{
  "assessment": {
    "decisions": [
      {
        "decided_by": "locality",
        "defect_id": "12",
        "finding_id": "f1",
        "id": "d1",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "17",
        "finding_id": "f2",
        "id": "d2",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "1",
        "finding_id": "f3",
        "id": "d3",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "13",
        "finding_id": "f4",
        "id": "d4",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "11",
        "finding_id": "f5",
        "id": "d5",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "6",
        "finding_id": "f6",
        "id": "d6",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "18",
        "finding_id": "f7",
        "id": "d7",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "4",
        "finding_id": "f8",
        "id": "d8",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "2",
        "finding_id": "f9",
        "id": "d9",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "3",
        "finding_id": "f10",
        "id": "d10",
        "outcome": "matched",
        "reason": null
      }
    ],
    "judge": null,
    "judged": false,
    "scorer": {
      "commit": "3c151df56e62cfdea90b84dd8b265f7e0f4bebff",
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "bench-score",
      "version": "1"
    },
    "state": "measured"
  },
  "benchmark": {
    "input_fingerprint": "69301578538a",
    "key_fingerprint": "bd331c0b144e",
    "policy_fingerprint": "c53f8cfc8c75",
    "prompt_fingerprint": "74234e98afe7",
    "subject": "proxy"
  },
  "build": {
    "commit": "b0f313c0b59a66ecc7612396dc8db0ea5da13a7a",
    "digest": null,
    "dirty": false,
    "label": "afi 0.30.0",
    "version": "0.30.0"
  },
  "configuration": {
    "fingerprint": "a5df80571ddb",
    "label": "default",
    "models": [
      {
        "effort": "high",
        "model": "anthropic/claude-opus-5",
        "protocol": null,
        "provider": "anthropic",
        "role": "agent"
      }
    ],
    "profile": null,
    "resolved": {
      "effort": "high",
      "instructions": [],
      "sandbox": {
        "backend": "macOS Seatbelt",
        "mode": "read-only",
        "network": "denied"
      },
      "source": "openrouter",
      "system_prompt": {
        "file": null,
        "mode": "builtin"
      },
      "tools": [
        "read_file",
        "write_file",
        "edit_file",
        "list_dir",
        "search_files",
        "glob_files",
        "run_bash",
        "wait_background"
      ]
    }
  },
  "coverage": {
    "chunks": null,
    "files_failed": 0,
    "files_kept": null,
    "files_skipped": 0,
    "files_unreviewed": 0,
    "hunks": null,
    "state": "measured"
  },
  "evidence": [
    {
      "digest": "sha256:193df5be5cea0debdde399c80da5e51b5a40033b69bab0aec3804bf2aacc8848",
      "media_type": "application/json",
      "path": "summary.json",
      "role": "summary"
    },
    {
      "digest": "sha256:6e88bb7ca31746652faa5be347c8d16fd47a4f019e1dd9374fdb1cb085941af7",
      "media_type": "application/json",
      "path": "findings.json",
      "role": "findings"
    },
    {
      "digest": "sha256:383e834161f06171b3fffb1ea864e8bb5b4e6a3354806184f8d488718e740dad",
      "media_type": "application/json",
      "path": "meta.json",
      "role": "meta"
    },
    {
      "digest": "sha256:bd9a12d505fdbaba0a8a50fc4d067a7446daa08475460a890909f46649d5bedd",
      "media_type": "application/json",
      "path": "spend.json",
      "role": "spend"
    },
    {
      "digest": "sha256:e674f10b3c116c64859ede267b5a27b062d3097a74187c386865012d2b03f0f6",
      "media_type": "application/jsonl",
      "path": "result.jsonl",
      "role": "result"
    },
    {
      "digest": "sha256:a5165041056531ee359e8b92f76248d61fc77aee6a47c7338dcfe1d15ade2566",
      "media_type": "text/plain",
      "path": "stderr.txt",
      "role": "stderr"
    },
    {
      "digest": "sha256:6f367d26d664e5bbb9278803e83807273b7087894197fd3ea2109c3b3284c7a4",
      "media_type": "application/gzip",
      "path": "afi-home/logs.tar.gz",
      "role": "traffic"
    }
  ],
  "execution": {
    "billing_limit_usd": 12.0,
    "budget_usd": 12.0,
    "deadline_exceeded": false,
    "exit_code": 0,
    "finished_at": "2026-08-31T15:36:31Z",
    "started_at": "2026-08-31T15:34:08Z",
    "wall_seconds": 143.0
  },
  "extensions": {
    "afi": {
      "found_per_pass": {
        "agent": 10
      },
      "passes": null,
      "review_seconds": 142.229,
      "tier1_only": false,
      "variant_hash": null
    }
  },
  "findings": {
    "items": [
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "forget(&index, &gone)` runs unconditionally, and `gone` is filled at line 137 even when `dry_run` is true \u2014 so `POST /v1/admin/cache/sweep?dry_run=true` deletes every index entry naming a blob the\u2026\n\nforget(&index, &gone)` runs unconditionally, and `gone` is filled at line 137 even when `dry_run` is true \u2014 so `POST /v1/admin/cache/sweep?dry_run=true` deletes every index entry naming a blob the sweep *would* have removed (`fs::remove_file(path)` at line 252 has no dry-run guard). The route documented as \"reports what one would reclaim without removing anything\" (docs/operations.md, admin.rs:87) silently unlinks the name index, turning the next build's hits into a full refetch storm against upstreams.",
