de1d",
    "test/fixtures/vienna-manifest.json": "1b21ab81983284920c22f857a1480741335b5513d003a23b38f9d1c2378bc1c7",
    "test/fixtures/vienna-manifest.sha256": "061b8fe166b4744e4cef87c02d642f85561a404ffc8158873835af5a77c9a6f2",
    "VIENNA-EXECUTOR.md": "4aed87b9797df54408cde1103a70a1080bd84cb11ad2c7e9dc8f60b94c6fb37e"
  },
  "superseded_claim": "Provisional87-test proof did not cover persisted state changed after adapter open. Independent parent/Cody reproductions showed cached read logging could overwrite current quantities. FIX3 reload/nonmutating read and shared-state locking closes this scoped local defect; prior claim superseded.",
  "decision": "Final DTD FIX-THEN-SHIP2/2, judge KEEP /private/tmp/dtd-cycle1221-final.l8xVdk; conditional parent/Cody independent verification still required"
}