        "id": "f1",
        "locations": [
          {
            "end_line": 140,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 140
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "clear_partials` unlinks *every* file in `incoming` with no age or liveness test, but that directory holds the in-flight temporary of each running fetch (`BlobStore::temp_path`, store.rs:204) and of\u2026\n\nclear_partials` unlinks *every* file in `incoming` with no age or liveness test, but that directory holds the in-flight temporary of each running fetch (`BlobStore::temp_path`, store.rs:204) and of each index write (store.rs:147). A sweep \u2014 automatic every `CAIRN_SWEEP_INTERVAL`, 15m by default \u2014 deletes the temp of a download that is proceeding fine; the writer's `fs::rename(&temp, &target)` at store.rs:259 then fails with ENOENT and the client gets a 500 on a perfectly good artifact. The doc comment's premise (\"a fetch that is not coming back\") is untrue for anything currently streaming.",
        "id": "f2",
        "locations": [
          {
            "end_line": 232,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 232
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "sort_by_key(|candidate| candidate.age)` sorts *ascending*, i.e. newest first, the opposite of the comment above it and of the eviction policy documented in config.rs:63.\n\nCombined with the `age >= min_age` gate at line 120, the sweep removes the youngest blobs that have just cleared the grace period and keeps the oldest, so the cache evicts exactly what a pipeline is still using. Needs `sort_by_key(|c| std::cmp::Reverse(c.age))`.",
        "id": "f3",
        "locations": [
          {
            "end_line": 102,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 102
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "values()` returns `sweep_bytes_reclaimed` in slot 4 and `sweep_blobs_removed` in slot 5, but `COUNTERS` (lines 50-57) names slot 4 `cairn_proxy_sweep_blobs_removed_total` and slot 5\u2026\n\nvalues()` returns `sweep_bytes_reclaimed` in slot 4 and `sweep_blobs_removed` in slot 5, but `COUNTERS` (lines 50-57) names slot 4 `cairn_proxy_sweep_blobs_removed_total` and slot 5 `..._bytes_reclaimed_total`. The two sweep counters are exported under each other's names, so the metric docs/operations.md tells operators to alert on reports a blob count, not bytes. Swap the two loads.",
        "id": "f4",
        "locations": [
          {
            "end_line": 94,
            "path": "services/proxy/src/metrics.rs",
            "start_line": 94
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "performance",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "reclaim` calls the synchronous `Sweeper::sweep` directly on the runtime thread, as does `Sweeper::run` at sweep.rs:84 inside the spawned task.\n\nThe module doc (sweep.rs:14-18) deliberately uses blocking `std::fs`, and routes/mod.rs:125 admits a sweep \"legitimately takes longer than ten seconds\" \u2014 that is a tokio worker blocked for the whole walk, stalling every download futures scheduled on it. Both call sites need `tokio::task::spawn_blocking`.",
        "id": "f5",
        "locations": [
          {
            "end_line": 76,
            "path": "services/proxy/src/routes/admin.rs",
            "start_line": 76
          }
        ],
        "severity": "performance",
        "title": "performance"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "the HTTP route bypasses the `running` mutex by calling `sweep()` instead of `run()`, so the \"one sweep at a time\" invariant the lock exists to keep (sweep.rs:10-12, 65-67) does not hold for the\u2026\n\nthe HTTP route bypasses the `running` mutex by calling `sweep()` instead of `run()`, so the \"one sweep at a time\" invariant the lock exists to keep (sweep.rs:10-12, 65-67) does not hold for the on-demand route. Two concurrent admin sweeps, or one racing the interval sweep, each compute `remaining` from a total the other is already shrinking and together take the store far below the ceiling.",
        "id": "f6",
        "locations": [
          {
            "end_line": 76,
            "path": "services/proxy/src/routes/admin.rs",
            "start_line": 76
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "an unreferenced blob is removed with no grace period at all, but a miss commits the blob (cache.rs:151) before it writes the index entry (cache.rs:163) \u2014 during that window nothing points at it.\n\nA sweep landing there deletes the blob the request just stored; if it lands between the commit and `open_blob` (cache.rs:90) the request fails with the \"already missing from the store\" 500. The unreferenced branch should still respect `min_age`.",
        "id": "f7",
        "locations": [
          {
            "end_line": 119,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 119
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "fs::metadata` follows symlinks, contradicting the comment directly above it (a symlink is counted at its target's size, not the link's) and, worse, making `collect` recurse into symlinked\u2026\n\nfs::metadata` follows symlinks, contradicting the comment directly above it (a symlink is counted at its target's size, not the link's) and, worse, making `collect` recurse into symlinked directories \u2014 a link pointing at an ancestor inside `CAIRN_BLOB_DIR` recurses until the stack overflows. Use `fs::symlink_metadata`.",
        "id": "f8",
        "locations": [
          {
            "end_line": 164,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 164
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "a failed `fs::remove_file` at line 126 only logs, then falls through to count the blob in `removed`/`bytes` and push it into `gone`.\n\nSpace that was never reclaimed is reported to the operator and added to `cairn_proxy_sweep_bytes_reclaimed_total`, and its index entries are dropped though the blob is still there \u2014 `clear_partials` gets this right with its `continue` at line 234.",
        "id": "f9",
        "locations": [
          {
            "end_line": 134,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 134
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "remaining >= self.max_bytes` evicts when the store is exactly at the ceiling, though `cache_max_bytes` is documented as \"the most the blob store may hold\" (config.rs:63); should be `>`.",
        "id": "f10",
        "locations": [
          {
            "end_line": 120,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 120
          }
        ],
        "severity": "bug",
        "title": "bug"
      }
    ],
    "problems": [],
    "state": "measured"
  },
  "harness": {
    "adapter": {
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "afi",
      "version": "1"
    },
    "commit": "3c151df56e62cfdea90b84dd8b265f7e0f4bebff",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": true,
    "id": "bench",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "incremental": {
    "carried_count": null,
    "mode": "not_recorded",
    "prior_reviewed_sha": null,
    "reused_tokens": null,
    "state_source": null
  },
  "label": "opus-5",
  "metrics": {
    "anchor_max": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_median": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_missed": {
      "reason": "no judging pass has looked beyond the scored slack",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "carried": {
      "reason": "the reviewer reported no reuse figure",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "category_defect": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.6153846153846154
    },
    "category_maintainability": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.0
    },
    "category_performance": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.3333333333333333
    },
    "category_security": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "f1": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "finding_count": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "found": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "intended": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "judge_bill": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "usd",
      "value": null
    },
    "missed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "precision": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "recall": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "review_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 0.795385
    },
    "seconds": {
      "reason": null,
      "state": "measured",
      "unit": "seconds",
      "value": 143.0
    },
    "tier_1": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 1.0
    },
    "tier_2": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.2857142857142857
    },
    "tier_3": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "tier_4": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "tokens": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 107659
    },
    "total_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 0.795385
    },
    "unkeyed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    }
  },
  "producer": {
    "commit": "3c151df56e62cfdea90b84dd8b265f7e0f4bebff",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": true,
    "id": "benchee",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "reviewer": {
    "id": "afi",
    "label": "afi review",
    "repository_url": "https://github.com/smykla-skalski/afi",
    "tool": {
      "interface": "cli",
      "name": "afi"
    }
  },
  "run_id": "afi/opus-5/20260831T152643Z",
  "runtime": {
    "architecture": "arm64",
    "cache_mode": null,
    "cpus": 14,
    "memory_bytes": 38654705664,
    "os": "Darwin",
    "provider_route": "openrouter",
    "region": null,
    "runner_image": null
  },
  "schema": "benchee-run-1",
  "stamp": "20260831T152643Z",
  "status": {
    "reason": null,
    "state": "completed"
  },
  "target": {
    "base_sha": null,
    "diff_digest": "sha256:c921265207938d025d4f2fb47329c377b767144efa630b4072a3836de9cea371",
    "pull_request": 8,
    "repository_url": "https://github.com/smykla-skalski/cairn",
    "reviewed_sha": "9b51f95ef609a219e211e37b082cd2e6913190e0"
  },
  "usage": {
    "reason": null,
    "state": "measured",
    "value": {
      "cached_input_tokens": 0,
      "input_tokens": 105232,
      "models": null,
      "output_tokens": 2427,
      "reasoning_tokens": 8342,
      "requests": 3,
      "stages": []
    }
  }
}
